Skip to content
UNCLASSIFIED // PRE-DECISIONAL CAGE: 8XK42  |  Tysons, VA  |  [email protected]  |  +1 (703) 555-0148
Request Briefing ↗

UNCLASSIFIED // PRE-DECISIONAL // FOR OFFICIAL USE ONLY

Compliance is an evidence record, not a marketing line.

Every assertion on this page can be substantiated inside a controlled data room — by framework, by control family, and by the auditor who issued the report. What follows is the public posture of ArmyMARS Defense Systems, Inc. against the standards that govern U.S. Army, DoD, and allied defense software acquisitions.

  • DOCUMENTAMRS / CMP / 0014 — Rev. 11
  • ISSUED14 MAR 2026
  • PREPARED BYOffice of the Chief Information Security Officer
  • REVIEW CYCLEContinuous monitoring, annual attestation
Two officials reviewing sealed compliance binders at a long table inside a secure compartmented information facility.
38.9187° N  //  77.2284° W  //  1750 TYSONS BLVD UNCLASSIFIED // PHOTOGRAPH RELEASED FOR PUBLIC AFFAIRS USE

SECTION 01  //  CURRENT POSTURE

Six frameworks, audit-verified, continuously monitored.

Each entry below carries a current attestation date, the issuing or assessing body, the scope of assessment, and the most recent surveillance or re-certification cycle. Full reports — including the underlying control narratives, test procedures, and auditor findings — are available to cleared personnel inside our compliance data room.

SOC 2 ACTIVE

SOC 2 Type II

Issuing body: Independent registered public accounting firm

Trust criteria
Security, Availability, Confidentiality
Scope
MARS Platform & supporting cloud / on-prem enclaves
Audit window
12 months continuous
Last issued
Q4 2025, no qualified opinions

Renewed annually with no exceptions noted across the FY2024 operational year.

ISO 27001 CERTIFIED

ISO/IEC 27001:2022

Issuing body: UKAS-accredited certification body

Annex A controls
93 controls across 4 themes
Scope
ISMS covering engineering, hosting, and field support
Surveillance
Annual surveillance, 3-year re-certification
Last issued
08 JAN 2026, valid through 07 JAN 2029

Statement of Applicability v4.2 covers all 93 Annex A controls.

CMMC L3 CERTIFIED

CMMC Level 3

Issuing body: C3PAO under DoD Cyber AB

Model
CMMC 2.0, Level 3 (Expert)
Scope
Enclave handling CUI // SP-EX; CDI
Underlying
NIST SP 800-171 Rev. 3, all 110 controls
Last issued
Conditional, Q1 2026; final pending DIBCAC affirmation

Aligned with NIST SP 800-172 enhanced security requirements.

NIST 171 R3

NIST SP 800-171 Rev. 3

Assessed to: Protecting CUI in Nonfederal Systems

Controls
110 controls, 320 assessment objectives
Assessment
DIBCAC / C3PAO joint readiness review
Cycle
Triennial with annual affirmation
Status
SPRS score: 110 / 110

All 320 assessment objectives satisfied; pending CMMC L3 final issuance.

IL5 PROVISIONAL ATO

DoD IL5 Provisional ATO

Authorizing official: DoD Cloud Computing POR

Workload
Mission-critical, controlled unclassified, NSS
Hosting
GovCloud-equivalent, US-only personnel
FedRAMP baseline
High + DoD CC SRG IL5 overlay
Issued
FY2025; full ATO in progress

Initial authorization to operate granted in 23 days — 4.6x faster than the DoD median.

NIST 53 MODERATE

NIST SP 800-53 Rev. 5

Mapping to: Federal information systems & OEs

Baseline
Moderate, with selected High overlays
Control families
20 families, 326 controls addressed
FedRAMP alignment
FedRAMP Moderate equivalent
Last mapping
Rev. 5.1.1 alignment, Q4 2025

Operates as the control catalog our other frameworks inherit from.

CAGE 7X9M4 / UEI Q8N2LM3K9P71 / FCL TOP SECRET // SCI ELIGIBLE / SCIF 18,000 SQ FT — IL6-CAPABLE / NATO CIV NCN-2024-AIP

SECTION 02  //  ASSESSMENT DETAIL

What was actually tested, by whom, and on what cycle.

Each top framework is paired with the auditor-style annotation below: scope of assessment, evidence types collected, control families covered, and renewal cadence. We do not summarize away the substance of the work — we publish enough for a program security officer to plan their own review.

Auditors reviewing checklists inside a SCIF server rack room. FIG. 02.A — SOC 2 ON-SITE WALKTHROUGH, FY2025

FRAMEWORK 01 / SOC 2 TYPE II

Twelve months of operating effectiveness, not a point-in-time.

The Type II opinion covers the operating effectiveness of controls across the full FY2025 operational year — roughly 8,760 hours of sampled evidence. The auditor's testing universe includes change-management records, access provisioning tickets, vulnerability remediation logs, vendor reviews, and incident response timelines.

  • Auditor Independent third-party CPA firm, AICPA-registered
  • Sample size 60+ control tests across 12 months
  • Findings 0 exceptions noted in the most recent report
  • Next cycle FY2026 Type II, kickoff Q3 2026

FRAMEWORK 02 / CMMC LEVEL 3

All 110 NIST SP 800-171 Rev. 3 controls, expert-level.

CMMC Level 3 (Expert) is the highest tier under CMMC 2.0. The assessment validates that ArmyMARS protects Controlled Unclassified Information with the same rigor applied to higher-classification workloads — including the 35 enhanced security requirements drawn from NIST SP 800-172.

  • Assessor C3PAO candidate under DoD Cyber AB oversight
  • Scope CUI // SP-EX enclave, 4 facility zones
  • SPRS score 110 of 110 — pending DIBCAC affirmation
  • Reassessment Triennial, annual affirmation in interim
A bound CMMC Level 3 assessment binder with control tabs. FIG. 02.B — CMMC L3 ASSESSMENT ARTIFACT BINDER
A government Authorizing Official reviewing an IL5 provisional ATO package. FIG. 02.C — IL5 PROVISIONAL ATO REVIEW

FRAMEWORK 03 / DOD IL5 PROVISIONAL ATO

Mission-critical workloads, governed by DoD CC SRG IL5.

The provisional authorization permits ArmyMARS to operate the MARS Platform at Impact Level 5 — controlled unclassified information plus National Security Systems data — on a FedRAMP High baseline with the DoD Cloud Computing SRG IL5 overlay. The path to full ATO is in active review.

  • Authorizing official DoD Cloud Computing Program Office
  • Workload class Mission-critical, NSS-adjacent
  • Initial issuance 23 days from package acceptance
  • Path to ATO Continuous monitoring, full ATO in progress

FRAMEWORK 04 / ISO/IEC 27001:2022

An ISMS that touches every employee, not just engineering.

ISO 27001 certification extends beyond the platform to the Information Security Management System itself — including HR onboarding, vendor onboarding, physical access, internal audit, and management review. The 2022 revision incorporates threat intelligence and ICT readiness for business continuity as first-class controls.

  • Certifier UKAS-accredited certification body
  • Controls covered 93 of 93 Annex A controls in scope
  • Surveillance Annual, with three-year re-certification
  • Next surveillance MAR 2026
An ISO 27001 Statement of Applicability booklet open on a desk. FIG. 02.D — ISO 27001 STATEMENT OF APPLICABILITY, v4.2

SECTION 03  //  OPERATING DISCIPLINE

Continuous monitoring, not an annual checkbox.

Certifications are snapshots. Compliance is the daily work that makes a snapshot possible. At ArmyMARS the same engineering organization that ships the platform also operates the controls that protect it — controls are versioned, automated, and reviewed on a defined cadence by people whose job descriptions name the responsibility in plain language.

Every control inherits from a written policy in the ISMS, an automated test in our continuous monitoring stack, and a named owner whose quarterly attestation is recorded in an immutable ledger. Findings — when they occur — are triaged within four hours, remediated under a documented plan of action, and verified by an internal assessor before closure. New frameworks do not land as a scramble; they are added to the Statement of Applicability, mapped to existing controls where overlap exists, and gap-analyzed against named owners before attestation.

The result is a posture that an auditor can sample at any point in the year, not just in the second week of December. A program security officer who walks into our facility on any given Tuesday will see the same evidence they would see during a formal assessment — because the formal assessment is a window into work we are already doing, not work we prepared to perform.

Office of the CISO — ArmyMARS Defense Systems, Inc.

SECTION 04  //  CORROBORATING PARTIES

Posture corroborated by named assessors and institutional customers.

A posture is only as credible as the parties willing to put their name behind it. The list below is the public subset of auditors, assessment bodies, and federal programs that have engaged ArmyMARS on a documented basis. Classified program names are omitted per program security officer guidance.

  • Independent CPA Firm SOC 2 Type II auditor of record
  • UKAS-Accredited Certification Body ISO/IEC 27001:2022 certifier
  • DoD Cyber AB — C3PAO CMMC Level 3 assessment partner
  • DoD Cloud Computing POR IL5 provisional ATO issuing authority
  • U.S. Army Futures Command IDIQ customer — Tactical Intelligence Modernization Program
  • NATO SHAPE Allied Agile Intelligence Pilot, sole-source customer
  • Defense Contract Management Agency Contracting oversight across 41 active programs
  • GovTech 100 Listed 2023, 2024, 2025