Government Services · SDVOSB· VOSB
CISO-level GRC and AI governance for the public sector
VAST Management Corp is an SDVOSB/VOSB-certified advisory firm helping federal agencies and their prime contractors govern AI, secure systems, and pass audits. Core services span four areas: AI governance, cybersecurity GRC, ATO/RMF readiness, and workforce development. Every engagement is led personally by a doctoral-level CISO (C|CISO, CISSP, PMP) and sized for senior-expert delivery, not staff augmentation. As a certified SDVOSB, VAST is directly awardable through simplified-acquisition, sole-source, task-order, and subcontract vehicles.
NIST AI RMF
ISO/IEC 42001
FISMA · FedRAMP
OMB M-25-21 / 22
EO 14179
EO 14409
Company Snapshot
- President & CEO
- Dr. Noel G. Alexander
- Established
- 2003
- CAGE Code
- 20SA4
- Unique Entity ID
- ZKH3ZV6L4JK4
- FEIN
- 20-0312439
- Certifications
- SDVOSB · VOSB
- Credentials
- C|CISO · CISSP · PMP
Core Competencies
End-to-end GRC depth across the federal enterprise
Seven practice areas across cybersecurity governance, AI oversight, compliance and authorization, resilience, and program delivery.
AI Governance & Assurance
- NIST AI RMF and ISO/IEC 42001 implementation
- OMB M-25-21 / M-25-22 readiness
- AI use-case inventory, acceptable-use, and ethics frameworks
- AI vendor and model risk assessment
Cybersecurity Governance & Executive Advisory
- Fractional and virtual CISO advisory
- Security program build-out, strategy, and roadmaps
- Policy and standards development
- Zero Trust strategy (OMB M-22-09)
- Executive and board-level cyber risk reporting
Security Authorization, RMF & Continuous Monitoring
- NIST RMF implementation and ATO support
- System Security Plans, SARs, and body-of-evidence documentation
- NIST SP 800-53 and CSF control assessments; POA&M development and closure
- ISSO support, continuous monitoring, and FISMA execution
- C-SCRM and third-party risk (NIST SP 800-161)
Independent Assessment, Evaluation & Advisory Studies
- Independent security control assessments and program evaluations
- Independent verification and validation (IV&V) and readiness reviews
- Cyber risk posture assessments with reproducible, auditable scoring
- Policy, feasibility, and program studies
Incident Response & Resilience
- Incident response plan development and testing
- Tabletop exercises and crisis simulations
- Business continuity and disaster recovery planning
- Breach notification and CISA / CIRCIA coordination
Training & Workforce Development
- Security awareness program development and delivery
- Federal AI governance course series
- Role-based cybersecurity curriculum design
- Courseware development
Program, Acquisition & Project Support
- PMP-aligned program and project management
- PMO stand-up and support
- Acquisition and procurement support; requirements and market research
- Earned value management and schedule risk analysis
Signature Interest
The AIGRF: a reproducible score, not a consultant opinion
VAST’s AI Governance and Risk Framework is a deterministic assessment that produces an auditable AI Risk Index (ARI) on a 0 to 100 scale. Every control maps to binding federal authority, giving an authorizing official evidence they can defend.
- 84 controls across 14 governance domains
- Mapped to EO 14179, the OMB AI memos, NIST AI RMF, and the 800-series
- Five CMMI-aligned maturity tiers, from Initial to Optimized
- Repeatable, evidence-based, and defensible under audit
Core Competencies
End-to-end GRC depth across the federal enterprise
Nine practice areas spanning cybersecurity governance, AI oversight, compliance and authorization, resilience, and program delivery, led by a doctoral-level CISO.
Core Competencies
CodeWeTrust c2m
Nine practice areas spanning cybersecurity governance, AI oversight, compliance and authorization, resilience, and program delivery, led by a doctoral-level CISO.
- Blind-audit and on-premise deployment protect source-code IP
- AI-generated code vetting for the modern SDLC
- SBOM output in both SPDX and CycloneDX formats
- Supports compliance decisions throughout the software lifecycle
Why VAST
Doctoral-level CISO leadership
Agencies engage a single accountable practitioner-scholar rather than a rotating bench, backed by more than two decades of governance, risk, and compliance delivery across commercial and global environments.
- Fractional vCISO model: CISO-level judgment and accountability without a full-time executive hire
- Advisory leadership on NIST AI RMF, ISO/IEC 42001, and OMB M-25-21 and M-25-22
- End-to-end coverage from strategy through authorization readiness and workforce training
- SBA-certified SDVOSB and VOSB, eligible for set-aside and sole-source awards
Credentials & Authorities
Certified leadership, aligned to federal mandates
C|CISO
Certified Chief Information Security Officer
CISSP
Certified Information Systems Security Professional
PMP
Project Management Professional
CPC
Certified Professional Coach
NIST AI RMF
NIST SP 800-53
OMB M-25-21 / M-25-22
FISMA
FedRAMP
EO 14179
EO 14409
ISO/IEC 42001
NAICS Codes
541512 Computer Systems Design Services
541611 Administrative Management & General Management Consulting
541330 Engineering Services
541618 Other Management Consulting Services
541690 Other Scientific & Technical Consulting Services
541519 Other Computer Related Services
611430 Professional & Management Development Training
611420 Computer Training
PSC / Service Codes
R410 Program Evaluation / Review / Development
R707 Contract, Procurement & Acquisition Support
R420 Certifications & Accreditations
U008 Training / Curriculum Development
R408 Program Management & Support
R499 Professional Services, Other
R425 Engineering & Technical
DJ01 IT & Telecom Security & Compliance Support
Signature Instrument
The AIGRF: a reproducible score, not a consultant opinion
Request a capability briefing, a teaming discussion, or a walkthrough of the AIGRF instrument for your agency.