ISO/IEC 17020 accredited inspection body · Cleared facility (FCL)

Cybersecurity · compliance · assessment

Security outcomes that hold up under independent scrutiny.

DASATECH serves federal agencies, defense organizations, government contractors and cloud service providers. We cover gap assessment, documentation, penetration testing, remediation, authorization and the continuous monitoring that follows.

ISO/IEC 17020Accredited inspection body
ClearedFacility clearance (FCL)
10+ yrsFedRAMP High & DoD IL4–IL6
FedRAMPHigh, Moderate, Low · Rev. 5 baselines
DoD SRGImpact Levels 4, 5 and 6
FISMA / RMFSP 800-37 Rev. 2 · 800-53 Rev. 5
DFARS252.204-7012 · NIST SP 800-171
HIPAA / HITECHSecurity Rule safeguards

Organizational qualifications

Credentials that change who is allowed to assess you.

ACCREDITATION

ISO/IEC 17020 accredited

Our assessment and inspection work is delivered under an internationally recognized standard for impartiality and technical competence. An external body assessed it against that standard.

CLEARANCE

A cleared facility

DASATECH holds a facility clearance, so we can support classified government programs and sensitive national security work that most compliance firms cannot be cleared to touch.

MULTI-CLOUD

Hands-on across every major platform

Microsoft Azure Government, AWS GovCloud, AWS Commercial, Google Cloud Platform and hybrid environments, for architecture work and assessment alike.

Capabilities

Nine services, one discipline: evidence that holds up under review.

Every engagement produces artifacts an assessor, an agency reviewer or a prime’s supply-chain team can act on without a second round of questions.

Sample output

What an assessment actually tells you.

A control-family view of where the evidence supports your claims and where it does not, with the weak families named before anyone else names them.

CONTROL SATISFACTION BY FAMILY, SP 800-53 REV. 5 AC92%AT100%AU74%CA88%CM66%CP81%IA58%IR95%MA100%MP89%PE97%PL100%PS93%RA71%SA84%SC62%SI79%SR55%≥90% SATISFIED70–89%<70%, PRIORITY
Control satisfaction across the eighteen SP 800-53 Rev. 5 families.

Example values, shown to illustrate the format of the output rather than results from any engagement.

Why DASATECH

Assessors who have also had to write the package.

Most delays trace back to documentation rather than security. A control narrative that does not match the architecture. A POA&M with no remediation path. Evidence that proves the wrong thing.

We have worked both sides of that table for federal agencies and their contractors. That is why our reports get accepted, and why our timelines are shorter than the rework cycle you are trying to avoid.

  • Independent. We do not sell the tooling or the remediation labor we assess, so findings are not a sales channel.
  • Framework-fluent. One system usually answers to several frameworks at once; we map the overlap so a control is tested once and reused.
  • Written for the reviewer. Deliverables follow the templates and language the receiving agency, prime or assessor already reads.
  • Senior-led. The consultant who scopes your engagement is the consultant who performs it.
  • Honest about gaps. A finding you learn from us is cheaper than the same finding from a 3PAO.

Frameworks

What each regime actually asks of you.

Federal Information Security Modernization Act

FISMA obliges federal agencies (and the private organizations operating systems on their behalf) to run their systems under the NIST Risk Management Framework. In practice that means categorizing the system, selecting and implementing a control baseline, having those controls independently assessed, and obtaining an authorization decision from an Authorizing Official.

DASATECH runs the cycle end to end, or joins a stalled one and finishes it.

FISMA SA&A service

RMF steps

  • Prepare (scope, roles, system boundary)
  • Categorize (FIPS 199 and SP 800-60 information types)
  • Select (SP 800-53 Rev. 5 baseline and tailoring)
  • Implement (controls and control narratives)
  • Assess (SP 800-53A testing, SAR and POA&M)
  • Authorize (risk decision by the AO)
  • Monitor (ongoing ConMon and reauthorization)

Federal Risk and Authorization Management Program

FedRAMP is the standardized authorization path for cloud services sold to the federal government. The bar is high and the package is large: a system security plan against the Rev. 5 baselines, more than a dozen supporting plans, and an independent assessment before any agency will consider sponsorship.

We build that package, run the readiness review that finds the problems before the 3PAO does, and support you through the audit and into continuous monitoring.

FedRAMP advisory service

Package components

  • FIPS 199 categorization and boundary definition
  • System Security Plan and control implementation summary
  • Policies and procedures across all control families
  • ISCP, CMP, IRP, rules of behavior, user guide
  • Privacy threshold and impact analysis
  • Continuous monitoring plan and monthly reporting

DFARS 252.204-7012 and NIST SP 800-171

Any contractor whose systems process, store or transmit Covered Defense Information or CUI carries a standing obligation to implement NIST SP 800-171 and to report an assessment score in SPRS. That obligation has been contractual for years and has not moved. It applies whether or not anyone comes to check.

We assess the 110 requirements, correct the score, build the SSP and POA&M, and get you ready for whichever assessment type your contract calls for.

NIST SP 800-171 service

Where contractors lose points

  • CUI boundary never formally defined
  • SPRS score self-reported without evidence behind it
  • Policies written generically, not to the 14 families
  • MFA and FIPS-validated cryptography partially deployed
  • No audit log review actually performed
  • POA&M items with no owner and no date

HIPAA Security Rule and the HITECH Act

Organizations that create, receive, maintain or transmit electronic protected health information must implement administrative, physical and technical safeguards, and must perform an accurate risk analysis of where that ePHI lives. That risk analysis is the single most commonly cited deficiency in enforcement actions.

We test the safeguards against real evidence and give you a report that shows a regulator, a customer or an acquirer exactly where you stand.

HIPAA assessment service

Assessment scope

  • Administrative safeguards and workforce controls
  • Physical safeguards and facility access
  • Technical safeguards, encryption and audit controls
  • Business associate agreements and flow-down
  • Breach notification readiness
  • ePHI inventory and data flow mapping

Our own tooling

We build AI-native tools for regulated work, and we run them ourselves.

Two platforms, both born from our own delivery work. AssessIQ executes assessments across FedRAMP, FISMA, DoD SRG and FedRAMP 20x. Proposal iQ finds federal and state opportunities, analyzes the solicitation and drafts the response.

In both, the expert keeps every judgment call. What comes out of the schedule is the reading and the cross-referencing around it.

120 hrsRecovered per assessor month
10Framework configurations
5,262Catalog procedures built in
14 daysModerate analysis phase

Engagement model

Fixed scope. Named deliverables. A date.

We scope from the contract clause or the framework requirement, not from an hourly estimate. You get the list of documents you will receive, who produces each one, what we need from your team, and when it lands.

Tell us what the contract requires. We’ll tell you what it takes.

A 30-minute scoping call is usually enough to size the gap, name the deliverables and give you a realistic date for authorization.