Compliance & Security Certifications

We are building our federal compliance posture deliberately and transparently. This page shows our roadmap — what we have, what we are actively pursuing, and when we plan to achieve each milestone.

Compliance Roadmap Active SAM.gov Registered
Active Certifications

Our Compliance Framework

We maintain active certifications and continuous compliance posture across cybersecurity, quality management, and federal-specific frameworks.

CMMC Level 2
◎ In Pursuit — Assessment Planned

Cybersecurity Maturity Model Certification Level 2 — covering all 110 NIST SP 800-171 security practices for the protection of Controlled Unclassified Information (CUI). Assessed by a Certified Third-Party Assessment Organization (C3PAO).

110 PracticesCUI ProtectionC3PAO AssessedDoD DIB
FedRAMP Ready
◎ Planned — Applicable When Cloud Services Expand

FedRAMP authorization will be required as we offer cloud-hosted services to federal agencies. We are building our technical and documentation posture toward FedRAMP Ready status and will pursue JAB authorization as our cloud service offering matures.

FedRAMP ModerateAWS GovCloudJAB In Review
ISO/IEC 27001:2022
◎ In Pursuit — ISMS Being Established

ISO/IEC 27001:2022 certification demonstrates a mature information security management system — a differentiator for federal clients. We are establishing our ISMS documentation and controls now, with a target certification date within 12–18 months.

ISMS CertifiedAnnual Surveillance3-Year Cycle
SOC 2 Type II
◎ Planned — Audit Scoped for Year 2

We plan to undergo our first SOC 2 Type II audit once we have established our internal controls and completed at least one year of operating evidence. This is targeted for our second year of federal operations.

Security TSCAvailability TSCConfidentiality TSC
NIST SP 800-171 Rev. 2
◎ In Progress — Gap Assessment Underway

Full compliance with all 110 security requirements in NIST SP 800-171, with a documented System Security Plan (SSP) and Plan of Action & Milestones (POA&M) maintained for every CUI system. Available for CO review.

110 ControlsSSP on FilePOA&M Current
Section 508 / WCAG 2.1 AA
● Committed Standard — Applied to All Deliverables

All software delivered under federal contracts meets Section 508 of the Rehabilitation Act and WCAG 2.1 Level AA accessibility standards. We conduct formal VPAT assessments and automated + manual accessibility testing on every release.

VPAT ProvidedWCAG 2.1 AAManual Testing
Regulatory Alignment

Federal Regulatory Frameworks We Support

Framework / RegulationApplicabilityOur Posture
EO 14028 — Improving CybersecurityAll Federal AgenciesAligning
FISMA / FIPS 200All Federal IT SystemsPreparing
OMB Circular A-130Federal Info ResourcesReviewing
DFARS 252.204-7012DoD ContractorsIn Progress
FAR 52.204-21All Federal ContractorsIn Progress
HIPAA / HITECHHealth Agencies (HHS, VA)Applicable When Awarded
FedRAMP (NIST SP 800-53 Rev. 5)Cloud ServicesReady / In Progress
Privacy Act / M-19-15PII SystemsApplicable When Awarded