1 · Federal registrations

Identity primitives every federal sub needs before a prime can issue a sub-PO. All active.

UEI (Unique Entity ID)Active QDL3BAL1NLY3
CAGE CodeActive 212P3
SAM.gov registrationActive
DUNSN/A — deprecated in favor of UEI as of 2022
Capability StatementView online HTML

Cloud & platform registrations

Vendor program registrations, listed separately from federal registrations. Registration is not certification and carries no tier.

AWS Partner NetworkRegistered Registration only — no competency, tier, or designation claimed
Google Cloud Partner NetworkRegistered Registered tier — no advanced tier, competency, or certification claimed
Hosting postureAWS GovCloud / Azure Government deployments when the engagement requires it — not pursued as a cloud service provider

2 · NAICS codes

Five codes registered under our active SAM.gov registration.

CodeDescription
541511Custom Computer Programming Services
541512Computer Systems Design Services
541519Other Computer Related Services
541715Research and Development in the Physical, Engineering, and Life Sciences
518210Computing Infrastructure Providers, Data Processing, Hosting, and Related Services

Management-consulting NAICS (541611, 541618, 541690) are deliberately excluded — we do not pursue strategy-consulting work; these codes would dilute the discrete-software-delivery positioning.

3 · Cybersecurity & data handling

What a prime's compliance officer or CISO checks first. We operate in the civilian / unclassified lane only. For a plain-English summary written for program IT as well as primes, see our Security & Data Handling one-pager.

NIST SP 800-171 practicesPlanned Formal self-assessment not yet completed; no SPRS submission on file. Performed per CUI engagement when required
Government cloud hostingDeployment option AWS GovCloud or Azure Government inside a client- or prime-approved authorization boundary; OlenArc holds no FedRAMP authorization
FedRAMP authorization as CSPNot pursued — we are not a Cloud Service Provider; hosting environments are approved per engagement
Plain-English security summaryPublished See our Security & Data Handling one-pager
Personnel clearancesNot pursued — civilian / unclassified posture only

What we can state today

  • Civilian / unclassified work only; no clearances held or pursued.
  • OlenArc does not accept CUI by default. Any CUI requirement would be scoped and agreed in writing per engagement before acceptance.
  • No formal NIST SP 800-171 self-assessment has been performed, and no SPRS submission is on file.
  • No FedRAMP authorization, SOC 2 report, or ISO 27001 certification is held.
  • Security controls, hosting environment, and data-handling requirements are confirmed per engagement and documented in the SOW.

Security questionnaires are answered per engagement, in writing, under mutual NDA — send yours to Team@OlenArc.com.

4 · Domain compliance

Compliance posture for civilian-agency program domains we typically deliver into.

Accessibility (Section 508 / WCAG 2.1 AA)In delivery Accessibility requirements and testing are incorporated into project delivery; conformance documentation is produced per engagement, not claimed in advance
HIPAA-aware development practicePer engagement OlenArc does not accept PHI by default. Any PHI scope requires confirmed safeguards, written contractual terms, and client or prime approval before acceptance.
Data sovereignty-aware designOperational See Federal & Teaming › Responsible Data Use

5 · Insurance posture

General Liability and Professional Liability / E&O are active and in force, underwritten by Next Insurance (a licensed U.S. carrier). A Certificate of Insurance (COI) — with a prime named as additional insured where the agreement requires — is available on request.

General LiabilityActive $1M each occurrence / $2M aggregate
Professional Liability / Errors & Omissions (E&O)Active $1M per claim / $1M aggregate
Cyber LiabilityBindable on award $1M–$5M
Workers' CompensationAs required by state and engagement structure

Policies will be flow-down friendly to typical prime requirements (FAR 52.228-7 indemnification clause and related sub-agreement language).

Need a COI on file?

Need a Certificate of Insurance for a teaming conversation or sub-PO? Email Team@OlenArc.com with subject "Insurance COI request" — we’ll send our current COI (with your entity named as additional insured where the agreement requires) within 2 business days.

6 · Set-aside eligibility

OlenArc is not currently eligible for federal small-business set-aside programs. This affects how a prime's 50% self-performance math works under FAR 52.219-14.

8(a) Business DevelopmentNot eligible — ownership requirements
HUBZoneNot eligible — HUBZone area and employee-residency criteria not met
WOSB / EDWOSBNot applicable
SDVOSB / VOSBNot applicable

Practical implication for an 8(a) prime: OlenArc is a non-similarly-situated entity. Sub-performance counts toward the 50% subcontracting allowance under FAR 52.219-14 — not toward the prime's self-performance.

7 · Certifications we deliberately do not pursue

Where we're out of lane. Primes often ask about these; we disqualify ourselves early from work that isn't a fit.

Certification / postureWhy we do not pursue
CMMC Level 2No DoD CUI work in our scope. We operate in the civilian / unclassified lane.
DFARS 252.204-7012Same — we do not pursue DoD CUI contracts. A formal self-assessment would be required before OlenArc accepts any CUI scope.
FedRAMP authorization (as CSP)We are not a Cloud Service Provider. Hosting environments (including AWS GovCloud / Azure Government) are selected and approved per engagement; OlenArc holds no FedRAMP authorization.
ISO 9001 / 27001ROI does not justify for our team size at this stage. Open to pursuing if a specific task order makes one a gating requirement.
HITRUST CSFNot in the healthcare-data scale that justifies HITRUST. OlenArc does not accept PHI by default; any PHI scope requires confirmed safeguards, written contractual terms, and client or prime approval before acceptance.
Facility / personnel security clearancesCivilian / unclassified posture only. Personnel-eligibility requirements (e.g., Public Trust screening) are confirmed per engagement before commitment — not promised in advance.
DCAA-compliant accounting systemNot pursuing cost-plus contract structures. Fixed-price and T&M engagements only.

Compliance, procurement, or BD intake question?

Email or book a 25-minute call. We respond within two business days.

Book a call