Skip to main content
    SectorsPublic sector and defense

    Tell us the constraint first, and we will tell you if we are wrong for it.

    Programs in this sector are judged on control, provenance and the ability to answer in writing. Reign operates software delivery tooling as a single-tenant dedicated instance, including in your own cloud account, and records how each change was proposed, reviewed and approved. Air-gapped operation and sovereign deployment are in development rather than available, and we would rather say that in the first paragraph than in the last.

    Two available today, one in beta Start a conversation Deployment options →

    Our control design is aligned to the FedRAMP Moderate baseline. That is the entire claim. We hold no authorization, no 3PAO-validated package, no Marketplace listing and no readiness designation, and none of those is in progress today.

    What we can take today said first
    Available today Single-tenant dedicated instance Your own cloud AWS or Azure account A named engineer visible in the record In development air-gapped operation sovereign deployment neither is available and neither is being sold no date is offered Not our program CMMC Controlled unclassified ITAR no claim of any kind The entire claim aligned to the FedRAMP Moderate baseline. No authorization. If the constraint is in the third column, we are not the supplier. We would rather the conversation ended early and accurately.
    The deployment constraint decides whether this is a conversation worth having, so it goes first rather than last.
    The pressure

    The supplier is part of the assessment, not a detail beside it.

    The scrutiny is applied to us as much as to the software. Answers have to be durable, written down, and the same on every occasion they are asked for.

    01Where it runs is a requirement, not a preference
    Many programs carry constraints on location and on whether a system may reach a public network at all.

    Those constraints are not negotiated after signature. They decide whether there is an engagement, which is why the figure above puts them before anything else on the page.

    AskIs your deployment constraint written into the requirement, or assumed to be solvable later?

    02Provenance has to be recoverable without memory
    Long programs outlast the teams that start them.

    The chain from a requirement to a change to the person who approved it has to be recoverable years afterwards, by somebody who was not there.

    AskWho would you ask today about a change made three program phases ago?

    03CMMC is paused, and the obligation is not
    The Department of War suspended CMMC Phase II on 13 July 2026 and stood up a reform task force.

    Phase 1 self-assessment requirements remain in force, DFARS 252.204-7012 remains contractually binding, and NIST SP 800-171 compliance with SPRS score posting is unchanged. The certification mechanism is in abeyance; the duty to protect controlled unclassified information is not. If anything the exposure on a self-attested score is sharper now.

    AskWhen was your SPRS score last supported by evidence somebody outside the team could follow?

    04FedRAMP restructured in June
    Consolidated Rules for 2026 launched on 25 June 2026, and FedRAMP 20x is the primary path rather than a pilot.

    Rev5 is in managed sunset: legacy Ready submissions closed in July 2026, CR26 becomes mandatory for all stakeholders on 1 January 2027, and no new Rev5 applications are accepted after 11 June 2027. Any supplier describing itself purely in Rev5 terms is describing last year.

    AskDoes your authorization requirement name a regime, or just a baseline?

    What the frameworks ask

    Two frameworks we describe, and three we do not claim.

    We describe these because they shape how AI-enabled delivery is discussed in this sector. Describing a framework is not a statement of standing under it, and the third row is the one this page exists to be clear about.

    What is measuredWhose figure, and whenWhy it is on this page
    NIST AI Risk Management Framework 1.0 — a voluntary framework organised around four functions: Govern, Map, Measure and Manage. Establish accountability, understand context and risk, assess systems against that understanding, and act on what is found.United States, NIST. Published 26 January 2023, current. Generative AI profile NIST AI 600-1 published 26 July 2024.A revision is underway under the July 2025 AI Action Plan with no announced publication date, so anything built against the current text should expect movement.
    ISO/IEC 42001:2023 — a management system standard for artificial intelligence: stated policy, defined roles, risk assessment, documented controls, and a mechanism for continual improvement that produces records rather than intentions.International. Published 18 December 2023, unchanged.Certifiable and increasingly a procurement signal. We hold no certification under it and make no claim of one.
    CMMC, controlled unclassified information, and ITAR — the three requirements a program most often carries in this sector.CMMC Phase II suspended 13 July 2026; program paused in Phase 1. DFARS 252.204-7012 and NIST SP 800-171 unchanged.We make no claim of any kind under any of the three and we are not the supplier for a program that requires them today. That is a statement about us, not a comment on the regimes.

    Our control design is aligned to the NIST SP 800-53 Moderate baseline used by FedRAMP. We are not FedRAMP authorized: no agency ATO, no 3PAO-validated package, no Marketplace listing, and no reciprocity of any kind. A federal agency cannot rely on that alignment to meet a FedRAMP requirement, and we would rather write that sentence ourselves than have it discovered.

    Where the record fits

    The deployment constraint decides whether there is a conversation.

    This is the part of the page most likely to end one early. We would rather it ended early and accurately. What is available today is a single-tenant dedicated instance, in infrastructure iTmethods operates or in your own AWS or Azure account. Air-gapped operation and sovereign deployment are in development, neither is available and neither is being sold.

    What the record carries
    For each change: what was proposed, what the checks reported, who reviewed it, who approved it and when, recoverable years later without relying on anybody’s memory. A named engineer is embedded for the agreed population, is accountable for the work in front of them, and appears in the record.
    The part worth being precise about. A sovereignty requirement is answered with “in development”. It is not answered with a promise, a roadmap date, or a form of words designed to keep the meeting going. iTmethods makes no compliance, certification or accreditation claim under any framework. How the boundary works → · Regulatory alignment →
    Shared responsibility

    Who holds what, and what we will not hold.

    Written down before anything moves, because in a program assessment an unwritten boundary becomes the finding.

    WhoWhat they hold
    iTmethodsOperate the delivery toolchain as a single-tenant dedicated instance, in your own cloud account if that is the requirement. Access control, recorded change history, and a named engineer visible in the record.
    Your programWhere the work must run and what it may not touch. The authorization boundary. Every approval. The determination of whether our control design satisfies a requirement, which belongs to your own risk and assessment functions and not to us.
    Nobody, todayA program requiring CMMC certification, handling controlled unclassified information, or falling under ITAR. Air-gapped or sovereign deployment. We are not the supplier for those, and this row exists so that nobody has to find that out in month three.
    Before the scoping call

    The questions that arrive every time.

    Are you FedRAMP authorized?
    No. Our control design is aligned to the NIST SP 800-53 Moderate baseline used by FedRAMP, and that is the entire claim. There is no agency ATO, no 3PAO-validated package and no Marketplace listing, and no authorization is in progress. Note also that FedRAMP restructured on 25 June 2026 under Consolidated Rules for 2026, so “Moderate” is Rev5 framing and Rev5 is sunsetting.
    Can you support a CMMC program?
    Not today, and the suspension does not change that answer. The Department of War suspended CMMC Phase II on 13 July 2026, but Phase 1 self-assessment, DFARS 252.204-7012 and NIST SP 800-171 all remain in force. We make no claim under any of them. If your program carries a CMMC obligation, we are the wrong supplier and we would rather say so in the first meeting.
    When will sovereign deployment be available?
    We do not know, and we are not going to offer you a date. Air-gapped operation and sovereign deployment are both in development, neither is available and neither is being sold. What is available today is a single-tenant dedicated instance, including deployment into your own AWS or Azure account, which answers a residency requirement but not a sovereignty one.
    What can you actually evidence today?
    The only figures we publish about this way of working are our own. Across eight of our own repositories, 326 merge requests were merged. Median time from merge request open to merge was 19 hours. 326 of 326 merged with a recorded approval from a named iTmethods engineer. Measured on our own engineering, 11 July to 11 August 2026, GitLab, release commits excluded, internal environment only, two-person team. The method is written up in full at what we measured. It is not a customer result, and we do not present it as one.
    Which deployment shapes can we have?
    A single-tenant dedicated instance, in your own AWS or Azure account or in infrastructure iTmethods operates. Both are available today, which includes deployment into your own cloud account; Google Cloud is planned for 2027. Air-gapped and sovereign are in development. There is no multi-tenant or shared option at any tier. Deployment options states which is which without softening any of them.
    AWS Advanced Tier Services Partner SOC 2 Type II on Reign Ops
    AWS Advanced Tier Services Partner and Validated Managed Service Provider. Twenty-one years operating regulated engineering environments.
    Next step

    Tell us the constraint first.

    Start with where the work must run and what it may not touch, and we will tell you in the first meeting whether we are the right supplier. Sometimes the answer is no, and that is a useful meeting too.