< Back to AI & Software Readiness Audit
EFAIRA Domain IV

Security and Compliance

Boundary controls, framework alignment, host environment posture, and the audit trail that lets oversight reconstruct every AI decision and human approval. Federal-grade or not, scored against NIST, FedRAMP, CMMC, and federal data residency requirements.

The Points

5 scored points inside this domain.

Each point sits on the EFAIRA 30-point scorecard. Each point has a defined evidence baseline and a color-coded readiness mark on the Encore Readiness Receipt.

18

Boundary controls and data flow

What federal data crosses the system boundary. Controls are documented, testable, and aligned to applicable frameworks.

19

NIST, FedRAMP, and CMMC alignment

Authorization-readiness position. NIST 800-53 mapping. FedRAMP and CMMC posture at the level required by the procurement. NIST AI Risk Management Framework alignment, including the April 2026 Trustworthy AI in Critical Infrastructure profile where applicable.

20

Audit trail and tamper-evidence

Every AI decision and every human approval can be reconstructed for oversight. Tamper-evident logging in place. Audit posture sufficient for OMB M-25-22 routine inspection.

21

Data residency, host environment, and tenancy isolation

Where federal data physically resides. AWS GovCloud, Azure Government, or commercial cloud posture. FIPS 140-2 compliant hardware. CONUS residency where required. U.S. persons administration where applicable. Multi-tenancy isolation that prevents customer data from leaking into vendor model training.

22

FedRAMP authorization level alignment to procurement value

Is the contractor's FedRAMP authorization at the level the procurement actually requires? Low when High is required is a procurement-blocker. The contractor's authorization path must be realistic for the contract timeline, not aspirational.

Score Domain IV on your federal pursuit.

Encore engages with contractors and federal agencies through separate paths. Pick the right one for your role.