How to Build a Defense Tech Startup: Lessons From the Tactical Edge
Defense tech raised $125 billion from 2020 to 2024. Reveal Technology won military contracts by inverting the playbook: building for the corporal on the ground, not the program manager at a desk. Here is the company-building version of that story, from bottom-up product design to the ATO ladder to why compliance ends up being the moat.
Between 2016 and 2020, investors put roughly $40 billion into defense and dual-use technology. From 2020 to 2024, by Garrett Smith’s count, that tripled to $125 billion. The national security market wants new technology, and the legacy contractors haven’t been delivering it fast enough.
Garrett is co-founder and CEO of Reveal Technology and a Marine Corps Reserve Lieutenant Colonel, and he built the company out of a problem he had personally carried in Afghanistan. On episode 90 he walked us through how two Marines got a software company into the hands of special operators, through the compliance regime, and onto a program of record. This post is the company-building half of that conversation: product, go-to-market, compliance, capital and culture. The other half, the counter-drone problem Garrett calls the single biggest technology shortfall in national defense, has its own post: Counter-Drone Technology.
What is a defense tech startup, and why is the market open now?
A defense tech startup builds technology whose first or most important customer is a military or a national-security agency. Some are pure defense; many are dual-use, selling the same sensor, model or mapping engine to commercial customers as well. What makes them a different kind of company is the buyer, which purchases through programs, authorizes software before it may run on its networks, and pays out of multi-year budgets.
The money is following the mission. The $125 billion figure is Garrett’s, from the episode; the shape of the curve is public. PitchBook data published by J.P. Morgan puts venture investment into US defense tech startups at a peak of about $55 billion in 2021 and roughly $38 billion in the first half of 2025 alone, on pace for a new record. Whichever series you prefer, the direction is the same: capital that once avoided anything with a Pentagon logo now competes for it.
Garrett’s explanation for why the door is open starts with the incumbents.
“Legacy companies fail when they get too comfortable.”
Garrett Smith, co-founder and CEO of Reveal Technology, on episode 90
Comfort is expensive in a market whose adversaries iterate weekly. The primes still build the ships and the fighters; the opening for startups is everything that has to change faster than a decade-long acquisition program can: software at the edge, autonomy, sensing, identity, counter-drone systems. Much of it is hardware plus software plus a hard technical problem, which is why so much of defense tech is also deep tech, with deep tech’s timelines and deep tech’s moats.
How do you design a product for the tactical edge? Be your own customer
Most legacy vendors sell top-down: engage senior program managers, generate requirements, secure funding, push a product down to the end user. By the time the operator touches it, nobody has asked whether it solves their actual problem.
Reveal did the opposite. Garrett and co-founder Andrew Dixon are both Marine officers who served in Afghanistan, and they lived the problem they later solved: outdated maps, low-resolution imagery, no way to generate intelligence at the point of the problem. Their flagship product, Farsight, lets an operator ingest drone video on a mobile device and produce high-resolution 2D and 3D maps in the field. Reveal’s own description is “a sophisticated GEOINT capability in the palm of your hand”, with the analytics resident on the device so it works with no network at all. “We were our customers,” Garrett said. “That allowed us unique insight into the product development phase.”
“To build it right, you have to be your own customer.”
Garrett Smith, Reveal Technology, episode 90
Not every founder gets to be a Marine. The transferable version is to get as close to the user as the rules allow: hire the operator onto the team, spend the exercise week in the dirt with the prototype, and treat every complaint from a sergeant as a requirement no program office would have written down. The edge matters for a reason Garrett’s team understood from the inside: command and control usually happens miles from the problem, and intelligence that arrives after the decision isn’t intelligence. Companies that build with that kind of empathy consistently outperform companies that build to a requirements document. It’s the same lesson Andrew Rubin learned building Illumio, in a market where the buyer at least resembles the user.
How do you sell to the military? The bottom-up go-to-market
In defense, the buyer and the user are rarely the same person. The economic buyer sits at a headquarters desk; the user is a corporal on the ground. Garrett’s team ran both ends at once:
- Start with end users. Prototypes into the hands of corporals, sergeants and lieutenants during exercises, producing fast feedback and real product-market fit.
- Build groundswell demand. Once operators wanted the product, they became advocates and the demand signal flowed upward.
- Engage the top in parallel. Members of Congress, program managers and senior DoD decision-makers, to line up funding and procurement.
- Let demand pull the sale. “The economic buyer is always going to come along when there’s an intensive groundswell of support and demand signal.”
It’s the Silicon Valley playbook adapted for defense: build something people love, then let adoption drive the business case. The adaptation is step three. In a commercial sale, bottom-up adoption can carry a deal all the way to a signature. In defense, somebody still has to put the money in a budget line, so the top-down conversation runs alongside the bottom-up one from the start, and the demand signal from the field is what keeps those meetings short.
The groundswell has a product-security angle. Operators talk across units, so the product that spreads is the one that works on a phone in the field, offline, and keeps its data on the device. Product security built in early (device-resident data, hardened authentication, audit trails) makes a prototype adoptable, and every piece of it is evidence you will reuse on the ladder that comes next.
What are IATT, ATO, TRL and a program of record? The defense compliance ladder
A great product isn’t enough. Every defense startup climbs the same ladder, and the rungs have acronyms.
Interim Authorization to Test (IATT). Time-limited permission to run your system in an operational environment, on a real network, for testing. It’s the rung that lets an exercise turn into a pilot.
Authorization to Operate (ATO). The formal decision by an authorizing official to accept the risk of running your system. The DoD’s Risk Management Framework instruction, DoDI 8510.01, lists the possible outcomes as an interim authorization to test, an ATO, an ATO with conditions, or a denial. Commercial founders can think of it as the moment a SOC 2 report gets read, except the reader can say no and owns the network.
Technology Readiness Levels (TRL). A nine-point maturity scale that NASA describes as “a type of measurement system used to assess the maturity level of a particular technology”. TRL 6 is a fully functional prototype, TRL 7 is that prototype demonstrated in its operational environment, TRL 9 is technology proven in a real mission. Program offices use it as shorthand for how much risk you are asking them to carry, and Integration Readiness Levels do the same job for how well your pieces fit with theirs.
Program of record. The prize. The Defense Acquisition University glossary (the school now goes by Warfighting Acquisition University) defines it as a program “as recorded in the current Future Years Defense Program”, normally after formal program initiation at Milestone B, and adds, deadpan, that the term “is no longer used throughout the acquisition community and has been eliminated from most of the DoD publications.” Everyone still says it, for the same reason everyone says “SOC 2 certified”: the meaning is clear. A program of record is a funded, multi-year commitment instead of a pilot renewed one exercise at a time.
Reveal’s climb is the illustrative case. Six and a half years in, the company won a US Special Operations Command program of record for a biometrics product, beating legacy contractors; Reveal’s site now lists Identifi as a USSOCOM program of record, announced in May 2026. That took years of exercises, an acquisition (more on that below), and a compliance history the incumbents assumed a startup couldn’t build.
Why is compliance both the barrier to entry and the moat?
Handled poorly, the regime above can add years. Handled well, it becomes the reason the next startup can’t follow you.
Start with the surprise: reciprocity between agencies is mostly a myth. On paper it exists. DoDI 8510.01 says the department “will use cybersecurity reciprocity to reduce redundant testing, assessing, documenting, and the associated costs in time and resources.” In practice, Garrett found that fully satisfying Customer X does not make you adoptable by Customer Y. Each agency has its own authorizing official, its own network and its own onboarding friction, and a federal growth plan that assumes one ATO travels is a plan that stalls. What does travel is your evidence: the system security plan, the control implementations, the scan history, and the people who have answered an assessor before.
His second point is the counterintuitive one. Garrett recommends partnering with the end adopter early and being transparent about what you don’t know: “That actually engenders a huge amount of trust.” The hurdle is where the relationship gets built.
“No one shows up fully compliant. You build trust by getting there together.”
Garrett Smith, Reveal Technology, episode 90
For founders used to commercial frameworks like SOC 2, the defense stack is a different scale, but the same principle holds: treat compliance as a competitive advantage rather than a checkbox. The pieces you will meet, and where they stand as of September 2026:
- CMMC, if you handle Federal Contract Information or Controlled Unclassified Information under a DoD contract. Level 2 maps to the 110 security requirements in NIST SP 800-171. The Pentagon’s CMMC page (now written in the name of the Department of War) says the first phase began on November 10, 2025, that implementation “is paused in Phase 1,” and that the Phase II third-party assessment requirements scheduled for November 2026 were suspended on July 13, 2026 while a reform task force does its work. The 110 controls haven’t gone anywhere: the DFARS clause in your contract requires them, and the self-assessment and annual affirmation still stand.
- ITAR, if your product or its technical data is a defense article. Export-controlled data changes who may touch your repositories and your cloud, and it changes your hiring.
- FedRAMP, if you sell cloud services to civilian agencies. FedRAMP describes itself as “a government-wide program that provides a standardized approach to security assessment”, and its 20x effort is rebuilding authorization around “the security decisions that matter most.”
One more thing changes when the customer is a government: the shelf life of the data. Your customer’s classification schedule decides how long your data has to stay secret, not your retention policy, which makes harvest now, decrypt later a present-tense design constraint for a defense startup rather than a future worry. And if your technology matters to a foreign government, assume you are already a target; a security program built for state-grade adversaries belongs in the plan before the first IATT, because the authorizing official will ask about it anyway.
Who does all of this? At a startup, usually an engineer you would rather keep on the roadmap. That’s the in-house, on-demand, or do-nothing decision we wrote about in In-House, On-Demand, or YOLO?, and in defense the do-nothing option isn’t on the menu.
How should a defense tech startup raise money? Why VC doesn’t fit at first
VCs want fast early growth; defense sales cycles are long. Reveal bootstrapped for the first several years, deliberately avoiding high burn: “We didn’t get too far out over our skis.” Later they raised a Series A led by Next Frontier Capital and a Series B led by Ballistic Ventures, once the demand signal from the field was something an investor could see.
The government itself is a funding source. Reveal’s site notes it executed Option Year 1 of a $33.6 million STRATFI contract in August 2025, the kind of award designed to carry a promising prototype across the years between demo and program. Patient capital and a small, focused team can outperform a well-funded but overextended competitor, because the thing that kills a defense startup is rarely a rival’s feature. It’s a burn rate that needs a contract to close on a schedule the government doesn’t keep.
The acquisition playbook: how defense startups become consolidators
As defense startups mature, they become consolidators, the pattern the legacy primes have followed for decades, now happening earlier in a company’s life. Reveal acquired a biometrics company, battle-hardened its prototype, and won a multi-year SOCOM program. In January 2026 it added Anomaly Six, whose capabilities the company says “directly complement” Farsight and Identifi. Garrett sees it as a repeatable model: identify emerging requirements through end-user relationships, acquire the right technology, refine it, and deliver through the channels you have already cleared.
It works because the authorization history and the operator relationships are the scarce assets. A great sensor company with no authorizations is worth more inside a company that has them, which is the moat paying out a second time.
The company plans to expand into electronic warfare and signals, including network and cybersecurity tools, all optimized for the tactical edge, the same edge where counter-drone defense is becoming mission-critical. Deterrence, not war, is the real product of defense innovation, and Garrett treats a program of record as a license to keep earning it rather than a finish line.
“We intend to prove our value every day.”
Garrett Smith, Reveal Technology, episode 90
What a mission-driven culture buys you, and where to start
The last lesson is about people. Garrett’s view is that a great team is the baseline, and the real variable is focus: pick the wrong mission and the best team in the world is building a project with friends. The mission has to be one you can care about for the whole lifespan of a young company, and in national security that isn’t hard to find. “Purpose is the best cure for noise,” he told us, and he carries the Marine Corps version of it into the company: “At the end of the day, you’re fighting for the person to your left and the person to your right.”
That culture is what gets a small team through a multi-year climb with no reciprocity waiting at the top.
If you’re building for the tactical edge, the sequence is the one Reveal ran. Build with operators before you build for a requirements document. Run the top-down conversation in parallel, not later. Treat the first IATT as the start of a relationship, budget for each agency’s ladder separately, and don’t raise ahead of the demand signal. The compliance regime will feel like the barrier for the first couple of years; from the third year on, it’s yours.
If Controlled Unclassified Information is about to show up in your contracts, a CMMC Level 2 readiness assessment will show you how much of the 110 controls you already have and what the climb to the first authorization realistically looks like. And if you want the story from the man who lived it, Garrett tells it in 43 minutes on episode 90.
Defense tech startup frequently asked questions
- What is a defense tech startup?
- A defense tech startup builds technology whose first or most important customer is a military or national-security agency: sensors, autonomy, mapping, communications, biometrics, cybersecurity, or the software that ties them together. Many are dual-use and sell the same product commercially. What sets them apart from ordinary SaaS is the buyer: a government that purchases through programs, authorizes systems before they may run, and pays out of multi-year budgets rather than on a credit card.
- What is an ATO, and how is it different from an IATT?
- An Authorization to Operate (ATO) is a formal decision by a government authorizing official to accept the risk of running your system on their network, made under the Risk Management Framework. An Interim Authorization to Test (IATT) is the time-limited permission that usually comes first, letting a prototype run in an operational environment for testing. DoD Instruction 8510.01 lists both, plus ATO with conditions and denial, as the possible authorization decisions.
- What is a Technology Readiness Level (TRL)?
- A nine-point scale, developed by NASA and used across the Department of Defense, for how mature a technology is. TRL 1 is basic research, TRL 6 is a fully functional prototype, TRL 7 is a prototype demonstrated in its operational environment, and TRL 9 is technology proven in a real mission. Program offices use it as shorthand: asking whether you are at TRL 7 yet is asking whether the thing has worked in the field.
- What is a program of record?
- A program of record is an acquisition program with its own funded line in the Future Years Defense Program, the Pentagon's multi-year budget plan, normally after formal program initiation at Milestone B. Practically, it means the government has committed to buy and sustain your capability for years instead of funding it one exercise at a time. The Defense Acquisition University glossary notes the term has been dropped from most official publications; everyone in the industry still uses it.
- Do I need CMMC, ITAR, or FedRAMP to sell to the Department of Defense?
- Usually at least one. CMMC applies if you handle Federal Contract Information or Controlled Unclassified Information under a DoD contract; Level 2 maps to the 110 requirements of NIST SP 800-171, and as of September 2026 the DoD says implementation is paused in Phase 1 (self-assessments), with Phase II third-party assessments suspended pending a reform task force. ITAR governs defense articles and their technical data. FedRAMP applies when you sell cloud services to federal civilian agencies. The data you touch and the contract you sign decide which apply.
- Is compliance reciprocity real when selling to the federal government?
- On paper, yes: DoD Instruction 8510.01 says the department will use cybersecurity reciprocity to reduce redundant testing, assessing and documenting. In practice, Garrett Smith of Reveal Technology found it mostly a myth. Satisfying one agency's requirements rarely makes you adoptable by the next, because each has its own authorizing official, network and onboarding friction. Plan and budget for each customer's climb, and reuse your evidence rather than expecting to reuse your authorization.
- Should a defense tech startup raise venture capital early?
- Often not in the first years. Defense sales cycles run long, and a high burn rate forces growth the market cannot deliver on schedule. Reveal Technology bootstrapped for several years, kept the team small, and raised a Series A and then a Series B once the demand signal from operators was real. Non-dilutive money from government contracts can carry a company through the early climb, and patient investors who know the sector are worth waiting for.
- How do you sell to the military as a startup?
- Start with the people who will use the product, not the people who sign for it. Get prototypes into operators' hands during exercises, fix what they hate, and let their demand signal rise through the chain while you brief program managers and, where it fits, Congress in parallel. The economic buyer follows the groundswell. Then expect to earn an IATT, an ATO and eventually a program of record, one customer at a time.