Compliance is flowed down to every tier. We build to it.
Government subcontracts flow down accessibility, privacy, security, and data-residency obligations to every tier. FISTA builds subcontract work packages to those standards from the specification onward: WCAG 2.1 AA and Section 508, FERPA and HIPAA data handling, NIST-aligned controls, UK and EU GDPR, Cyber Essentials and Essential Eight control areas, and in-region hosting, with restricted data staying with the prime.
- 150+
- projects delivered
- 50+
- companies served
- 99.9%
- verified uptime
- 47%
- efficiency gains
- 12+
- countries reached
Standards by market
Which standards flow down to a subcontractor in each market?
The same four families in every market with different names: accessibility, privacy, a security framework, and where data may live and who may touch it. A prime's flow-down set usually adds personnel requirements such as clearances or screening. This table names the instruments FISTA maps its work to in each market; the market pages go deeper.
| Market | Accessibility | Privacy | Security framework | Hosting, residency, personnel |
|---|---|---|---|---|
| United States | Section 508; WCAG 2.1 AA under the 2024 DOJ Title II rule for state and local | FERPA (education), HIPAA (health), state privacy laws | NIST CSF, SP 800-53, SP 800-171 for CUI; CJIS for law-enforcement data | FedRAMP or StateRAMP-authorized cloud; offshore restrictions; clearances stay with the prime |
| United Kingdom | WCAG 2.2 AA via the Public Sector Bodies Accessibility Regulations | UK GDPR and the Data Protection Act 2018 | Cyber Essentials control areas; NCSC guidance | UK-region hosting; offshoring disclosure under G-Cloud terms; security-cleared work stays with the prime |
| European Union | EN 301 549 and the Web Accessibility Directive | GDPR; SCCs for any transfer | NIS2 for essential and important entities; national baselines | EU-region hosting; national-language interface with the prime |
| Japan | JIS X 8341-3 (aligned to WCAG) | APPI, including cross-border transfer rules | Government security guidelines; ISMAP for cloud services | ISMAP-registered cloud; Japanese-language deliverables with partner review |
| GCC | WCAG-aligned government web standards | UAE PDPL; Saudi PDPL; Qatar PDPPL | Saudi NCA Essential Cybersecurity Controls; UAE and Qatar national frameworks | In-country data residency; local entity and local-content rules met through the prime |
| Canada | WCAG 2.1 AA under the Accessible Canada Act and provincial law | Privacy Act and PIPEDA; provincial statutes | ITSG-33; CCCS cloud guidance | Protected B in Canadian-hosted environments; Reliability Status screening stays with the prime |
| Australia | WCAG 2.1 AA under the Digital Service Standard | Privacy Act and the Australian Privacy Principles | ISM; Essential Eight maturity; PSPF | Hosting Certification Framework; IRAP-assessed cloud; clearances stay with the prime |
Instruments named here are the public standards and statutes FISTA maps its engineering controls to. Which ones apply is set by each contract. This is general guidance, not legal advice.
Engineering controls
How does FISTA build to these standards?
By treating each obligation as a specification requirement with a test, not as paperwork after delivery. The controls below are applied to every government work package and produce the evidence a prime's security reviewer or a contracting officer asks for: what was built, who could access what, and how conformance was verified.
- 01
Secure software development lifecycle
Threat modeling at specification, mandatory code review, dependency and secret scanning in CI, and a release gate that fails on unresolved high findings.
SDLC - 02
Least-privilege, named access
Individual accounts, MFA, role-based access scoped to the work package, time-bound elevation, and removal at exit, with the access list available to the prime at any time.
Access - 03
Encryption and key management
Encryption in transit and at rest on every environment FISTA touches, with keys managed in the prime's or the agency's key service, never in code or configuration.
Data - 04
Audit logging
Application and infrastructure logs that identify who did what and when, retained per the contract and available to the prime's security team.
Evidence - 05
De-identified development data
Development and test environments run on synthetic or de-identified data by default; production personal, protected, or classified data stays with the prime.
Privacy - 06
Accessibility engineering
Semantic components, keyboard and screen-reader testing, automated checks in CI, manual assistive-technology passes, and a conformance report for what FISTA delivers.
Accessibility - 07
In-region infrastructure as code
Environments defined as code in the region the contract requires, with the prime owning the accounts and FISTA holding only the access the work package needs.
Residency - 08
Documentation and evidence package
Specification, test results, security scan outputs, accessibility conformance, runbooks, and a change record per task order, formatted for contracting-officer review.
Acceptance
Workshare
How does offshore delivery stay inside the rules?
By putting the restricted work where the rules require it and the rest where it is best delivered. Offshore restrictions in government contracts almost always concern data access and personnel, not where code is written. FISTA's workshare keeps restricted data, cleared access, and the customer interface with the prime and delivers engineering against de-identified data.
| Stays with the prime | FISTA delivers offshore | FISTA Solutions Inc. provides |
|---|---|---|
| Customer relationship, contracting officer interface, and program management | Application, API, and integration development against de-identified or synthetic data | US contracting counterparty and USD invoicing from the Delaware entity |
| Access to personal, protected, or classified data and any work requiring cleared personnel | Test automation, accessibility testing, performance testing, and release engineering | Written teaming and subcontract terms, including reviewed flow-downs |
| Production environments holding restricted data, and hosting in the required region | Infrastructure as code, CI/CD pipelines, and observability for environments you own | Named key personnel and substitution terms |
| Security accreditation, authority to operate, and questionnaire ownership | AI agent engineering, retrieval systems, and document-processing pipelines | Evidence package and documentation per task order |
| Local-language customer interface and in-country presence where required | Technical documentation, runbooks, and knowledge transfer material | Single accountable delivery owner for every work package |
Plain statement
What will FISTA tell you about certifications?
Exactly what is held, what is in progress, and what is not held, in the due-diligence pack, in writing. This website does not claim ISO, SOC, CMMI, Cyber Essentials, StateRAMP, FedRAMP, IRAP, ISMAP, or any other certification or registration, and it does not claim security clearances. What it describes is the engineering FISTA does, which a reviewer can test directly.
Primes are exposed when a subcontractor's marketing implies an attestation the contract later requires and the subcontractor cannot produce. FISTA's position is the opposite: the pages describe engineering controls, the pack states certification and registration status as it is on the day it is sent, and any gap relevant to a solicitation is raised during the teaming agreement review so it can be carved out, covered by the prime, or scheduled.
Where a certification or attestation is a hard requirement for FISTA's workshare, that requirement is written into the agreement with a date, and the work package is scoped so that delivery does not depend on an attestation FISTA does not yet hold.
Security review
How does FISTA handle a security questionnaire?
As a delivery task with an owner and a deadline. The questionnaire is answered from FISTA's security practices summary, every answer is backed by evidence or a stated gap, and gaps come with either a remediation date or a proposed carve-out. The prime receives a package it can forward to the agency without rewriting it.
- 1
Intake
The prime shares the questionnaire, the framework it maps to, and the deadline; FISTA assigns an owner and confirms scope against the work package.
OutputOwned questionnaire with scope confirmed
- 2
Answer with evidence
Each control answered from the security practices summary with the evidence attached: policies, configurations, scan outputs, access lists, or architecture diagrams.
OutputDraft responses with evidence index
- 3
State the gaps
Controls FISTA does not meet are marked as such with a remediation plan and date or a proposed carve-out to the prime's scope. Nothing is answered optimistically.
OutputGap register with owners
- 4
Review and forward
The prime's security lead reviews with FISTA's owner; the final package is formatted for the agency and kept for the next questionnaire.
OutputAgency-ready security package
Regulatory and procurement references on this page are general guidance for planning a teaming engagement, not legal advice. Confirm obligations with your contracts and legal teams for each solicitation.
Clear answers
What primes ask before teaming.
Straightforward guidance for evaluating scope, fit, and the next step.
01Can offshore engineers access personal or protected data?
Only where the flow-down and the governing data agreement, such as a DPA or a HIPAA business associate agreement, permit it, and only under the named-access controls described above. The default on every FISTA government work package is de-identified or synthetic development data, with production data staying in the prime's environment.
02What is the difference between Section 508 and WCAG 2.1 AA?
Section 508 is the US federal accessibility law; its 2017 refresh incorporates WCAG 2.0 AA. The 2024 Department of Justice rule under ADA Title II requires WCAG 2.1 AA for state and local government web content and apps, with compliance dates from 2026. FISTA builds to WCAG 2.1 AA, which satisfies both.
03How do you handle CUI and CMMC?
Controlled unclassified information stays in the prime's authorized environment under NIST SP 800-171 controls, and FISTA's workshare is scoped so development does not require CUI access. Department of Defense work subject to CMMC is not FISTA's entry point; the sub-first model on these pages targets SLED and federal civilian scopes.
04How are GDPR transfers handled for UK and EU work?
Hosting stays in the UK or EU region the contract requires. Where FISTA engineers need any access to personal data, the transfer is covered by standard contractual clauses or the UK international data transfer agreement, a data processing agreement, and a transfer impact assessment, with de-identified data used wherever the work allows.
05Does FISTA hold security clearances?
No claim is made. Work that requires cleared or screened personnel, in any market, stays with the prime under the workshare, and the teaming agreement says so. FISTA's engineers work on the packages that can be delivered against de-identified data in environments the prime controls.
06Is this page legal advice?
No. It is general guidance for planning a teaming engagement and describes the standards FISTA maps its engineering to. Which obligations apply to a given contract is determined by the solicitation and the prime contract, and should be confirmed with your contracts and legal teams.
Six markets
Every market FISTA subcontracts in
- 01SLED and federal civilianUnited StatesOpen the market brief
- 02G-Cloud, CCS, NHS, TEDUK and EuropeOpen the market brief
- 03Digital Agency-era programsJapanOpen the market brief
- 04UAE, KSA, Qatar, Kuwait, Bahrain, OmanMENAOpen the market brief
- 05Federal supply arrangements, provincesCanadaOpen the market brief
- 06BuyICT, DTA, statesAustraliaOpen the market brief
Continue exploring
Related capabilities
Sub-first, on the record
Send the flow-down set. We will tell you what we meet and what stays with you.
Share the clauses, the framework, and the data classification for the work package. FISTA returns a control-by-control response with evidence, honest gaps, and a workshare that keeps restricted work where the contract requires.