Federal subcontracting for prime contractors that need software engineers
Foundry Peak is a small software firm that works as a federal subcontractor alongside prime contractors. We supply engineers who join your agile team, follow your processes, and build to the security and accessibility standards federal programs require. Today we support a federal law-enforcement system as a subcontractor inside a prime team.
What Foundry Peak brings to a federal subcontracting team
Primes usually need one of three things from a small software sub: extra delivery capacity, a skill the team lacks, or a partner that can own a well-defined slice of the work. We can do all three for web and cloud software.
Our engineers have worked inside a prime team on a federal law-enforcement system, so we understand what a prime needs from a sub: people who show up to every ceremony, close tickets without hand-holding, and never surprise the program manager. We would rather flag a risk early than explain a missed sprint goal.
- Full-stack web development: front ends, APIs, databases and background jobs
- Cloud infrastructure, deployment pipelines, and monitoring
- Data work: migrations, reporting, and integrations between systems
- Accessibility engineering and testing against the Revised 508 Standards
- Product operations experience from running our own platform, LobbyScape
Agile cadence and ceremonies
We work inside your cadence, not beside it. On our current federal work we run two-week sprints with daily standups, sprint planning, backlog refinement, and code review on every change. Where a team follows the Scrum Guide in full, we take part in every event: sprint planning, a daily scrum of 15 minutes or less, a sprint review, and a retrospective, with backlog refinement as an ongoing activity.
Every change has to meet the team definition of done before it counts. We estimate in your units, update tickets in your tracker, and raise blockers in standup instead of in a status report a week later.
Security and documentation for ATO-bound systems
Federal systems operate under an authorization to operate, granted through the NIST Risk Management Framework in SP 800-37. A subcontractor does not grant the ATO, but our code and our paperwork feed it. We build to the controls in NIST SP 800-53 Revision 5 and write documentation that assessors can use.
We write that documentation as we go, in the same sprint as the code it describes. Documentation left for the end of a release is the most common reason an assessment slips, and it is the easiest problem for a disciplined sub to prevent. If the program publishes an Accessibility Conformance Report, we supply test results for the features we built.
- Control implementation descriptions for the parts of the system we build, ready for the system security plan
- Remediation of scan and assessment findings, tracked against the plan of action and milestones
- Configuration, change and dependency records that support continuous monitoring
- Section 508 conformance: the Revised 508 Standards incorporate WCAG 2.0 Level A and AA, and we test to WCAG 2.1 AA as a stricter internal bar
- When our own systems handle controlled unclassified information, we apply NIST SP 800-171 Revision 3 as the contract requires
Onboarding into the prime's tools and processes
We expect to adopt your environment, not bring our own. That means your issue tracker, repositories, CI pipeline, chat, and security training. We complete required onboarding steps, such as background investigations and agency training, on the schedule the program sets, and we use government-furnished equipment where the contract calls for it.
We also keep our own house in order: named points of contact, written handoff notes for every engineer, and timesheets and invoices that match the task order structure your contracts team uses.
In the first sprint, a new Foundry Peak engineer pairs with someone on your team, ships a small change through the full pipeline, and reads the existing system documentation. By the second sprint they carry their own tickets. We keep a written onboarding checklist for each program so a replacement can ramp up the same way if staffing ever changes.
Small business status and NAICS codes
Foundry Peak, LLC is a small business founded in 2024 in Pensacola, Florida. We fit best on teams where a capable small-business sub adds delivery strength. Small size has practical upsides for a prime: our leadership is directly reachable, decisions are quick, and we can match a contract start date without a long internal approval chain. Our NAICS codes are:
- 541511 Custom Computer Programming Services
- 541512 Computer Systems Design Services
- 541519 Other Computer Related Services
- 513210 Software Publishers
- 518210 Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services
- 541611 Administrative Management and General Management Consulting Services
Related services
Common questions
What does a software subcontractor do on a federal contract?
A software subcontractor supplies engineers or a defined piece of work under the prime contractor. On agile programs, the sub usually joins the prime team, works from the shared backlog, follows the prime processes and security rules, and delivers code that supports the program documentation and authorization to operate.
Which NAICS codes does Foundry Peak work under?
Foundry Peak, LLC is a small business that works primarily under NAICS 541511, Custom Computer Programming Services. Related codes are 541512 Computer Systems Design, 541519 Other Computer Related Services, 513210 Software Publishers, 518210 Computing Infrastructure and Hosting, and 541611 Management Consulting. Ask us for registration details for a specific opportunity.
Which Section 508 standard applies to federal web applications?
The Revised 508 Standards, with compliance required since January 18, 2018, incorporate WCAG 2.0 Level A and Level AA success criteria by reference. That is the legal baseline. Many teams test to WCAG 2.1 AA as a stricter internal target, since it includes every WCAG 2.0 criterion plus additional ones.
How do subcontractors support an authorization to operate (ATO)?
Subcontractors support an ATO by building to the required NIST SP 800-53 controls, writing implementation descriptions for the system security plan, fixing findings tracked in the plan of action and milestones, and keeping configuration and change records that feed continuous monitoring. The authorizing official, not the contractor, grants the ATO.
Teaming on a bid?
Send us the program, the scope, and the timeline. We will tell you quickly whether we are a fit.