AWS Public Sector Blog
Army R&D team uses agentic engineering to build secure, compliant code

Modern warfare demands software that moves at the speed of the mission. For U.S. defense research and development (R&D) organizations, this means building, testing, and fielding software faster than ever while meeting some of the most complex security and compliance requirements in the federal government. Traditional infrastructure approaches designed for waterfall development cycles can’t keep pace with the iterative, continuous nature of modern software delivery.
A security-compliant, defense-focused R&D secure coding solution was purpose-built for the U.S. Army to solve exactly this problem. The foundation is a more secure, cloud-based Amazon Web Services (AWS) landing zone that enables agile software development at scale without sacrificing compliance, security, or mission focus. In this post, we explain how developers reduced critical software delivery process times by up to 75% using AWS GovCloud (US) and AI-powered agentic engineering using this solution, how it empowers teams by accelerating authorization cycles across distributed teams, and how it meets Impact Level 5 (IL5) compliance requirements. Significant benefits of agentic engineering are shown in the graphic below: faster software delivery, shorter timelines from authorization to operate to MVP in production, and significantly.
Figure 1 Key outcomes include faster software delivery, faster start from authorization to Minimum Viable Product, and faster security compliance reviews using agentic software engineering.
Modernizing defense R&D without compromising security
Defense R&D organizations face challenges that commercial cloud solutions alone can’t address. Programs must meet IL5 compliance standards requiring rigorous controls across every layer of the stack. Developers, program managers, and defense industry partners don’t all work from the same network. They’re spread across different locations and classification environments.
Cyber, safety, and operational requirements have historically led teams into waterfall approaches to define system requirements in detail before building. This approach lacks the agility to respond to changing environments, missions, and technologies. That means they can’t realize the full benefits of Development-Security-Operations (DevSecOps) practices. Legacy infrastructure limits collaboration across cross-functional teams and partner companies, slowing time to capability.
Defense developers are taking a new approach to software acquisition that embraces agile principles and DevSecOps best practices. That requires a modern infrastructure foundation to support iterative, continuous software development.
Secure development solution to build compliant software
The team created a secure development solution built on AWS GovCloud (US) Landing Zone that enforces Zero Trust and enables scalable collaborative coding, as shown in the diagram below.

This DevSecOps solution with Zero Trust enables more secure, scalable software collaboration. At the center of everything is the Zero Trust Access Gateway. This is the single point of policy enforcement. Every user, every device, and every session is continuously verified. There’s no implicit trust based on network location.
The entire solution operates within a defined Authority To Operate (ATO) Boundary authorized for IL5 data and workloads. By having a solution-level ATO, individual programs don’t need to go through the full 12-month authorization process independently. They inherit the solution’s security posture. New partners and tenants can start developing and testing software immediately without lengthy onboarding delays.
On the left side, partner access means partner companies can connect. They come through the Zero Trust gateway, get verified, and then access only the specific project resources they’re authorized for.
Integrated testing connects the solution to external systems: hardware-in-the-loop sets, simulation environments, and test ranges. Code developed in this solution can be pushed directly to test infrastructure without manual transfer steps.
On the right, developer access is how government engineers connect. They use the same Zero Trust verification, same policy enforcement, and same experience, regardless of where they’re physically located. In this environment, collaboration is easier and software can be built faster to meet compliance.
Secure data exchange means users can move artifacts, source code, compiled binaries, test data, and media between environments and partners more securely. This is often the biggest bottleneck in collaborative projects, and this solution automates it. This links secure development with operations pipelines.
Built on Landing Zone architecture on AWS
Specific AWS GovCloud (US) infrastructure underpins the software coding landing zone, nesting layers of security to accelerate IL5 compliance and meet Zero Trust mandates.
AWS GovCloud (US)
This is a physically isolated set of AWS Regions designed specifically for sensitive government workloads. AWS GovCloud (US) Regions are logically and physically administered exclusively by AWS personnel that are U.S. citizens. AWS GovCloud (US) meets Federal Risk and Authorization Management Program (FedRAMP) High and DoD IL5 requirements while providing AWS Services available in commercial Regions with additional compliance controls that the U.S. government requires. These workloads run in AWS GovCloud (US) to meet classification and data sovereignty requirements.
Landing Zone Accelerator on AWS
This provides the foundational multi-account architecture that organizes the cloud environment. It serves as the blueprint for how accounts, networks, security controls, and governance policies are structured.
This open-source solution deploys the architecture automatically following AWS and DoW best practices while setting up organizational units, configuring centralized logging, enabling security services, and establishing network connectivity in a standardized, repeatable way. For software coding, the landing zone provides the scaffolding: separate accounts for each tenant, shared services accounts for common tools, a security account for centralized monitoring, and network accounts for connectivity.
IL5 compliance is achieved through built-in security controls and governance guardrails. Rather than configuring hundreds of security controls manually, the landing zone deploys them automatically. Service Control Policies prevent unauthorized actions, AWS Config rules continuously evaluate compliance, Amazon GuardDuty monitors for threats, and AWS CloudTrail logs every API call. If a tenant attempts a noncompliant action such as opening a port to the internet, guardrails prevent it automatically.
Zero Trust architecture integration
This integration replaces the traditional perimeter defense model where users inside the network are trusted. Zero Trust verifies every access request against the user’s identity, device posture, location, and behavior — every time, with no trusted network assumed. The Zero Trust capability provides cloud-based security to enforce these policies. Users connect to the solution where their identity is verified, device health is inspected, and access is granted only to the specific applications they’re authorized for.
Network-agnostic access
This is a direct result of Zero Trust. Developers no longer need a government-issued laptop on a government network with a hardware VPN token. They authenticate through the Zero Trust gateway, prove their identity and device policy compliance, and gain access. This is transformative for defense partners who previously required dedicated circuits to collaborate, which took time to provision and access.
AWS services powering the secure coding solution
Landing Zone Accelerator on AWS • AWS Organizations • AWS GovCloud (US) • AWS Config • AWS CloudTrail • AWS Transit Gateway • Amazon Elastic Kubernetes Service • AWS CloudFormation
Adding agentic workflows to accelerate mission impact and innovation
The secure coding solution’s landing zone is actively supporting DoW R&D programs today. Distributed teams collaborate securely and deliver software faster than legacy environments allowed. Programs that previously faced 12-month authorization and contracting cycles to spin up new cloud environments now deploy minimum viable products (MVPs) in as little as 3 months, which is a 75% reduction in time to capability. That speed matters. Partners can rapidly integrate frontline insights and deliver relevant software solutions to the field as mission requirements evolve.
The solution also provides a cloud-based digital engineering workspace that integrates cyber, safety, and airworthiness verification into the iterative agile process rather than treating them as end-of-cycle gates. For DoW programs, this is a critical distinction. Safety and airworthiness certification can’t be an afterthought. Building verification in from the start means teams avoid a compliance bottleneck right before fielding.
Most recently, the solution integrated multiple AI models on AWS GovCloud (US) to address two of the most time-intensive processes in defense software delivery. For Security Technical Implementation Guides (STIG) compliance automation, an AI agent autonomously processes code against all 286 STIG rules and produces a structured compliance report for human review. A process that previously took 3 weeks now completes in 2–3 hours, which isn’t an incremental improvement but a fundamentally different category of speed.
For agentic engineering workflows, a chat-based agent integrated with coding capabilities gives engineers the ability to query, synthesize, and report on program data using natural language. Tasks that previously required hours can now be completed in under 5 minutes. Future applications under exploration include ticket triage automation and AI-assisted code review.
Secure Development Solution demonstrated metrics that make a difference to accelerate secure coding for defense systems, as shown in the graphic below.

Figure 3 AI-assisted agentic engineering supports human decision making with data preparation for compliance automation and chat queries for DevSecOps
This AI-assisted collaboration delivers measurable mission impact with a 75% reduction in time to capability. That number isn’t theoretical. The team compressed what was traditionally a 12-month authorization and environment provisioning cycle into 3 months to deploy a MVP. Programs that previously spent their entire first year standing up coding environments now make and deploy code within their first 90 days.
A concrete example illustrates the impact: A specific R&D program involving distributed defense industrial partner teams needed to collaboratively build control software in a secure environment. Before the secure coding platform, getting those teams connected, authorized, and collaborating took the better part of a year. The Army team onboarded them into a shared workspace with appropriate access controls in weeks. Those teams now iterate on code together in real time with automated testing against hardware-in-the-loop systems.
The solution provides a cloud-based digital engineering workspace that goes beyond source code management to integrate modeling tools, simulation environments, and collaboration platforms—all within the IL5 boundary.
Critically, this agentic coding solution integrates cyber, safety, and other tests into the agile process with humans at the center. These aren’t afterthoughts or phase gates at the end: Automated checks run with every build. When a developer pushes code, the pipeline automatically evaluates it against cybersecurity requirements, safety constraints, and operational tests. Issues are caught and fixed in hours, not months. Government engineers can focus their time on human decision-making after the AI engineering workflows organize their data. Lessons learned can be continually added into the agentic engineering reviews, speeding the cycle while improving software quality and security compliance.
A replicable model for secure coding
The secure coding solution is more than a single program’s infrastructure. It’s a replicable model for how software-focused organizations can modernize software delivery while maintaining the security, compliance, and mission focus needed. The landing zone is designed to scale. Additional tenants and programs can onboard using the same standardized, repeatable architecture, reducing the time and cost of standing up compliant cloud infrastructure from months to weeks.
This more secure coding solution is architected to rapidly evolve while supporting the agentic engineering approach. New missions can expand to include modeling and simulation and technical documentation creation. New AI models can be integrated alongside emerging AWS GovCloud (US) capabilities such as Amazon Kiro for AI-assisted coding, Amazon Quick for analysis, research, and report generation, and Amazon Bedrock AgentCore to deploy, monitor, and evaluate agent-based workflows. Collaborative engineers will be able to develop in the unclassified solution and push code to classified production environments.
The principles that make this environment replicable are straightforward. The architecture is network-agnostic and secure-by-design, with zero trust enforcement that works across any network or classification environment. Every capability is tied to a real program outcome, not technology for its own sake. And the solution is proven through real-world R&D programs, with support for acquisition development programs and generative AI use cases that demonstrate measurable impact at scale.
AI-powered agentic engineering supports human decisions
This case study shows how AI-powered agentic engineering supports humans in making effective, timely decisions to deliver needed defense capabilities. Other R&D organizations interested in modernizing their software development capabilities can explore how the secure coding environment on AWS enables more secure, agile DevSecOps at scale. Whether you’re looking to accelerate delivery timelines, streamline compliance automation, or adopt cloud-based development practices, the AWS team is ready to support your cloud journey. To learn more, visit AWS GovCloud (US) or reach out to the team at AWS.