FISTA Solutions does not load Google Analytics until you accept. Rejecting keeps optional analytics off. Read the Cookie Policy.

Compliance and security / flow-downs

Compliance is flowed down to every tier. We build to it.

Government subcontracts flow down accessibility, privacy, security, and data-residency obligations to every tier. FISTA builds subcontract work packages to those standards from the specification onward: WCAG 2.1 AA and Section 508, FERPA and HIPAA data handling, NIST-aligned controls, UK and EU GDPR, Cyber Essentials and Essential Eight control areas, and in-region hosting, with restricted data staying with the prime.

150+
projects delivered
50+
companies served
99.9%
verified uptime
47%
efficiency gains
12+
countries reached

Standards by market

Which standards flow down to a subcontractor in each market?

The same four families in every market with different names: accessibility, privacy, a security framework, and where data may live and who may touch it. A prime's flow-down set usually adds personnel requirements such as clearances or screening. This table names the instruments FISTA maps its work to in each market; the market pages go deeper.

Government IT compliance instruments that flow down to subcontractors, by market.
MarketAccessibilityPrivacySecurity frameworkHosting, residency, personnel
United StatesSection 508; WCAG 2.1 AA under the 2024 DOJ Title II rule for state and localFERPA (education), HIPAA (health), state privacy lawsNIST CSF, SP 800-53, SP 800-171 for CUI; CJIS for law-enforcement dataFedRAMP or StateRAMP-authorized cloud; offshore restrictions; clearances stay with the prime
United KingdomWCAG 2.2 AA via the Public Sector Bodies Accessibility RegulationsUK GDPR and the Data Protection Act 2018Cyber Essentials control areas; NCSC guidanceUK-region hosting; offshoring disclosure under G-Cloud terms; security-cleared work stays with the prime
European UnionEN 301 549 and the Web Accessibility DirectiveGDPR; SCCs for any transferNIS2 for essential and important entities; national baselinesEU-region hosting; national-language interface with the prime
JapanJIS X 8341-3 (aligned to WCAG)APPI, including cross-border transfer rulesGovernment security guidelines; ISMAP for cloud servicesISMAP-registered cloud; Japanese-language deliverables with partner review
GCCWCAG-aligned government web standardsUAE PDPL; Saudi PDPL; Qatar PDPPLSaudi NCA Essential Cybersecurity Controls; UAE and Qatar national frameworksIn-country data residency; local entity and local-content rules met through the prime
CanadaWCAG 2.1 AA under the Accessible Canada Act and provincial lawPrivacy Act and PIPEDA; provincial statutesITSG-33; CCCS cloud guidanceProtected B in Canadian-hosted environments; Reliability Status screening stays with the prime
AustraliaWCAG 2.1 AA under the Digital Service StandardPrivacy Act and the Australian Privacy PrinciplesISM; Essential Eight maturity; PSPFHosting Certification Framework; IRAP-assessed cloud; clearances stay with the prime

Instruments named here are the public standards and statutes FISTA maps its engineering controls to. Which ones apply is set by each contract. This is general guidance, not legal advice.

Engineering controls

How does FISTA build to these standards?

By treating each obligation as a specification requirement with a test, not as paperwork after delivery. The controls below are applied to every government work package and produce the evidence a prime's security reviewer or a contracting officer asks for: what was built, who could access what, and how conformance was verified.

  1. 01

    Secure software development lifecycle

    Threat modeling at specification, mandatory code review, dependency and secret scanning in CI, and a release gate that fails on unresolved high findings.

    SDLC
  2. 02

    Least-privilege, named access

    Individual accounts, MFA, role-based access scoped to the work package, time-bound elevation, and removal at exit, with the access list available to the prime at any time.

    Access
  3. 03

    Encryption and key management

    Encryption in transit and at rest on every environment FISTA touches, with keys managed in the prime's or the agency's key service, never in code or configuration.

    Data
  4. 04

    Audit logging

    Application and infrastructure logs that identify who did what and when, retained per the contract and available to the prime's security team.

    Evidence
  5. 05

    De-identified development data

    Development and test environments run on synthetic or de-identified data by default; production personal, protected, or classified data stays with the prime.

    Privacy
  6. 06

    Accessibility engineering

    Semantic components, keyboard and screen-reader testing, automated checks in CI, manual assistive-technology passes, and a conformance report for what FISTA delivers.

    Accessibility
  7. 07

    In-region infrastructure as code

    Environments defined as code in the region the contract requires, with the prime owning the accounts and FISTA holding only the access the work package needs.

    Residency
  8. 08

    Documentation and evidence package

    Specification, test results, security scan outputs, accessibility conformance, runbooks, and a change record per task order, formatted for contracting-officer review.

    Acceptance

Workshare

How does offshore delivery stay inside the rules?

By putting the restricted work where the rules require it and the rest where it is best delivered. Offshore restrictions in government contracts almost always concern data access and personnel, not where code is written. FISTA's workshare keeps restricted data, cleared access, and the customer interface with the prime and delivers engineering against de-identified data.

How restricted work stays with the prime while FISTA delivers offshore.
Stays with the primeFISTA delivers offshoreFISTA Solutions Inc. provides
Customer relationship, contracting officer interface, and program managementApplication, API, and integration development against de-identified or synthetic dataUS contracting counterparty and USD invoicing from the Delaware entity
Access to personal, protected, or classified data and any work requiring cleared personnelTest automation, accessibility testing, performance testing, and release engineeringWritten teaming and subcontract terms, including reviewed flow-downs
Production environments holding restricted data, and hosting in the required regionInfrastructure as code, CI/CD pipelines, and observability for environments you ownNamed key personnel and substitution terms
Security accreditation, authority to operate, and questionnaire ownershipAI agent engineering, retrieval systems, and document-processing pipelinesEvidence package and documentation per task order
Local-language customer interface and in-country presence where requiredTechnical documentation, runbooks, and knowledge transfer materialSingle accountable delivery owner for every work package

Plain statement

What will FISTA tell you about certifications?

Exactly what is held, what is in progress, and what is not held, in the due-diligence pack, in writing. This website does not claim ISO, SOC, CMMI, Cyber Essentials, StateRAMP, FedRAMP, IRAP, ISMAP, or any other certification or registration, and it does not claim security clearances. What it describes is the engineering FISTA does, which a reviewer can test directly.

Primes are exposed when a subcontractor's marketing implies an attestation the contract later requires and the subcontractor cannot produce. FISTA's position is the opposite: the pages describe engineering controls, the pack states certification and registration status as it is on the day it is sent, and any gap relevant to a solicitation is raised during the teaming agreement review so it can be carved out, covered by the prime, or scheduled.

Where a certification or attestation is a hard requirement for FISTA's workshare, that requirement is written into the agreement with a date, and the work package is scoped so that delivery does not depend on an attestation FISTA does not yet hold.

Security review

How does FISTA handle a security questionnaire?

As a delivery task with an owner and a deadline. The questionnaire is answered from FISTA's security practices summary, every answer is backed by evidence or a stated gap, and gaps come with either a remediation date or a proposed carve-out. The prime receives a package it can forward to the agency without rewriting it.

  1. 1

    Intake

    The prime shares the questionnaire, the framework it maps to, and the deadline; FISTA assigns an owner and confirms scope against the work package.

    Output

    Owned questionnaire with scope confirmed

  2. 2

    Answer with evidence

    Each control answered from the security practices summary with the evidence attached: policies, configurations, scan outputs, access lists, or architecture diagrams.

    Output

    Draft responses with evidence index

  3. 3

    State the gaps

    Controls FISTA does not meet are marked as such with a remediation plan and date or a proposed carve-out to the prime's scope. Nothing is answered optimistically.

    Output

    Gap register with owners

  4. 4

    Review and forward

    The prime's security lead reviews with FISTA's owner; the final package is formatted for the agency and kept for the next questionnaire.

    Output

    Agency-ready security package

Regulatory and procurement references on this page are general guidance for planning a teaming engagement, not legal advice. Confirm obligations with your contracts and legal teams for each solicitation.

Clear answers

What primes ask before teaming.

Straightforward guidance for evaluating scope, fit, and the next step.

01Can offshore engineers access personal or protected data?

Only where the flow-down and the governing data agreement, such as a DPA or a HIPAA business associate agreement, permit it, and only under the named-access controls described above. The default on every FISTA government work package is de-identified or synthetic development data, with production data staying in the prime's environment.

02What is the difference between Section 508 and WCAG 2.1 AA?

Section 508 is the US federal accessibility law; its 2017 refresh incorporates WCAG 2.0 AA. The 2024 Department of Justice rule under ADA Title II requires WCAG 2.1 AA for state and local government web content and apps, with compliance dates from 2026. FISTA builds to WCAG 2.1 AA, which satisfies both.

03How do you handle CUI and CMMC?

Controlled unclassified information stays in the prime's authorized environment under NIST SP 800-171 controls, and FISTA's workshare is scoped so development does not require CUI access. Department of Defense work subject to CMMC is not FISTA's entry point; the sub-first model on these pages targets SLED and federal civilian scopes.

04How are GDPR transfers handled for UK and EU work?

Hosting stays in the UK or EU region the contract requires. Where FISTA engineers need any access to personal data, the transfer is covered by standard contractual clauses or the UK international data transfer agreement, a data processing agreement, and a transfer impact assessment, with de-identified data used wherever the work allows.

05Does FISTA hold security clearances?

No claim is made. Work that requires cleared or screened personnel, in any market, stays with the prime under the workshare, and the teaming agreement says so. FISTA's engineers work on the packages that can be delivered against de-identified data in environments the prime controls.

06Is this page legal advice?

No. It is general guidance for planning a teaming engagement and describes the standards FISTA maps its engineering to. Which obligations apply to a given contract is determined by the solicitation and the prime contract, and should be confirmed with your contracts and legal teams.

Sub-first, on the record

Send the flow-down set. We will tell you what we meet and what stays with you.

Share the clauses, the framework, and the data classification for the work package. FISTA returns a control-by-control response with evidence, honest gaps, and a workshare that keeps restricted work where the contract requires.