# Does Julia have some kind of NIAP certification or 3rd party government assessment?

**URL:** <https://discourse.julialang.org/t/does-julia-have-some-kind-of-niap-certification-or-3rd-party-government-assessment/137287>\
**Category:** New to Julia\
**Tags:** question\
**Created:** [May 26, 2026, 7:03pm UTC](https://discourse.julialang.org/t/does-julia-have-some-kind-of-niap-certification-or-3rd-party-government-assessment/137287 "2026-05-26T19:03:38Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bad\_Goose](https://avatars.discourse-cdn.com/v4/letter/b/b38774/32.png) [@Bad\_Goose](https://discourse.julialang.org/u/Bad_Goose)\
**Post date:** [May 26, 2026, 7:03pm UTC](https://discourse.julialang.org/t/does-julia-have-some-kind-of-niap-certification-or-3rd-party-government-assessment/137287/1 "2026-05-26T19:03:38Z")

</div>

Does this language have some kind of assessment for working in a classified environment? I am trying to determine the eligeability and I have not been able to find anything as of yet. I see memory safe languages are recommended, but Julia is not named in any of the CISA/NSA/FBI lists of approved languages. Thanks!

---

<div class="post-metadata">

**Author:** ![ufechner7](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ufechner7/32/51363_2.png) [@ufechner7](https://discourse.julialang.org/u/ufechner7)\
**Post date:** [May 26, 2026, 7:24pm UTC](https://discourse.julialang.org/t/does-julia-have-some-kind-of-niap-certification-or-3rd-party-government-assessment/137287/2 "2026-05-26T19:24:46Z")

</div>

> [@Bad\_Goose](#):
>
> Does this language have some kind of assessment for working in a classified environment?

Most likely it does not have this kind of assessment. Try to get it assessed. But I have no idea who is usually doing such an assessment, and who pays for it.

---

<div class="post-metadata">

**Author:** ![Benny](https://avatars.discourse-cdn.com/v4/letter/b/49beb7/32.png) [@Benny](https://discourse.julialang.org/u/Benny)\
**Post date:** [May 26, 2026, 10:28pm UTC](https://discourse.julialang.org/t/does-julia-have-some-kind-of-niap-certification-or-3rd-party-government-assessment/137287/3 "2026-05-26T22:28:10Z")

</div>

No. NIAP certifies commercial IT products, not programming languages used to make them. There is no list of American government-_approved_ languages. You’re talking about a recent cybersecurity recommendation to shift to memory-safe languages, which:

- cannot address many security issues. For just one example, Python and Ruby are explicitly named as memory-safe, and those have `eval` or similar functions that allow easy source code injection, no memory vulnerabilities needed. Julia is in the same boat.
- have exceptions to eliminate redundant safety checks or implement safe operations in the first place. Notably, Rust strictly delineates this on the language-level with `unsafe`. Julia has plenty of ways to opt out of default memory safety, like `@inbounds`.
- vary wildly in memory safety features. For example, eliminating data races could be anywhere from guaranteed to opt-out to opt-in. Julia is in the latter half of that spectrum.
- aren’t mandated. Notoriously memory-unsafe languages like C and C++ are still allowed, especially as dependencies for more convenient memory-safe languages including Julia. Porting everything is explicitly discouraged on occasion.

There’s no replacement for static analysis and tests. Languages just vary what needs to be verified and how often. Memory safety features are only one broad factor and can be outweighed by the availability of security assessment tooling.

---

<div class="post-metadata">

**Author:** ![mihalybaci](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/mihalybaci/32/13528_2.png) [@mihalybaci](https://discourse.julialang.org/u/mihalybaci)\
**Post date:** [May 27, 2026, 12:07pm UTC](https://discourse.julialang.org/t/does-julia-have-some-kind-of-niap-certification-or-3rd-party-government-assessment/137287/4 "2026-05-27T12:07:32Z")

</div>

I think the information you are looking for would come from JuliaHub (the company) since they would need to have the certifications to work with government agencies. I imagine they have some assessments just based on the groups listed on the [JuliaHub customer page](https://juliahub.com/offerings/government). Poking around the JuliaHub website, or a short email to them, would probably answer most of your questions.

---

<div class="post-metadata">

**Author:** ![Bad\_Goose](https://avatars.discourse-cdn.com/v4/letter/b/b38774/32.png) [@Bad\_Goose](https://discourse.julialang.org/u/Bad_Goose)\
**Post date:** [May 29, 2026, 3:44pm UTC](https://discourse.julialang.org/t/does-julia-have-some-kind-of-niap-certification-or-3rd-party-government-assessment/137287/5 "2026-05-29T15:44:41Z")

</div>

Thank you, I will try there!

---

<div class="post-metadata">

**Author:** ![Palli](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/palli/32/3380_2.png) [@Palli](https://discourse.julialang.org/u/Palli)\
**Post date:** [May 30, 2026, 5:17pm UTC](https://discourse.julialang.org/t/does-julia-have-some-kind-of-niap-certification-or-3rd-party-government-assessment/137287/7 "2026-05-30T17:17:57Z")

</div>

> [@Benny](#):
>
> Python and Ruby are explicitly named as memory-safe, and those have `eval`

Julia is arguably as memory-safe, or _more_, than Python (or most languages, likely Ruby too), assuming you run as:

```julia-auto
julia --check-bounds=yes

```

[If you don’t do that, it’s still more memory safe than C or C++. Just you trust the programmer to not opt out of the safety for speed, which is done selectivity in Julia, unlike C or C++, sort of more like Rust.]

Which gives same default as Python an Java etc.

Python relies much more on calling fast code another languages, e.g. unsafe language like C. That’s also possible in Julia with e.g. `ccall` keyword (and happens with \_jll dependencies). Even memory-safe languages like Rust allow that in unsafe regions.

When you call other languages (in Julia with `ccall` or indirectly do that, with dependency code, usually \_jll), e.g in C language, then you rely on that code, i.e. it’s no more safe than that (trusted, but potentially buggy) code.

---

<div class="post-metadata">

**Author:** ![adienes](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/adienes/32/37459_2.png) [@adienes](https://discourse.julialang.org/u/adienes)\
**Post date:** [May 30, 2026, 5:38pm UTC](https://discourse.julialang.org/t/does-julia-have-some-kind-of-niap-certification-or-3rd-party-government-assessment/137287/8 "2026-05-30T17:38:56Z")

</div>

> [@Palli](#):
>
> Julia is arguably as memory-safe, or _more_, than Python

I would find this a very ambitious position to defend, and I would not recommend advertising the language this way.

---

<div class="post-metadata">

**Author:** ![Tortar](https://avatars.discourse-cdn.com/v4/letter/t/6bbea6/32.png) [@Tortar](https://discourse.julialang.org/u/Tortar)\
**Post date:** [May 30, 2026, 9:46pm UTC](https://discourse.julialang.org/t/does-julia-have-some-kind-of-niap-certification-or-3rd-party-government-assessment/137287/9 "2026-05-30T21:46:01Z")

</div>

Why though? Maybe the _more_ part is too ambitious, but what about saying it is as memory-safe as Python?

---

<div class="post-metadata">

**Author:** ![adienes](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/adienes/32/37459_2.png) [@adienes](https://discourse.julialang.org/u/adienes)\
**Post date:** [May 30, 2026, 10:02pm UTC](https://discourse.julialang.org/t/does-julia-have-some-kind-of-niap-certification-or-3rd-party-government-assessment/137287/10 "2026-05-30T22:02:19Z")

</div>

because I think it is much easier to encounter unsafe memory access in julia than it is in python.

---

<div class="post-metadata">

**Author:** ![Benny](https://avatars.discourse-cdn.com/v4/letter/b/49beb7/32.png) [@Benny](https://discourse.julialang.org/u/Benny)\
**Post date:** [May 30, 2026, 10:30pm UTC](https://discourse.julialang.org/t/does-julia-have-some-kind-of-niap-certification-or-3rd-party-government-assessment/137287/11 "2026-05-30T22:30:03Z")

</div>

> [@Palli](#):
>
> assuming you run as:
> 
> ```julia-auto
> julia --check-bounds=yes
> 
> ```

A non-default flag specifically for ignoring `@inbounds` has no equivalents in Python or Ruby, so the comparison is more of an opinion. A Pythonista could just as easily use the same facts to argue that base Python doesn’t let you shoot yourself in the foot with `@inbounds`, that the unsafe stuff is in other languages where it belongs (two-language _solution_).
