Orbital FederalFederal

Our Baseline

The standards ledger

Security has a body of doctrine, most of it written for government facilities and programs that cannot be allowed to fail. This is the reference set we practice from — and translate for private owners.

ICD 705 · ICS 705-01/-02

Sensitive Compartmented Information Facilities

The Intelligence Community directive and standards governing design, construction, accreditation, and management of SCIFs and secure spaces, implemented through the IC Tech Spec. The most demanding facility-security standard in general use, and the backbone of both our secure-space and CST practice.

32 CFR Part 117

NISPOM — National Industrial Security Program

The operating rule for contractors safeguarding classified information: facility clearances, physical safeguarding, personnel security, insider threat, and self-inspection. We help owners carry NISPOM obligations as practice rather than paperwork.

32 CFR Part 170

CMMC — Cybersecurity Maturity Model Certification

The program rule establishing CMMC levels and assessment requirements for protecting FCI and CUI in the defense industrial base. Phase 1 of the acquisition rollout took effect 10 November 2025; later phases were suspended in July 2026 pending program review, while the underlying obligations continued unchanged.

NIST SP 800-171

Protecting CUI in Nonfederal Systems

The control set behind SPRS scoring and CMMC Level 2 — and the standard a government-led assessment measures you against. We assess implementation control by control, with evidence noted rather than asserted.

DFARS 252.204-7012 · -7019 · -7020 · -7021

Defense Cyber Clauses

Safeguarding covered defense information, cyber incident reporting, SPRS score submission, government assessment access, and the CMMC requirement itself. These clauses are how cyber obligations actually reach you, and they flow down to your subcontractors.

FAR · DFARS

Acquisition Regulation & Defense Supplement

The broader contract clauses through which security requirements reach private industry — safeguarding, facility access, and the flow-downs that arrive attached to federal and defense work. We map what applies and build facilities and programs that satisfy it.

NIST SP 800-53

Physical & Environmental Protection Controls

The PE control family — the point where physical and cyber compliance are the same conversation, and a common language between your security program and your customers' auditors.

NERC CIP-014

Physical Security of Critical Grid Assets

Risk assessment and physical protection requirements for the transmission infrastructure the grid — and every data center on it — depends on. Relevant doctrine for substations, on-site generation, and energy-adjacent campuses.

UFC 4-010-01

DoD Minimum Antiterrorism Standards for Buildings

The Department's criteria for standoff, structural hardening, and site design against attack. We apply its logic — proportionately — to civilian facilities whose loss would be intolerable.

TIA-942 · ASIS/ANSI

Data Center & Industry Standards

TIA-942's facility security provisions, Uptime-aligned resilience thinking, and the ASIS body of standards for risk assessment, security management, and investigations — the commercial layer of the reference set.

TSCM & TEMPEST

Technical Security Doctrine

Technical surveillance countermeasures practice, and the TEMPEST and emanations security requirements that attach to certain programs. Where a requirement must be satisfied by a certified or government-designated authority, we coordinate rather than substitute.

Reference set

Kept current, deliberately

This file moves. Rules get amended, phases get suspended, revisions supersede. We track it as a working obligation of the practice — and tell clients what applies to their contracts today, not what applied when a policy was announced.

On authority Standards fluency is not a substitute for cognizant authority. Accreditation, certification, and regulatory decisions rest with the responsible government offices and authorized assessment organizations. Our work ensures that when those offices look, the facility and the program are ready.

Next Step

Which of these apply to you?

That question has a definitive answer. A requirements mapping is usually where we start.

Prefer to talk? 866.960.7475 · info@orbitalfederal.com