Skip to main content

Black Duck initiates FedRAMP authorization for Polaris platform

Companies mentioned

Black Duck initiated the Federal Risk and Authorization Management Program (FedRAMP) Moderate authorization process for its Black Duck Polaris Platform and entered into an agreement with stackArmor to support the effort, a step the company said was meant to expand its U.S. federal cloud services and enable adoption by federal agencies.

Black Duck framed the activity as part of expanding its U.S. federal cloud services and delivering secure, compliant cloud solutions to federal agencies, noting the move aligned with efforts to make Polaris available through the FedRAMP Marketplace.

FedRAMP Moderate was described in the release as a standardized framework for security assessment, authorization, and continuous monitoring to streamline adoption of trusted cloud solutions across government agencies. The companies identified stackArmor as a FedRAMP engineering and advisory firm with pre-built security frameworks and automation intended to support authorization work.

Black Duck and stackArmor said they had agreed to fast-track the Polaris authorization by applying stackArmor's expertise and security frameworks; the release also stated that stackArmor had guided over 60 cloud service providers through compliance work that resulted in Authorization to Operate certification.

“We're not just pursuing FedRAMP approval—we're redefining how federal agencies secure their applications in the cloud,” said Jason Schmitt, CEO of Black Duck. “Polaris will give government customers the flexibility and confidence they demand, aligning with the federal mandate to modernize IT and eliminate the burden of on-premises systems. This is about delivering security at speed, scale, and certainty.”

Black Duck targeted FedRAMP “In Process” status by June 2026 and a listing in the FedRAMP Marketplace.

Press release, provided by Cision on behalf of Synopsys. Read the original.

Graph Connections

1st source this quarter, one of 12 sources referencing Synopsys. Previous coverage: Black Duck releases report on AI code security gap (December).

  • Rapid7 Acquires Kenzo Security for Command Platform Expansion

    Decision Insights Signals · March 26, 2026

    Rapid7 acquired Kenzo Security to expand its Command Platform for MDR and agentic SecOps, including entity-centric data mesh multi-agent investigations.

  • Rapid7 Reports Inducement Grants under Nasdaq Listing Rule 5635(c)(4)

    Decision Insights Signals · March 26, 2026

    Rapid7 announced inducement equity awards to employees and contractors of Kenzo Security as a material inducement tied to Rapid7’s March 26, 2026 acquisition. The awards include 467,945 RSUs for Kenzo staff and 525,769 PSUs for founders Harish Singh and Partha Naidu (max). Vesting and performance periods are described under Nasdaq Rule 5635(c)(4).

  • Netskope Explains Three Mobile Governance Models for Data Protection

    Decision Insights Coverage · March 26, 2026

    It compares three mobile governance models—corporate device MDM, personal devices enrolled in MDM, and managed apps on unmanaged devices—and discusses enforcement trade-offs.