, ,

Digging Out of the Messy Middle, One Modernization Step at a Time

As an acquisitions officer, I worked on two failing major IT modernization programs. Not one. Two. And I count myself lucky for it, because those programs taught me what the mission needed far better than any program that stayed on schedule ever could. I watched teams pour years into systems that shipped late, missed the need and never reached a single user.

You don’t have to wear a military uniform to know that feeling. Across government services, the same pattern repeats. A team knows its technology has to change, but the mission still rides on systems built decades ago. Legacy applications don’t integrate cleanly with modern ones, and the fear of breaking something critical turns caution into paralysis. Call it the messy middle. Most government IT teams live there right now.

Standing still may feel safe, but delay is the expensive option. Wait long enough and software that was merely behind starts actively holding the mission back. Every year in the messy middle raises the cost of leaving it.

I’ve made the case before that the real barrier is mindset, not machinery. Naming that is easy. Knowing what to do next is harder, and the answer isn’t a giant leap toward modernization, but a series of deliberate, incremental steps.

Start Small and Scale

Getting out of the messy middle is a method, not a moment. Gall’s Law holds that complex systems that work evolve from simpler systems that worked; try to build the whole thing at once and you get something that doesn’t work at all. So you start with the smallest version that works and scale in three moves: get an honest baseline of what the old system does, replace it in slices, and deliver continuously.

Start with the baseline. Keep the legacy system running and watch how it behaves in production, because that behavior is the most honest record of what it actually does. Build behavioral or digital twins that reproduce those outputs and confirm the modern version matches before you change anything that matters. Matching first keeps the transition smooth and the risk of disruption low.

Then replace it in slices. Change one piece at a time, validate each against real users and real workloads, and let production, not a roadmap, show you what works. Every slice that proves itself becomes the footing for the next.

Deliver continuously. Instead of one massive release years out, you ship small, measurable improvements, and each deployment buys down the uncertainty around the next. In government, that flow requires a path to production and every system needs an Authorization to Operate (ATO) before it can go live. Traditionally, that sign-off is a one-time gate at the end, slow to earn and good for three years, so a team can build continuously and still stall. A continuous ATO (cATO) runs security and compliance in parallel, so authorization keeps pace with delivery. Treat security as backlog work, sized next to features, rather than saved for the end. Without it, continuous delivery is a bullet on a slide deck, not a capability you have.

Strung together, those three moves trade one big bet for a series of small, recoverable ones, the only way to modernize a system you can’t afford to break.

Getting Unstuck Just Got More Urgent

The method rests on one capability: the ability to deliver continuously and securely. That used to be the blocker. Now it’s becoming the baseline. The Department of War’s 2025 State of DevSecOps report documented 78 acquisition programs on the Software Acquisition Pathway, the faster route built for modern software, and a March 2025 directive made it the preferred pathway. The report treats continuous authorization, not one-time sign-off, as the direction for managing risk. Civilian agencies are following, from federal health organizations adopting cATO to the push to modernize FedRAMP.

Even as that capability spreads, AI is widening the gap between teams that can ship and teams that can’t. The throughline at Prodacity, where government technology leaders learn to ship software in the age of AI, is that AI raises the bar on delivery rather than replacing it: It speeds up a team that can already ship and does nothing for one that can’t. Getting out of the messy middle is more urgent now, not less.

The exit from that middle never arrived as a finished plan. It came the first time a real user put hands on something we shipped and showed us we were wrong. Their reaction moved us further than any roadmap could.

The way out of the messy middle rewards action and learning over certainty. Deliver one real thing, learn from how people use it, build on what works, and you dig out, one deliberate step at a time.


As Rise8’s Director of Growth, Carlo is focused on creating and cultivating a great customer and employee experience to support the scaling of Rise8. As a conduit to government and commercial prospects, Carlo educates on the culture and expertise of Rise8, and ways to partner to deliver outcomes that matter. Before becoming a Riser, Carlo served six years as an acquisition officer managing software programs within the Air Force and Space Force. Carlo was one of the first project managers turned product manager at Kessel Run, responsible for delivering the first major product adopted by AOCs across the globe. The Air Force sent Carlo to the Space Force to help stand up the Space Force’s first software factory, Kobayashi Maru, and Section 31, where he served as the Director of Product. Despite helping lead digital transformation efforts for two major organizations, there was only so much he could do as a Captain. Wanting to continue to pursue his passion and to have an even larger impact outside of the military, he separated and decided to rejoin forces with Bryon at Rise8 to continue enabling innovation through people, culture, and software.

Photo by Red Shuheart on Unsplash

Leave a Comment

Leave a comment

Leave a Reply