Working with us as a subcontractor

Fixed-scope work packages, cleared key personnel, and no-cost proposal support

We take a defined work package, put a named principal on it, and we do not market to your customer.

Where we fit

Three lanes on a teamed bid

AI assurance

High-impact determinations, impact assessments, guardrails, bias and hallucination testing, and secure CUI deployment.

ATO / FedRAMP / cATO

Control narratives, SSPs, POA&Ms, 3PAO evidence, Continuous ATO (cATO) enablement, and continuous monitoring.

Visibility / zero trust

Logging maturity, SIEM, CAASM, endpoint modernization, segmentation, IAM, and privileged access.

Also available

cATO, fractional leadership, proposal support, and hiring

cATO (Continuous ATO)

Continuous authorization evidence pipelines, control automation, and sustainment so authorizations keep pace with change.

vCISO / vISSO

Fractional senior security leadership for programs that need ISSO or CISO coverage without a full-time hire.

Proposal support

Competitive analysis, PWS gap analysis, solutioning, and technical demo support on teamed bids.

Hiring

Cleared senior placement for key-personnel slots - resumes, commitment letters, and fit to labor categories.

What you can assign us

Eight scoped offerings, priced by work package

Offerings, deliverables, duration, and compliance driver
OfferingDeliverablesWeeksCompliance driver
High-Impact AI Determination and Impact AssessmentUse-case inventory; high-impact determination memo; AI impact assessment; pre-deployment test report; monitoring plan; human oversight, appeal and feedback process design.4–6OMB M-25-21 §4(b), recurring for every new high-impact deployment
AI Guardrail and Assurance EngineeringGrounding and citation enforcement; hallucination, bias and prompt-injection test harness; red-team findings; evaluation baseline; drift monitoring; human validation workflow.6–8OMB M-25-21; NIST AI RMF; CISA secure AI and agentic AI guidance
Secure AI Architecture for CUI and Sensitive DataWalled-garden or air-gapped inference design; private networking and service controls; model/data portability; authorization-aligned architecture and control mapping.6–10OMB M-25-22 acquisition terms; FedRAMP; ATO prior to deployment
ATO and FedRAMP Readiness SprintNIST SP 800-53 Rev. 5 gap matrix; SSP narratives; POA&M sequencing; 3PAO evidence prep; Rev. 5 transition and key-security-indicator assessment.6–10FedRAMP consolidated 2026 rules; Rev. 5 closes to new applications in 2027
Logging and Continuous Event Monitoring ReadinessIT, OT, and IoT asset reconciliation; M-26-14 logging maturity gap analysis; draft agency logging plan; SIEM and pipeline architecture; retention and searchability design.4–8OMB M-26-14, with maturity milestones running from late 2026 through 2027
CAASM and Vulnerability Data ReconciliationEDR, CMDB, cloud and scanner reconciliation; duplicate and identity conflict resolution; coverage metrics; risk-based remediation mapping; executive dashboarding.4–6CISA BOD 26-04 risk-based remediation; BOD 23-01; CDM reporting
Endpoint and Virtual Desktop Security ModernizationEDR migration; multi-tenant policy architecture; detection tuning; secure AVD or VMware Horizon design; STRIDE threat modeling; endpoint baseline and coverage assurance.6–10Zero trust device pillar (OMB M-22-09); FISMA continuous monitoring
Security Control Validation and STIG AutomationAutomated STIG/SCAP scanning; custom audit files and baselines; IaC and container security gates; security-stack health checks; control-validation evidence pipeline.4–6NIST SP 800-53 Rev. 5 assessment; DoD STIG compliance; cATO evidence automation

Also available: cATO (Continuous ATO), vCISO/vISSO coverage, proposal support, hiring support for cleared seniors, fractional AI security architect or chief cyber architect support, named cleared key personnel, and no-cost technical volume or orals help on teamed bids.

The week ranges are planning estimates for a single system or boundary, and we confirm them with you before award. The compliance references are there to help you scope - we do not commit to a date until we have looked at the environment.

How we contract

Firm-fixed-price work package

Discrete deliverable, fixed price. No approved accounting system required from us.

T&M subcontract

Negotiated hourly rates against your awarded labor categories.

Key-personnel placement

Named cleared senior resource with letter of commitment.

Advisory retainer

Set days per month for senior architecture and governance support.

Pricing: usually firm-fixed-price after a brief scoping call. Labor-category ranges are available to support bid shaping when needed.

What primes ask us first

How many people can you put on?

Senior principals own the work we take. If the requirement runs larger, we can bring in additional cleared senior people we have worked with before. We would rather be one focused subcontractor on your team than claim capacity we cannot staff.

Do you have corporate past performance?

Not under the Legate Solutions LLC name yet, and we would rather tell you that up front than bury it. The delivery history sits with our principals. Where the RFP allows it, we ask for a neutral rating and let the key personnel and the technical approach do the work.

Can you take cost-reimbursable work?

Fixed price is usually the easiest path. For T&M, we work under your awarded labor categories at agreed rates. If the requirement needs a DCAA-approved accounting system, flag it early so we can structure the role correctly.

How fast can you support a proposal?

Quickly. We can usually return comments within 24 hours and draft a scoped technical section within three business days once the assignment is clear. Resumes and commitment letters can follow your format.

Will you go around us to the customer?

No. For a named opportunity, we can sign exclusivity and will not market around you or team with a competitor on the same requirement. We are not trying to build a prime business.

What do you cost?

We usually price by work package after a short no-cost scoping call. If you need labor-category ranges for bid shaping, we can typically provide them within 48 hours of RFP release.

Proof points

Platforms we have actually run

AI & LLM

M365 Copilot, Copilot Studio, Azure OpenAI, Vertex AI, Claude, Bedrock, Ollama, RAG

Endpoint & EDR

CrowdStrike, Defender, Carbon Black, Tanium, Cylance, McAfee ePO, Intune, SCCM

Network & perimeter

Palo Alto NGFW, VMware NSX, Cisco R&S, Juniper Junos (MX / PTX / ACX), Contrail, IP/MPLS, BGP, IS-IS, TIC 3.0, AD / DNS / DHCP

Virtual desktop & datacenter

Azure Virtual Desktop, VMware Horizon, vSphere, FlexPod, Veeam

Vulnerability & CAASM/CTEM

Tenable (Nessus, .sc, ACAS), Tripwire IP360, Axonius, Armis, ServiceNow HWAM

Identity & privileged access

CyberArk PAM and EPM, Venafi, Entra ID, HSM

SIEM, data & GRC

Splunk, Elastic, Sentinel, Cribl, Databricks, RSA Archer, Phantom SOAR

Automation & test

Ansible, OpenSCAP, STIG, GitLab CI/CD, Docker, Checkov, Prowler, Selenium, OWASP ZAP, IXIA/Keysight, Python