Skip to content
technologyingovernment.com
Menu
  • Home
  • Expert Insights
  • News
  • Advertise
  • About TIG
  • Contact
Menu

NARA Expands Cyber Risk Management With Telos Xacta Cloud Platform

Posted on September 9, 2026

The National Archives and Records Administration is expanding its use of Telos cybersecurity software, adding cloud-based automation and artificial intelligence capabilities to the agency’s governance, risk and compliance program.

Under the contract, NARA will deploy Xacta 360 and Xacta.ai as software-as-a-service offerings. Telos said the work builds on its existing support for the agency, although the company did not disclose the contract’s value, period of performance or implementation schedule.

The deployment gives NARA a centralized platform for managing security authorization workflows, assessing controls, maintaining compliance documentation and monitoring risk. Those tasks are central to the federal authorization process, but they often require security teams to gather evidence from multiple systems and repeatedly update large collections of documents.

Xacta 360 is designed to organize that work around a common risk-management environment. Xacta.ai adds automated analysis intended to identify relevant information, assist with documentation and surface risk or compliance insights. Telos says the AI component can reduce manual effort, but the announcement does not provide performance data showing how much time the agency expects to save.

A high-impact cloud environment

The full Xacta platform has a Federal Risk and Authorization Management Program High authorization. That designation applies the government’s most stringent FedRAMP security baseline and permits a cloud service to process sensitive unclassified information with potentially severe consequences if confidentiality, integrity or availability is compromised.

FedRAMP authorization gives agencies a standardized body of security evidence to review, but it does not make a service automatically appropriate for every workload. NARA will remain responsible for assessing how the platform is configured, connected to agency systems and operated within its own risk environment.

That distinction is especially important for an agency responsible for preserving permanent federal records and providing records-management guidance across the government. Cybersecurity failures could affect not only internal operations but also the availability, integrity and long-term trustworthiness of federal information.

For NARA, a cloud-based GRC platform could make it easier to maintain a current view of controls and risks across systems. Centralized workflows may also improve consistency when staff prepare authorization packages or respond to changing requirements. The value will depend on the quality of the underlying evidence and the degree to which the platform connects with the agency’s security tools and operational data.

AI assistance still requires oversight

Applying AI to compliance work is an increasingly common vendor strategy because federal security programs generate large volumes of structured and unstructured information. The technology can help summarize evidence, identify gaps and draft routine material, but it can also produce incomplete or incorrect conclusions if source data are outdated or prompts and models are not adequately governed.

NARA will therefore need controls for human review, traceability and accountability when AI-generated output contributes to a risk decision. Security officials must be able to determine what evidence supported an assessment and who approved the result. Data handling, model behavior and access permissions will also require continued monitoring.

The contract represents an actual agency deployment rather than a general product-availability announcement. Still, the public information establishes the tools NARA plans to use, not the outcomes it has achieved. Measures such as reduced authorization time, fewer documentation errors, improved control visibility and faster remediation would provide a clearer picture of the project’s value after implementation.

The bottom line is that NARA is consolidating more of its cyber risk and compliance work in a FedRAMP High cloud service and adding AI-assisted analysis to the process. The move could reduce administrative burden, but its success will depend on integration, reliable source data and disciplined human oversight.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Lockheed Martin Rolls Out Germany’s First F-35A, Starting a Path to More Interoperable NATO Operations
  • Week in Review: Events Shaping Government Priorities and Spending
  • Innoviz LiDAR Receives Israeli Defense Recognition for Counter-Drone and Perimeter Security Uses
  • Cemtrex’s Vicon Receives Federal Surveillance Orders and Adds Faster Video Review Tools
  • Leonardo DRS Wins KDDX Electric-Propulsion Work to Support Advanced Naval Systems
  • Home
  • Expert Insights
  • News
  • Advertise
  • About TIG
  • Contact
©2026 technologyingovernment.com | Design: Newspaperly WordPress Theme