Compliance & security posture
For prime BD intake teams and compliance officers. Where OlenArc stands on every registration, certification, and compliance posture a federal subcontractor gets asked about — including the ones we deliberately do not pursue. Registrations, insurance, and core security practices are active today; the deep DoD-specific artifacts (formal NIST self-assessment, SPRS) have not been performed — they would be scoped per engagement if a CUI requirement ever applies. OlenArc does not accept CUI by default. For a plain-English summary, see our Security & Data Handling one-pager.
Last updated: June 2026. For compliance-officer questions: Team@OlenArc.com (response within two business days).
1 · Federal registrations
Identity primitives every federal sub needs before a prime can issue a sub-PO. All active.
| UEI (Unique Entity ID) | Active QDL3BAL1NLY3 |
|---|---|
| CAGE Code | Active 212P3 |
| SAM.gov registration | Active |
| DUNS | |
| Capability Statement | View online HTML |
Cloud & platform registrations
Vendor program registrations, listed separately from federal registrations. Registration is not certification and carries no tier.
| AWS Partner Network | Registered |
|---|---|
| Google Cloud Partner Network | Registered |
| Hosting posture |
2 · NAICS codes
Five codes registered under our active SAM.gov registration.
| Code | Description |
|---|---|
| 541511 | Custom Computer Programming Services |
| 541512 | Computer Systems Design Services |
| 541519 | Other Computer Related Services |
| 541715 | Research and Development in the Physical, Engineering, and Life Sciences |
| 518210 | Computing Infrastructure Providers, Data Processing, Hosting, and Related Services |
Management-consulting NAICS (541611, 541618, 541690) are deliberately excluded — we do not pursue strategy-consulting work; these codes would dilute the discrete-software-delivery positioning.
3 · Cybersecurity & data handling
What a prime's compliance officer or CISO checks first. We operate in the civilian / unclassified lane only. For a plain-English summary written for program IT as well as primes, see our Security & Data Handling one-pager.
| NIST SP 800-171 practices | Planned |
|---|---|
| Government cloud hosting | Deployment option |
| FedRAMP authorization as CSP | |
| Plain-English security summary | Published |
| Personnel clearances |
What we can state today
- Civilian / unclassified work only; no clearances held or pursued.
- OlenArc does not accept CUI by default. Any CUI requirement would be scoped and agreed in writing per engagement before acceptance.
- No formal NIST SP 800-171 self-assessment has been performed, and no SPRS submission is on file.
- No FedRAMP authorization, SOC 2 report, or ISO 27001 certification is held.
- Security controls, hosting environment, and data-handling requirements are confirmed per engagement and documented in the SOW.
Security questionnaires are answered per engagement, in writing, under mutual NDA — send yours to Team@OlenArc.com.
4 · Domain compliance
Compliance posture for civilian-agency program domains we typically deliver into.
| Accessibility (Section 508 / WCAG 2.1 AA) | In delivery |
|---|---|
| HIPAA-aware development practice | Per engagement |
| Data sovereignty-aware design | Operational |
5 · Insurance posture
General Liability and Professional Liability / E&O are active and in force, underwritten by Next Insurance (a licensed U.S. carrier). A Certificate of Insurance (COI) — with a prime named as additional insured where the agreement requires — is available on request.
| General Liability | Active |
|---|---|
| Professional Liability / Errors & Omissions (E&O) | Active |
| Cyber Liability | Bindable on award |
| Workers' Compensation |
Policies will be flow-down friendly to typical prime requirements (FAR 52.228-7 indemnification clause and related sub-agreement language).
Need a COI on file?
Need a Certificate of Insurance for a teaming conversation or sub-PO? Email Team@OlenArc.com with subject "Insurance COI request" — we’ll send our current COI (with your entity named as additional insured where the agreement requires) within 2 business days.
6 · Set-aside eligibility
OlenArc is not currently eligible for federal small-business set-aside programs. This affects how a prime's 50% self-performance math works under FAR 52.219-14.
| 8(a) Business Development | |
|---|---|
| HUBZone | |
| WOSB / EDWOSB | |
| SDVOSB / VOSB |
Practical implication for an 8(a) prime: OlenArc is a non-similarly-situated entity. Sub-performance counts toward the 50% subcontracting allowance under FAR 52.219-14 — not toward the prime's self-performance.
7 · Certifications we deliberately do not pursue
Where we're out of lane. Primes often ask about these; we disqualify ourselves early from work that isn't a fit.
| Certification / posture | Why we do not pursue |
|---|---|
| CMMC Level 2 | No DoD CUI work in our scope. We operate in the civilian / unclassified lane. |
| DFARS 252.204-7012 | Same — we do not pursue DoD CUI contracts. A formal self-assessment would be required before OlenArc accepts any CUI scope. |
| FedRAMP authorization (as CSP) | We are not a Cloud Service Provider. Hosting environments (including AWS GovCloud / Azure Government) are selected and approved per engagement; OlenArc holds no FedRAMP authorization. |
| ISO 9001 / 27001 | ROI does not justify for our team size at this stage. Open to pursuing if a specific task order makes one a gating requirement. |
| HITRUST CSF | Not in the healthcare-data scale that justifies HITRUST. OlenArc does not accept PHI by default; any PHI scope requires confirmed safeguards, written contractual terms, and client or prime approval before acceptance. |
| Facility / personnel security clearances | Civilian / unclassified posture only. Personnel-eligibility requirements (e.g., Public Trust screening) are confirmed per engagement before commitment — not promised in advance. |
| DCAA-compliant accounting system | Not pursuing cost-plus contract structures. Fixed-price and T&M engagements only. |
Compliance, procurement, or BD intake question?
Email or book a 25-minute call. We respond within two business days.