For contractors
RMF when nobody on the team does RMF full time.
Large primes staff compliance departments. Small and mid-size contractors have an engineer who also owns the ATO, and a program manager who finds out something is due next week. The tooling has to reduce total work, not add a system to keep in sync.
- Per system, unlimited users
- NIST SP 800-53 Rev 5
- eMASS round-trip
- Built by a small business
- Ref
- C-01
- Kind
- The constraint
What actually makes RMF hard on a lean team.
It is not that the controls are difficult to understand. It is that the work is spread across people whose day job is something else, over a period long enough that whoever made a decision has usually moved on by the time somebody needs to know why.
So the failure is rarely a wrong answer. It is an undocumented one — a control marked satisfied for a reason nobody wrote down, evidence in a folder nobody can map to a control, an implementation statement describing a configuration that changed two sprints ago.
- Decisions recorded where they are made, with who made them
- Evidence bound to controls on arrival, not at review time
- Change surfaces as scoped work rather than as a discovery
- Documents generated from the record instead of maintained beside it
- Ref
- C-02
- Kind
- Pricing
- Unit
- per system
Per seat is the wrong unit for a small team.
RMF is a team sport. An ISSO, an assessor, a program manager and three engineers all need to be in the record — and the moment a license makes you think twice about adding someone, the record stops reflecting what the team actually knows.
CertiField is priced per system with unlimited users. Bring everyone.
- Ref
- C-03
- Kind
- Path
The path, end to end.
The same six steps a prime runs, without needing six people to run them.
-
Categorize
FIPS 199 impact levels, the high-water mark, and the system narratives that describe what is being authorized.
-
Select
NIST SP 800-53 Rev 5 baselines seeded from the NIST OSCAL catalog, tailored into a per-system control set.
-
Implement
Implementation statements, evidence, STIG applicability and the engineering data behind each control.
-
Assess
Assessment procedures, per-CCI results, determinations and findings, each bound to what it was assessed against.
-
Authorize
SSP, SAR, POA&M and the authorization package, generated from the record rather than assembled beside it.
-
Monitor
Architecture change, inventory drift, evidence continuity and the reassessment scope each of them creates.
- Ref
- C-04
- Kind
- Who we are
- Built by
- Alethia Software
Built by a small business doing the same work.
CertiField came out of DoD delivery work at Alethia Software — an 8(a) and woman-owned small business — where the same problem kept recurring: the system shipped, the package went stale, and somebody spent a quarter reconstructing an authorization story that had been true six months earlier.
We are not describing a market we researched. We are describing the work we were doing.
Next step