Every August, Black Hat generates more cybersecurity commentary than anyone can absorb. This year, Merlin was on the ground meeting with technology partners and federal customers, walking the floor, and listening closely to the conversations shaping the market.
This year's floor told a clear story: a wave of company announcements centered on how to use AI effectively for cyber defense. Alongside that came a second, related trend: companies building solutions to manage agentic AI itself. That ranged from tools that manage and secure agentic identities to solutions that help humans understand, control, and enforce policy for the agentic systems that are changing how the workforce works with machines.
Federal partners are, as always, asking hard questions about capability first. But the more interesting conversations were about how these solutions map to mission outcomes, not just what they do on a spec sheet.
Here are three takeaways that stood out:
For years, cybersecurity companies considering the federal market wrestled with a fundamental question: Can we sell to government at all? That conversation has changed.
As Matt Hartman observed, the question we heard repeatedly at Black Hat was much more practical: How quickly can we get there?
For vendors, that makes speed to market increasingly strategic. Federal demand exists; the challenge is being positioned to capture it.
Federal buyers are still looking for strong technology, and capability remains a priority. But once a solution demonstrates mission fit, another question quickly follows: how ready is it for federal deployment?
Bob saw capability and mission fit remaining front and center, particularly around AI. Across the floor, companies were showing how AI can be put to work in cyber defense, while a new class of solutions is emerging to help organizations secure and ensure responsible use of agentic AI systems. For federal customers, the opportunity is not AI for AI’s sake but rather applying these capabilities in ways that improve mission outcomes while maintaining the visibility and control government environments require.
Once that capability and mission fit are established, federal readiness becomes critical. Certification status and the path to deployment can materially affect how quickly an agency can turn interest into adoption.
The vendor landscape reflected another important shift towards consolidation.
As Matt put it, government customers are looking for outcomes, not another crowded category of indistinguishable tools.
Miguel Sian saw the same shift from the technology side. As AI increases the speed and scale of both attacks and defenses, adding another standalone tool is not enough. Organizations are looking for more unified approaches that simplify operations and strengthen resilience. Exposure Management is becoming a critical component of that security operating model, bringing together continuous testing, risk-based prioritization, automated remediation, and resilience. The emphasis shifts from generating more findings to driving measurable security outcomes.
At the same time, Bob saw no shortage of innovation from smaller companies tackling consequential security problems across both commercial and government environments. The speed of innovation is increasing, creating opportunities for focused technologies to solve specific mission challenges, even as buyers become more selective about how those capabilities fit into the broader security stack.
AI is also expanding the Zero Trust conversation to non-human identities. As Miguel noted, autonomous agents need the same disciplined approach to trust: limited privileges, just-in-time access, and appropriate human oversight.
These trends are connected. Buyers want less complexity, but that does not mean less innovation. They are rewarding technologies, whether from established platforms or emerging companies, that integrate effectively, address clear mission needs, and deliver measurable outcomes.
Considered together, these trends indicate a larger change in how cybersecurity companies will compete in the federal market. Great products increasingly need great ecosystems.
As FedRAMP certification increasingly influences speed to deployment, and buyers concentrate their attention on fewer, more capable solutions, technology alone is not enough. The best positioned vendors will combine differentiated products with the partners, integrations, certification pathways, and channels required to put those products into federal buyers’ hands quickly and responsibly.
For cybersecurity companies building or investing in solutions to serve the federal market, that changes the equation. The competitive advantage is no longer simply what you sell but rather how effectively your ecosystem helps you get there. Black Hat 2026 showed a federal cybersecurity market that is not becoming less competitive. It is becoming more efficient about how it competes.
This is where Merlin is designed to help. We bring together federal market expertise, FedRAMP acceleration, partner ecosystem development, and go-to-market execution to help cybersecurity companies move from strong technology to real government adoption. As buyers prioritize speed, resilience, integrated outcomes, and trusted ecosystems, Merlin helps vendors reduce friction, strengthen their federal position, and reach the market with the partnerships and pathways needed to compete effectively.