Skip to main content

Compliance as code for federal DevSecOps. Now accepting design partners

REAEGIS
COMPLIANCE INTELLIGENCE

Six dimensions of compliance posture that do not appear in a standard control assessment — until contract award.

NIST SP 800-53 assessment coverage is necessary but not sufficient for maintaining DoD contract eligibility in 2026. These six dimensions each carry specific regulatory obligations, fixed deadlines, or direct contract liability exposure that operate independently of the control implementation baseline.

Six live modules

Computed from your system state. Not typed into forms.

SPRS Score Calculator

DFARS 252.204-7021

The Supplier Performance Risk System score is the numerical representation of a contractor's NIST SP 800-171 posture, computed per the DoD Assessment Methodology. Each of the 110 practices carries a point weight of 1, 3, or 5. Unimplemented practices are deducted. Maximum: +110. Minimum: -203.

The score is entered into SPRS and affirmed annually by a senior official. Prime contractors increasingly set minimum score thresholds — frequently 88 or above — as pre-qualification criteria. A contractor below that threshold may not reach the technical evaluation.

REAEGIS computes the score continuously from the control implementations already maintained in the program. The gap-to-threshold analysis identifies the specific practices, in point-weight order, that when implemented would bring the score to the target threshold.

FedRAMP 20x KSI Dashboard

RFC-0024 · Sept 30, 2026

FedRAMP 20x replaces narrative security authorization documentation with Key Security Indicators — objectively measurable, continuously validated security properties. RFC-0024 requires all FedRAMP providers to produce OSCAL-formatted KSI assessment packages by September 30, 2026. This applies to every provider holding current FedRAMP authorization, not only 20x participants.

The Moderate baseline includes 61 KSIs spanning access management, vulnerability management, audit and logging, boundary protection, incident response, and supply chain. Each KSI maps to one or more FedRAMP controls and must be validated against objective evidence.

REAEGIS evaluates KSIs automatically from connected system data: finding age and severity for vulnerability KSIs, SBOM currency for supply chain KSIs, evaluation records for monitoring KSIs. The resulting assessment package is produced in OSCAL format, signed with Cosign, and ready for PMO submission.

Penetration Testing (CA-8)

NIST SP 800-53 CA-8

CA-8 in NIST SP 800-53 Rev 5 requires penetration testing to verify that security controls are implemented correctly and that the security posture is adequate. FedRAMP mandates annual penetration testing with documented results. C3PAO assessors for CMMC Level 2 evaluate whether penetration testing has been conducted and whether findings have been tracked to demonstrated closure.

The CA-8 assessment objective requires evidence of: the test methodology, the scope boundary, the findings, the remediation actions, and the verification that findings were resolved. A penetration test report that exists only as a PDF with no systematic remediation tracking satisfies none of the assessment objectives beyond the existence of the test itself.

REAEGIS ingests penetration test reports, maps each finding to the applicable NIST controls, creates POA&M items with the correct remediation timelines per finding severity, and tracks each finding through the remediation lifecycle to closure with verifiable evidence.

Subcontractor Compliance Portal

DFARS 252.204-7021(c)

DFARS 252.204-7021(c) requires prime contractors to flow CMMC requirements to all subcontractors who handle Federal Contract Information or Controlled Unclassified Information. The prime is responsible for ensuring subcontractor compliance — it cannot be delegated away or assumed from a subcontractor's self-declaration.

This creates a material compliance gap for prime contractors managing large subcontractor bases. The documentation burden is significant: each subcontractor's CMMC status, SPRS score, CMMC UID, and assessment date must be maintained and producible on demand.

REAEGIS provides a structured assessment workflow: subcontractors receive an invitation, complete a documented self-assessment, and submit an attested compliance posture. The prime sees computed compliance scores, SPRS scores, and assessment dates across the entire supply chain. The resulting evidence package satisfies the flow-down documentation requirement under DFARS 252.204-7021(c).

NIST SP 800-171 Rev 3 Transition

NIST SP 800-171 Rev 3 · May 2024

NIST SP 800-171 Revision 3 published May 2024 restructures the requirement set from 110 practices across 14 families to 97 requirements with 88 Organization-Defined Parameters that must be populated with values appropriate for each environment.

The DoD has published defined ODP values for many of these parameters. Among them: identifier reuse must be prevented for a minimum of 10 years (IA family). Programs currently operating under Rev 2 must update SSP narratives, control implementations, and assessment procedures to address these ODPs before the transition mandate takes effect.

REAEGIS computes the Rev 2 to Rev 3 crosswalk from existing control data, identifies unaddressed ODPs, pre-populates DoD-defined ODP values, and flags controls requiring updated narratives.

AI Governance Assessment

OMB M-25-21 · NIST AI RMF

CMMC 2.0 and NIST SP 800-171 contain no exemptions for artificial intelligence systems. An AI tool with access to a system processing, storing, or transmitting CUI is a system component subject to the full requirements of the applicable control baseline — including access control, audit logging, configuration management, and incident response.

OMB M-25-21 requires agencies to ensure that AI tools used in government work are assessed for risk and governed appropriately. OMB M-26-04 imposes specific obligations for contractors procuring or deploying large language models in federal programs.

REAEGIS inventories AI tools present in the program environment, assesses each against the applicable compliance framework, quantifies the exposure from non-compliant AI usage, and produces the OMB-required governance attestation.

Start with your free CMMC assessment.

The CMMC Scoping Wizard runs all seven steps free — no account required. See your gap against 110 practices and your estimated SPRS score in 20 minutes.

Get started

Authorization is not a destination.It is a system property.

REAEGIS is the infrastructure that maintains it — converting every commit, scan, and approval into evidence your Authorizing Official can act on.

Explore the platform