Compliance and Security: CMMC, FedRAMP, and Vendor Risk
The certifications and screenings that run alongside your pipeline, not just at submission time, and why they decide which contracts you can even see.
For: Teams bidding on DoD, cloud, or supply-chain work where compliance is a bid requirement, not paperwork.
What you need
- Your applicable compliance frameworks identified (not every contract needs every framework)
- A current NIST SP 800-171 self-assessment score if you handle CUI
- A list of subcontractors or suppliers you plan to team with
1. CMMC: know your level before you bid
CMMC readiness is checked against controls, evidence, and scoring — CMMC Level 2 is the bar for most DoD work touching Controlled Unclassified Information (CUI). Solicitations increasingly list a required CMMC level in Section L; if you cannot show current evidence, you are not eligible to submit, regardless of price or past performance.
2. FedRAMP: for cloud and SaaS offerings
Selling a cloud service to a federal agency generally requires a FedRAMP authorization. The platform helps build the System Security Plan (SSP), track the Plan of Action and Milestones (POA&M) for open findings, and export in OSCAL format, the machine-readable format 3PAOs and agencies now expect.
3. Third-party risk: screen before you team
Before you name a subcontractor in a proposal, screen them against denied-party lists and known risk signals. A disqualified sub named in your proposal can disqualify your bid, not just theirs — this is a pink-team check, not an afterthought.
4. This runs continuously, not once
Unlike a pink/red/green review that happens per-bid, compliance status is account-level and ongoing: your CMMC evidence, FedRAMP POA&M items, and vendor screening results carry forward into every future bid. Getting them right once pays off on every subsequent submission.