At Net-Inspect, we are committed to safeguarding your sensitive, military, and proprietary data. We proudly support a diverse range of clients across industries, providing them with a secure platform designed to meet or exceed industry security standards.
The U.S. Department of Defense (DoD) DFARS Clause 252.204.7012 (b) (2) (ii)(D) specifies strict requirements for contractors who utilize external cloud service providers to handle Controlled Unclassified Information (CUI). These providers must meet security standards equivalent to the FedRAMP Moderate Baseline, an intensive compliance framework derived from the NIST 800-53 standards.
As Net-Inspect does not have direct U.S. Government contracts, we cannot be FedRAMP certified or be listed on the FedRAMP Marketplace. The FedRAMP Equivalency Requirements are the mandated, rigorous controls ensuring that we provide the same level of security demanded by the government, including an annual review by a certified FedRAMP assessor.
To ensure our platform remains secure, Net-Inspect partners with SecureIT, a certified FedRAMP Third Party Assessment Organization (3PAO) and a leader in security consulting. SecureIT conducts annual FedRAMP Moderate Equivalency assessments for Net-Inspect, in compliance with the January 2024 DoD memorandum. These assessments cover:
Thanks to this partnership, Net-Inspect is thoroughly evaluated and committed to meeting compliance requirements each year.
The 32 CFR Part 170 Cybersecurity Maturity Model Certification (CMMC) 2.0 Rule has been released, and DoD direct supplier certification may be required.
Net-Inspect does not have a requirement to implement CMMC 2.0, as we are not a direct US Government supplier. For our customers with the CMMC 2.0 requirement, it specifies:
Defense contractors must confirm that any Cloud Service Providers (CSPs) used by the contractor to handle CUI meet Federal Risk and Authorization Management Program (FedRAMP) Moderate Baseline or the equivalent requirements. Specifically,
1. Net-Inspect must achieve 100% compliance with the latest FedRAMP Moderate security control baseline via an assessment conducted by a FedRAMP-recognized Third Party Assessment Organization,
2. Provide a body of evidence to the contractor (including the System Security Plan, Security Assessment Plan, Security Assessment Report performed by the 3PAO, and Plan of Action and Milestones), and
3. Comply with DFARS 252.204-7012 requirements for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment
As our customers plan and execute their CMMC 2.0 certification, Net-Inspect will partner with you and deliver a compliant BoE for the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) assessment.
Please note: The extensive Body of Evidence (BoE) will be delivered as you enter the DIBCAC assessment, as some of the documentation must include recent scans and may only be valid during the month of audit.
Net-Inspect is fully committed to supporting your company’s security initiatives. We work closely with your security teams to ensure our platform aligns with your organization’s expectations and requirements. With Net-Inspect, you gain a trusted partner that prioritizes your data’s safety and ensures a secure experience for all users. For more information regarding a security and compliance posture, please do not hesitate to contact us. We are happy to assist.