Security-first protection built for the pace exploration demands.
Our security program is designed around recognized government and industry frameworks, structured to protect engineering data and program information while enabling the decision velocity and commercial integration that next-generation exploration architectures require.
Last updated: August 2026
Monarch Space Systems, Inc. implements a layered security program to protect proprietary engineering data, sensitive program information, supplier and customer data, and limited human resources data. Our controls are mapped to recognized government and industry frameworks including NIST SP 800-171, NIST SP 800-53, and the NIST Cybersecurity Framework.
Data may reside across cloud services, endpoints, and controlled repositories. All environments are subject to access controls, encryption, monitoring, and periodic review consistent with the data classification assigned.
Consistent with NASA's emphasis on streamlined operations and commercial integration, our security architecture is designed to enable rapid, secure collaboration with government customers, prime contractors, and commercial partners — ensuring that data protection accelerates mission progress rather than constraining it.
Controls aligned with recognized government and industry frameworks.
Protecting Controlled Unclassified Information (CUI)
Security controls aligned with NIST SP 800-171 requirements for protecting CUI in nonfederal systems and organizations.
Official SourceSecurity & Privacy Controls
Organizational controls designed consistent with the NIST SP 800-53 catalog of security and privacy controls for information systems.
Official SourceCSF 2.0
Risk management practices structured around the NIST CSF core functions: Govern, Identify, Protect, Detect, Respond, and Recover.
Official SourceSafeguarding Covered Defense Information
Practices designed to address DFARS cyber incident reporting and safeguarding requirements applicable to covered defense information.
Official SourceCybersecurity Maturity Model Certification
Implementing practices intended to support future CMMC assessment readiness as the program matures and requirements are finalized.
Official SourceITAR / EAR
Processes to support handling of export-controlled data in accordance with ITAR and EAR requirements as applicable to a given contract or data set.
Official SourcePublic-safe overview of implemented security practices.
Principled approach to data from collection through disposal.
We minimize the collection of personal data to what is necessary for business operations, contractual obligations, and legal requirements. Customer and partner confidential information is protected through access controls, NDAs, and contractual commitments.
Where applicable, our practices consider requirements under data protection regulations. For details on personal data handling, see our Privacy Policy.
Analytics access is restricted to authorized personnel and is used exclusively for aggregated performance evaluation. Security controls applicable to production systems extend to analytics administration infrastructure.
We maintain processes intended to support handling of export-controlled and program-sensitive information (e.g., ITAR/EAR) as applicable to a contract or data set. This includes need-to-know access controls, U.S. Person verification, and technology control plans where required by contract or regulation.
For a comprehensive overview of our export compliance posture, visit our ITAR & Export Compliance page. Official regulatory references:
Security policies and procedures are reviewed at least annually and updated to reflect evolving threats, regulatory changes, and lessons learned from incidents and assessments. Audits and assessments are conducted as required by customer contracts and internal governance.
Protecting Controlled Unclassified Information in Nonfederal Systems
Security and Privacy Controls for Information Systems and Organizations
Framework for Improving Critical Infrastructure Cybersecurity
DoD Cybersecurity Maturity Model Certification
Safeguarding Covered Defense Information and Cyber Incident Reporting
International Traffic in Arms Regulations
Export Administration Regulations
NASA Security of Information and Information Systems
Cybersecurity and Infrastructure Security Agency Guidance
Report incidents and get response guidance
We can provide additional security documentation under NDA.