DHS Automated Vetting Process for Mobile Apps Could Cut Costs
The Science & Technology Directorate sees improvements for quickly approving mobile apps for government use.

Federal agencies faced a new security challenge when their employees transitioned to remote work in March: quickly and efficiently vetting mobile apps for use on government smartphones. The Department of Homeland Security developed an automated security vetting process for mobile apps, cutting out hours of work and thousands of dollars to help streamline remote work.
Vetting just one mobile app according to the National Security Agency’s NIAP standards previously consumed as many as 60 hours of work and could cost a federal agency anywhere from $40,000 to $80,000. The entire timeline could take anywhere from three to six months, DHS Mobile Security R&D Program Manager Vincent Sritapan told GovernmentCIO Media & Research.
Sritapan wanted his automated test to reduce the amount of time it takes to vet a mobile app. His team was able to get the automated portion of the test down to just two hours over the course of the study. According to the June 29 report, if the right changes are made, it may be possible to automate as much as 90% of testing.
“Our hope is it can drive down costs and at the end of the day reduce costs and not just the time,” he said.
Sritapan’s automated test is also superior to the former vetting process because it ensures standardization, greater accuracy and “more robust results.”
“If you check between different labs or analysts, you’re going to find the technical expertise and methodology is going to vary quite a bit,” Sritapan said of the former vetting process for mobile apps. “Why is it costing me $20,000 at one place and $40,000 at another place? It really depends. So being able to do it with an automated tool, consistency is the key thing. It is more accurate.”
Automating the vetting process not only saves time, but also allows for more layers of vetting to ensure the greatest degree of accuracy possible. It also highlights potential security issues in an app and explains how to fix them.
“By hand you can test for criteria one way, but the tool will test it two or three different ways,” Sritapan said. “If I have analyst A do it one way and analyst B do it a different way, you may find the labs come out with different results for the same app, so this does bring consistency and reduces human error. You still need a human in the loop, but overall I think it’s a step in the right direction.”
The automated test will also allow federal agencies to test more mobile apps, potentially allowing federal employees to use more apps on their government phones than before.
“Time [and money] has been a barrier to entry for folks, they say we’d love to do this and follow the rules, but in truth we can only afford so much,” Sritapan said. “Can you test, and can you test in a way that’s scaleable and automated?”
Sritapan’s long-term goal is for other organizations outside the federal government to use the test as well.
“If I were an enterprise, a bank or health organization, for my users, I would want their apps to be checked,” he said. “Yes the official stores like Google Play and the Apple App Store do their own types of security and privacy checks, but what we allow as an enterprise might be different than what we allow as an individual.”
A GPS tracking app, for example, might be fine when you’re hiking, but not when you’re at work if you work in an industry or for an organization with security sensitivities.
“It just happens to be that NIAP is the highest bar you can get,” Sritapan said.
Note: A previous version of this article misrepresented how much of the test was automated. It has been revised to clarify that part of the test has been automated and there are still some manual processes present.
This is a carousel with manually rotating slides. Use Next and Previous buttons to navigate or jump to a slide with the slide dots
-
VA CIO Targets Modern IT and Smarter Workforce Alignment
Agency leaders told lawmakers they are focused on trimming legacy systems and restructuring its workforce to streamline operations.
3m read -
Pentagon's $200M AI Contracts Signal Broader Effort to Transform Talent
The Army is leveraging Silicon Valley, reservist programs and new hiring strategies to integrate critical digital skills in its ranks.
5m read -
AI Foundations Driving Government Efficiency
Federal agencies are modernizing systems, managing risk and building trust to scale responsible AI and drive government efficiency.
43m watch -
Inside DOD’s Push to Grow the Cyber Workforce Through Academia
Diba Hadi gives her first interview since becoming principal director of the DOD’s Cyber Academic Engagement Office.
15m listen -
Agencies Tackle Infrastructure Challenges to Drive AI Adoption
Federal agencies are rethinking data strategies and IT modernization to drive mission impact and operational efficiency as new presidential directives guide next steps.
5m read Partner Content -
Generative AI Demands Federal Workforce Readiness, Officials Say
NASA and DOI outline new generative AI use cases and stress that successful AI adoption depends on strong change management.
6m read -
The Next AI Wave Requires Stronger Cyber Defenses, Data Management
IT officials warn of new vulnerabilities posed by AI as agencies continue to leverage the tech to boost operational efficiency.
5m read -
Federal CIOs Push for ROI-Focused Modernization to Advance Mission Goals
CIOs focus on return on investment, data governance and application modernization to drive mission outcomes as agencies adopt new tech tools.
4m read -
Fed Efficiency Drive Includes Code-Sharing Law, Metahumans
By reusing existing code instead of rewriting it, agencies could dramatically cut costs under the soon-to-be-enacted SHARE IT Act.
5m read -
Agencies Push Data-Driven Acquisition Reforms to Boost Efficiency
New initiatives aim to increase visibility of agency spending, improve data quality and create avenues to deploy solutions across government.
5m read -
Data Transparency Essential to Government Reform, Rep. Sessions Says
Co-Chair of the Congressional DOGE Caucus Rep. Pete Sessions calls for data sharing and partnerships to reduce waste and improve efficiency.
5m read -
DOD Turns to Skills-Based Hiring to Build Next-Gen Cyber Workforce
Mark Gorak discusses DOD’s efforts to build a diverse cyber workforce, including skills-based hiring and partnerships with over 480 schools.
20m listen