Compliance Requirements Built Into the Delivery Lifecycle

Lizentia helps organizations translate contractual, regulatory, security, privacy and accessibility obligations into system requirements, controls, documentation and operating procedures. Compliance depends on the client's industry, data, deployment environment, contract and use case. Lizentia does not present itself as universally certified against every framework.

Compliance-by-design approach

  1. 1Obligation discovery — identify contractual, regulatory, security, privacy and accessibility obligations applicable to the engagement
  2. 2Data and system classification — categorize what is processed, where, and at what sensitivity
  3. 3Control mapping — translate obligations into specific architecture and configuration controls
  4. 4Architecture and configuration — design and build controls into the system rather than retrofitting them
  5. 5Evidence collection — capture documentation that demonstrates control operation
  6. 6Testing and validation — verify controls through testing, review and acceptance
  7. 7Release approval — confirm obligations are met before production deployment
  8. 8Continuous monitoring and review — maintain and re-verify controls over the operational life of the system

Standards and obligation matrix

The matrix below is CMS-managed. Each entry carries its relevance, the Lizentia support model, client responsibility, deployment dependency, current status and supporting documentation. Status labels reflect the actual relationship to each framework — never "Certified" unless verified evidence has been uploaded and approved.

Framework / obligationStatus
NIST Cybersecurity FrameworkContract-dependent
NIST SP 800-53 controlsContract-dependent
State & local government security requirementsContract-dependent
Section 508Contract-dependent
WCAGContract-dependent
ADA digital-accessibility requirementsContract-dependent
HIPAA & HITECH (when applicable)Contract-dependent
FERPA (when applicable)Contract-dependent
State privacy lawsContract-dependent
Records-retention requirementsContract-dependent
Payment-card requirements (when payment processing is in scope)Contract-dependent
CJIS requirements (when expressly included in the contract)Contract-dependent
Client-specific security standardsContract-dependent
SupportedContract-dependentEnvironment-dependentClient-controlledNot currently representedUnder assessment

Security and privacy controls

These controls are configured to the applicable solution and contract. Their presence and depth depend on the deployment environment and the obligations discovered during scoping.

  • Role-based access
  • Least privilege
  • Authentication requirements
  • Encryption configuration
  • Logging
  • Audit trails
  • Change control
  • Vulnerability management
  • Secure development practices
  • Data retention
  • Incident handling
  • Backup and recovery planning
  • Vendor and subprocessor review
  • Access reviews
  • Environment separation

Evidence and documentation

  • Requirements matrices
  • Control mappings
  • Architecture diagrams
  • Data-flow diagrams
  • Access-control matrices
  • Test results
  • Risk registers
  • Remediation plans
  • Release approvals
  • Operational procedures
  • Training records
  • Audit exports

Shared responsibility

Compliance is not delivered by one party. Responsibility is divided across the parties that own each layer of the system.

Lizentia

Delivery, configuration, documentation and managed-operation controls within the agreed scope of work

Customer

Business ownership of data, approval of requirements, acceptance of controls and operational decisions

Cloud / infrastructure provider

Underlying platform security, availability and infrastructure-level controls

Third-party integration providers

Controls owned by external systems connected through integrations

Authorized users

Account security, appropriate use and adherence to access policies

Compliance status transparency

"Framework alignment, certification and authorization are not interchangeable. Lizentia publishes only compliance claims supported by current evidence."

Procurement documentation

Security questionnaires, architecture documentation, accessibility materials and applicable control mappings may be provided during a qualified procurement or due-diligence process, subject to confidentiality requirements. Documentation is released to verified buyers through a controlled channel rather than published openly.

Need compliance information for a procurement or due-diligence process?

Request compliance documentation and our team will respond through a confidential procurement channel.