What we operate. What we don't claim.
Federal engagements need a posture statement, not a marketing claim. Below is the operating posture ITC maintains today · the controls we actually run, the assessments we keep current, and the certifications we are NOT claiming. NYC MBE certified. SAM.gov active. SBA 8(a) application submitted 2026, under review.
NIST SP 800-171 Rev. 3 · self-assessment
110 controls, refreshed quarterly. SPRS scores published to contracting officers on request, under mutual NDA.
110-control walk every quarter
ITC operates the full NIST 800-171 Rev. 3 self-assessment refreshed on a calendar quarter. Each control is scored, evidenced, and dated. The score sheet is internal, the SPRS submission is what goes to government.
Published to SPRS on request
Contracting officers and primes can request the current SPRS score under mutual NDA. Score plus POA&M plus assessment date · those three together are the only artifact a CO needs to verify posture.
Not a 3PAO assessment
We do NOT claim a third-party assessment under DFARS 252.204-7012. When a solicitation calls for one, we scope the C3PAO engagement into the bid budget honestly. The line between self and 3PAO matters and we keep it visible.
CMMC Level 2 · readiness stance
CMMC 2.0 Final Rule (Dec 2024) requires Level 2 third-party assessment for primes handling CUI. We operate a readiness stance, not a certification claim.
800-171 controls in place
The NIST 800-171 baseline that CMMC L2 inherits is operational today, evidenced under § 01 above.
Not yet scheduled
We have not yet scheduled a formal Level 2 assessment with a C3PAO. When required, we scope it into the proposal.
Scope C3PAO into the bid
If the engagement requires Level 2 cert as a flow-down to subs, we add the C3PAO engagement to the proposal cost basis.
Team with a holding prime
Or we team with a prime that already holds the cert. We do not assert a Level 2 status we have not earned.
What we operate · what we don't claim
The honest scope line. Left column is the operating posture today. Right column is what is NOT held, NOT in audit, NOT being prepared.
- FedRAMP-aligned cloud · AWS GovCloud, Azure Government, Google Workspace Federal per engagement scope
- Zero Trust principles per NIST SP 800-207 in network and identity design
- NIST SP 800-53 Rev. 5 controls for ATO-track engagements
- Endpoint detection and response on every engineer's workstation
- MFA via hardware FIDO2 keys for any account with admin access
- Quarterly internal access review · removal within 24 hours of role change
- Annual security awareness training (NIST 800-50 baseline)
- Incident response runbooks per NIST 800-61 Rev. 2 · tabletop quarterly
- Service-organization attestations of any type · not held, not in audit, not preparing
- FedRAMP authorization · the entity is not authorized; we operate FedRAMP-aligned cloud per scope
- CMMC Level 1, 2, or 3 certification · readiness only
- ISO 27001 · not pursued; controls operational under NIST 800-171
- HUBZone: no · parent-firm application denied 2023; solicitation disclosure remains “HUBZone: no”
- SBA 8(a) program participation · application submitted 2026 and under SBA review, not awarded
- GSA MAS award · pursuing, not holding
- NYS MWBE · not held. The 2026 Fast Track route was closed to ITC as a Delaware-formed entity; no standard application is pending today
- TAA compliance without solicitation-specific scoping
- Brand-name flow-downs from primes without a written sub-agreement
- Standing 24/7 SOC or NOC operations
- 3PAO formal assessment under DFARS 252.204-7012 · scoped per engagement
Certifications we do hold
Four lines, each verifiable in a public registry. No marketing varnish on any of them.
DSBS #MWCERT2022-353
NYC Department of Small Business Services. Expires 2027-05-31. NMSDC-certified MBE · NY/NJ MSDC · through 2027-06-30.
Active through 2027-06-11
UEI PR9KWJPM4JU9 · CAGE 91CE1. Reps and certs current. NAICS list filed.
Application under review
Submitted 2026, under SBA review. We will publish the determination on this page when it lands.
Registered vendor
NYC PASSPort vendor VS00075284. NYC MBE certified through 2027-05-31.
How to verify · under mutual NDA
Six artifacts. Contracting officers and prime capture managers can request any of them. We reply same business day.
Current SPRS score
The current NIST 800-171 self-assessment score as submitted to SPRS, plus the assessment date and the basic-versus-medium classification. Under mutual NDA.
Current SSP + POA&M
System Security Plan and Plan of Action & Milestones for in-scope engagements. Real document, real dates, real remediation timeline. Under mutual NDA.
DFARS 252.204-7012 representation
The clause-by-clause representation that goes into a federal proposal. What we comply with, what flows down, and where the 3PAO line sits.
Sample CMMC readiness gap analysis
A redacted example of the gap analysis we run before a Level 2 engagement. Useful for a capture manager scoping the C3PAO budget.
Cyber insurance endorsement
Hartford Workers' Comp policy 46 WEG CC0S3C-001 (04/30/2026 to 04/30/2027). Hartford General Liability bound on-award. COI furnished by request.
Referee list past engagements
Two named public-sector references plus additional under NDA. PPQs available to contracting officers on request. The referees are real and will pick up the phone.