Tell us the constraint first, and we will tell you if we are wrong for it.
Programs in this sector are judged on control, provenance and the ability to answer in writing. Reign operates software delivery tooling as a single-tenant dedicated instance, including in your own cloud account, and records how each change was proposed, reviewed and approved. Air-gapped operation and sovereign deployment are in development rather than available, and we would rather say that in the first paragraph than in the last.
Our control design is aligned to the FedRAMP Moderate baseline. That is the entire claim. We hold no authorization, no 3PAO-validated package, no Marketplace listing and no readiness designation, and none of those is in progress today.
The supplier is part of the assessment, not a detail beside it.
The scrutiny is applied to us as much as to the software. Answers have to be durable, written down, and the same on every occasion they are asked for.
Those constraints are not negotiated after signature. They decide whether there is an engagement, which is why the figure above puts them before anything else on the page.
AskIs your deployment constraint written into the requirement, or assumed to be solvable later?
The chain from a requirement to a change to the person who approved it has to be recoverable years afterwards, by somebody who was not there.
AskWho would you ask today about a change made three program phases ago?
Phase 1 self-assessment requirements remain in force, DFARS 252.204-7012 remains contractually binding, and NIST SP 800-171 compliance with SPRS score posting is unchanged. The certification mechanism is in abeyance; the duty to protect controlled unclassified information is not. If anything the exposure on a self-attested score is sharper now.
AskWhen was your SPRS score last supported by evidence somebody outside the team could follow?
Rev5 is in managed sunset: legacy Ready submissions closed in July 2026, CR26 becomes mandatory for all stakeholders on 1 January 2027, and no new Rev5 applications are accepted after 11 June 2027. Any supplier describing itself purely in Rev5 terms is describing last year.
AskDoes your authorization requirement name a regime, or just a baseline?
Two frameworks we describe, and three we do not claim.
We describe these because they shape how AI-enabled delivery is discussed in this sector. Describing a framework is not a statement of standing under it, and the third row is the one this page exists to be clear about.
| What is measured | Whose figure, and when | Why it is on this page |
|---|---|---|
| NIST AI Risk Management Framework 1.0 — a voluntary framework organised around four functions: Govern, Map, Measure and Manage. Establish accountability, understand context and risk, assess systems against that understanding, and act on what is found. | United States, NIST. Published 26 January 2023, current. Generative AI profile NIST AI 600-1 published 26 July 2024. | A revision is underway under the July 2025 AI Action Plan with no announced publication date, so anything built against the current text should expect movement. |
| ISO/IEC 42001:2023 — a management system standard for artificial intelligence: stated policy, defined roles, risk assessment, documented controls, and a mechanism for continual improvement that produces records rather than intentions. | International. Published 18 December 2023, unchanged. | Certifiable and increasingly a procurement signal. We hold no certification under it and make no claim of one. |
| CMMC, controlled unclassified information, and ITAR — the three requirements a program most often carries in this sector. | CMMC Phase II suspended 13 July 2026; program paused in Phase 1. DFARS 252.204-7012 and NIST SP 800-171 unchanged. | We make no claim of any kind under any of the three and we are not the supplier for a program that requires them today. That is a statement about us, not a comment on the regimes. |
Our control design is aligned to the NIST SP 800-53 Moderate baseline used by FedRAMP. We are not FedRAMP authorized: no agency ATO, no 3PAO-validated package, no Marketplace listing, and no reciprocity of any kind. A federal agency cannot rely on that alignment to meet a FedRAMP requirement, and we would rather write that sentence ourselves than have it discovered.
The deployment constraint decides whether there is a conversation.
This is the part of the page most likely to end one early. We would rather it ended early and accurately. What is available today is a single-tenant dedicated instance, in infrastructure iTmethods operates or in your own AWS or Azure account. Air-gapped operation and sovereign deployment are in development, neither is available and neither is being sold.
Where this sits against the rest of Reign.
Four motions at four different stages of maturity. We state the stage every time, because in this sector the stage is the answer.
A single-tenant dedicated instance, in your own AWS or Azure account or in infrastructure iTmethods operates. Both are available today, which includes deployment into your own cloud account; Google Cloud is planned for 2027. Air-gapped and sovereign are in development. There is no multi-tenant or shared option at any tier. Deployment options →
Who holds what, and what we will not hold.
Written down before anything moves, because in a program assessment an unwritten boundary becomes the finding.
| Who | What they hold |
|---|---|
| iTmethods | Operate the delivery toolchain as a single-tenant dedicated instance, in your own cloud account if that is the requirement. Access control, recorded change history, and a named engineer visible in the record. |
| Your program | Where the work must run and what it may not touch. The authorization boundary. Every approval. The determination of whether our control design satisfies a requirement, which belongs to your own risk and assessment functions and not to us. |
| Nobody, today | A program requiring CMMC certification, handling controlled unclassified information, or falling under ITAR. Air-gapped or sovereign deployment. We are not the supplier for those, and this row exists so that nobody has to find that out in month three. |
The questions that arrive every time.
Are you FedRAMP authorized?
Can you support a CMMC program?
When will sovereign deployment be available?
What can you actually evidence today?
Which deployment shapes can we have?
Tell us the constraint first.
Start with where the work must run and what it may not touch, and we will tell you in the first meeting whether we are the right supplier. Sometimes the answer is no, and that is a useful meeting too.