Sonar joins Carahsoft GSA Schedule to target US public sector

Sonar's SonarQube code verification platform is now available to US federal, state and local agencies via Carahsoft's GSA Schedule contract.

A brightly lit, modern control room features a large curved screen displaying a network graphic, multiple workstations with black monitors and chairs, and server racks on either side, with natural light entering through tall windows and ove

Sonar, the code quality and security vendor behind SonarQube, has been added to Carahsoft Technology's General Services Administration (GSA) Schedule contract, making its AI code verification and governance platform formally accessible to US federal, state and local government bodies, as well as educational institutions. The listing also extends to Carahsoft's SEWP V and NASPO ValuePoint contract vehicles, broadening the procurement routes available to public-sector buyers.

The move is a distribution play as much as a product announcement. GSA Schedule placement removes a significant procurement friction for agencies that lack the flexibility to run custom vendor evaluations, allowing them to acquire Sonar's tools through an already-vetted vehicle at pre-negotiated terms. Carahsoft operates as a government IT aggregator and has similar arrangements with a wide range of enterprise software vendors.

What agencies get

SonarQube's core capability is static analysis: automated scanning of code for bugs, security vulnerabilities and complexity issues before software reaches production. The platform spans automated code review, test coverage reporting and real-time security analysis across the software development lifecycle. Sonar maps its output to several compliance frameworks relevant to US government procurement, including NIST's Secure Software Development Framework (SSDF), OWASP, CWE, STIG and CASA, and supports continuous audit readiness reporting.

A more recent addition to the product is AI-native code review, brought in through Sonar's acquisition of Gitar. That capability is positioned specifically at the emerging challenge of verifying code generated by agentic AI systems, where the volume and opacity of AI-written output makes manual review impractical. Nathan Jones, Sonar's Vice President of Public Sector, said the GSA listing would help agencies "innovate with confidence while maintaining the accountability, auditability and resilience their missions demand."

SonarQube also supports self-managed deployment, which is a meaningful differentiator for high-security government environments where cloud-hosted analysis tools may not meet air-gap or data-residency requirements.

Market context

The DevSecOps tooling market serving the US public sector is active. Agencies have faced sustained pressure to improve software supply-chain security since the 2021 executive order on cybersecurity, and the subsequent guidance from CISA and the Office of Management and Budget has sharpened demand for tools that can demonstrate SSDF alignment and produce machine-readable compliance evidence.

Sonar occupies a recognised position in the static analysis and technical-debt management space, having been named a Leader in the Gartner Magic Quadrant for Technical Debt Management Tools. Its cited user base of more than seven million developers, along with enterprise customers including Nvidia, Goldman Sachs and ServiceNow, gives it credibility with procurement officers evaluating commercial track record.

Competitors in the code security and quality space include Veracode, Checkmarx and Semgrep, several of which also hold GSA Schedule positions. The differentiating argument Sonar is making centres on agentic-AI code review: as agencies adopt AI-assisted development environments, the argument runs that traditional review processes cannot keep pace with AI-generated output, making automated verification a mission-critical control rather than a developer convenience.

Whether that argument translates into material public-sector revenue will depend on agencies' pace of AI adoption in software development, which remains uneven across the federal landscape. The Gitar acquisition and GSA listing together suggest Sonar is positioning early for what it expects to be a growing compliance requirement around AI-generated code in government systems.