Skip to main content

Government

Assessments and artifacts that survive procurement review.

Federal civilian and defense programs, and state and local agencies. Independent of the platforms under evaluation.

The federal challenge

Most federal IT spending sustains existing systems. Critical legacy risks remain.

$754M/year

Operating and maintaining 11 critical federal legacy systems

GAO identified 11 critical federal legacy systems that collectively cost approximately $754 million annually to operate and maintain. Seven operated with known cybersecurity vulnerabilities, four contained unsupported hardware or software, and eight relied on outdated programming languages.

U.S. GAO, GAO-25-107795

View source
~$83B

Planned FY2025 Operations & Maintenance spending

Approximately 79% of planned IT spending across the 24 CFO Act agencies was allocated to Operations & Maintenance. The remaining 21% was allocated to Development, Modernization & Enhancement. O&M includes existing IT broadly and should not be interpreted as legacy-system spending alone.

U.S. GAO, GAO-25-107795

View source

Federal IT Spending Distribution (FY2025)

24 CFO Act Agencies

Operations & Maintenance79.0%

Nearly four out of every five planned IT dollars across the 24 CFO Act agencies were allocated to operating and maintaining existing IT capabilities

Development, Modernization & Enhancement21.0%

Limited budget available for new capabilities and modernization initiatives

O&M includes existing IT broadly and is not synonymous with legacy-system spending.

What GAO Found in 11 Critical Legacy Systems

Known Cybersecurity Vulnerabilities7 of 11

Seven of the critical legacy systems were operating with known cybersecurity vulnerabilities

Unsupported Hardware/Software4 of 11

Four contained hardware, software, or operating systems no longer supported by vendors

Outdated Languages8 of 11

Eight relied on outdated programming languages, increasing sustainment and workforce challenges

Not everything old needs to be replaced.

A stable system that still meets mission, security, resilience, cost, supportability, and operational requirements may be the right system to keep.

Sometimes the answer is replacement. Sometimes it is hardening, segmentation, improved monitoring, a new integration pattern, replacing a dependency, or changing the operating model.

The decision should come from evidence — not from a vendor's preferred platform.

Modernization itself carries risk.

GAO warns that incomplete modernization planning increases the likelihood of cost overruns, schedule delays, and overall project failure.

The Freedom Project works in that upstream decision window — before architecture becomes a procurement commitment, before assumptions become contract requirements, and before technical decisions become implementation costs.

Architecture should inform the decision before it becomes a contract.

BEFORE

Understand before you procure

Baseline current state, dependencies, mission constraints, technical debt, lifecycle cost, cybersecurity risk, resilience, and target-state requirements.

DURING

Evaluate what is being proposed

Compare vendor and implementation proposals against the approved architecture, requirements, cost assumptions, migration strategy, staffing, security controls, schedule, and technical risk.

AFTER

Validate what was delivered

Confirm implementation matches the approved architecture and requirements. Preserve evidence, decision provenance, governance records, residual risk, and sustainment considerations.

Implementation assurance

Where the scope fits our capabilities, The Freedom Project can execute defined implementation work directly.

For larger or specialized programs, we can help agencies evaluate prospective implementation teams and independently assess whether proposed architecture, staffing, schedule, cost assumptions, migration strategy, security controls, resilience, and vendor dependencies are credible. The objective is simple: help ensure the solution that gets implemented is the solution the organization actually intended to buy.

Why The Freedom Project

Independent advice grounded in operating experience.

Principal-led

11+ years of DoD systems engineering and technical leadership experience

Security & Authorization

Security compliance work spanning 20+ national-security systems, including authorization packages, NIST/FISMA alignment, FedRAMP-aware environments, and classified systems

Enterprise & Cloud

Former AWS Enterprise Account Engineer with experience across large-scale cloud architectures

Independent by Design

Recommendations follow the environment, mission, constraints, evidence, and lifecycle needs — not a reseller quota or required implementation contract

How we engage

Independent advisory across federal, defense, and state and local.

Federal civilian

Lifecycle cost analysis, current- and target-state architecture, FedRAMP-aware design, procurement requirements, and decision records that can survive capital planning, contracting, audit, and inspector-general review.

Defense & intelligence

Architecture and governance informed by secure, zero-trust, classified, and air-gapped environments, including authorization evidence, mission dependencies, implementation constraints, and AI GRC where models are introduced.

State & local

Architecture and cost justification for cities, counties, and state agencies operating constituent-facing systems, multi-vendor environments, constrained budgets, and public procurement processes.

Decision platform

AIM — the evidence behind the decision.

AIM brings current-state assessment, organizational constraints, architecture, lifecycle cost, procurement evidence, risk, and decision history into a structured modernization record.

Assess

Current state, dependencies, constraints, technical debt, security, and mission context.

Compare

Target-state options, lifecycle cost, architecture, risk, procurement considerations, and implementation alternatives.

Preserve

Evidence, approvals, governance decisions, AI-assisted work, decision provenance, implementation changes, and sustainment history.

AI governance eventually becomes an architecture problem. Agencies cannot meaningfully govern what AI may access, influence, automate, or authorize without understanding the systems, identities, data, APIs, dependencies, and authority underneath it.

Before modernization becomes procurement, understand what you're changing.

Establish the architecture, dependencies, lifecycle cost, security implications, operational risk, and implementation requirements before committing to a platform or contractor.

Unclassified inquiries only

Do not send CUI, classified, or otherwise protected information through the public site.

Request a briefing

For organizations exploring an assessment, modernization decision, architecture review, or advisory engagement.

Request a briefing

Open RFI intake

For unclassified RFIs, sources-sought notices, and procurement inquiries.

Open RFI intake