By Rohit Gupta August 11, 2026

Rohit Gupta is CEO of Aretum

As a hard-core technologist with a Computer Science background as well as a Government Contracting Services CEO, I am fortunate to keep in touch with many emerging technologies being used in both commercial and government organizations.

There are many areas of the Federal Government operational space that are using new technologies. If you exclude AI-based modernization advancements and fairly common ones like cloud computing, microservices, zero trust architecture and no/low-code platforms, I believe there are still a number of technology categories that are quietly changing how software delivery organizations, security teams, and mission-focused organizations operate. Public sector missions cover many areas including civilian government, defense, intelligence, public safety, and even critical infrastructure related to energy, water, and transportation, so the applicability of new technologies is fairly broad.

Many areas outside of AI are driving significant investment because they improve the government agencies’ resilience, speed, compliance, and operational effectiveness, and save taxpayer money without sacrificing mission goals. Modernization is really the common thread across many of these technologies. Government agencies rarely modernize just to adopt a new tool—they modernize to improve agility, security, resilience, and maintainability. Some technologies I will talk about in this article are foundational to modernization, while others are enabling capabilities. Across government, modernization efforts increasingly emphasize outcomes rather than technology adoption for its own sake. Common outcome improvements that Federal Government CIOs and CTOs look for include faster delivery of software and digital services, reduced technical debt, improved cybersecurity and compliance and greater operational resilience.

Some of the areas that both Aretum and I have seen improvements through the use of modern technologies include:

Platform Engineering – this is where internal developer platforms have replaced ad hoc DevOps and DevSecOps work. Modernization in Platform Engineering increasingly means moving the organization’s approach from project-specific infrastructure to standardized internal platforms that provide self-service capabilities, security guardrails that have been pre-configured, and reusable services. Instead of every development team assembling its own CI/CD pipelines, Docker container build approaches, Kubernetes clusters, security tooling and deployment processes, organizations now build internal developer platforms that provide standardized, self-service capabilities.

Software Supply Chain Security – with threats from international state actors and non-state actors, government organizations and their contractors are ensuring that we can tie every component of software being deployed to the government’s environments to its source. This includes not just government production environments but also development and multiple pre-production environments. Modern software supply chain security now includes advancements in Secure Bill of Materials, signing of artifacts, tagging and subsequent checking of components for provenance, as well as dependency risk management and secure build pipelines. These approaches ensure supply chain security is vetted at every step of the build-and-deploy process in a tamper-proof manner.

Cloud Native Operations – this is an area that has seen significant improvements in the last few years and is still being actively improved. Orchestration frameworks like Kubernetes have matured significantly, GitOps has become the default standard for building and deploying applications and services, and service meshes are widely being adopted. Instead of just infrastructure-as-code (iAc) using tools like Terraform, organizations are also implementing policy-as-code for infrastructure compliance, Kubernetes admission policies, deployment guardrails and regulatory controls.

Digital Twins – This technology is primarily in use in design and engineering organizations in the government because this technology is replacing document-based processes with continuously updated digital models. Some critical examples include defense aircraft lifecycle management, shipbuilding for the Navy, space systems at NASA and the Space Force, and Infrastructure planning at the Dept. of Energy. The increasing use of digital twins supports simulation, predictive maintenance, continuous verification and rehearsal of missions without any compromise on understanding outcomes once a system goes live in production.

Observability advancements – Modern systems have moved from basic monitoring to true observability across the board. Modern observability still utilizes logs and dashboards like prior generations tools, but also includes metrics, traces, events, and user experience that is directly tied to business outcomes for the systems it is observing. The goal is to perform faster root-cause analyses and reliable operations reducing mean time to recovery.

Post quantum cryptography –We all know that quantum is drastically changing the Government’s vulnerabilities to bad actors who intend to break into our systems using the advances in quantum. We also have the “harvest now, decrypt later” threat, where adversaries collect and store encrypted data today to decrypt it later once functioning quantum computers exist. Post quantum cryptography ensures that the level to which quantum computing has literally changed how encryption, cryptography, key generation and management, and cybersecurity have changed, is addressed in all future deployments of systems.

Government agencies with sensitive information that must remain secure are beginning to adopt cryptographic algorithms designed to withstand future quantum attacks in defense, intelligence, and critical infrastructure. Migrating to PQC techniques for existing systems is fairly widespread. The President’s fairly recent Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks” on June 22, 2026 mandates that civilian federal agencies transition their most sensitive IT systems to post-quantum cryptography (PQC) by December 31, 2030, and digital signatures by December 31, 2031.