Security & Compliance

Infab Softworks' commitment to security is integral to delivering high-quality software for the defense and aerospace sectors. We prioritize the protection of our customers' sensitive information and operate within a robust cybersecurity framework built on the standards of integrity, confidentiality, and availability.

Our posture aligns with the DoD's CMMC program final rule. Read the Federal Register notice

Our security posture

ITAR / DDTC

In place

DDTC registered and ITAR compliant. All employees are U.S. persons, and all stored ITAR data is encrypted on AWS GovCloud.

CMMC Level 2

Self-assessed (SPRS)

CMMC Level 1 and Level 2 self-assessment is complete, and our CMMC Level 2 score is posted in SPRS (the Supplier Performance Risk System). Third-party (C3PAO) certification is pending, and we will pursue it once it becomes available and is required.

SSP & ISMS

Established

Our System Security Plan (SSP) and Information Security Management System (ISMS) are established and maintained, aligning our policies, procedures, and controls with international standards.

Third-party penetration testing

Annual

Infab engages an independent third party to perform penetration testing every year. Findings drive remediation and continuous hardening of our systems.

Secure cloud infrastructure

In place

Our systems run on AWS GovCloud using FedRAMP-compliant cloud services, keeping customer data within a controlled, government-grade environment.

What's nextTargeting 2027

ISO 27001 certification

We are preparing for an ISO 27001 audit to formally certify our information security management system.

FedRAMP Moderate equivalency

Not required, as our systems are not in direct use by the Federal Government. For customers bound to FedRAMP Moderate controls, we will provide documentation demonstrating equivalency.

CMMC Level 2 C3PAO certification

Once C3PAO assessment is available to us and contractually required, we will engage a C3PAO to certify our CMMC Level 2 compliance.

Our posture in detail

The frameworks that shape how we protect customer data, and where Infab stands against each one today.

01Controlled Unclassified Information

CMMC & DFARS 252.204-7012

DFARS 252.204-7012 and the DoD's CMMC program govern how defense contractors safeguard Controlled Unclassified Information (CUI) and Federal Contract Information (FCI). For our customers in the defense and aerospace sectors, that obligation flows down to every partner that stores or processes their data, and Infab is one of those partners. Meeting these requirements is a precondition for handling the work our customers trust us with, not an optional add-on.

Infab has completed its CMMC Level 1 and Level 2 self-assessment against the NIST SP 800-171 security requirements that DFARS 252.204-7012 mandates, and our resulting CMMC Level 2 score is posted in the Supplier Performance Risk System (SPRS). That means a contracting officer or prime can verify our standing through the same government system they use for every other supplier, rather than taking our word for it.

We treat the assessment as a living program rather than a one-time exercise. Our System Security Plan and supporting policies are maintained on an ongoing basis as controls and threats evolve. Third-party (C3PAO) certification is the natural next step, and we will pursue it as soon as an assessment slot is available to us and our contracts require it.

02Cloud service provider

FedRAMP Moderate controls

For customers who work with federal agencies, the security of the cloud beneath their supply chain matters as much as the security of their own environment. Infab runs entirely on AWS GovCloud, using FedRAMP-authorized cloud services that keep customer data inside a controlled, government-grade boundary staffed and operated under U.S. jurisdiction.

Under FedRAMP, Infab is considered a Cloud Service Provider (CSP). Because our systems are not in direct use by the Federal Government, a full FedRAMP authorization is not required of us today. That distinction is deliberate in how we describe our posture: we speak in terms of equivalency to the Moderate baseline rather than claiming an authorization to operate that would not accurately reflect our position.

We are committed to FedRAMP Moderate equivalency so that customers who are contractually bound to those controls can rely on documented evidence of ours. When a security reviewer needs to map our environment to the Moderate baseline, we can provide the artifacts to support that review rather than leaving a gap in their own compliance package.

03Verified from the outside

Independent testing

A self-assessment tells you whether your controls exist; a determined adversary tells you whether they hold. Every year, Infab commissions an independent third party to attempt to compromise our systems the way a real attacker would, probing for the weaknesses that internal reviews are prone to overlook.

Findings from each engagement are triaged by severity, remediated, and folded back into our security program so that the same class of issue does not resurface. We treat the report as a roadmap for hardening rather than a grade to be filed away, and the remediation work becomes part of how the platform evolves.

This annual cadence keeps our defenses measured against current threats rather than the assumptions we held when a system was first built. Just as importantly, it gives our customers independent, outside evidence that the posture described on this page reflects how our systems actually behave under pressure.

InfabCAGE 06V71DUNS 128263681NAICS: 518210, 541511, 541519© 2026 Infab Softworks, LLC

All Rights Reserved.