Compliance frameworks, security audits, and quality certifications this company maintains.
CACI holds CMMI Development Level 3 appraisal across its technology development and systems engineering practices, meeting DoD acquisition standards for disciplined software and systems development on SIGINT, EW, and enterprise IT programs.
Regulatory
FedRAMP Moderate
CertifiedCACI operates FedRAMP Moderate authorized cloud environments supporting DoD and civilian agency digital modernization programs, enabling CACI to host government workloads in compliant cloud infrastructure for enterprise IT managed services.
CACI's information security management practices are ISO 27001:2022 certified, providing government clients assurance that CACI's handling of sensitive program information — including classified program data and CUI — meets internationally recognized security standards.
CACI holds ISO 9001:2015 quality management certification, supporting consistent service delivery and continuous improvement across its SIGINT technology development, enterprise IT managed services, and intelligence mission analytics programs.
Regulatory
DoD CMMC Level 3
CompliantCACI meets CMMC Level 3 (Advanced) requirements for protecting Controlled Unclassified Information across its DoD program environments, enabling performance on DoD contracts requiring advanced cybersecurity practices including SIGINT and EW development programs.
Regulatory
ITAR Registered
CompliantCACI is ITAR registered with DDTC, required for its SIGINT hardware development, EW systems work, and defense technology programs that involve defense articles and technical data subject to International Traffic in Arms Regulations.
CACI complies with NIST SP 800-171 across its program delivery and corporate IT environments, protecting CUI as required by DoD contracts and supporting CMMC Level 3 assessment readiness across its technology and mission programs.
CACI's managed IT service delivery operations are SOC 2 Type II certified, giving DoD and civilian agency clients independently audited assurance over the security, availability, and confidentiality of CACI-managed IT environments.
CACI implements NIST SP 800-53 security controls across government-facing IT systems and cloud environments, supporting Authority to Operate (ATO) and continuous ATO (cATO) processes for DoD and IC programs.
Regulatory
FAR 52.203-13 Ethics
CompliantCACI maintains a comprehensive business ethics and compliance program meeting FAR 52.203-13 contractor code of business ethics and conduct requirements, including an ethics hotline, mandatory training, and annual compliance program reporting to government oversight bodies.