Certifications
Appraised, audited, and certified against six standards.
Every certification below is current and independently assessed.

Audited for handling Controlled Unclassified Information.
CMMC Level 2 requires the 110 security controls in NIST SP 800-171 to be implemented and evidenced, and it applies to contractors that store, process, or transmit Controlled Unclassified Information on Department of Defense contracts. Some Level 2 requirements can be met by self-assessment. OCH holds the certification assessment, conducted by an accredited third-party assessment organization.

Appraised at Level 3 in both constellations.
CMMI Level 3 requires processes to be defined and standardized across the organization rather than assembled project by project, and it is confirmed by a benchmark appraisal led by a certified lead appraiser. OCH is appraised in Services, covering delivery and support, and in Development, covering software engineering. The appraisal is number 71098 and expires April 17, 2027.

Quality management.
ISO 9001 sets requirements for a quality management system: documented processes, defined responsibilities, measured results, and corrective action when those results fall short. Certification is held through recurring surveillance audits by an accredited registrar rather than granted once.

Service management.
ISO 20000 is the international standard for IT service management, covering incident, problem, change, capacity, and continuity processes. It is the auditable counterpart to ITIL practice, and it governs how OCH runs service desk and operations work.

Information security management.
ISO 27001 requires a risk-based information security management system: identified assets, assessed risks, controls selected against those risks, and evidence that the controls operate. Its control set overlaps substantially with NIST SP 800-53, which is the catalog federal authorization packages are built from.

Certified for AI management systems.
ISO 42001 governs how AI systems are specified, tested, and controlled through their lifecycle. Very few federal IT firms hold it. It is the standard behind the AI-accelerated modernization work described in the capability index.