We design to recognized federal and industry frameworks so that our engineering decisions map cleanly onto the language a government reviewer already uses. Status labels below are deliberate and conservative.
How to read this page
Alignment status definitions
These labels describe internal practice only. None of them indicate certification, authorization, endorsement, or an audited result.
Practices Implemented
The described practices are in place today as part of normal operations.
Program Alignment
Our program is structured around this guidance, with implementation maturing and gaps tracked internally.
Roadmap
A future goal. Not in place today, and no certification, authorization, or assessment is claimed.
Frameworks
Framework familiarity and alignment
FAR 52.204-21
Federal Acquisition Regulation
Current status: Practices Implemented
Basic safeguarding of covered contractor information systems.
The fifteen basic safeguarding requirements — access limitation, authentication, media handling, boundary protection, and update management — are implemented as baseline operating practice.
The program is organized around the CSF functions. Govern and Protect are the most mature; Detect and Recover continue to expand as monitoring and testing coverage grows.
NIST SP 800-53
NIST Special Publication
Current status: Program Alignment
Security and privacy control catalog for federal systems.
Used as the control vocabulary when an agency specifies a baseline. Control families are mapped to our implemented practices during engagement planning rather than asserted generically.
NIST SP 800-171
NIST Special Publication
Current status: Program Alignment
Protecting controlled unclassified information in nonfederal systems.
Internal self-assessment activity is structured around the 800-171 requirement families, with gaps tracked in a plan of action. No third-party assessment or score is claimed.
Vendor onboarding, criticality tiering, provenance review, and flow-down expectations are informed by C-SCRM concepts from this publication.
OWASP ASVS
OWASP
Current status: Practices Implemented
Application Security Verification Standard.
Used as a verification checklist for authentication, session management, access control, and data protection requirements during application review.
OWASP Top 10
OWASP
Current status: Practices Implemented
Most critical web application security risks.
Every application review covers the Top 10 categories, and the API Security Top 10 is applied additionally to service interfaces.
CIS Controls
Center for Internet Security
Current status: Practices Implemented
Prioritized safeguards for cyber defense.
Implementation Group 1 safeguards form the baseline for asset inventory, access control, secure configuration, and data recovery. CIS Benchmarks inform configuration standards.
MITRE ATT&CK
MITRE
Current status: Practices Implemented
Adversary tactics and techniques knowledge base.
Used for threat modeling and to describe testing coverage in terms of realistic adversary techniques rather than tool output.
MITRE D3FEND
MITRE
Current status: Program Alignment
Countermeasure knowledge graph.
Applied when mapping identified techniques to defensive countermeasures so mitigation recommendations are specific rather than generic.
CMMC
Department of Defense
Current status: Roadmap
Cybersecurity Maturity Model Certification.
Readiness support is offered as a service, and internal readiness is a roadmap item. IEP ALLY APP LLC is not CMMC certified and holds no CMMC assessment result.
FedRAMP Principles
GSA / FedRAMP PMO
Current status: Roadmap
Cloud security authorization principles.
Cloud practices are designed around FedRAMP security principles. IEP ALLY APP LLC holds no FedRAMP authorization and is not listed in the FedRAMP Marketplace.
SOC 2 Principles
AICPA
Current status: Roadmap
Trust services criteria for security and availability.
Policy structure and evidence practices are influenced by the trust services criteria. No SOC 2 examination has been performed and no report exists.
ISO 27001 Concepts
ISO/IEC
Current status: Roadmap
Information security management system concepts.
Policy ownership, review cycles, and risk treatment follow ISMS concepts. IEP ALLY APP LLC is not ISO 27001 certified and holds no certificate.
Roadmap
Planned compliance maturity
Formal validation activities are goals on our roadmap, presented without committed dates.
Phase 1
Status: Complete
Baseline Security Program
Establish the foundational control set expected of a small business handling federal information: identity, MFA, encryption, and least privilege.
Multi-factor authentication on administrative systems
Encryption in transit and at rest
Role-based access and account separation
FAR 52.204-21 basic safeguarding practices
Phase 2
Status: In Progress
Documented Policies
Convert practice into a versioned, owned, and reviewable policy library with published public summaries.
Policy library with owners and review dates
Public policy summaries
Exception handling process
Annual policy review cycle
Phase 3
Status: In Progress
Internal Risk Assessments
Perform structured self-assessment against NIST guidance and record the outcome in a maintained risk register.
NIST SP 800-171 self-assessment activity
Risk register with treatment decisions
Plan of action for identified gaps
Recurring reassessment cadence
Phase 4
Status: In Progress
Vendor Risk Program
Formalize vendor onboarding, tiering, and reassessment aligned to cyber supply chain risk management concepts.
Vendor inventory and criticality tiering
Pre-onboarding security evaluation
Recurring reassessment
Flow-down security requirements
Phase 5
Status: Planned
Continuous Improvement
Mature detection, testing, and evidence collection so control effectiveness is demonstrable, not asserted.
Expanded logging and alerting coverage
Recurring recovery and tabletop exercises
Independent security testing
Evidence repository for customer reviews
Phase 6
Status: Planned
Future Certification Goals
Pursue formal third-party validation when engagement requirements justify it. No certification or authorization is claimed today.
CMMC readiness assessment (roadmap item)
SOC 2 readiness evaluation (roadmap item)
ISO 27001 gap analysis (roadmap item)
FedRAMP pathway evaluation if a cloud offering requires it (roadmap item)
Roadmap items describe intended future activity. Items marked as roadmap or planned are not in place today and do not represent certification, authorization, or an assessment result.
IEP ALLY APP LLC does not hold FedRAMP authorization, SOC 2 attestation, ISO 27001 certification, or CMMC certification. Framework references describe familiarity and practice alignment only. They do not represent certification, authorization, endorsement, audit, or verified compliance status.
Requesting security documentation?
Contracting officers, prime contractors, integrators, and auditors can request review materials through our secure documentation workflow.