Skip to main content
Engagement Logistics

Working with us: access, clearances, and practical logistics

Schedules rarely slip on engineering. They slip on access: a network credential with a six-week queue, a data-handling question nobody asked, a signature that had to happen before the first file moved. Here is every gate we see, who clears it, and how long each one takes.

The start date is set by access, not by engineering

By the time a program office or a prime calls us, the technical question is usually settled. Someone has a model to build, a data pipeline to repair, an evaluation that has to survive an assessor. What decides when the work actually starts is almost never the engineering. It is access: whether the data can be handed to a contractor at all, which credential the network requires, which agreement had to be signed before the first file moved, and who inside the agency owns the sponsorship. Those items have lead times measured in weeks, and none of them run any faster because the engineering plan is good.

So we treat access as the first work package, with an owner and a date on every line, the same way we treat a build. On the first call our engineers ask three questions before anything else: what data does the work touch, whose environment does it run in, and what date do you need someone producing. The answers set the critical path. Everything else on the schedule hangs off them.

This piece walks through each gate in the order it usually bites. Export control and U.S.-person status. Export-controlled technical data and the certification that lets it move. Controlled Unclassified Information. Protected health information. Credentials and background investigations. Classified structure. Whose environment hosts the work. Then the day-to-day cadence of remote delivery, and the short list of things to send us so we can hand back a dated access plan.

U.S.-person status and what it actually gates

Three separate rules get collapsed into one vague question on most kickoff calls. Separating them saves weeks, because each has a different test and a different owner.

Export control. The ITAR defines a U.S. person at 22 CFR 120.62: U.S. citizens, lawful permanent residents, and protected individuals under 8 U.S.C. 1324b(a)(3). The EAR treats release of controlled technology to a foreign person inside the United States as a deemed export at 15 CFR 734.13. Everyone on our team who touches export-controlled technical data is a U.S. person as those regulations define the term. That is the test the rule writes, and it is the test a program security officer is actually required to apply.

Small-business eligibility. SBIR and STTR eligibility turns on ownership and control, at 13 CFR 121.702. The firm must be more than 50 percent directly owned and controlled by one or more individuals who are citizens or permanent resident aliens of the United States, or by other qualifying small businesses. Precision Federal is a U.S.-owned, U.S.-controlled small business with no foreign ownership, foreign funding, or foreign control to disclose, which is the corporate fact the foreign-affiliation screening questions ask for.

Classified access. Only the third rule turns on citizenship. Eligibility for a personnel security clearance runs through the National Industrial Security Program Operating Manual at 32 CFR Part 117. It is a separate track from the first two and should be discussed separately.

What usually sets the start date

Government network account and device issue
92%
Background investigation and badge sponsorship
87%
Approved transfer path for sensitive data
81%
Subcontract execution and clause flow-downs
76%
Privacy or health-data agreement review
70%
Nondisclosure and proprietary-information papers
64%

Editorial weighting from public guidance and practitioner reading — illustrative, not a measured statistic.

Export-controlled technical data: the DD-2345 route

Precision Federal is certified under the Joint Certification Program and holds an approved DD Form 2345, the Militarily Critical Technical Data Agreement, administered by the Defense Logistics Agency. Our CAGE code is 1AYQ0. What that buys a program office is short and practical: unclassified technical data whose public release is withheld under 10 U.S.C. 130 and DoD Directive 5230.25 can be released to us on the strength of a certification that already exists, rather than a one-off arrangement negotiated at the moment the data is needed.

In practice this is the material carrying Distribution Statements B through F under DoDI 5230.24: drawings, interface control documents, test data, performance specifications, source code for defense articles. A certification runs five years and belongs to the firm, so a prime does not have to sponsor it, and a contracting officer can verify it before the subcontract is signed. Ask for the CAGE code and the certification date, hand them to your security office, and that gate closes the same day.

Handling has its own rules and they are worth stating so nobody improvises. Since 2020 the ITAR has treated end-to-end encrypted technical data as not an export under 22 CFR 120.54(a)(5), provided the cryptography meets the FIPS 140 standard, the keys stay with U.S. persons, and the ciphertext is not intentionally stored in a country listed at 22 CFR 126.1. That provision is what makes cloud collaboration workable, and it is why controlled work lands in AWS GovCloud (US), Azure Government, or an equivalent U.S.-region tenancy with U.S.-person administrators rather than a general-purpose consumer drive. It also means a screen share of a controlled drawing on an ordinary meeting platform is a release decision, not an IT convenience. We set the meeting platform question before the kickoff, not during it.

CUI: what changes the moment it lands

Controlled Unclassified Information has a real legal frame behind it: Executive Order 13556, the National Archives implementing rule at 32 CFR Part 2002, and the Department of Defense program at DoDI 5200.48. The framework matters less than the marking. The category on the banner tells us which controls attach, and the limited dissemination controls tell us who may see it.

Below CUI, the floor for any covered contractor system is the fifteen basic safeguarding requirements at FAR 52.204-21. On defense contracts, DFARS 252.204-7012 raises that to the security requirements in NIST SP 800-171 and adds two operational duties people forget until they need them: cyber incidents get reported to DIBNet within 72 hours of discovery, and the report requires a DoD-approved medium assurance certificate that takes time to obtain. The same clause requires any external cloud service used to store covered defense information to meet the FedRAMP Moderate baseline or the equivalent. Self-assessment scoring under DFARS 252.204-7019 and 252.204-7020 lands in SPRS, and the CMMC program rule at 32 CFR Part 170, with its acquisition clause at DFARS 252.204-7021, has begun phasing into solicitations with self-assessment at the lower levels.

What we need from you is one line of text. Tell us the marking that will appear on the data, whether any limited dissemination control applies, and which system of record it comes from. That single line determines the enclave, the transfer method, the logging, and whether a subcontract needs the 7012 flow-down before anything moves. Our engineers would rather answer it three weeks early than discover it in the middle of an extract.

Access is the first work package, with an owner and a date on every line. A program that starts that package on day one starts the engineering four to six weeks sooner than a program that starts it at kickoff.

PHI and other health data

Health work adds a second regime on top of whatever federal controls already apply. Where we handle protected health information for a covered entity, a business associate agreement is required by 45 CFR 164.502(e), with the required contract terms specified at 45 CFR 164.504(e). The Security Rule obligations are direct, not inherited: administrative safeguards at 45 CFR 164.308, physical at 164.310, technical at 164.312. A business associate that discovers a breach notifies the covered entity without unreasonable delay and no later than 60 days, under 45 CFR 164.410.

Two provisions do most of the practical work on an AI engagement. The minimum necessary standard at 45 CFR 164.502(b) means we scope the extract to the fields the model actually needs, which is usually far fewer than the fields the source system contains. And the de-identification standard at 45 CFR 164.514(b) gives two defensible routes: Safe Harbor removal of the eighteen identifier classes, or expert determination that the re-identification risk is very small. We decide which route applies before the first extract, because retrofitting de-identification after a model has been fit on identified records is a rebuild, not an edit.

Federal health work layers more on. Records maintained on behalf of an agency can bring the Privacy Act into play through 5 U.S.C. 552a(m), with the notification and handling clauses at FAR 52.224-1 and 52.224-2 and the training requirement at FAR 52.224-3. Veterans Affairs work carries the contract security and privacy appendices from VA Handbook 6500.6. Derived artifacts inherit obligations too, so embeddings, feature stores, and model checkpoints trained on protected records are handled at the sensitivity of their source, and the disposition plan for them is written into the statement of work rather than assumed.

The credential clock

Physical and logical access to a federal facility or network runs on HSPD-12 and the FIPS 201-3 credential standard, with the contractor identity clause at FAR 52.204-9. The badge itself is quick. The investigation behind it is not. Low-risk positions run a Tier 1 investigation off the SF-85, public-trust positions use the SF-85P, and national-security positions use the SF-86, each with fingerprint submission and adjudication that is entirely inside the government's control.

The long pole is almost always sponsorship, not paperwork. Someone inside the agency has to initiate the request, name the position sensitivity, and stay on it. When a contracting officer's representative starts that on the day the subcontract is signed, the work usually begins on schedule. When it starts at kickoff, the first month is spent waiting. Interim network access, where the agency permits it, is often available after fingerprints and a favorable initial review, which is why we ask early whether interim access is on the table at all.

Standard onboarding sequence

1
Access call: data types, environment, target start date, named owners on both sides
Day 1
2
Papers move in parallel: NDA, teaming or subcontract, certification verification
Days 1–5
3
Sponsorship initiated for badge, investigation tier, and network account
Week 1
4
Transfer path agreed and tested with a non-sensitive sample file
Week 2
5
Environment stand-up, repository, logging, and the evaluation suite
Weeks 2–3
6
First running increment demonstrated against real data
Weeks 3–5

Clearances: how the structure is built

Classified work follows a different track, and stating the mechanics plainly saves everyone a call. A facility clearance is not something a company grants itself or applies for on its own. It requires sponsorship by a government contracting activity or by a cleared prime with a classified contract and a demonstrated need, under the NISPOM at 32 CFR Part 117. Eligibility for a personnel clearance is limited to U.S. citizens under the same rule. What is classified on a given contract, and at what level, is defined by the DD Form 254 that rides with it.

Most AI, machine learning, data, and cloud engineering is buildable at the unclassified and CUI level, with the classified portion isolated behind a defined interface. That is how we scope it. The model development, the pipeline, the evaluation suite, and the software all get built in the controlled enclave. Where a task has to be performed inside a classified space, it goes to cleared personnel at the facility that holds the clearance for that contract, and we specify the interface: data formats, schemas, test vectors, acceptance thresholds, and the exact procedure for running that suite on the inside. Done that way the handoff is mechanical, and the classified boundary stops being a schedule risk.

If your program does require cleared performance from day one, say so in the first email. It changes the team structure, and it is better designed at proposal time than negotiated after award.

Whose environment the work runs in

Three patterns cover nearly every engagement, and they have very different lead times. Naming yours early is the single most useful thing a partner can do.

Your environment, government furnished. A government laptop plus a network account, or a virtual desktop into the agency enclave. Highest assurance, longest queue, and the pattern that most depends on an internal sponsor keeping the request moving.

Our environment. Work performed in a U.S.-region controlled tenancy with U.S.-person administrators, hardware-token multifactor, a private repository, encrypted storage, retained logs, and defined data disposition at close-out. This is the fastest path to a first increment, and it fits pre-award prototyping, unclassified research data, de-identified health data, and export-controlled technical data handled under the encryption provision described above.

The prime's enclave. We are added as users under your System Security Plan and your authorization boundary. Fast when the enclave already exists and your security officer can add accounts. The one item to confirm is which clauses flow down to us and which of your controls we inherit rather than duplicate.

Remote delivery, in practice

Our base is Central Time in Ames, Iowa. That overlaps the full working day of an Eastern-time program office, and stays open through mid-afternoon Pacific for West Coast integrators and labs. Our bench spans Eastern to Pacific, so review coverage runs wider than a single office would. The practical effect is that a question asked at 8:00 in Washington gets worked the same morning, and a question asked at 3:00 in Los Angeles gets an answer before the day ends.

The delivery rhythm is deliberately boring, because boring is what survives a busy program manager. One standing working session each week with the technical lead. A written status every week that says what shipped, what is blocked, who owns the unblock, and what ships next. A shared board that mirrors that status, so nobody has to ask. Running code demonstrated every two weeks against real data rather than slides. Everything lands in your repository or a repository you can pull from on request, and the evaluation suite is a deliverable from the first increment, not a report at the end.

Travel is available and we do it when it earns its place: kickoff, a design review, an install, a demonstration to the end user. Between those, remote delivery on a written cadence moves faster than a travel schedule and costs your program less.

Data rights, settled up front

The other item worth closing before day one is rights. On defense work the technical data and software rights clauses are DFARS 252.227-7013 and 252.227-7014, and SBIR and STTR deliverables carry the separate protection at DFARS 252.227-7018, which runs twenty years from award under the current SBIR policy direction. Civilian agencies generally work from FAR 52.227-14. Legends and markings have to be applied at delivery. Retroactive marking is a losing argument.

Our practice is to state the rights assertion in the proposal, mark deliverables as they are delivered, keep a software bill of materials with the license of every open-source component, and separate anything developed exclusively at private expense from anything developed under the contract. It costs a few hours at the start and it removes an argument in month five. We are glad to align our assertions with a prime's before submission so the package is consistent.

The access items that gate day one

The table below is what we send after a first call, filled in with names and dates. It is deliberately short. Six lines cover most engagements.

Access itemWho arranges itTypical lead time
Nondisclosure and proprietary information agreementEither side; we sign yours or send ours1–3 days
Export-controlled data certification checkYour security office, against CAGE 1AYQ0Same day
Subcontract or teaming agreement with flow-downsYour contracts office, with our review1–3 weeks
Approved transfer path for CUI or sensitive dataYour ISSO or program security officer3–10 days
Business associate agreement for health dataYour privacy office1–2 weeks
Badge, investigation, and network accountAgency sponsor or contracting officer's representativeWeeks to months

What to send us

Every item above moves faster when it starts early, and every one of them is blocked until someone says what the constraint is. So the ask is small. Send the constraints before you send the statement of work.

  • The data types the work touches: public, CUI with its marking, export-controlled technical data, protected health information, or Privacy Act records.
  • Whose environment the work runs in: government furnished, ours, or your enclave.
  • The credential the environment requires: and whether interim access is permitted.
  • Whether any task must be performed in a classified space: and at what level, per the DD Form 254 if one exists.
  • The date you need someone producing: and the date of the milestone behind it.
  • Who owns each item on your side: a name and an email, not an office.

Send those six lines and you get back a dated access plan: every gate, the owner, the lead time, the critical path, and the earliest honest start date. If something on the list would take longer than your schedule allows, we say so in that same reply and propose the sequence that starts the engineering sooner. That is a better conversation to have in week one than in week six.

Frequently asked questions

What does U.S.-person status mean for export-controlled work?

The ITAR defines a U.S. person at 22 CFR 120.62 as a U.S. citizen, a lawful permanent resident, or a protected individual under 8 U.S.C. 1324b(a)(3). Release of controlled technology to a foreign person inside the United States counts as a deemed export under 15 CFR 734.13. Everyone on our team who touches export-controlled technical data is a U.S. person under that definition.

What does DD-2345 certification let a contractor receive?

Unclassified technical data withheld from public release under 10 U.S.C. 130 and DoD Directive 5230.25, typically carrying Distribution Statements B through F under DoDI 5230.24. Certification is issued through the Joint Certification Program administered by the Defense Logistics Agency, runs five years, and belongs to the firm, so your security office can verify it against the CAGE code before a subcontract is signed.

Can controlled data be worked in a commercial cloud?

Yes, within limits. DFARS 252.204-7012 requires an external cloud service holding covered defense information to meet the FedRAMP Moderate baseline or equivalent. For export-controlled technical data, 22 CFR 120.54(a)(5) treats properly end-to-end encrypted data as not an export when the cryptography meets the FIPS 140 standard, keys stay with U.S. persons, and storage avoids the countries listed at 22 CFR 126.1. In practice that means a U.S.-region government-community tenancy with U.S.-person administrators.

How is health data handled on an AI engagement?

Under a business associate agreement required by 45 CFR 164.502(e), with terms per 164.504(e) and Security Rule safeguards at 164.308, 164.310, and 164.312. We scope the extract to the minimum necessary under 164.502(b) and decide the de-identification route under 164.514(b), Safe Harbor or expert determination, before the first extract rather than after a model has been trained.

How much lead time does contractor access usually need?

Agreements move in days. Data transfer paths and enclave accounts move in one to two weeks. Badges, investigations, and government furnished devices are the long pole and are controlled entirely by the sponsoring agency. The single biggest accelerator is starting sponsorship on the day the subcontract is signed instead of at kickoff.

1 business day response

Tell us the access constraints first

Email [email protected] with three lines: the data types the work touches, whose environment it runs in, and the date you need someone producing. You get back a dated access plan within one business day, naming every gate, its owner, its lead time, and the earliest honest start date.

Send your three linesHow we workMore insights →
UEI Y2JVCZXT9HP5CAGE 1AYQ0NAICS 541512JCP / DD-2345 CERTIFIED