All articles

Booz Allen Hamilton signs enterprise license agreement with Chainguard

Tom White, Senior Director, Public Sector Partners

We're excited to announce an enterprise license agreement (ELA) between Chainguard and Booz Allen Hamilton — one of the most significant steps we've taken to bring secure-by-default open source software to the heart of the U.S. government. More than 6,000 Booz Allen engineers will now have access to Chainguard Containers and Chainguard Libraries across programs supporting the Department of War, the Intelligence Community, and federal civilian agencies.

Why this agreement matters

Federal software teams face a familiar tension: move fast, but don't cut corners on security. Navigating Authority to Operate (ATO) processes, managing common vulnerabilities and exposure (CVE), and meeting supply chain mandates all take real engineering time. Time that could be spent delivering mission outcomes.

Booz Allen's decision to expand the use of Chainguard across its entire federal portfolio is a direct response to that challenge. It reflects a shared belief that security can't be bolted on after the fact. It has to be built in from the start.

Results already at scale

This ELA grew out of results already proven in production. When Booz Allen scaled one of its largest programs to support hundreds of government customers and increasingly complex development environments, its engineering teams turned to Chainguard Containers to streamline vulnerability remediation and strengthen the security posture of a critical mission ecosystem. The impact was immediate — fewer CVEs, faster compliance timelines, and more time spent delivering capability.

"Federal missions require both speed and trust. The federal mission requires both speed and trust. Chainguard's container images give our engineers a strong foundation for both — they are minimal, continuously rebuilt to remove known vulnerabilities, and shipped with a transparent supply chain. Expanding the use of Chainguard across our delivery environments can help us accelerate secure, reliable outcomes for our customers," said Leo Barella, Senior Vice President and Chief Information Officer at Booz Allen Hamilton.

"The work Booz Allen does touches nearly every corner of the federal government. When an organization of that scale decides that the integrity of every software component is non-negotiable and backs it up with how they build software, it sets a new bar for the industry," said Dan Lorenc, CEO and Co-founder of Chainguard. "By expanding the use of Chainguard, they're proving that speed and security aren't a tradeoff."

Secure by default, from day one

At the center of this agreement is Chainguard Containers — a catalog of over 2,600 container images, each built from source in hardened infrastructure. Every image ships with zero known CVEs at time of release, signed SBOMs and attestations for full supply chain transparency, and FIPS-validated cryptography to support federal compliance requirements. For Booz Allen engineers, that means starting every project on a secure foundation, without spending cycles hunting vulnerabilities or rebuilding images from scratch.

Looking ahead

Booz Allen Hamilton works across nearly every corner of the federal government. When an organization at this scale makes a firm-wide commitment to secure software, it changes what good looks like across the whole ecosystem. We're proud to be their partner in that work.

To learn more about how Chainguard supports federal agencies and their mission partners, visit chainguard.dev/solutions/public-sector.

Share this article

Related articles

Want to learn more about Chainguard?

Contact us