IT Custom SolutionFour Practices, One Firm · Est. MMXXI
§ Compliance Posture · NIST 800-171 + CMMC

What we operate. What we don't claim.

Federal engagements need a posture statement, not a marketing claim. Below is the operating posture ITC maintains today · the controls we actually run, the assessments we keep current, and the certifications we are NOT claiming. NYC MBE certified. SAM.gov active. SBA 8(a) application submitted 2026, under review.

§ Posture lead
Lu Fagbure · Founder & Director
§ Federal posture
UEI PR9KWJPM4JU9 · CAGE 91CE1
§ Effective
2026-04-30 · Reviewed quarterly
§ 01

NIST SP 800-171 Rev. 3 · self-assessment

110 controls, refreshed quarterly. SPRS scores published to contracting officers on request, under mutual NDA.

§ A · Self-assessment

110-control walk every quarter

ITC operates the full NIST 800-171 Rev. 3 self-assessment refreshed on a calendar quarter. Each control is scored, evidenced, and dated. The score sheet is internal, the SPRS submission is what goes to government.

§ B · SPRS submission

Published to SPRS on request

Contracting officers and primes can request the current SPRS score under mutual NDA. Score plus POA&M plus assessment date · those three together are the only artifact a CO needs to verify posture.

§ C · 3PAO honesty

Not a 3PAO assessment

We do NOT claim a third-party assessment under DFARS 252.204-7012. When a solicitation calls for one, we scope the C3PAO engagement into the bid budget honestly. The line between self and 3PAO matters and we keep it visible.

§ 02

CMMC Level 2 · readiness stance

CMMC 2.0 Final Rule (Dec 2024) requires Level 2 third-party assessment for primes handling CUI. We operate a readiness stance, not a certification claim.

§ Baseline

800-171 controls in place

The NIST 800-171 baseline that CMMC L2 inherits is operational today, evidenced under § 01 above.

§ C3PAO

Not yet scheduled

We have not yet scheduled a formal Level 2 assessment with a C3PAO. When required, we scope it into the proposal.

§ Path A

Scope C3PAO into the bid

If the engagement requires Level 2 cert as a flow-down to subs, we add the C3PAO engagement to the proposal cost basis.

§ Path B

Team with a holding prime

Or we team with a prime that already holds the cert. We do not assert a Level 2 status we have not earned.

§ 03

What we operate · what we don't claim

The honest scope line. Left column is the operating posture today. Right column is what is NOT held, NOT in audit, NOT being prepared.

In scope
  • FedRAMP-aligned cloud · AWS GovCloud, Azure Government, Google Workspace Federal per engagement scope
  • Zero Trust principles per NIST SP 800-207 in network and identity design
  • NIST SP 800-53 Rev. 5 controls for ATO-track engagements
  • Endpoint detection and response on every engineer's workstation
  • MFA via hardware FIDO2 keys for any account with admin access
  • Quarterly internal access review · removal within 24 hours of role change
  • Annual security awareness training (NIST 800-50 baseline)
  • Incident response runbooks per NIST 800-61 Rev. 2 · tabletop quarterly
Out of scope
  • Service-organization attestations of any type · not held, not in audit, not preparing
  • FedRAMP authorization · the entity is not authorized; we operate FedRAMP-aligned cloud per scope
  • CMMC Level 1, 2, or 3 certification · readiness only
  • ISO 27001 · not pursued; controls operational under NIST 800-171
  • HUBZone: no · parent-firm application denied 2023; solicitation disclosure remains “HUBZone: no”
  • SBA 8(a) program participation · application submitted 2026 and under SBA review, not awarded
  • GSA MAS award · pursuing, not holding
  • NYS MWBE · not held. The 2026 Fast Track route was closed to ITC as a Delaware-formed entity; no standard application is pending today
  • TAA compliance without solicitation-specific scoping
  • Brand-name flow-downs from primes without a written sub-agreement
  • Standing 24/7 SOC or NOC operations
  • 3PAO formal assessment under DFARS 252.204-7012 · scoped per engagement
§ 04

Certifications we do hold

Four lines, each verifiable in a public registry. No marketing varnish on any of them.

§ NYC MBE

DSBS #MWCERT2022-353

NYC Department of Small Business Services. Expires 2027-05-31. NMSDC-certified MBE · NY/NJ MSDC · through 2027-06-30.

§ SAM.gov

Active through 2027-06-11

UEI PR9KWJPM4JU9 · CAGE 91CE1. Reps and certs current. NAICS list filed.

§ SBA 8(a)

Application under review

Submitted 2026, under SBA review. We will publish the determination on this page when it lands.

§ NYC PASSPort

Registered vendor

NYC PASSPort vendor VS00075284. NYC MBE certified through 2027-05-31.

§ 05

How to verify · under mutual NDA

Six artifacts. Contracting officers and prime capture managers can request any of them. We reply same business day.

§ A

Current SPRS score

The current NIST 800-171 self-assessment score as submitted to SPRS, plus the assessment date and the basic-versus-medium classification. Under mutual NDA.

§ B

Current SSP + POA&M

System Security Plan and Plan of Action & Milestones for in-scope engagements. Real document, real dates, real remediation timeline. Under mutual NDA.

§ C

DFARS 252.204-7012 representation

The clause-by-clause representation that goes into a federal proposal. What we comply with, what flows down, and where the 3PAO line sits.

§ D

Sample CMMC readiness gap analysis

A redacted example of the gap analysis we run before a Level 2 engagement. Useful for a capture manager scoping the C3PAO budget.

§ E

Cyber insurance endorsement

Hartford Workers' Comp policy 46 WEG CC0S3C-001 (04/30/2026 to 04/30/2027). Hartford General Liability bound on-award. COI furnished by request.

§ F

Referee list past engagements

Two named public-sector references plus additional under NDA. PPQs available to contracting officers on request. The referees are real and will pick up the phone.

§ 06
§ Posture packet

Send the solicitation. We'll send the posture packet.

§ SPRS ·Score on request, under NDA
§ UEI ·PR9KWJPM4JU9 · CAGE 91CE1