Skip to content

// DOCUMENT 04 · RESOURCES / COMPLIANCE MATRIX

Six papers that say yes.

Every claim below is third-party attested. The certifications, audits, and consortium memberships that follow are the artifact a contracting officer would otherwise request by phone — printed here, in the open, in the order DoD source-selection memos expect to find them.

  • REFCDY-CMP-2024.11
  • REV04 · 18 NOV 2024
  • CLASSUNCLASSIFIED // FOUO
  • CUSTODIANOFFICE OF THE CISO

// 01 · CERTIFICATION REGISTER

Six standards. Six audits. One matrix.

The procurement officer's working copy. Each panel names the standard, the audit body, the last assessment date, the scope, and the artifact you can request on letterhead.

STANDARD // MIL-STD-882EPERIOD // 2024VALUE // SYSTEM SAFETY
01

MIL-STD-882E — System Safety

Department of Defense Standard Practice for System Safety. Our Athena middleware and USV autonomy stack are certified against the 882E task hazard-analysis workflow, with a Hazard Tracking System (HTRL) maintained in the loop on every program of record.

Audit Body
Naval Sea Systems Command (NAVSEA) Safety Office
Scope
Unmanned Surface Vessel family & edge-node runtime
Last Assessment
August 2024 · zero Cat 1 findings
STANDARD // DO-178CPERIOD // 2023–2024VALUE // LEVEL B
02

DO-178C — Level B Software

Software Considerations in Airborne Systems and Equipment Certification. Athena's flight-critical modules are designed and verified to Design Assurance Level B, with independent tool-qualification per DO-330 and traceability through the requirements baseline.

Audit Body
DER-assisted audit, FAA-recognized
Scope
Flight-critical autonomy modules
Last Assessment
March 2024 · zero major non-conformities
STANDARD // CMMI-DEVPERIOD // 2024VALUE // MATURITY LEVEL 3
03

CMMI® for Development — Level 3

Capability Maturity Model Integration. Our engineering pipeline is appraised at CMMI-DEV v2.0 Maturity Level 3 across all 20 process areas, with defined institutional processes for requirements, configuration, measurement, and risk.

Appraised By
CMMI Institute, ISACA
Scope
Arlington HQ & integration lab
Last Appraisal
June 2024 · zero major non-conformities
STANDARD // ISO 27001:2022PERIOD // 2024VALUE // INFORMATION SECURITY
04

ISO/IEC 27001:2022

Information Security Management Systems. Cyberdyne holds an accredited ISO 27001:2022 certification covering the full Statement of Applicability, including Annex A controls for classified handling, secure development, and supplier relationships.

Certifying Body
ANSI-accredited registrar
Scope
Autonomy software development, integration, sustainment
Last Surveillance
September 2024 · zero major non-conformities
STANDARD // SOSPAPERIOD // 2023–2024VALUE // OPEN MIDDLEWARE
05

SOSPA-Aligned Open Middleware

Sensor Open Systems Architecture protocol compliance. Our middleware publishes and consumes STK and SOSPA-conformant interfaces, allowing plug-and-prime substitution with any other vendor on the SOSPA reference implementation without recompilation of mission code.

Conformance Tested
SOSPA Conformance Test Suite v3.1
Scope
Athena SDK, edge gateway, ground-control adapter
Last Test
February 2024 · passed
CONSORTIA // NDIA / OMSPERIOD // SINCE 2018VALUE // OPEN MISSION SYSTEMS
06

Open Mission Systems Consortium

Cyberdyne is a founding member of the Open Mission Systems (OMS) consortium and an active contributor to the Autonomy Stack Working Group at the National Defense Industrial Association (NDIA). Our CTO chairs the OMS conformance review board for the maritime track.

Working Groups
Autonomy Stack, Maritime Interface, Time-Sensitive Networking
Tenure
Founding member, since 2018
Status
Active · good standing

Request the unabridged certification matrix on letterhead, with audit reports and surveillance findings attached, via the briefing request form.

Request the Full Package

// INTERLUDE · TECHNICAL BRIEF / AT-A-GLANCE AUDIT REGISTER

Lift any line into a source-selection memo.

  1. CERTIFICATIONS HELD

    06

    MIL-STD-882E · DO-178C L-B · CMMI L3 · ISO 27001:2022 · SOSPA · OMS

  2. ZERO MAJOR NON-CONFORMITIES

    04/04

    Across the four most recent external audits (2023–2024)

  3. PLATFORM FIELD COUNT

    1,180+

    Across 19 allied nations, all running the certified Athena stack

  4. UPTIME / 36 MONTHS

    99.9994%

    9,300+ edge nodes, zero mission-aborting faults

// 02 · WHY THESE STANDARDS

Each acronym gates a specific failure mode.

A non-engineering program manager needs to know what passing these standards prevents — in operational terms, not in compliance jargon.

CHAPTER I

System Safety — MIL-STD-882E

A program that fails 882E cannot field a platform that operates near people, ports, or partnered forces. The standard forces a documented hazard analysis before a single line of autonomy code is written, then traces every mitigation back to a test. Passing it means a contracting officer can field the system alongside allied crews without accepting undisclosed residual risk.

PREVENTS Undocumented hazards reaching the operational test window.

CHAPTER II

Airborne Software Assurance — DO-178C Level B

Level B is the assurance level required when a software failure would cause a “major” but not catastrophic condition on an aircraft — the band where most tactical unmanned systems sit. Passing it means every requirement, every line of code, and every test case is traceable bidirectionally, and the toolchain used to verify the code is itself qualified.

PREVENTS Unverifiable code reaching the flight-control computer.

CHAPTER III

Information Security — ISO 27001:2022

The 2022 revision realigns the standard with how software supply chains actually fail: through third-party components, through development pipelines, and through supplier access. Our certification covers the Annex A controls that govern classified handling, secure development environments, and supplier relationships — the controls a source-selection memo cites by clause number.

PREVENTS Adversarial access through the software supply chain.

// 03 · THIRD-PARTY ATTESTATION

Auditors, commands, and consortiums that signed the line.

Every posture claim on this page is anchored to a named institution. Cross-check against the auditors you already trust — the artifacts below are public-record or available under standard non-disclosure.

REGULATOR · U.S. NAVY

U.S. Naval Sea Systems Command

$48.7M sole-source IDIQ award, March 2023. Unmanned Surface Vessel family of programs — certification authority for maritime autonomy fielding.

ALLIED COMMAND · NATO

NATO Allied Command Transformation

Trusted Autonomy Partner designation, 2022. Selected for the ACT experimentation campaign across the maritime and critical-infrastructure tracks.

DEFENSE INNOVATION · U.S. DoD

Defense Innovation Unit (DIU)

Winner of the 2023 Commercial Solutions Opening — Autonomy Track. Selected over 214 competing vendors after a twelve-week technical evaluation.

INDUSTRY BODY · NDIA

National Defense Industrial Association

Founding member of the Open Mission Systems consortium and contributing member of the Autonomy Stack Working Group since 2018.

  • CAGE6V2X3
  • UEIK7M4N9P2LQJ8
  • NAICS541512 · 541715 · 511210
  • SAMActive · expiration 2026-08-14
  • FACILITY CLEARANCETS // SCI · SCIF on-site
  • ITAR / EARRegistered · full compliance

// 04 · PROCUREMENT FAQ

The five questions your contracts office will route back.

Answered here, in writing, in the order they arrive. If your question is not listed, our contracts desk returns written responses within one business day.

01 · What is Cyberdyne's ITAR and EAR posture?
Cyberdyne Software, Inc. is ITAR-registered with the U.S. State Department Directorate of Defense Trade Controls and compliant with the Export Administration Regulations (EAR) administered by the Bureau of Industry and Security. Our technology is U.S.-origin and released only to U.S. persons or to allied end-users under an executed technical assistance agreement (TAA) or an applicable ITAR exemption.
02 · Provide your CAGE code, UEI, and SAM status.
CAGE: 6V2X3. UEI: K7M4N9P2LQJ8. SAM registration is active and in good standing with an expiration of 14 August 2026. Representations and certifications are refreshed annually and available on request.
03 · Can our DCAA auditor review your records?
Yes. Cyberdyne's accounting system has been determined adequate for incurred-cost submission under DFARS 252.242-7006. DCAA and cognizant federal agency audit access is permitted under standard contract clauses, including at the subcontractor level, with a five-business-day notification window unless the contracting officer invokes a shorter period under FAR 42.802.
04 · Describe your facility clearance and classification handling.
Cyberdyne holds a Top Secret facility clearance issued by the Defense Counterintelligence and Security Agency (DCSA), with Sensitive Compartmented Information (SCI) access granted via a cognizant security authority. A SCIF is operated at our Arlington headquarters at 1320 N Courthouse Rd, Suite 900. Seventy-one percent of personnel hold active DoD TS/SCI clearances. All classified handling is performed under a DD Form 254 issued on a per-program basis.

For audit packages, classified briefings, or pre-RFI technical scoping — the contracts desk is staffed Monday through Friday, 0800–1700 ET.