SOC 2 · PCI DSS · NIST 800-53 · NIST CSF
Close the security findings holding up your deal, your audit, or your contract.
We find where your encryption lives and what's weak, fix the findings, engineer the controls around them, and document what can't change, with evidence your assessor will accept.
Partners & VerificationsAnthropic Cyber Verification · Vanta MSP · Google Cloud Partner · Red Hat Partner
Start here
PQC Readiness
Step one is finding it: every cipher, certificate, and key you run, mapped to what PCI DSS 12.3.3 and your customers ask for.
Deliverables
Cryptographic Readiness Report
The evidence you hand to your customer or assessor: an executive scorecard they can read at a glance, what you run and where it lives, and the plan for what has to change.
Risk Register
Yours to keep. Every cryptographic finding ranked, costed, and mapped to the frameworks you answer to. A single fix clears every framework it maps to.
Scope
- Cryptographic inventory (CBOM) and PQC gap analysis
- Viability monitoring and a documented response plan
- CNSA 2.0 algorithm-alignment for federal boundaries
- Framework mapping: PCI DSS 12.3.3, NIST 800-53 SC family, NERC CIP-011-3, IEC 62443 cryptographic requirements (mapping only)
Price
From $5,000
per PCI CDE or production environment · $7,500 per federal ATO boundary
What we engineer
Then we fix what it finds.
The inventory is the first control. The program builds the rest around it: identity, the edge, your workloads, and the AI you run, on the systems you already own, with the evidence wired into your compliance platform and checked against what it actually reports.
Scanner flagged it?
Fix the encryption findings
Weak TLS, certificates, and ciphers, closed under your scanner's own finding names, plus the "when you can't fix it" path.
See Vulnerability Remediation →Where the inventory leads
GRC Engineering
Your full control program, engineered inside your systems and kept audit-ready, starting from the cryptographic findings.
See the program →Building with sensitive data?
Keep it in your boundary
Web apps, MCP servers, and private AI built and secured inside your own systems, with the evidence to show it.
See what we build →The evidence
The Risk Register, yours to keep.
The Cryptographic Readiness Report is what you hand over. The Risk Register is what you keep: every finding ranked by how long the data it protects has to stay secret, costed, and mapped to the frameworks you answer to. Each one carries a recommended treatment (remediate, mitigate, or accept), and the decision stays with the owner you name. Where legacy or OT hardware can't run modern encryption, as in NERC CIP environments, the accept path comes with the compensating-control documentation your assessor expects. One remediation clears every framework it maps to, and each finding scopes what comes next. The action plan stays yours whether or not the work continues with us.
Every row: finding, surface, severity, business impact, frameworks satisfied, recommended treatment and owner, remediation and effort, the program it routes to, and status.
Start with where your encryption lives.
PQC Readiness finds it and maps it into your Risk Register. Everything after is scoped from what it shows.
Advisor, MSP, or agency? You keep the client and the relationship. We're the engineering arm, findings to you first. See the partner program →
Don't take our word for it
See where yours lives, free.
Run it on your own site and see what an assessor, an auditor, or a customer review would see in your encryption. No signup.
Unable to scan
Email these results to yourself
FEDLIN receives a copy and may follow up.
Check your inbox.
This scan covers your public TLS surface only. In-boundary endpoints, firmware, code dependencies, and your full cryptographic inventory require a dedicated assessment.
scan_post_quantumathttps://mcp.fedlin.com/mcpFrom the Blog
Latest field notes

DKIM Key Too Short: Rotating From 1024 to 2048 Bits
A scanner or a customer's security review flagged your DKIM key as too short. It's a cryptography finding with a clean fix, and the rotation can happen without a single message bouncing.

Post-Quantum Roadmap by October: Where to Start, and the Questions to Ask First
The roadmap is due in October. If you haven't started yet, here are actions you can take today to get a jump-start: where to begin, the questions that decide your first moves, and a free scan that puts a data point on the board.

How the 2026 Water-Utility Attacks Worked
The July attacks on water systems turned on internet-exposed controllers reachable with no novel exploit. An account of the compromise, how the access worked, and what closes it.
Frequently Asked Questions
What does working with FEDLIN look like?
Engagements start with a scoping call about your architecture and the review in front of you: a SOC 2, a PCI-DSS assessment, an enterprise security review, or investor diligence. From there the work is a build. We measure what your buyer requires, engineer the fixes, and hand you the evidence that clears it.
Does FEDLIN do architecture or engineering?
Both, by design. Every engagement starts with the architecture decision (which controls, where, and why) before anything is built. The design and the build are complementary and can be delivered on their own or together.
We don't have a security team. Can FEDLIN run the whole program?
That's a common place to be as you grow. FEDLIN builds your control program as a scoped project, then keeps it running on a monthly retainer sized to what's at stake: the controls, the evidence wired into your GRC platform, and the program that clears the review and keeps it clear.
What's the difference between FEDLIN and a GRC platform like Vanta?
A GRC platform monitors and collects evidence from controls that already exist. FEDLIN builds those controls: IAM configurations, pipeline gates, secrets management, infrastructure hardening, and the NIST AI RMF layer for agentic systems. When a GRC platform is in the picture, FEDLIN wires the controls so it has something real to monitor. When there's no platform yet, FEDLIN can stand one up in your environment as part of the build.
Do you work with companies building with LLMs or agentic systems?
Yes, and it is a core capability. LLM integrations, MCP servers, and agentic pipelines open a security surface standard assessments are not designed to reach. If your team ships AI features on infrastructure you run yourself, FEDLIN builds the NIST AI RMF control layer those systems need, mapped to the frameworks your build operates under.
What does OMB M-26-15 mean for federal contractors?
OMB M-26-15 directs federal civilian agencies to inventory their cryptography and plan the move to NIST's post-quantum algorithms (ML-KEM, ML-DSA, and SLH-DSA). Contractors feel it through what agencies ask of them: an inventory of the cryptography in the systems you run for them, a migration plan, and post-quantum support written into product and contract requirements. Executive Order 14412 separately directs a proposed FAR rule that would extend NIST's post-quantum standards to covered contractors, so the contractors who build the inventory now are ahead of the FAR rule. FEDLIN produces that inventory for your ATO boundary and sequences the migration from it.
How does NIST AI RMF implementation work for self-hosted AI?
NIST AI RMF defines the functions (govern, map, measure, manage) but doesn't prescribe how to implement them on infrastructure you run yourself. FEDLIN builds those controls at the infrastructure layer: context boundaries, access scoping for MCP servers and agentic pipelines, prompt injection coverage, and audit logging mapped to the govern and manage functions. Every control is built into your own environment and produces evidence you hold.
What's the relationship between NIST CSF and NIST 800-53?
NIST CSF is the framework designed for communication. It gives founders, executives, and non-technical stakeholders a clear language for security posture across five functions: Identify, Protect, Detect, Respond, Recover. NIST 800-53 is the technical control catalog underneath it, the specific controls that implement what CSF describes. FEDLIN assesses and builds to both. Every major framework, from SOC 2 to PCI-DSS to CMMC, maps back to this foundation.
What does principal-led mean in practice?
You work directly with the principal security architect, the person who owns the architecture, the engagement, and the build. Delivery draws on a vetted partner network where scope requires it: penetration testing, specialized infrastructure work, or govtech contracting.
Do you work with fractional advisors, agencies, or MSPs?
Fractional advisors, MSPs, and agencies bring FEDLIN in for the specialist work their clients need and can't keep on staff: cryptographic readiness and crypto-agility, edge and identity hardening, NIST CSF and GRC engineering, and self-hosted AI security. You keep the client, the relationship, and the advisory lead. FEDLIN does the engineering, findings to you first. See the partner program for how this works.
