Overview
In federal procurement
DJ01 is the federal PSC for IT security and compliance support delivered as labor: assessing posture, scoping ATO packages, and planning remediation. Agencies use it for cybersecurity advisory and compliance-documentation contracts. ITC advises against NIST 800-53, NIST 800-171, and CMMC framework requirements and produces written documentation; ITC is not itself certified under these frameworks and does not operate a standing 24/7 SOC, and says so.
How a contracting officer reads this code.
UEI PR9KWJPM4JU9 · CAGE 91CE1 ·
is filed in ITC's SAM PSC assertions.
The same capability, commercially
Commercially, DJ01 maps to the compliance and security-advisory engagement that regulated mid-market firms (healthcare, finance, contractors) buy to satisfy their own customers’ due diligence: a written gap analysis and remediation roadmap. The advisory capability is the same as the government version. ITC delivers advisory and documentation only, not third-party audit or attestation services.
Mid-market, SMB, and enterprise buyers.
A PSC only matters when the buyer is a federal agency. The underlying service is the same for commercial buyers.
What falls under DJ01
The work, and the ITC services that deliver it.
We are happy to consult on which PSC and NAICS best represent the work for your specific scope.
NIST 800-53 / 800-171 gap analysis
CMMC 2.0 readiness advisory
ATO package scoping (SSP, SAR, POA&M)
Security documentation for vendor due diligence
Common questions
Is ITC certified under the frameworks it advises on?
No. ITC provides advisory and documentation against NIST and CMMC requirements but is not itself certified under those frameworks, and it does not operate a standing 24/7 security operations center. ITC delivers advisory only, not third-party audit or attestation.
Related codes
Send the scope
We'll confirm the right PSC and NAICS for your solicitation, government or commercial.