In the public sector, every system is also a public record
Government technology has to serve everyone, including citizens on old phones, people using screen readers and people with low digital confidence. It has to survive security audits and freedom-of-information requests, and it has to be maintained long after the original contractor has gone. That changes how you build: accessibility, security and documentation are requirements from day one, not extras.
We build accessible public websites and citizen portals, harden identity and access, run penetration tests and remediation before formal audits, design secure cloud hosting on approved providers, and document controls against the framework you are assessed on.
Challenges public-sector teams describe
Accessibility, audit and legacy are the recurring themes.
“Our site failed the security audit”
A mandatory audit found vulnerabilities, and hosting cannot proceed until they are fixed and retested.
“We must meet accessibility guidelines”
Portals and PDFs need to meet WCAG, GIGW 3.0 or Section 508, and nobody knows where to start.
“The original vendor is gone”
A critical system has no documentation, no source control and no one who understands it.
“Citizens queue for things that could be online”
Paper forms and office visits for services that could be self-service.
“Admin access is shared and unlogged”
Several staff and vendors use the same accounts, with no audit trail.
“Procurement asks for controls we can’t evidence”
Tender requirements list security frameworks the team has never mapped.
Public-sector solutions with accountability built in
Each solution produces documentation as well as working software.
Accessible citizen portals
The challenge
Public websites and services that exclude users with disabilities, older devices or low bandwidth.
Our approach
We design and build with accessible components, plain language and lightweight pages, test with automated tools plus manual screen-reader and keyboard checks, and document conformance.
What you get
- WCAG 2.1/2.2 AA and GIGW 3.0 design
- Lightweight, mobile-first pages
- Manual assistive-technology testing
- Accessibility statement and report
Audit preparation & remediation
The challenge
A formal security audit is mandatory before hosting or renewal, and earlier attempts have failed.
Our approach
We run a pre-audit penetration test, fix the vulnerabilities in code and configuration, harden the server and CMS, and support you through the formal audit by the designated auditor.
What you get
- Pre-audit VAPT (OWASP-based)
- Code and configuration fixes
- Server and CMS hardening
- Support during the formal audit
Identity & privileged-access hardening
The challenge
Shared administrator accounts, no MFA and no record of who changed what.
Our approach
We introduce SSO and MFA, individual named accounts, role-based access, privileged-access controls and centralised, tamper-evident logging.
What you get
- SSO and MFA
- Named, role-based accounts
- Privileged-access controls
- Tamper-evident audit logging
Legacy system rescue & documentation
The challenge
A critical application with no documentation, no source control and a departed vendor.
Our approach
We recover the source into version control, document architecture and operations, fix urgent security issues, set up backups and monitoring, and plan a gradual modernisation.
What you get
- Source recovered into version control
- Architecture and runbook documentation
- Urgent security fixes
- Modernisation roadmap
Controls mapping for tenders & assessments
The challenge
Tenders and assessments demand alignment to ISO 27001, NIST or CMMC, and evidence the team does not have.
Our approach
We map requirements to your existing controls, close the gaps, write policies and procedures, and track evidence in a GRC platform so the next tender or assessment is faster.
What you get
- Requirement-to-control mapping
- Policies and procedures
- Gap remediation
- Evidence tracked in a GRC tool
Frameworks public-sector systems are judged against
Requirements vary by country and by contract. These are the ones we most often design for.
GIGW 3.0
The Guidelines for Indian Government Websites and Apps (2023) cover accessibility, usability, content and security for government websites and mobile apps.
Security audit before hosting
Government sites are typically required to pass a security audit by a CERT-In empanelled auditor before hosting. We are not an empanelled auditor: we prepare, remediate and support you through it.
Section 508 & ADA Title II
Federal ICT must meet Section 508 (aligned to WCAG 2.0 AA). The DOJ’s 2024 ADA Title II rule requires WCAG 2.1 AA for state and local governments, with deadlines tied to population that have since been revised.
CMMC 2.0
The DFARS rule implementing the Cybersecurity Maturity Model Certification took effect on 10 November 2025 and is being phased into defence contracts. Level 2 aligns with NIST SP 800-171 for controlled unclassified information.
NIST CSF 2.0 & ISO 27001
NIST released CSF 2.0 in February 2024, adding a Govern function. Together with ISO 27001 it is the most common basis for public-sector security requirements.
MeitY-empanelled cloud
Government workloads in India generally run on cloud service offerings empanelled by MeitY. We design and secure deployments on those providers.
Status as of October 2026. Regulations change; we help you design, implement and evidence technical controls. Legal interpretation belongs with your counsel, and certifications or audit opinions are issued by independent bodies, not by us.
Standards and platforms we work with
- WCAG 2.1 / 2.2
- GIGW 3.0
- Section 508
- OWASP Top 10
- NIST SP 800-53 / 800-171
- ISO 27001
- WordPress
- Drupal
- Laravel
- MeitY-empanelled cloud
- AWS GovCloud-style patterns
- Keycloak / SSO
Security products we run
Built and run within our group, and used for evidence and testing.
SemperWise
AI-first cybersecurity: VAPT, pentesting & compliance on SemperWise One™ Our group’s cybersecurity practice: VAPT, secure code review, red teaming and compliance support. Visit semperwise.com
GRC Platform
Governance, Risk & Compliance, automated Policies, risks, controls and evidence in one platform, ready for audits and tender questionnaires. Visit grc.radiatus.comA typical first engagement: pre-audit readiness
Two to four weeks, fixed scope, focused on passing the formal security and accessibility checks.
Scope & requirements
We confirm which audits, guidelines and frameworks apply and agree the systems in scope.
Test
Penetration test plus an accessibility audit of key pages and services.
Remediate
Vulnerability and accessibility fixes in code, CMS and server configuration.
Retest & document
Retest, a remediation report and support while the formal audit takes place.
Guides and terms for public-sector teams
Questions public-sector teams ask us
No. We prepare systems for audit: we test, fix and harden them, and support you while a CERT-In empanelled auditor (or other designated body) performs the formal audit and issues the certificate.
Yes. We audit against GIGW 3.0 and WCAG 2.1/2.2 AA, fix templates and components, guide content teams on documents and media, and provide a conformance report.
We work directly with public bodies where procurement allows it, and as a technical subcontractor to system integrators. Eligibility depends on each tender’s criteria, so we will tell you honestly whether we qualify.
Yes. We recover the source and configuration, document the system, fix urgent security issues and put backups and monitoring in place before planning any modernisation.
We help with the technical side: gap assessment against NIST SP 800-171, implementing controls and preparing evidence. Formal CMMC Level 2 certification assessments are carried out by authorised third-party assessment organisations (C3PAOs).
Audit deadline, accessibility requirement or orphaned system?
Tell us which requirement you face. We will tell you what it will take to meet it.






Compliance-first delivery