Our Baseline
The standards ledger
Security has a body of doctrine, most of it written for government facilities and programs that cannot be allowed to fail. This is the reference set we practice from — and translate for private owners.
ICD 705 · ICS 705-01/-02
Sensitive Compartmented Information Facilities
The Intelligence Community directive and standards governing design, construction, accreditation, and management of SCIFs and secure spaces, implemented through the IC Tech Spec. The most demanding facility-security standard in general use, and the backbone of both our secure-space and CST practice.
32 CFR Part 117
NISPOM — National Industrial Security Program
The operating rule for contractors safeguarding classified information: facility clearances, physical safeguarding, personnel security, insider threat, and self-inspection. We help owners carry NISPOM obligations as practice rather than paperwork.
32 CFR Part 170
CMMC — Cybersecurity Maturity Model Certification
The program rule establishing CMMC levels and assessment requirements for protecting FCI and CUI in the defense industrial base. Phase 1 of the acquisition rollout took effect 10 November 2025; later phases were suspended in July 2026 pending program review, while the underlying obligations continued unchanged.
NIST SP 800-171
Protecting CUI in Nonfederal Systems
The control set behind SPRS scoring and CMMC Level 2 — and the standard a government-led assessment measures you against. We assess implementation control by control, with evidence noted rather than asserted.
DFARS 252.204-7012 · -7019 · -7020 · -7021
Defense Cyber Clauses
Safeguarding covered defense information, cyber incident reporting, SPRS score submission, government assessment access, and the CMMC requirement itself. These clauses are how cyber obligations actually reach you, and they flow down to your subcontractors.
FAR · DFARS
Acquisition Regulation & Defense Supplement
The broader contract clauses through which security requirements reach private industry — safeguarding, facility access, and the flow-downs that arrive attached to federal and defense work. We map what applies and build facilities and programs that satisfy it.
NIST SP 800-53
Physical & Environmental Protection Controls
The PE control family — the point where physical and cyber compliance are the same conversation, and a common language between your security program and your customers' auditors.
NERC CIP-014
Physical Security of Critical Grid Assets
Risk assessment and physical protection requirements for the transmission infrastructure the grid — and every data center on it — depends on. Relevant doctrine for substations, on-site generation, and energy-adjacent campuses.
UFC 4-010-01
DoD Minimum Antiterrorism Standards for Buildings
The Department's criteria for standoff, structural hardening, and site design against attack. We apply its logic — proportionately — to civilian facilities whose loss would be intolerable.
TIA-942 · ASIS/ANSI
Data Center & Industry Standards
TIA-942's facility security provisions, Uptime-aligned resilience thinking, and the ASIS body of standards for risk assessment, security management, and investigations — the commercial layer of the reference set.
TSCM & TEMPEST
Technical Security Doctrine
Technical surveillance countermeasures practice, and the TEMPEST and emanations security requirements that attach to certain programs. Where a requirement must be satisfied by a certified or government-designated authority, we coordinate rather than substitute.
Reference set
Kept current, deliberately
This file moves. Rules get amended, phases get suspended, revisions supersede. We track it as a working obligation of the practice — and tell clients what applies to their contracts today, not what applied when a policy was announced.
Next Step
Which of these apply to you?
That question has a definitive answer. A requirements mapping is usually where we start.
Prefer to talk? 866.960.7475 · info@orbitalfederal.com