Skip to content

Security & Compliance

Compliance Frameworks

We design to recognized federal and industry frameworks so that our engineering decisions map cleanly onto the language a government reviewer already uses. Status labels below are deliberate and conservative.

How to read this page

Alignment status definitions

These labels describe internal practice only. None of them indicate certification, authorization, endorsement, or an audited result.
Practices Implemented
The described practices are in place today as part of normal operations.
Program Alignment
Our program is structured around this guidance, with implementation maturing and gaps tracked internally.
Roadmap
A future goal. Not in place today, and no certification, authorization, or assessment is claimed.

Frameworks

Framework familiarity and alignment

  • FAR 52.204-21

    Federal Acquisition Regulation

    Current status: Practices Implemented

    Basic safeguarding of covered contractor information systems.

    The fifteen basic safeguarding requirements — access limitation, authentication, media handling, boundary protection, and update management — are implemented as baseline operating practice.

  • NIST CSF 2.0

    NIST Cybersecurity Framework

    Current status: Program Alignment

    Govern, Identify, Protect, Detect, Respond, Recover.

    The program is organized around the CSF functions. Govern and Protect are the most mature; Detect and Recover continue to expand as monitoring and testing coverage grows.

  • NIST SP 800-53

    NIST Special Publication

    Current status: Program Alignment

    Security and privacy control catalog for federal systems.

    Used as the control vocabulary when an agency specifies a baseline. Control families are mapped to our implemented practices during engagement planning rather than asserted generically.

  • NIST SP 800-171

    NIST Special Publication

    Current status: Program Alignment

    Protecting controlled unclassified information in nonfederal systems.

    Internal self-assessment activity is structured around the 800-171 requirement families, with gaps tracked in a plan of action. No third-party assessment or score is claimed.

  • NIST SP 800-161

    NIST Special Publication

    Current status: Program Alignment

    Cybersecurity supply chain risk management practices.

    Vendor onboarding, criticality tiering, provenance review, and flow-down expectations are informed by C-SCRM concepts from this publication.

  • OWASP ASVS

    OWASP

    Current status: Practices Implemented

    Application Security Verification Standard.

    Used as a verification checklist for authentication, session management, access control, and data protection requirements during application review.

  • OWASP Top 10

    OWASP

    Current status: Practices Implemented

    Most critical web application security risks.

    Every application review covers the Top 10 categories, and the API Security Top 10 is applied additionally to service interfaces.

  • CIS Controls

    Center for Internet Security

    Current status: Practices Implemented

    Prioritized safeguards for cyber defense.

    Implementation Group 1 safeguards form the baseline for asset inventory, access control, secure configuration, and data recovery. CIS Benchmarks inform configuration standards.

  • MITRE ATT&CK

    MITRE

    Current status: Practices Implemented

    Adversary tactics and techniques knowledge base.

    Used for threat modeling and to describe testing coverage in terms of realistic adversary techniques rather than tool output.

  • MITRE D3FEND

    MITRE

    Current status: Program Alignment

    Countermeasure knowledge graph.

    Applied when mapping identified techniques to defensive countermeasures so mitigation recommendations are specific rather than generic.

  • CMMC

    Department of Defense

    Current status: Roadmap

    Cybersecurity Maturity Model Certification.

    Readiness support is offered as a service, and internal readiness is a roadmap item. IEP ALLY APP LLC is not CMMC certified and holds no CMMC assessment result.

  • FedRAMP Principles

    GSA / FedRAMP PMO

    Current status: Roadmap

    Cloud security authorization principles.

    Cloud practices are designed around FedRAMP security principles. IEP ALLY APP LLC holds no FedRAMP authorization and is not listed in the FedRAMP Marketplace.

  • SOC 2 Principles

    AICPA

    Current status: Roadmap

    Trust services criteria for security and availability.

    Policy structure and evidence practices are influenced by the trust services criteria. No SOC 2 examination has been performed and no report exists.

  • ISO 27001 Concepts

    ISO/IEC

    Current status: Roadmap

    Information security management system concepts.

    Policy ownership, review cycles, and risk treatment follow ISMS concepts. IEP ALLY APP LLC is not ISO 27001 certified and holds no certificate.

Roadmap

Planned compliance maturity

Formal validation activities are goals on our roadmap, presented without committed dates.
  1. Phase 1

    Status: Complete

    Baseline Security Program

    Establish the foundational control set expected of a small business handling federal information: identity, MFA, encryption, and least privilege.

    • Multi-factor authentication on administrative systems
    • Encryption in transit and at rest
    • Role-based access and account separation
    • FAR 52.204-21 basic safeguarding practices
  2. Phase 2

    Status: In Progress

    Documented Policies

    Convert practice into a versioned, owned, and reviewable policy library with published public summaries.

    • Policy library with owners and review dates
    • Public policy summaries
    • Exception handling process
    • Annual policy review cycle
  3. Phase 3

    Status: In Progress

    Internal Risk Assessments

    Perform structured self-assessment against NIST guidance and record the outcome in a maintained risk register.

    • NIST SP 800-171 self-assessment activity
    • Risk register with treatment decisions
    • Plan of action for identified gaps
    • Recurring reassessment cadence
  4. Phase 4

    Status: In Progress

    Vendor Risk Program

    Formalize vendor onboarding, tiering, and reassessment aligned to cyber supply chain risk management concepts.

    • Vendor inventory and criticality tiering
    • Pre-onboarding security evaluation
    • Recurring reassessment
    • Flow-down security requirements
  5. Phase 5

    Status: Planned

    Continuous Improvement

    Mature detection, testing, and evidence collection so control effectiveness is demonstrable, not asserted.

    • Expanded logging and alerting coverage
    • Recurring recovery and tabletop exercises
    • Independent security testing
    • Evidence repository for customer reviews
  6. Phase 6

    Status: Planned

    Future Certification Goals

    Pursue formal third-party validation when engagement requirements justify it. No certification or authorization is claimed today.

    • CMMC readiness assessment (roadmap item)
    • SOC 2 readiness evaluation (roadmap item)
    • ISO 27001 gap analysis (roadmap item)
    • FedRAMP pathway evaluation if a cloud offering requires it (roadmap item)

Roadmap items describe intended future activity. Items marked as roadmap or planned are not in place today and do not represent certification, authorization, or an assessment result.

IEP ALLY APP LLC does not hold FedRAMP authorization, SOC 2 attestation, ISO 27001 certification, or CMMC certification. Framework references describe familiarity and practice alignment only. They do not represent certification, authorization, endorsement, audit, or verified compliance status.

Requesting security documentation?

Contracting officers, prime contractors, integrators, and auditors can request review materials through our secure documentation workflow.