Department of Defense
DoD Software Contractor
Software development for Department of Defense programs, as a subcontractor or through RFPs. NIST 800-53 and CMMC requirements scoped in the design phase. Based in Mt Pleasant, SC, near NIWC Atlantic.
What does a DoD software contractor do?
A DoD software contractor builds, modernizes, and maintains software for Department of Defense programs under FAR/DFARS-compliant contracts. We have come into public-sector work as a subcontractor through a prime contractor and by responding to RFPs. When a program requires them, we scope CMMC, NIST SP 800-171, NIST 800-53 and Section 508 requirements in the design phase.
DoD software contracting differs from civilian agency work in three critical ways: personnel clearance requirements on classified programs, stricter cybersecurity frameworks (CMMC and NIST SP 800-171 for CUI; for national security and classified systems, the CNSSI No. 1253 baselines and overlays, which build on NIST SP 800-53), and procurement complexity (DFARS clauses, OTAs, and multiple-award IDIQs are standard).
CMMC and DoD cybersecurity requirements
CMMC (Cybersecurity Maturity Model Certification) Level 2 requires the 110 security requirements of NIST SP 800-171 Rev 2 for systems handling Controlled Unclassified Information. CMMC Level 3 adds 24 requirements selected from NIST SP 800-172 and a government-led DIBCAC assessment, and requires a Final Level 2 (C3PAO) status first.
CMMC Level 2 (NIST SP 800-171 Rev 2)
The CMMC level for contractors that handle CUI, assessed by self-assessment or by a C3PAO certification assessment, as the solicitation requires. Its 110 security requirements are those of NIST SP 800-171 Rev 2 (CMMC still cites Rev 2 although NIST has since published Rev 3), spanning access control, configuration management, incident response, media protection, risk assessment, and system and information integrity, among other families.
NIST 800-53 (federal ATO baseline)
The NIST 800-53 Rev 5 control catalog applies to systems that need a formal Authorization to Operate. The System Security Plan (SSP) documents how each control is implemented, and the package moves through assessment to the authorize step. On an ATO-bound build, we scope these controls in the design phase.
eMASS
eMASS (Enterprise Mission Assurance Support Service) is the DISA-managed web application DoD uses to manage cybersecurity assessment and authorization packages. In September 2025 DoD announced the Cybersecurity Risk Management Construct (CSRMC), which moves from the previous Risk Management Framework toward continuous monitoring and a constant ATO posture.
CUI Handling
CUI (Controlled Unclassified Information) handling covers development environments, data stores, and code repositories: CUI category identification, marking, access control, and incident response procedures. When an engagement involves CUI, we scope the NIST SP 800-171 requirements in the design phase.
South Carolina: a DoD contracting hub
South Carolina's DoD installations include NIWC Atlantic (North Charleston, a Navy information warfare center), Joint Base Lindsey Graham (Joint Base Charleston until its renaming on Aug. 10, 2026; home to the 437th Airlift Wing), Shaw Air Force Base (20th Fighter Wing and Ninth Air Force headquarters), and Fort Jackson (the Army's main Basic Combat Training center). Code and Trust is based in Mt Pleasant, SC, within two hours of all four.
12 mi
NIWC Atlantic
15 mi
Joint Base Lindsey Graham
95 mi
Shaw AFB
100 mi
Fort Jackson
DoD software contractor: common questions
DoD software contractor questions from program managers and prime contractors most often cover how a contractor comes onto a program, NIWC Atlantic, contract vehicles, and eMASS in the ATO process.
How does Code and Trust work on DoD programs?
We have come into public-sector work as a subcontractor through a prime contractor and by responding to RFPs. Clearance and CMMC requirements are confirmed per program, in writing, before any proposal.
What is NIWC Atlantic?
NIWC Atlantic (Naval Information Warfare Center Atlantic) is a Navy warfare center in North Charleston, SC, near Code and Trust's Mt Pleasant, SC office. Its stated mission is research, development, prototyping, engineering, test and evaluation, installation, and sustainment of integrated information warfare capabilities and services, with an emphasis on expeditionary tactical capabilities and enterprise IT and business systems.
What contract vehicles support DoD software development?
DoD software work flows through multiple-award IDIQs and governmentwide acquisition contracts, for example GSA Alliant 2 and 8(a) STARS III, OTAs (Other Transaction Agreements for prototype projects), direct agency contracts under simplified acquisition, and SBIR/STTR phase contracts. Which vehicle fits depends on the program and on the prime contractor that holds it.
What is eMASS in the DoD ATO process?
eMASS (Enterprise Mission Assurance Support Service) is the DISA-managed web application DoD uses to manage cybersecurity assessment and authorization packages. In September 2025 DoD announced the Cybersecurity Risk Management Construct (CSRMC), which moves from the previous Risk Management Framework toward continuous monitoring and a constant ATO posture. When a system needs an ATO, we scope the NIST 800-53 controls in the design phase, so the documentation describes the system that was built.
Related federal software services
DoD software contracting connects to the federal software development overview, cleared developer staffing (clearance requirements confirmed per program), DHS software contracting for programs that span both defense and homeland security missions, and our Mt Pleasant, SC office.
Ready to discuss a DoD engagement?
DoD engagements start with a 30-minute call covering component, program, contract vehicle, clearance requirements, and CMMC level. Code and Trust is based in Mt Pleasant, SC, near NIWC Atlantic.
Tell us the program, and we will reply in writing with whether and how we can support it.