For contractors

RMF when nobody on the team does RMF full time.

Large primes staff compliance departments. Small and mid-size contractors have an engineer who also owns the ATO, and a program manager who finds out something is due next week. The tooling has to reduce total work, not add a system to keep in sync.

  • Per system, unlimited users
  • NIST SP 800-53 Rev 5
  • eMASS round-trip
  • Built by a small business
Ref
C-01
Kind
The constraint

What actually makes RMF hard on a lean team.

It is not that the controls are difficult to understand. It is that the work is spread across people whose day job is something else, over a period long enough that whoever made a decision has usually moved on by the time somebody needs to know why.

So the failure is rarely a wrong answer. It is an undocumented one — a control marked satisfied for a reason nobody wrote down, evidence in a folder nobody can map to a control, an implementation statement describing a configuration that changed two sprints ago.

  • Decisions recorded where they are made, with who made them
  • Evidence bound to controls on arrival, not at review time
  • Change surfaces as scoped work rather than as a discovery
  • Documents generated from the record instead of maintained beside it
Ref
C-02
Kind
Pricing
Unit
per system

Per seat is the wrong unit for a small team.

RMF is a team sport. An ISSO, an assessor, a program manager and three engineers all need to be in the record — and the moment a license makes you think twice about adding someone, the record stops reflecting what the team actually knows.

CertiField is priced per system with unlimited users. Bring everyone.

Ref
C-03
Kind
Path

The path, end to end.

The same six steps a prime runs, without needing six people to run them.

  1. Categorize

    FIPS 199 impact levels, the high-water mark, and the system narratives that describe what is being authorized.

  2. Select

    NIST SP 800-53 Rev 5 baselines seeded from the NIST OSCAL catalog, tailored into a per-system control set.

  3. Implement

    Implementation statements, evidence, STIG applicability and the engineering data behind each control.

  4. Assess

    Assessment procedures, per-CCI results, determinations and findings, each bound to what it was assessed against.

  5. Authorize

    SSP, SAR, POA&M and the authorization package, generated from the record rather than assembled beside it.

  6. Monitor

    Architecture change, inventory drift, evidence continuity and the reassessment scope each of them creates.

Ref
C-04
Kind
Who we are
Built by
Alethia Software

Built by a small business doing the same work.

CertiField came out of DoD delivery work at Alethia Software — an 8(a) and woman-owned small business — where the same problem kept recurring: the system shipped, the package went stale, and somebody spent a quarter reconstructing an authorization story that had been true six months earlier.

We are not describing a market we researched. We are describing the work we were doing.

Next step

See what your RMF process looks like when the package keeps up with the system.