Compliance frameworks, security audits, and quality certifications this company maintains.
SAIC holds CMMI Maturity Level 3 certification across its software and systems engineering delivery organizations, demonstrating repeatable, defined processes for program execution that meet DoD acquisition standards and are required for prime contractor eligibility on major defense IT programs.
SAIC's information security management systems are certified to ISO 27001, providing enterprise-wide controls covering classified and unclassified network operations, data handling, and incident response — a baseline requirement for managing sensitive government information across SAIC's program delivery environments.
SAIC operates FedRAMP High-authorized cloud environments supporting DoD Impact Level 4 and 5 workloads, enabling federal agency customers to migrate sensitive controlled unclassified information (CUI) to SAIC-managed cloud infrastructure without agency-by-agency authorization processes.
SAIC is compliant with the Cybersecurity Maturity Model Certification (CMMC) Level 2 requirements, satisfying the DoD's contractor cybersecurity baseline that applies to all companies handling Controlled Unclassified Information on DoD contracts — essential for SAIC's continued eligibility across its defense program portfolio.
SAIC's program delivery environments and IT systems comply with NIST Special Publication 800-171 requirements for protecting Controlled Unclassified Information in non-federal systems, a mandatory standard for DoD contractors that underpins SAIC's ability to handle sensitive defense information across its 26,000-employee workforce.
SAIC complies with International Traffic in Arms Regulations (ITAR) governing the export and handling of defense articles and technical data, applicable to SAIC's systems engineering and integration work on classified defense programs involving controlled military technology and hardware.
SAIC's managed services and cloud operations environments maintain SOC 2 Type II certification, providing independent validation of security, availability, and confidentiality controls for government customers using SAIC-operated IT infrastructure under long-term managed services contracts.
SAIC's health IT programs supporting the Department of Veterans Affairs, HHS, and other federal health agencies are operated in compliance with HIPAA's security and privacy rules, protecting electronic protected health information processed under SAIC's federal health IT modernization and EHR integration contracts.
SAIC holds ISO 9001 quality management system certification across its program management and delivery organizations, demonstrating consistent, process-driven service delivery that meets customer and regulatory requirements on SAIC's federal IT and engineering programs.
Regulatory
DFARS 252.204-7012
CompliantSAIC complies with DFARS clause 252.204-7012 governing safeguarding of covered defense information and cyber incident reporting, a mandatory requirement for all DoD contractors handling controlled technical information — directly applicable to SAIC's entire defense program portfolio covering IT, engineering, and managed security services.