{
    "$schema": "https://fedramp.gov/schemas/fedramp-certification-package-overview-schema-2026-06-24.json",
    "serviceIdentification": {
        "fedRampPackageId": "TODO: Pending FedRAMP assignment",
        "ueiNumber": "MG92A8AJK343",
        "providerName": "NextgenID, Inc.",
        "serviceName": "NextgenID User Interface as a Service (UIaaS)",
        "serviceAcronym": "UIaaS",
        "serviceDescription": "The NextgenID UIaaS is a SaaS offering that resides in the AWS East/West Infrastructure as a Service (IaaS) cloud environment. NextgenID UIaaS provides identity & credential management services utilizing Supervised Remote Identity Proofing (SRIP) services. NextgenID UIaaS provides clients with an identity-proofing solution meeting digital Identity Assurance Level 3 (IAL3), and lower, requirements. Applicants that have a requirement to provide evidence of their identity utilize the NextgenID UIaaS Identity Station and Identity as a Service software to self-enroll while being remotely supervised by a SRIP Agent so that the requirements for IAL3 are met. The NextgenID UIaaS Identity Station captures the applicant's biometrics and identity documentation, including biometrics (fingerprints and photo), documents (driver's license, passport, etc.), and other biographic information to verify the identity of the applicant. After the SRIP Agent has verified the applicant's identity, the NextgenID UIaaS transmits the package to the adjudicating agency.",
        "certificationType": "20x",
        "website": "https://www.nextgenid.com/",
        "logo": "https://www.nextgenid.com/wp-content/themes/nextgenid/public/nextgen-logo.svg"
    },
    "serviceProperties": {
        "serviceType": [
            "SaaS"
        ],
        "deploymentModel": "Government-Only Cloud",
        "businessCategory": [
            "Cybersecurity & Risk Management"
        ],
        "trustCenter": {
            "repositoryType": [
                "Trust Center"
            ],
            "url": "https://www.nextgenid.com/trust-center/",
            "repositoryDescription": "Public TrustCenter information for NextgenID UIaaS.",
            "authenticationRequired": false
        },
        "secureConfigurationGuidance": {
            "repositoryType": [
                "Secure Configuration Guidance"
            ],
            "url": "https://www.nextgenid.com/trust-center/#configuration",
            "repositoryDescription": "User Guide and Baseline Configuration Guides (CIS Benchmarks).",
            "authenticationRequired": false
        }
    },
    "contactInformation": [
        {
            "contactType": "Sales",
            "contactName": "NextgenID Sales",
            "contactEmail": "info@nextgenid.com",
            "contactPhone": "888-373-8648"
        },
        {
            "contactType": "Security",
            "contactName": "Jaafar Abdeen \u2014 Security Contact",
            "contactEmail": "jabdeen@nextgenid.com"
        },
        {
            "contactType": "System Owner",
            "contactName": "Michael Harris \u2014 System Owner",
            "contactEmail": "mharris@nextgenid.com",
            "contactPhone": "410-810-4910"
        }
    ],
    "certifiedServices": [
        {
            "serviceName": "Identity Station",
            "serviceDescription": "Self-enrollment stations located in client facilities. The Identity Station captures the applicant's biometrics and identity documentation, including biometrics (fingerprints and photo), documents (driver's license, passport, etc.), and other biographic information to verify the identity of the applicant. No PII is persisted on the Identity Station. Security Category: Moderate.",
            "dateAvailable": "2023-08-23"
        },
        {
            "serviceName": "Workflow Application",
            "serviceDescription": "The workflow software application installed on the Identity Station packages and encrypts the enrollee's data (the enrollment package) for transmission. Security Category: Moderate.",
            "dateAvailable": "2023-08-23"
        },
        {
            "serviceName": "Supervised Remote Identity Proofing (SRIP) System",
            "serviceDescription": "Connects Identity Stations and Trust Agents for remotely supervised enrollment sessions, supporting screen sharing and video conferencing through a built-in WebRTC-based communication infrastructure. Comprises the SRIP Agent Console and the SRIP Management Server. Security Category: Moderate.",
            "dateAvailable": "2023-08-23"
        },
        {
            "serviceName": "Command Center",
            "serviceDescription": "Enterprise-level reporting, monitoring, and deployment management system for the Identity Stations, enabling workflow creation, deployment scheduling, telemetry collection, and infrastructure monitoring. Comprises the Command Center Management Server and the Management Console. Security Category: Moderate.",
            "dateAvailable": "2023-08-23"
        },
        {
            "serviceName": "Transactional Gateway",
            "serviceDescription": "Facilitates the secure exchange of verification information between validation partners via API connections, including address verification, face matching, and pre-enrollment and package submission. Security Category: Moderate.",
            "dateAvailable": "2023-08-23"
        }
    ],
    "policies": [
        {
            "name": "Code of Conduct Policy",
            "file": "CODE OF CONDUCT POLICY.pdf",
            "summary": "Company-wide conduct standards covering trust and credibility, respect for the individual, equal employment and anti-harassment commitments, and reporting channels.",
            "wordCountApprox": 4056,
            "version": "1.0",
            "lastUpdated": "2021-12-01",
            "availability": "Available on request."
        },
        {
            "name": "NextgenID Rules of Behavior",
            "file": "NextgenID Rules of Behavior.docx",
            "summary": "Appropriate-use rules for NextgenID and client information technology resources, acknowledged by system users.",
            "wordCountApprox": 1454,
            "version": "1.1",
            "lastUpdated": "2026-01",
            "availability": "Available on request."
        },
        {
            "name": "Website Privacy Policy",
            "file": "nextgenid.com/privacy-policy/",
            "summary": "Public privacy policy for the NextgenID website, covering information collected, use, and visitor choices. The website does not collect biometric data; biometric capture occurs only within supervised enrollment services.",
            "wordCountApprox": 881,
            "lastUpdated": "2026-07-15",
            "availability": "Public.",
            "url": "https://www.nextgenid.com/privacy-policy/"
        },
        {
            "name": "Accessibility Statement",
            "file": "NextgenID-Accessibility-Statement.docx",
            "summary": "NextgenID's commitment to an accessible, inclusive, and user-friendly experience for all users, designed to support Section 508 of the Rehabilitation Act, the Web Content Accessibility Guidelines (WCAG) where applicable, and the Americans with Disabilities Act (ADA). Covers accessibility standards, continuous improvement through manual and automated accessibility testing, keyboard-only navigation and screen reader compatibility testing, and how to request assistance or report an accessibility barrier (support@nextgenid.com).",
            "wordCountApprox": 308,
            "lastUpdated": "2026-07",
            "availability": "Public.",
            "url": "https://www.nextgenid.com/wp-content/uploads/2026/07/NextgenID-Accessibility-Statement.docx"
        }
    ],
    "submissionApproachAndRationale": {
        "submissionRationale": "NextgenID is an excellent candidate for FedRAMP authorization because its platform is purpose-built to support federal agencies and other highly regulated organizations that require the highest levels of identity assurance. The NextgenID platform provides Identity Assurance Level 3 (IAL3) identity proofing, credentialing, and enrollment services that align with federal identity standards, including NIST SP 800-63, FIPS 201-3, and HSPD-12. NextgenID enables federal agencies to securely verify the identities of employees, contractors, and other authorized personnel before granting access to government facilities, cloud services, or sensitive information systems. The platform supports supervised remote identity proofing through certified operators, multi-modal biometric collection, physical identity document verification, advanced liveness detection, and tamper-resistant enrollment hardware. These capabilities are designed to reduce identity fraud while providing agencies with high-assurance identity verification that satisfies federal credentialing requirements.",
        "submissionApproach": "NextgenID is pursuing a FedRAMP 20x Class C authorization using a security-by-design approach that emphasizes automation, machine-readable evidence, and continuous validation of security controls. Rather than relying primarily on static documentation and point-in-time assessments, NextgenID has integrated security, compliance, and operational processes throughout the Cloud Service Offering (CSO) lifecycle to produce objective, repeatable evidence that demonstrates the ongoing effectiveness of its security program.\n\nThe submission package has been developed in accordance with the FedRAMP 20x principles of reducing documentation burden while increasing confidence through automated evidence collection, continuous monitoring, and independent validation. The authorization boundary includes all systems, services, interfaces, and information flows necessary to securely deliver the NextgenID platform. Security-relevant components are clearly defined, documented, and included within the assessment scope.\n\nTo support this approach, NextgenID has leveraged the FedRAMP authorized Vanta Governance Risk and Compliance (GRC) tool to implement automated control validation capabilities for each of the FedRAMP Key Security Indicators (KSI).\n\nSecurity controls are implemented using native cloud security capabilities, integrated security tooling, and automated workflows that provide measurable evidence of control effectiveness. This enables NextgenID to demonstrate compliance through operational evidence rather than relying solely on manual documentation.\n\nNextgenID also maintains a secure Trust Center that provides public security documentation and controlled access to restricted FedRAMP 20x Class C authorization artifacts for authorized government stakeholders."
    },
    "subProcessors": {
        "description": "To support the delivery, operation, and security of its Cloud Service Offering (CSO), NextgenID may engage carefully selected third-party service providers to perform specific business, operational, or technical functions on its behalf. When these providers process customer information in support of NextgenID's services, they operate as sub-processors under the direction and control of NextgenID.\n\nThis page identifies NextgenID's authorized sub-processors, their geographic locations, and the services they provide in support of our platform.\n\nPrior to engaging any sub-processor, NextgenID conducts a comprehensive due diligence review that includes technical, security, privacy, legal, operational, and compliance assessments. Each provider is evaluated to ensure it meets NextgenID's security, privacy, and risk management requirements, as well as applicable contractual and regulatory obligations, including those supporting FedRAMP and other federal compliance frameworks.\n\nNextgenID engages sub-processors only after they have successfully satisfied our vendor risk management process. All approved sub-processors are contractually required to implement appropriate administrative, technical, and physical safeguards to protect customer information and to maintain security controls that are commensurate with the services they provide. NextgenID continuously monitors the performance and security posture of its sub-processors throughout the duration of the business relationship to ensure ongoing compliance with our security and privacy standards.",
        "providers": [
            {
                "name": "Amazon Web Services (AWS)",
                "location": "Seattle, Washington, USA (Cloud services hosted in AWS GovCloud (US))",
                "servicesProvided": "Provides secure cloud infrastructure, compute, networking, storage, database services, encryption services, backup, monitoring, and disaster recovery capabilities that support the hosting and operation of the NextgenID Cloud Service Offering (CSO)."
            },
            {
                "name": "Microsoft Azure",
                "location": "Redmond, Washington, USA (U.S. Azure and Azure Government regions, as applicable)",
                "servicesProvided": "Provides cloud platform services supporting identity integration, application hosting, secure networking, and infrastructure services. Microsoft services may also support development, testing, and enterprise productivity functions where applicable."
            },
            {
                "name": "GitHub",
                "location": "San Francisco, California, USA",
                "servicesProvided": "Provides secure source code repository, version control, software collaboration, issue tracking, and DevSecOps workflow management to support the secure software development lifecycle (SDLC). GitHub Enterprise security features are used to protect source code and support secure development practices."
            },
            {
                "name": "BeyondTrust",
                "location": "Johns Creek, Georgia, USA",
                "servicesProvided": "Provides Privileged Access Management (PAM), privileged remote access, credential vaulting, session monitoring, and privileged account security to control and audit administrative access to NextgenID information systems."
            },
            {
                "name": "Okta",
                "location": "San Francisco, California, USA",
                "servicesProvided": "Provides Identity and Access Management (IAM), Single Sign-On (SSO), Multi-Factor Authentication (MFA), lifecycle management, and identity federation services for secure authentication and access to NextgenID systems and applications."
            }
        ]
    }
}