SOC2C

Is this your company? Buyers are checking Unanet Technologies here. Claim unanet.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Unanet Technologies logo

Unanet Technologies

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Unanet Technologies is SOC 2 Type II compliant. Unanet Technologies also holds FedRAMP, and GDPR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Unanet is a leading provider of ERP and CRM solutions purpose-built for Government Contractors, AEC, and Professional Services. Project-driven organizations depend on Unanet to turn their information into actionable insights, drive better decision-making, and accelerate business growth. All backed by a people-centered team invested in the success of your projects, people, and financials.

Compliance & infrastructure

Subprocessors

1
  • U
    Unanet Subprocessors · Unanet uses Sub-Processors to provide certain infrastructure services, and for o

Compliance leadership

The person who leads Unanet Technologies's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Unanet Technologies's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Unanet Secures FedRAMP Moderate Equivalency, Elevating Security and Compliance for Government ContractorsJan 2026

Dulles, VA, January 14, 2026 – Unanet, a leading provider in AI-first ERP and growth software for project-based businesses, today announced it has attained FedRAMP Moderate Equivalency for its ERP GovCon solution. This milestone enables government contractors (GovCons) to use Unanet’s FedRAMP Moderate Equivalent ERP solution with confidence under the stringent cybersecurity requirements set by the Federal Risk and Authorization Management Program (FedRAMP) for protecting and managing sensitive information. FedRAMP Moderate Equivalency delivers the same rigorous security controls as FedRAMP Authorization through an independent assessment against the NIST 800-53 controls. This means equivalent protection for sensitive data validated by a Third-Party Assessment Organization (3PAO). Unanet’s FedRAMP Moderate Equivalency is validated through an independent assessment by ControlCase, Unanet’s 3PAO. This process produces a complete FedRAMP documentation package and body of evidence, which supports government contractors seeking CMMC certification and DFARS 252.204-7012 compliance. “ControlCase recognizes Unanet’s achievement of FedRAMP Moderate Equivalency as a testament to their strong commitment to security and compliance. This milestone underscores Unanet’s dedication to providing secure, reliable cloud solutions for the government contracting community,” said Mike Jenner, CEO…

This listing is partial

5/11 details · 45%

SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Hosting
    Add where you host (AWS, GCP, Azure) and data residency.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Unanet Technologies SOC 2 compliant?
Unanet Technologies is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Unanet Technologies FedRAMP compliant?
According to Unanet Technologies's public trust center, Unanet Technologies is FedRAMP compliant. On SOC2C this listing is Listed.
Is Unanet Technologies GDPR compliant?
According to Unanet Technologies's public trust center, Unanet Technologies is GDPR compliant. On SOC2C this listing is Listed.
Is Unanet Technologies SOC 2 Type I or Type II?
Unanet Technologies is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Unanet Technologies's SOC 2 for a vendor risk assessment?
Yes. Unanet Technologies's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.

Answers published by Unanet Technologies

Reproduced from Unanet Technologies's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

What is the Cybersecurity Maturity Model Certification (CMMC) 2.0 Program?
The CMMC 2.0 Program is designed to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) that is shared with contractors and subcontractors of the Department of Defense (DoD) through acquisition programs. CMMC requires implementation of a set of security controls and third-party certification to protect FCI and CUI shared with defense contractors and subcontractors during contract performance. DoD published the CMMC final rule on October 15, 2024 and it took effect on December 16, 2024. It is anticipated that DoD contracts will be required to include CMMC compliance clauses by mid-2025. The DoD will use CMMC 2.0 to impose major cybersecurity requirements, assessment requirements, and affirmation requirements on both prime and subcontractors. CMMC 2.0 will require many defense contractors to obtain a third-party certification that they have successfully implemented the cybersecurity controls set forth in the NIST SP 800-171. Going forward, CMMC 2.0 will bar a defense contractor from performing an awarded contract if it has not certified that it is CMMC 2.0 compliant. The requirements at the different levels of compliance may be viewed here.
What is FedRAMP?
The Federal Risk and Authorization Management Program (FedRAMP®) was established in 2011 to provide a cost-effective, risk-based approach for the adoption and use of cloud services by the federal government. FedRAMP empowers agencies to use modern cloud technologies with an emphasis on security and protection of federal information. In December 2022, the FedRAMP Authorization Act was signed as part of the FY23 National Defense Authorization Act (NDAA). The Act codifies the FedRAMP program as the authoritative standardized approach to security assessment and authorization for cloud computing products and services that process unclassified federal information. FedRAMP is a government-wide program that promotes the adoption of secure cloud services across the federal government. It outlines a standardized approach to security and risk assessment for cloud technologies and federal agencies. FedRAMP is mandatory for all executive agency cloud deployments and service models at three risk impact levels: Low, Moderate, and High. What this means is that a cloud service provider (CSP) must go through the FedRAMP assessment and authorization process once. After the provider receives authorization for their cloud service offering (CSO), the security package can be reused by any federal agency.
How do FedRAMP and CMMC 2.0 program overlap?
The CMMC 2.0 Program is a DoD program that requires DoD contractors to satisfy a set of security controls and third-party certification to protect FCI and CUI shared with defense contractors and subcontractors during contract performance. The applicability of the CMMC level is determined at the government contractor level based on its relevant contracts and information handled. Defense contractors may be able to streamline their compliance with CMMC by using CSOs that are either FedRAMP equivalent or moderate authorized with agency approval. FedRAMP is a government program that requires a set of security controls for cloud service offerings (CSOs) that process, store, or generate CUI. If your CSO processes, stores, or generates CUI, then the CMMC will likely require the CSO provide a FedRAMP Moderate or Equivalent offering.
What is a FedRAMP Moderate Authorized designation?
This designation signifies that the cloud service offering (CSO) has undergone an assessment conducted by a certified Third-Party Assessment Organization (3PAO) and has been authorized by either the Joint Authorization Board (JAB) or a federal agency. This assessment evaluates security posture and alignment with FedRAMP Moderate security control baseline (NIST SP 800-53).
What is a FedRAMP Moderate Equivalent designation?
This designation signifies that the cloud service offering (CSO) has undergone an assessment conducted by a certified Third-Party Assessment Organization (3PAO) that meets the same security control baseline as FedRAMP Moderate, but through a different process. To achieve this designation, a CSO must achieve 100% compliance with the latest FedRAMP Moderate security control baseline (NIST SP 800-53).

Business & Industrial peers that completed SOC 2