Architecture
Segmentation, least privilege, and identity-aware access designed into the system rather than fitted afterwards. Every service reaches only what it must, and says so in configuration we can show an assessor.
Assurance
FedRAMP impact levels, DoD Cloud SRG IL2–IL6, and CMMC 2.0 Levels 1–3. We design to the ladder your programme is measured against, and we say plainly where we sit on it.
“What security level are you at?” is four different questions. Each of the ladders below measures something distinct, and a supplier who does not say which one they mean is not answering. Here is where each one applies, rung by rung.
Applies to: US civilian federal cloud services
Basis: Control baselines drawn from NIST SP 800-53
FedRAMP grades a cloud service by the damage its compromise would do. The level sets the size of the control baseline.
Loss of confidentiality, integrity or availability would have a limited adverse effect. Includes the FedRAMP Tailored / Li-SaaS path for low-risk software-as-a-service.
The workhorse level — roughly four in five FedRAMP authorisations, and the usual landing place for SaaS handling sensitive but unclassified government data.
Law enforcement, emergency services, financial and health systems where failure causes severe or catastrophic harm.
Applies to: US Department of Defense workloads
Basis: DISA maintains four active levels; IL1 and IL3 were retired or merged
The DoD grades by data sensitivity rather than service risk. FedRAMP Moderate maps to IL2; FedRAMP High maps to IL4 and IL5.
Unclassified information cleared for public release, plus non-critical mission data. Aligned with FedRAMP Moderate.
CUI and other mission-critical data on non-national-security systems. The level most defence-adjacent software has to reach.
Higher-sensitivity CUI, mission-critical information, and National Security Systems — with stricter separation and personnel requirements.
Classified information up to SECRET, hosted only in accredited environments connected to SIPRNet.
Applies to: The US Defense Industrial Base
Basis: NIST SP 800-171 at Level 2 and NIST SP 800-172 at Level 3
CMMC certifies not just that a control exists but that you have been managing it — a maturity dimension is assessed at Levels 2 and 3. Phase 2 begins in November 2026, when third-party assessment becomes mandatory for contractors handling CUI.
Basic cyber hygiene protecting Federal Contract Information (FCI). Annual self-assessment.
The full NIST SP 800-171 control set, protecting CUI. Assessed by a C3PAO every three years unless DoD designates otherwise.
Adds NIST SP 800-172 controls for the most sensitive programmes: continuous monitoring, zero-trust architecture and proactive threat detection. Assessed by the government every three years.
Applies to: Architecture maturity, across five pillars
Basis: Identity · Devices · Networks · Applications and Workloads · Data
Not a certification but the ladder an architecture is judged on. We use it to describe where a system is today and what the next rung actually costs.
Manual configuration, static policy, implicit trust inside the network.
Some automated provisioning and policy enforcement; visibility still partial.
Centralised visibility and identity control, policy enforced across pillars.
Continuous validation, dynamic least-privilege, automated response.
Segmentation, least privilege, and identity-aware access designed into the system rather than fitted afterwards. Every service reaches only what it must, and says so in configuration we can show an assessor.
Encryption at rest and in transit, managed key material, no credential ever living in source, and data boundaries that match the impact level the programme is authorised at.
Control evidence produced continuously by the pipeline that builds the system, so an assessment is a report on what already happens rather than a six-week scramble to reconstruct it.
Prompt injection and tool-abuse testing, output filtering, bounded agent permissions, and red-teaming of the agent path — the failure modes that traditional application security testing does not look for.
We will also tell you when a level does not apply to you. Paying for an assurance posture your programme is not measured against is a common and expensive mistake.
Tell us which one, and we will tell you what the gap actually costs.