Compliance Requirements Built Into the Delivery Lifecycle
Lizentia helps organizations translate contractual, regulatory, security, privacy and accessibility obligations into system requirements, controls, documentation and operating procedures. Compliance depends on the client's industry, data, deployment environment, contract and use case. Lizentia does not present itself as universally certified against every framework.
Compliance-by-design approach
- 1Obligation discovery — identify contractual, regulatory, security, privacy and accessibility obligations applicable to the engagement
- 2Data and system classification — categorize what is processed, where, and at what sensitivity
- 3Control mapping — translate obligations into specific architecture and configuration controls
- 4Architecture and configuration — design and build controls into the system rather than retrofitting them
- 5Evidence collection — capture documentation that demonstrates control operation
- 6Testing and validation — verify controls through testing, review and acceptance
- 7Release approval — confirm obligations are met before production deployment
- 8Continuous monitoring and review — maintain and re-verify controls over the operational life of the system
Standards and obligation matrix
The matrix below is CMS-managed. Each entry carries its relevance, the Lizentia support model, client responsibility, deployment dependency, current status and supporting documentation. Status labels reflect the actual relationship to each framework — never "Certified" unless verified evidence has been uploaded and approved.
| Framework / obligation | Status |
|---|---|
| NIST Cybersecurity Framework | Contract-dependent |
| NIST SP 800-53 controls | Contract-dependent |
| State & local government security requirements | Contract-dependent |
| Section 508 | Contract-dependent |
| WCAG | Contract-dependent |
| ADA digital-accessibility requirements | Contract-dependent |
| HIPAA & HITECH (when applicable) | Contract-dependent |
| FERPA (when applicable) | Contract-dependent |
| State privacy laws | Contract-dependent |
| Records-retention requirements | Contract-dependent |
| Payment-card requirements (when payment processing is in scope) | Contract-dependent |
| CJIS requirements (when expressly included in the contract) | Contract-dependent |
| Client-specific security standards | Contract-dependent |
Security and privacy controls
These controls are configured to the applicable solution and contract. Their presence and depth depend on the deployment environment and the obligations discovered during scoping.
- Role-based access
- Least privilege
- Authentication requirements
- Encryption configuration
- Logging
- Audit trails
- Change control
- Vulnerability management
- Secure development practices
- Data retention
- Incident handling
- Backup and recovery planning
- Vendor and subprocessor review
- Access reviews
- Environment separation
Evidence and documentation
- Requirements matrices
- Control mappings
- Architecture diagrams
- Data-flow diagrams
- Access-control matrices
- Test results
- Risk registers
- Remediation plans
- Release approvals
- Operational procedures
- Training records
- Audit exports
Compliance status transparency
"Framework alignment, certification and authorization are not interchangeable. Lizentia publishes only compliance claims supported by current evidence."
Procurement documentation
Security questionnaires, architecture documentation, accessibility materials and applicable control mappings may be provided during a qualified procurement or due-diligence process, subject to confidentiality requirements. Documentation is released to verified buyers through a controlled channel rather than published openly.
Related capabilities
Governance
Decision rights, layers and accountability across complex programs.
Read moreAccessibility
Accessibility as a delivery requirement, not a final review.
Read moreSupport & SLA Governance
Service accountability that continues after go-live.
Read moreSecurity Overview
Security-conscious architecture for mission-critical platforms.
Read more