Government
Assessments and artifacts that survive procurement review.
Federal civilian and defense programs, and state and local agencies. Independent of the platforms under evaluation.
The federal challenge
Most federal IT spending sustains existing systems. Critical legacy risks remain.
Operating and maintaining 11 critical federal legacy systems
GAO identified 11 critical federal legacy systems that collectively cost approximately $754 million annually to operate and maintain. Seven operated with known cybersecurity vulnerabilities, four contained unsupported hardware or software, and eight relied on outdated programming languages.
U.S. GAO, GAO-25-107795
View sourcePlanned FY2025 Operations & Maintenance spending
Approximately 79% of planned IT spending across the 24 CFO Act agencies was allocated to Operations & Maintenance. The remaining 21% was allocated to Development, Modernization & Enhancement. O&M includes existing IT broadly and should not be interpreted as legacy-system spending alone.
U.S. GAO, GAO-25-107795
View sourceFederal IT Spending Distribution (FY2025)
24 CFO Act Agencies
Nearly four out of every five planned IT dollars across the 24 CFO Act agencies were allocated to operating and maintaining existing IT capabilities
Limited budget available for new capabilities and modernization initiatives
O&M includes existing IT broadly and is not synonymous with legacy-system spending.
What GAO Found in 11 Critical Legacy Systems
Seven of the critical legacy systems were operating with known cybersecurity vulnerabilities
Four contained hardware, software, or operating systems no longer supported by vendors
Eight relied on outdated programming languages, increasing sustainment and workforce challenges
Not everything old needs to be replaced.
A stable system that still meets mission, security, resilience, cost, supportability, and operational requirements may be the right system to keep.
Sometimes the answer is replacement. Sometimes it is hardening, segmentation, improved monitoring, a new integration pattern, replacing a dependency, or changing the operating model.
The decision should come from evidence — not from a vendor's preferred platform.
Modernization itself carries risk.
GAO warns that incomplete modernization planning increases the likelihood of cost overruns, schedule delays, and overall project failure.
The Freedom Project works in that upstream decision window — before architecture becomes a procurement commitment, before assumptions become contract requirements, and before technical decisions become implementation costs.
Architecture should inform the decision before it becomes a contract.
Understand before you procure
Baseline current state, dependencies, mission constraints, technical debt, lifecycle cost, cybersecurity risk, resilience, and target-state requirements.
Evaluate what is being proposed
Compare vendor and implementation proposals against the approved architecture, requirements, cost assumptions, migration strategy, staffing, security controls, schedule, and technical risk.
Validate what was delivered
Confirm implementation matches the approved architecture and requirements. Preserve evidence, decision provenance, governance records, residual risk, and sustainment considerations.
Implementation assurance
Where the scope fits our capabilities, The Freedom Project can execute defined implementation work directly.
For larger or specialized programs, we can help agencies evaluate prospective implementation teams and independently assess whether proposed architecture, staffing, schedule, cost assumptions, migration strategy, security controls, resilience, and vendor dependencies are credible. The objective is simple: help ensure the solution that gets implemented is the solution the organization actually intended to buy.
Why The Freedom Project
Independent advice grounded in operating experience.
Principal-led
11+ years of DoD systems engineering and technical leadership experience
Security & Authorization
Security compliance work spanning 20+ national-security systems, including authorization packages, NIST/FISMA alignment, FedRAMP-aware environments, and classified systems
Enterprise & Cloud
Former AWS Enterprise Account Engineer with experience across large-scale cloud architectures
Independent by Design
Recommendations follow the environment, mission, constraints, evidence, and lifecycle needs — not a reseller quota or required implementation contract
How we engage
Independent advisory across federal, defense, and state and local.
Federal civilian
Lifecycle cost analysis, current- and target-state architecture, FedRAMP-aware design, procurement requirements, and decision records that can survive capital planning, contracting, audit, and inspector-general review.
Defense & intelligence
Architecture and governance informed by secure, zero-trust, classified, and air-gapped environments, including authorization evidence, mission dependencies, implementation constraints, and AI GRC where models are introduced.
State & local
Architecture and cost justification for cities, counties, and state agencies operating constituent-facing systems, multi-vendor environments, constrained budgets, and public procurement processes.
Decision platform
AIM — the evidence behind the decision.
AIM brings current-state assessment, organizational constraints, architecture, lifecycle cost, procurement evidence, risk, and decision history into a structured modernization record.
Assess
Current state, dependencies, constraints, technical debt, security, and mission context.
Compare
Target-state options, lifecycle cost, architecture, risk, procurement considerations, and implementation alternatives.
Preserve
Evidence, approvals, governance decisions, AI-assisted work, decision provenance, implementation changes, and sustainment history.
AI governance eventually becomes an architecture problem. Agencies cannot meaningfully govern what AI may access, influence, automate, or authorize without understanding the systems, identities, data, APIs, dependencies, and authority underneath it.
Before modernization becomes procurement, understand what you're changing.
Establish the architecture, dependencies, lifecycle cost, security implications, operational risk, and implementation requirements before committing to a platform or contractor.
Unclassified inquiries only
Do not send CUI, classified, or otherwise protected information through the public site.
Request a briefing
For organizations exploring an assessment, modernization decision, architecture review, or advisory engagement.
Request a briefingOpen RFI intake
For unclassified RFIs, sources-sought notices, and procurement inquiries.
Open RFI intake