Compliance & Engineering Services

Compliance Assessments & Continuous Monitoring

Procure individual BOM audits, scope custom advisory services, or deploy continuous lifecycle monitoring for your product family. Initial system evaluations provide up to five compliance flags at no cost to validate engine capabilities.

One-Time BOM Audit

Drone NDAA Assessment

$600 / BOM Audit

A comprehensive, one-time regulatory cross-reference. No payment is required at upload; orders are confirmed upon delivery of the findings to your secure workspace.

  • Complete identification of flagged components with exact regulatory citations.
  • Verified alternative components, where evidenced, for engineering review.
  • Exportable PDF audit report with a formal sign-off block.
  • Downloadable Excel component matrix for ERP integration.
Submit BOM for Assessment ↗

Custom Scope

Advisory Services & ERP Integration

Project parameters and delivery requirements are defined prior to pricing.

Blue UAS Listing
Submission preparation, documentation assembly, and direct support for DCMA assessor inquiries.
C-UAS Compliance
Counter-drone BOM evaluation against §889 and §1260H. Automated processing requires a custom-approved ruleset.
Enterprise SKU Mapping
Catalog alignment and supplier record verification for SAP MDG, Maximo, NetSuite, or X12 832. Existing plans begin at $125/month for 250 lines.

Active BOM Monitoring

Daily automated cross-referencing. Complete audit trails.

Monitoring billing interval

Regulatory lists change, and suppliers undergo acquisitions. Active monitoring provides daily checks against the Consolidated Screening List and FCC Covered List, delivering a documented monthly record of supplier ownership changes and lifecycle events where supported data is available.

Monitoring Level I

$199 / month

  • Up to 3 active BOMs / 500 total lines.
  • Daily regulatory screening and monthly reporting.
  • Billed monthly under a recurring service agreement. Annual agreements include a two-month discount.
Request Monitoring Coverage ↗

Monitoring Level II

$499 / month

  • Up to 10 active BOMs / 2,500 total lines.
  • Daily regulatory screening and monthly reporting.
  • Billed monthly under a recurring service agreement. Annual agreements include a two-month discount.
Request Monitoring Coverage ↗

Portfolio Monitoring

Custom Quote

For product families exceeding 10 BOMs or 2,500 lines, we establish dedicated coverage, API capacity, and a firm-fixed price in a written agreement.

Request a Portfolio Quote ↗

Monitoring is an optional add-on to completed audits. Coverage is confirmed before service activation. An organization owner must explicitly authorize a logged retention extension. Monitored BOMs are retained while the agreement is active and securely deleted 30 days after it terminates. Recurring charges are disclosed alongside any one-time audit purchase before checkout.

Enterprise Deployment · In Your Environment

For CUI and ITAR-controlled environments.

The matching engine is deployed directly inside your secure boundary. Processing and reporting remain inside your environment; catalog connections and outbound lookups are controlled by your organization.

From $50,000 / year

  • Scope includes architecture deployment and internal system integrations.
  • Designed to meet agreed CUI and ITAR data handling requirements.
  • Final scope, access controls, and maintenance requirements agreed in writing.
Discuss Enterprise Deployment ↗
CMMC Level 2
Self-assessment posted in SPRS
Per-organization encryption
Separate AES-256-GCM keys for Cloud files
Standard 30-day deletion
Watched BOMs: owner-approved retention extension
U.S. distributor lookups
Default; other catalogs require owner opt-in

A self-assessment is not C3PAO certification. Review the assessment and controls.

Deployment Architecture: Cloud vs. Enterprise (On-Premises)

The core matching engine operates across two distinct data boundaries. You must select your deployment model prior to submitting materials.

Where your data goes in each tier
CapabilityCloud DeploymentEnterprise (On-Premises)
Processing LocationBlue Ridge Federal managed cloud service.Engine deployed locally inside your controlled infrastructure.
Document ContentsUploaded to the secure cloud. Support access requires explicit, time-limited owner authorization.Remains entirely inside your boundary. Blue Ridge Federal never receives document contents.
EncryptionAES-256-GCM (isolated keys per organization); HTTPS in transit.Storage, keys, and access controls governed by your internal requirements.
Data RetentionStandard files purged 30 days post-completion. Active monitoring requires an explicit, logged owner retention extension; monitored BOMs are kept while the subscription is active and deleted 30 days after it ends. Purchased archive terms apply separately.You maintain complete control over data retention. Cloud 30-day deletion policies do not apply.
External LookupsDefaults to U.S. distributors (part numbers/supplier codes only). LCSC requires explicit opt-in.Only utilizes internal catalog connections and outbound routing authorized by your network.
Model AssistanceDisabled by default. Activation requires explicit owner consent (handling details in Security Policy).Providers and outbound data transmission must be explicitly approved in your deployment agreement.
CUI / ITAR DataNot Accepted. Strictly for unclassified commercial data.Accepted. Requires an enterprise agreement and internal verification of required controls prior to use.

Neither deployment tier constitutes a FedRAMP authorization or a substitute for your program’s internal security approvals. Review full security protocols.

Service Terms & Assessment Allowances

Initial Assessment Allowances
Organizations may utilize five part lookups every 48 hours. The Initial Feasibility Screening processes an entire submitted BOM and reveals the first five compliance flags at no cost to validate system capabilities. Generating the complete compliance matrix and exportable reports requires purchasing the BOM Audit.
Monitoring Billing & Cancellation
Active monitoring agreements can be billed monthly or annually. Annual agreements include a two-month discount. Recurring charges are transparently listed alongside any one-time audit purchases prior to checkout. Agreements remain active until explicitly canceled by an administrator.
Audit Record Limitations
The monthly monitoring record logs completed checks and any identified changes. A report indicating “no changes” confirms that the completed checks found no new derogatory information in the supported databases; it does not constitute a blanket certification. Unavailable supplier or lifecycle data is left unreported.
Data Immutability
To maintain strict compliance standards, the review workspace is read-only. We do not permit manual editing of findings within the application. Any required modifications necessitate an immutable revision log to ensure export documents preserve both original and edited values.