Certifications

The mountains we climb

Every certification we guide is one our SMEs have taken clients through, from Fortune 10 vendors to mid-market and startup product companies.

RequirementsControlsEvidenceValidationCertified

How a certification is earned

Requirements to certification, mapped.

Scope, framework, and timeline definition

Requirements1 of 5Controls2 of 5Evidence3 of 5Validation4 of 5Certification5 of 5

Scope, framework, and timeline definition

The certifications we guide

Eight Federal programs, one accountable team.

  • Who needs it. Vendors whose products use cryptography to protect Controlled Unclassified Information (CUI) in the US and Canada.

    Scope of work. · Initial Assessment (high level understanding of the product, scope, targeted user(s), implementation, targeted release and release date, etc.) · Gap Analysis and determination of targeted Level (1-4) for the cryptographic module (can be a software module, chip, complete hardware, firmware or software product...depends on the boundary) · Guidance on Post Quantum Cryptography (PQC), Implementation Guidance, etc. · Design consultation to close identified gaps in the architecture · Guidance to design future releases with “FIPS in mind” · Documentation preparation (Security Policy, Cryptographic Module Specification, Finite State Model, Vendor Evidence, etc.) · CAVP Algorithm Testing and Certification · Entropy Source Validation · Project Management · Testing Lab recommendations and pricing negotiations

Not sure which service you need?Start with a discovery call.

Start with a call