Home / Companies / Earthly / Blog / March 2026

March 2026 Summaries

2 posts from Earthly

Filter
Month: Year:
Post Summaries Back to Blog
Engineering organizations, especially those in defense contracting, face significant compliance challenges due to complex federal frameworks like FedRAMP, CMMC, and EO 14028, which require continuous verification rather than periodic audits. These frameworks demand extensive manual labor, with companies spending substantial time on compliance checks that can lead to severe project delays if missed. The lack of central enforcement and reliance on manual evidence assembly exacerbate these issues, as compliance steps are often skipped and audits become high-risk events. Automated solutions like Earthly Lunar aim to address these problems by collecting compliance data continuously during the software development lifecycle, thereby reducing the manual burden and enabling platform teams to focus on enhancing system reliability and delivery speed. Such tools are designed to operate in self-hosted, air-gapped environments, making them suitable for high-security contexts, and aim to provide reusable, composable compliance evidence across multiple projects and classification levels.
Mar 09, 2026 2,178 words in the original blog post.
The text provides an in-depth examination of federal compliance frameworks relevant to the Software Development Life Cycle (SDLC), detailing how these frameworks, such as EO 14028, NIST SSDF, DISA STIGs, CMMC, FedRAMP, FISMA, and ITAR, impose specific requirements on the development, testing, scanning, packaging, and deployment of software. These frameworks, while differing in scope and specificity, overlap significantly in their demands for SBOM generation, security scanning, container hardening, build provenance, secret management, version control, and continuous evidence collection. The article emphasizes the importance of automating these compliance processes for platform teams in defense technology companies and federal software vendors, noting that frameworks like EO 14028 and the NIST SSDF are particularly aimed at software producers selling to the federal government. It highlights that these requirements can be addressed through tools like Earthly Lunar, which provides automated guardrails for compliance, ensuring that standards are met as part of the development process, thus reducing the operational burden of manual compliance.
Mar 09, 2026 3,497 words in the original blog post.