---
title: "The compliance tax: what it actually costs to ship software to the U.S. government"
url: https://daily.dev/posts/the-compliance-tax-what-it-actually-costs-to-ship-software-to-the-u-s-government-l6l9q0ucg
source_url: https://earthly.dev/blog/building-software-for-government/
type: article
source: "Earthly"
published: 2026-03-09T22:37:04.966Z
updated: 2026-03-09T22:37:29.216Z
tags: ["security", "devsecops", "sbom"]
reading_time: 11
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# The compliance tax: what it actually costs to ship software to the U.S. government

**[Earthly](https://daily.dev/sources/earthly)** · 11 min read · 0 upvotes · 0 comments

## Summary

Engineering teams shipping software to the U.S. federal government face a compounding compliance burden from overlapping frameworks like FedRAMP, CMMC, STIG, ITAR, and EO 14028. Common failure modes include late compliance discovery, hand-assembled audit evidence, single artifact anomalies causing multi-month delays, lack of central enforcement, policy layer drift, and mandatory self-hosted/air-gapped deployment that eliminates most commercial DevOps tooling. Organizations routinely spend 40+ hours/month on manual compliance verification. The post outlines what an effective solution requires — continuous evidence collection at build time, centralized enforcement, gradual rollout, air-gap capability, and composable evidence across products — and introduces Earthly Lunar as a guardrails engine designed to address these needs.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://earthly.dev/blog/building-software-for-government/>

## Similar posts on daily.dev

- [The SDLC compliance surface: what federal frameworks actually require from your build pipeline](https://daily.dev/posts/the-sdlc-compliance-surface-what-federal-frameworks-actually-require-from-your-build-pipeline-zsyah1vrp) · Earthly · 0 upvotes · 0 comments
- [Achieving Compliance as a Platform Engineering Team by Helping Developers](https://daily.dev/posts/achieving-compliance-as-a-platform-engineering-team-by-helping-developers-jd6ofkndz) · InfoQ · 0 upvotes · 0 comments
- [DevOps Practices in Government and the Public Sector](https://daily.dev/posts/devops-practices-in-government-and-the-public-sector-qdrbcu87d) · Spacelift · 0 upvotes · 0 comments
- [3 reasons compliance is driving open source adoption](https://daily.dev/posts/3-reasons-compliance-is-driving-open-source-adoption-g3foxyqdh) · All Things Open · 1 upvotes · 0 comments
- [The Hidden Cost of Non-Compliance in AI](https://daily.dev/posts/the-hidden-cost-of-non-compliance-in-ai-kxwegyfnd) · WunderGraph · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#devsecops](https://daily.dev/tags/devsecops), [#sbom](https://daily.dev/tags/sbom)

[View this post on daily.dev](https://daily.dev/posts/the-compliance-tax-what-it-actually-costs-to-ship-software-to-the-u-s-government-l6l9q0ucg)
