REM5LLC
FedRAMP Marketplace

Advisor listing information

Published under FedRAMP MKT-CAS-WEB, which requires an advisory service to supply its listing information in consistent machine-readable and human-readable formats.

Every field below is rendered from the same source as /fedramp-advisor.json, which conforms to the FedRAMP Advisory Service Information Schema dated 2026-06-24. The two documents are generated from one object and validated against that schema on every build, so they cannot disagree.

advisorNamerequired
REM5 LLC
serviceDescriptionrequired
REM5 LLC is an independent advisory practice for commercial software companies entering and operating in United States federal and Department of Defense markets. We advise engineering and security teams on FedRAMP certification under the 2026 Consolidated Rules, on DoD Impact Level 4 and 5 authorization under the DoD Cloud Computing SRG, and on the engineering work underneath both: secure supply chain, FIPS-validated cryptography, DNSSEC, patch and System Security Plan automation, and Cloud Access Point design. Engagements are advisory. We work alongside the team that owns the authorization rather than producing its artifacts or meeting its ongoing requirements on its behalf.
contactInformationrequired · 2 entries
servicesOfferedrequired · 18 entries
  1. Federal Market StrategyStrategic direction for building a federal business: whether to pursue it at all, which agencies and programs to approach first, how to find and keep a sponsor, and what an authorization genuinely costs in engineering time rather than in consulting fees.
  2. Government, NIST and DoD RequirementsTranslating NIST SP 800-53, FIPS, and Department of Defense policy into engineering work a team can schedule. The goal is that engineers understand why a requirement exists, not just that it was assigned to them.
  3. Secure by Design Program DevelopmentBuilding the engineering culture, defaults, and controls that make an authorization a byproduct of how the team already works instead of a separate campaign run against a deadline.
  4. FedRAMP Certification AdvisoryAdvisory across FedRAMP certification under the 2026 Consolidated Rules: choosing among Certification Classes A through D, meeting Key Security Indicators, structuring evidence, and preparing for assessment. We advise the team that owns the certification; we do not produce its artifacts or meet its ongoing requirements on its behalf.
  5. DoD Impact Level AuthorizationAdvisory for Department of Defense Impact Level 4 and Impact Level 5 authorization under the DoD Cloud Computing SRG: what the authorization asks of the system and the engineering team, how it differs from FedRAMP certification, and how to sequence the two. IL5 now requires CNSSI 1253, the National Security System designation, and we advise on meeting those controls.
  6. CNSSI 1253 and National Security System ControlsAdvisory on CNSSI 1253, the National Security System designation now required for Impact Level 5: which controls apply to a given system, and how to meet them in a running system rather than on paper.
  7. FedRAMP Secure Configuration GuideProducing the customer-facing configuration guidance FedRAMP requires under SCG-CSO-RSC: how an agency securely accesses, configures, operates, and decommissions top-level administrative accounts, and what the settings only those accounts can reach actually do. Required of providers certified in Classes B, C, and D.
  8. 3PAO SelectionChoosing an independent assessor, and knowing what to ask before signing. Assessors differ in the architectures they have actually assessed, how they handle findings mid-assessment, their throughput, and whether they have worked at your certification class or Impact Level. REM5 does not perform assessments — we help you pick the organization that will.
  9. Authorization MaintenanceKeeping an authorization alive after the award: continuous monitoring, significant change handling, vulnerability response within required timelines, and the reporting cadence that agencies and sponsors rely on.
  10. IL4 and IL5 Cloud Access Point DesignDesigning connectivity that survives DoD Cloud Access Point and DISA connection review: boundary definition, CAP ingress and egress paths, and the network architecture decisions that are expensive to reverse once an authorization is underway.
  11. DISA Enterprise Service IntegrationDesigning the integrations an Impact Level 5 service has to make with DoD enterprise infrastructure: DISA EEMSG, MILProxy — the DNS proxy for .mil domains — and the DoD NIC. Planned for early these are routine; discovered late they force architecture changes.
  12. DNSSEC ImplementationZone signing, key generation and rotation, chain of trust to the parent zone, and resolver behavior under failure. Covers the operational practices that keep a signed zone from becoming an outage.
  13. Secure Supply ChainBuilding a supply chain you can make claims about: SBOM generation and consumption, build provenance and attestation, artifact signing and verification, dependency integrity, and the policy that decides what is allowed to ship. In DoD environments that extends to hardened base images and registries such as Iron Bank.
  14. NIST IR 8587 — Token and Assertion ProtectionAdvisory on meeting NIST IR 8587, Protecting Tokens and Assertions from Forgery, Theft, and Misuse: signing key management and scoping, token verification and validity periods, and the identity provider and authorization server architecture behind single sign-on, federation, and API access.
  15. FIPS ComplianceImplementing FIPS to meet FedRAMP and Department of Defense requirements: selecting validated cryptographic modules, configuring the stack to use them, and resolving the libraries and third-party components that need work before they will run under FIPS.
  16. System Security Plan AutomationGenerating and maintaining System Security Plan content from live system state instead of by hand, so the documented system and the running system describe each other and stay that way between assessments.
  17. CIS Benchmark and DISA STIG HardeningApplying and maintaining hardening baselines across the operating systems, containers, and services in scope: which benchmark or STIG applies to what, which deviations can be justified and how to document them, and keeping hardened images from drifting once they are running. We also advise on authoring new benchmarks and STIGs, and can help write them.
  18. Patching AutomationMeeting remediation timelines without a manual scramble: automated patch and image pipelines, vulnerability triage that distinguishes real exposure from scanner noise, and evidence that remediation happened when you said it did.

Requests from @fedramp.gov and @gsa.gov addresses sent to the contact information above are answered within five business days, perMKT-CAS-RFR.

FedRAMP lists advisory services in the Marketplace without formal quality review. A listing does not represent review or endorsement by FedRAMP. REM5 LLC is an advisory service and is not an independent assessment organization; we do not perform the independent assessments that FedRAMP certification requires.