Right-sized for the stage you're at — and built to scale with you into the next one.
Every engagement is led by the principal — the person who writes your roadmap sits with your auditors.
Billed monthly on a quarterly commitment. Taxes extra.
Our methods for intrusion detection, access control and attack recovery were built and defended in the open — at ACM and IEEE security venues — before they were ever billed to a client.
GOOGLE SCHOLAR PROFILE ↗Under its FedRAMP 20x overhaul — the Consolidated Rules for 2026 — FedRAMP has introduced Class A, an entry-level certification that lets a cloud service provider get listed in the federal Marketplace on the strength of an existing SOC 2 Type II, with no agency sponsor required. Class A is the lowest of four new lettered classes (A through D) that replace the old Low, Moderate and High baselines.
It's an on-ramp, not a destination. A Class A listing places you in the Marketplace's Preparation phase — enough for a federal agency to adopt your service for a low-risk pilot — and starts a two-year clock to earn a full Class B, C or D authorization.
The catch: a SOC 2 Type II makes you eligible, but it doesn't get you across the line. On top of your report you must implement and test roughly 25 mandatory FedRAMP rules and the 20x Key Security Indicators — continuous evidence, identity and access management, change management and incident response — then submit a complete evidence package through the FedRAMP PMO's Program Certification.
Don't navigate Class A alone — let Savannah Research Labs do it for you. Call for an initial consultation on your FedRAMP path: or .
This is exactly the preparation we run for you. We map your posture against the Class A requirements, stand up and test the mandatory FedRAMP rules and 20x KSIs, build the continuous-evidence pipeline they demand, assemble your SOC 2 and audit-engagement package, and manage your submission through the FedRAMP PMO — while we operate the SOC 2, ISO 27001 and other frameworks that get you there.

Mehdi brings 25 years of experience in security engineering and compliance to every engagement, anchored by a PhD specializing in cybersecurity from the University of British Columbia (UBC). His research on securing enterprise cloud and autonomous systems is reflected in a substantial body of peer-reviewed publications and patents in the field, including a Best Paper Award at IEEE/IFIP DSN.
At Savannah Research Labs, Mehdi leads every engagement personally as a hands-on vCISO — architecting and operationalizing enterprise-grade security programs, and directing multi-framework compliance leadership across SOC 2, ISO 27001, ISO 42001 and FedRAMP, from initial gap assessment and control implementation through formal audit and certification. The focus stays practical: security leadership and compliance outcomes that hold up under real scrutiny.