Leadership1 publisher3 min readPublished
FedRAMP's staffing conditions make federal SaaS revenue a hiring decision
Corelight's CISO writes that customers now grade suppliers on how their own security operations use AI, while FedRAMP gates federal SaaS sales on round-the-clock support and US-based employees. A June directive adds a 72-hour clock.
The Board Room · Leadership desk

What happened
- Corelight CISO Bernard Brantley writes that the sharpest customer question he fielded this year, first on a questionnaire and then on a call, asked how his own team uses AI to speed detection and response.
- CISA's Binding Operational Directive 26-04, issued in June 2026, gives federal agencies as little as 72 hours to remediate vulnerabilities that are actively exploited, internet-facing and automatable.
- The 2026 Benchmark Report from IANS, Artico Search and The CAP Group surveyed more than 650 CISOs and found that 95% now update their board.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- constraint A purchase order cannot close any of FedRAMP's conditions. Coverage hours and employment location are hiring decisions, and a vendor short of them is choosing between funding a rota and leaving the federal segment out of the plan.
- exposure On Brantley's account a supplier becomes reachable through its customer's clock even though the directive applies to agencies alone, and the vendor that answered yes on a questionnaire has already accepted the timeline.
- decision Funding AI inside security operations competes with every other line while roughly two in five security leaders cannot yet show a board a return, so the live choice is which single workflow gets it first.
- contradiction A board still funding security as regulatory defence is answering a question its buyers are not asking: Brantley names customer trust as the driver and says SEC enforcement has been uneven.
FedRAMP is where the requirement is hardest to route around. A federal agency cannot move to a SaaS provider without a FedRAMP-authorized offering, Brantley wrote, and the conditions he lists are about people: "FedRAMP requires 24/7 support, U.S.-based employees and a third-party assessor path." [4][5] Round-the-clock coverage is a rota and US-based employment is a hiring decision; third-party assessment runs on someone else's schedule. A vendor that has none of the three and wants federal revenue is looking at a headcount plan.
Directive 26-04 binds agencies, not their suppliers [6]. Brantley's claim is that the clock travels down the chain anyway: "A customer on a 72-hour clock needs its suppliers on that same timeline," he wrote [7]. He is forecasting what contracts will say, and he cites none. The calendar part is checkable. Seventy-two hours is three days, and of the seven days such a window could open on, four put a Saturday or a Sunday inside it [18]. "The customer doesn't only need to know your product is secure; they also need to ensure that your product enables them to meet their own requirements," Brantley wrote [8].
The AI answer costs money before it returns any. "Then a bill comes in that's four times higher than what headcount would have cost," Brantley wrote of moving too fast [12]; he does not show the underlying figures. He does cite KPMG's 2026 survey, in which 42% of security leaders said they struggle to show cybersecurity ROI to executives and boards [13]. His prescription is deliberately small: pick one workflow with a measurable line to revenue or margin, apply AI there, and find out whether the gain is two times or 20 times [14].
I read this as a network detection vendor's CISO describing his own sales funnel, and the column undercuts the regulatory version of events itself. "It's worth being honest about what isn't driving this: aggressive SEC enforcement," Brantley wrote [10]. He said enforcement under the SEC's cyber disclosure rule has been uneven and that, from what he has observed, markets have largely shrugged off disclosed incidents [9]. What he credits instead is customer trust, plus federal and regulated buyers running purchases through security teams instead of federal regulators [11].
The organizational claim is the thinnest part of the record. Brantley wrote that a 20% growth target used to mean hiring eight more account executives. The question now is whether a sales lead, a product owner and an engineer, all fluent in AI, can hit the same number without new people [15]. He reports no result from a team that has tried it. He also cites the 2026 Benchmark Report from IANS, Artico Search and The CAP Group, which surveyed more than 650 CISOs and found 95% now update their board [16]. The survey measures board access, a different thing from a vote on resourcing. On resourcing, Brantley wrote: "That's an organizational design question, and the CISO has a voice in the issue now because the tooling runs through the security stack." [21]
What to watch
- A vendor contract or SLA that writes the 72-hour window into supplier obligations would turn Brantley's forecast into a term.
- Published triage and detection-shipping numbers from an AI-run security operations centre would test his two-times-or-20-times threshold.
- Any change to FedRAMP's US-based staffing or third-party assessor conditions would reprice the federal segment for smaller vendors.