code/+/trust primary logo full color svg

Department of Homeland Security

DHS Software Contractor

Secure software development for Department of Homeland Security programs, as a subcontractor or through RFPs. DHS 4300A, NIST 800-53 and Section 508 requirements scoped in the design phase. Based in Mt Pleasant, SC.

What does a DHS software contractor deliver?

A DHS software contractor builds secure web applications, mission-critical data platforms, and legacy system modernizations for Department of Homeland Security components under contracts that carry HSAR clauses. We have come into public-sector work as a subcontractor through a prime contractor and by responding to RFPs. On a DHS build, we scope the DHS 4300A requirements, Section 508 accessibility and NIST 800-53 ATO documentation in the design phase.

DHS was created in 2002 by combining 22 federal departments and agencies. Its operational components, including CBP, CISA, FEMA, ICE, TSA, USCIS, the Coast Guard and the Secret Service, have distinct missions and compliance requirements. CBP and ICE programs involve law enforcement information that is handled as CUI. CISA programs intersect with critical infrastructure security. FEMA and USCIS programs prioritize public-facing accessibility.

DHS-specific compliance requirements

DHS software compliance layers three things on top of standard FISMA: DHS Policy Directive 4300A (Information Technology System Security Program, Sensitive Systems) adds DHS-specific requirements for unclassified systems; HSAR (Homeland Security Acquisition Regulation) adds DHS clauses to FAR contracts; and component requirements for law enforcement information (CBP/ICE) and critical infrastructure (CISA) extend the baseline further.

DHS 4300A Compliance

DHS Policy Directive 4300A, Information Technology System Security Program, Sensitive Systems, governs information security for DHS sensitive (unclassified) systems. DHS national security systems fall under the separate 4300B series. 4300A builds on FISMA and NIST SP 800-53 Rev 5 with DHS-specific control implementation, reporting and authorization requirements. When a DHS system needs an ATO, we scope the NIST baseline and the 4300A requirements in the design phase.

HSAR Contract Clauses

The Homeland Security Acquisition Regulation (HSAR) adds DHS-specific clauses to FAR-based contracts. Key HSAR clauses affect data rights, security incident reporting, and contractor access to DHS facilities and systems. Those clauses differ from the standard FAR Part 52 provisions.

Law Enforcement Information Handling

CBP and ICE programs routinely involve law enforcement information. Under the federal CUI Program, the legacy "Law Enforcement Sensitive" (LES) marking gives way to the Law Enforcement categories in the CUI Registry, each with its own handling requirements. On a system that handles that information, role-based access control, audit logging, and data compartmentalization are scoped in the design phase.

Section 508 for Public-Facing DHS Services

Public-facing DHS services, such as FEMA disaster assistance portals and USCIS case status tools, must meet the Revised Section 508 Standards, which incorporate WCAG 2.0 Level A and AA, serving a public that includes users with disabilities who depend on government digital services. Section 508 conformance and the Accessibility Conformance Report are scoped in the design phase.

DHS software contractor: common questions

DHS software contractor questions most often cover DHS-specific compliance beyond standard FISMA, contract vehicles for DHS work, law enforcement information handling, CISA, and Section 508 requirements for DHS public-facing systems. All five are answered below.

Does DHS software require special compliance beyond standard FISMA?

DHS sensitive (unclassified) systems must follow DHS Policy Directive 4300A, Information Technology System Security Program, Sensitive Systems, in addition to FISMA and NIST 800-53; national security systems follow the separate 4300B series. CBP and ICE programs handling law enforcement information have additional CUI handling requirements. CISA programs may involve ICS/SCADA security requirements. When a DHS system needs an ATO, we scope these requirements on top of the standard NIST RMF baseline in the design phase.

What contract vehicles support DHS software work?

DHS software work flows through multiple-award IDIQs and governmentwide acquisition contracts, for example GSA Alliant 2 and 8(a) STARS III, through DHS component contracts, and through OTAs for prototype work. DHS contracts carry Homeland Security Acquisition Regulation (HSAR) clauses on top of the FAR. We have come into public-sector work as a subcontractor through a prime contractor and by responding to RFPs.

What does law enforcement information require in DHS systems?

Under the federal CUI Program, law enforcement information is CUI: the legacy "LES" marking gives way to the Law Enforcement categories in the CUI Registry, and each category carries its own handling requirements. CBP and ICE programs routinely involve it. On a system that handles it, we scope access control, role-based data compartmentalization, and audit trails in the design phase.

What is CISA?

CISA (Cybersecurity and Infrastructure Security Agency) is a DHS component that calls itself America's Cyber Defense Agency. Its stated mission is to lead the national effort to understand, manage, and reduce risk to the nation's cyber and physical infrastructure. Its programs include Continuous Diagnostics and Mitigation (CDM), which strengthens the cybersecurity of government networks and systems.

What does Section 508 require for DHS-facing software?

DHS-facing software must meet the Revised Section 508 Standards, which incorporate WCAG 2.0 Level A and AA. DHS contracts can require an Accessibility Conformance Report (ACR) built on the VPAT template. On a DHS build, we scope Section 508 conformance and the Accessibility Conformance Report in the design phase.

Related federal software services

DHS software contracting connects to the federal software development overview, cleared developer staffing (clearance requirements confirmed per program), DoD software contracting for programs that span both homeland security and defense missions, and our Mt Pleasant, SC office.

Ready to discuss a DHS engagement?

DHS engagements start with a 30-minute call covering component, program, contract vehicle, data classification requirements, and Section 508 obligations. Code and Trust is based in Mt Pleasant, SC.

Tell us the program, and we will reply in writing with whether and how we can support it.