REM5LLC
REM5 LLC — Independent advisory

Are you stuck translating FedRAMP and DISA requirements?

REM5 brings expert advisory to help cloud service providers understand federal requirements and how to actually implement them. Most 3PAOs focus on the control gaps, but aren’t able to advise on a deep technical level on designs that meet the controls.

REM5 LLC is a battle hardened advisory firm, advising multiple large cloud service providers on how to meet the most stringent and emerging security controls. Whether you’re just getting going with FedRAMP 20x Class A (previously Low), or planning for FedRAMP Class D (previously High) or IL5, we can help.

Where the work happens
L1
Policy & strategy

Whether to pursue federal at all, and in what order.

L2
Documentation & assessment

The package, the assessor, the award.

Most advisory stops here

L3
Architecture & boundary

What the system actually looks like, and how it connects.

L4
Build & provenance

How code and keys become things you can prove claims about.

L5
Runtime

What happens after it ships, on a schedule you can meet.

The practice

More than control mapping and gap assessment.

Rather than waiting for costly gap assessments, have a discussion with us first. We’ll review your architecture and call out the big rocks that will block authorization. Then if you choose to do the gap assessment, it will be more valuable and be better scoped. Many customers skip the gap assessment altogether when REM5 LLC is engaged, and we have a very strong track record of getting cloud services authorized the first time.

Want to pursue the public sector more aggressively? We have helped our clients get both FedRAMP High and IL4 at the same time. Our record so far is under 2 years for both. We can help you understand the differences as well as the commonalities, and design your business practices to better succeed in the U.S. public sector.

Most engagements deliver a control matrix and a list of gaps. That tells you where you stand. It does not tell you how to remediate. How do we implement FIPS? How do we meet the supply chain security requirements? How do I design my DISA CAP peering? These are just a few of the questions we can help answer.

REM5 works at both layers. Strategy through to engineering. We help you build solutions to align with your business and with the risk. We will help right size solutions rather than boiling the ocean.

REM5 is not an independent assessor. It advises; it does not perform the independent assessments FedRAMP certification requires, and does not intend to. Engagements are advisory throughout. We work alongside the team that owns the authorization rather than producing its artifacts or meeting its ongoing requirements on its behalf.

Platform advisory

Independent, with no platform of our own.

Considering using a platform like Knox, Defense Unicorns, or stackArmor? We work with them too. We can help you choose which platform is best for you and collaborate with the platform vendors.

The great thing about an independent advisor is that we are just that, independent. We do not have a platform, we are not an assessor or 3PAO. This means we have unique insight across the industry.

Knox SystemsDefense UnicornsstackArmor
Services

Eighteen areas, across five layers.

Advisory

Direction, requirements, and the certification itself. L1–L2.

L1Policy & strategy

Federal Market Strategy

Strategic direction for building a federal business: whether to pursue it at all, which agencies and programs to approach first, how to find and keep a sponsor, and what an authorization genuinely costs in engineering time rather than in consulting fees.

L1Policy & strategy

Government, NIST and DoD Requirements

Translating NIST SP 800-53, FIPS, and Department of Defense policy into engineering work a team can schedule. The goal is that engineers understand why a requirement exists, not just that it was assigned to them.

L1Policy & strategy

Secure by Design Program Development

Building the engineering culture, defaults, and controls that make an authorization a byproduct of how the team already works instead of a separate campaign run against a deadline.

L2Documentation & assessment

FedRAMP Certification Advisory

Advisory across FedRAMP certification under the 2026 Consolidated Rules: choosing among Certification Classes A through D, meeting Key Security Indicators, structuring evidence, and preparing for assessment. We advise the team that owns the certification; we do not produce its artifacts or meet its ongoing requirements on its behalf.

L2Documentation & assessment

DoD Impact Level Authorization

Advisory for Department of Defense Impact Level 4 and Impact Level 5 authorization under the DoD Cloud Computing SRG: what the authorization asks of the system and the engineering team, how it differs from FedRAMP certification, and how to sequence the two. IL5 now requires CNSSI 1253, the National Security System designation, and we advise on meeting those controls.

L2Documentation & assessment

CNSSI 1253 and National Security System Controls

Advisory on CNSSI 1253, the National Security System designation now required for Impact Level 5: which controls apply to a given system, and how to meet them in a running system rather than on paper.

L2Documentation & assessment

FedRAMP Secure Configuration Guide

Producing the customer-facing configuration guidance FedRAMP requires under SCG-CSO-RSC: how an agency securely accesses, configures, operates, and decommissions top-level administrative accounts, and what the settings only those accounts can reach actually do. Required of providers certified in Classes B, C, and D.

L2Documentation & assessment

3PAO Selection

Choosing an independent assessor, and knowing what to ask before signing. Assessors differ in the architectures they have actually assessed, how they handle findings mid-assessment, their throughput, and whether they have worked at your certification class or Impact Level. REM5 does not perform assessments. We help you pick the organization that will.

L2Documentation & assessment

Authorization Maintenance

Keeping an authorization alive after the award: continuous monitoring, significant change handling, vulnerability response within required timelines, and the reporting cadence that agencies and sponsors rely on.

Engineering

The layers most advisory does not reach. L3–L5.

L3Architecture & boundary

IL4 and IL5 Cloud Access Point Design

Designing connectivity that survives DoD Cloud Access Point and DISA connection review: boundary definition, CAP ingress and egress paths, and the network architecture decisions that are expensive to reverse once an authorization is underway.

L3Architecture & boundary

DISA Enterprise Service Integration

Designing the integrations an Impact Level 5 service has to make with DoD enterprise infrastructure: DISA EEMSG, MILProxy (the DNS proxy for .mil domains), and the DoD NIC. Planned for early, these are routine. Discovered late, they force architecture changes.

L3Architecture & boundary

DNSSEC Implementation

Zone signing, key generation and rotation, chain of trust to the parent zone, and resolver behavior under failure. Covers the operational practices that keep a signed zone from becoming an outage.

L4Build & provenance

Secure Supply Chain

Building a supply chain you can make claims about: SBOM generation and consumption, build provenance and attestation, artifact signing and verification, dependency integrity, and the policy that decides what is allowed to ship. In DoD environments that extends to hardened base images and registries such as Iron Bank.

L4Build & provenance

NIST IR 8587 — Token and Assertion Protection

Advisory on meeting NIST IR 8587, Protecting Tokens and Assertions from Forgery, Theft, and Misuse: signing key management and scoping, token verification and validity periods, and the identity provider and authorization server architecture behind single sign-on, federation, and API access.

L4Build & provenance

FIPS Compliance

Implementing FIPS to meet FedRAMP and Department of Defense requirements: selecting validated cryptographic modules, configuring the stack to use them, and resolving the libraries and third-party components that need work before they will run under FIPS.

L4Build & provenance

System Security Plan Automation

Generating and maintaining System Security Plan content from live system state instead of by hand, so the documented system and the running system describe each other and stay that way between assessments.

L5Runtime

CIS Benchmark and DISA STIG Hardening

Applying and maintaining hardening baselines across the operating systems, containers, and services in scope: which benchmark or STIG applies to what, which deviations can be justified and how to document them, and keeping hardened images from drifting once they are running. We also advise on authoring new benchmarks and STIGs, and can help write them.

L5Runtime

Patching Automation

Meeting remediation timelines without a manual scramble: automated patch and image pipelines, vulnerability triage that distinguishes real exposure from scanner noise, and evidence that remediation happened when you said it did.

Contact

Start with the hard question.

The most useful first conversation is usually the one about whether to pursue federal at all, and at which class. Bring the awkward version of the question.