Secure software experimentation

COLOSSEUM

Test commercial software with mission-relevant data—before the ATO catch-22 stops progress.

COLOSSEUM (COLlaborative Laboratory for Operational Showcasing and Experimentation of Urgent Missions)—a CMMC Level 2 secure enclave for evaluating commercial software with CUI data under controlled, mission-relevant conditions.

Secure software experimentation

COLOSSEUM

Test commercial software with mission-relevant data—before the ATO catch-22 stops progress.

COLOSSEUM (COLlaborative Laboratory for Operational Showcasing and Experimentation of Urgent Missions)—a CMMC Level 2 secure enclave for evaluating commercial software with CUI data under controlled, mission-relevant conditions.

The recurring barrier

Software cannot earn mission confidence without being tested under real conditions against real platform data.

Many commercial applications can perform in a demonstration environment. Far fewer have been evaluated using representative workflows, mission-relevant data, and the security controls required to interoperate with military networks.

01

Evidence is required

The software needs credible evidence to justify adoption and procurement.

02

Evidence requires access

Credible evaluation depends on protected environments, data, and representative workflows.

03

Access requires maturity

That access is difficult to obtain before the software has demonstrated sufficient maturity.

COLOSSEUM was built to break that cycle.

The capability

A secure environment for mission-relevant software experimentation.

COLOSSEUM allows mission sponsors, requirements owners, technical teams, and commercial vendors to evaluate software in a secure, controlled environment against a full spectrum of data—from open source to controlled operational-system data.

COLOSSEUM does not replace the software authorization process. It reduces the risk of applying for authorization after mission validation is secured.

Controlled operational-system data

Controlled operational-system data

Visualize range and controlled access—not a claim that every data type is available for every engagement.

01

Test with greater realism

Evaluate applications using representative data, workflows, interfaces, and mission conditions.

02

Find problems earlier

Identify cybersecurity, integration, usability, performance, and data-handling issues earlier.

03

Generate decision-quality evidence

Give sponsors a clearer basis for deciding whether—and how—to advance a capability.

04

Reduce risk before fielding

Resolve critical unknowns before larger integration, authorization, or acquisition efforts.

How an engagement works

From mission question to decision evidence.

01

Define the mission question

Define what must be learned—not merely what the vendor wants to demonstrate.

02

Design the experiment

Identify the data, workflows, security controls, performance measures, and scenarios.

03

Prepare the environment

Coordinate the secure environment, participating technologies, interfaces, and plan.

04

Execute and observe

Evaluate the software under controlled, mission-relevant conditions with the sponsor involved.

05

Deliver the evidence

Document performance, limitations, integration risks, and recommended next steps.

Infrastructure

Purpose-built for controlled experimentation.

Available now

Secure cloud enclave

Controlled cloud infrastructure with multi-tenant architecture for independent, simultaneous application evaluation.

Available now

CMMC Level 2 environment

A secure environment for software experimentation involving CUI data.

Coming in 2027

Hybrid high-performance computing

Planned capacity for AI training and development.

Appropriate use cases

What belongs in COLOSSEUM

+ AI and machine-learning applications
+ Mission planning and decision-support tools
+ Data fusion and analytics
+ Logistics and readiness software
+ Commercial applications requiring CUI data
+ Multi-vendor software integrations
+ Any software capability that must demonstrate mission utility before broader authorization or fielding

Capability in action

Evaluating non-traditional software in Weapon Open System Architecture (WOSA).

WOSA case study

A repeatable, level playing field for vendor evaluation.

The Air Force Research Laboratory is using COLOSSEUM to identify and evaluate non-traditional software vendors for potential future platform integration.

The mission need

Commercial applications cannot be compared credibly when vendors arrive with different infrastructure, data access, and test conditions.

How COLOSSEUM is being used

COLOSSEUM provides a WOSA-compliant hardware and networking environment for a series of three-day, hackathon-style evaluation events. Each vendor operates in an isolated tenant.

Common environment

The same representative hardware, networking environment, and mission scenario.

Protected execution

Applications remain isolated, protecting proprietary software and information.

Government-defined scoring

A transparent rubric of mission KPIs established by the Government platform lead.

What the engagement produces

Documented performance against government-defined mission KPIs

Technical and integration findings for each application

Evidence for future platform integration consideration

Bring us the software challenge

Do not ask whether the software looks promising. Determine whether it can perform where the mission needs it.

COLOSSEUM helps defense organizations evaluate commercial software with greater realism, security, and technical rigor—before uncertainty becomes execution risk.