SITE LIVENDA AVAILABLE ON REQUESTFEDRAMP · SOC 2 · PCI DSS · ISO 27001REQUEST A BRIEFINGSECURITY & DISCLOSURE
NDA Standard

Defence

Organizations in the defense supply chain operate under sustained, targeted adversarial pressure and strict compliance requirements. We provide the technical assessment and engineering work that supports both.

What this sector needs

Defense contractors and suppliers face a combination most sectors don't: adversaries with real resources and intent, plus formal compliance requirements (frequently including FedRAMP and CMMC-aligned controls) that demand technical evidence, not just policy documentation.

Typical technical environments

Environments we see in this sector vary widely — from traditional on-prem infrastructure with air-gapped or segmented networks, to hybrid cloud deployments built around AWS GovCloud or Azure Government, to modern Kubernetes-based platforms supporting program software. Legacy systems running alongside newer cloud-native infrastructure is common, and the security posture of that boundary is frequently where the real risk sits.

Common security failures

Engagement boundaries

Access model and scope depend on the engagement type — this isn't one-size-fits-all across our services:

Whatever the engagement, access is defined in the scope of work before anything starts — not assumed or expanded mid-engagement.

Evidence and reporting

Findings are delivered as a technical report with severity ranking, supporting evidence, and remediation guidance specific enough for your engineering team to act on without a follow-up call. For assessments run under contractual confidentiality or classification handling requirements, evidence packaging and retention terms are agreed as part of scoping — not applied as a generic default. See Security & Disclosurefor our baseline evidence-handling practices.

Supply-chain security

A hardened prime contractor environment doesn't close the risk if a subcontractor with system access isn't held to the same standard. We assess supply-chain exposure as part of infrastructure and penetration-testing engagements where relevant — mapping what access third parties actually have, not just what the contract says they should have.

Cloud and Kubernetes concerns

Government cloud environments (AWS GovCloud, Azure Government) carry the same misconfiguration risks as commercial cloud, plus additional boundary and access requirements specific to the environment. Where Kubernetes is in play — increasingly common for program software — our Kubernetes Security Assessment covers cluster configuration, RBAC, and workload isolation with the same technical depth we'd apply anywhere else.

Compliance relationship

ACS has prepared infrastructure for and passed FedRAMP audits — this is direct engineering experience, not advisory-only. OurCompliance Security Engineeringservice implements the technical controls a FedRAMP assessment tests; the formal authorization decision itself sits with the accredited 3PAO and authorizing agency, not with ACS. See FedRAMP Readiness for framework-specific detail.

How ACS supports this

Engagement model

Work in this sector is conducted under NDA as standard practice. Specific engagement history is restricted by contractual and confidentiality requirements — see ourcase studies for what can be shared, and ourAbout page for how ACS handles confidentiality.

DEFENCE SECTOR — FAQ

Do you work with subcontractors as well as prime contractors?

Yes. Assessment and engineering scope is defined by your actual environment and contractual obligations, not by where you sit in the supply chain.

Can engagements be scoped around classified or CUI-adjacent systems?

We work with unclassified environments, including those handling Controlled Unclassified Information (CUI). We don't hold personnel clearances for classified work — tell us your environment during scoping and we'll confirm fit before you commit to anything.

Do you support CMMC-related technical work?

CMMC control implementation follows the same infrastructure-engineering model as our FedRAMP work — technical controls implemented and validated, not just documented. It's not yet a page of its own on this site; ask directly and we'll confirm current scope.

How is evidence handled for a sector with strict data-handling requirements?

Engagement evidence is scoped, encrypted in transit and at rest where it must leave your environment, and retained only as long as the engagement and any agreed retest period require. See Evidence & Reporting below and our Security & Disclosure page.

What access model applies to a defense-sector infrastructure assessment?

Read-only access to the relevant systems, scoped to what the assessment needs — this is the standard model for our Infrastructure Security Assessment engagement. It's not universal across every service; see Engagement Boundaries below for what differs by engagement type.

Can you coordinate with our existing FSO or facility security requirements?

Yes — tell us your facility and personnel security constraints during scoping. Engagement logistics (on-site vs. remote, escort requirements, equipment restrictions) are worked out before the engagement starts, not discovered mid-engagement.

Contact Us

Tell us your environment and compliance requirements. We'll scope an engagement that fits both.