Federal Subcontracting Partner

The subcontracting partner federal primes actually want to call back.

Cijara Group delivers program management, regulatory, and AI advisory support to federal prime contractors - on time, on plan, and aligned to your scorecard goals.

2026
Year Founded
7
Core NAICS
NC
Headquartered
Cijara Group emblem with oak tree
Est. 2026

Capabilities

Mission support, shaped to your scope.

Four practice areas, one operating principle: make the prime's delivery cleaner, faster, and more defensible.

Responsible AI

Governance is the differentiator.

Plenty of firms can build a model. Far fewer can hand a contracting officer the paper trail that lets an agency deploy it - and defend it. Cijara Group turns Responsible AI obligations into deliverables that close the gap between a technical capability and an approved deployment.

Compliance-led, not model-led

We lead with program management and FAR/DFARS compliance, then apply AI governance inside that discipline. Agencies buy defensible process; the model is the easy part.

Artifacts a CO can accept

High-impact AI determinations, use-case inventories, risk-management plans mapped to the NIST AI RMF Govern/Map/Measure/Manage functions, model documentation, and human-oversight runbooks - written to survive IG and OMB review.

Calibrated to the live buying triggers

OMB M-25-21 and M-25-22 replaced the rescinded M-24-10 / M-24-18 on April 3, 2025 and carry binding agency deadlines: CAIO designation, published AI use-case inventories, minimum risk practices for high-impact AI, and Responsible AI evaluation criteria in procurement.

Right-sized obligations

Each use case carries only the controls that actually apply, and the agency can defend that calibration on review. Governance that slows delivery is governance that gets waived.

AI Policy FAQ

The deadlines driving the buy.

M-25-21 and M-25-22 set binding obligations with dates attached. Those dates - not general AI enthusiasm - are what turn an agency requirement into a funded action.

See our AI Advisory capability →

What are OMB M-25-21 and M-25-22?

M-25-21 (Accelerating Federal Use of AI) and M-25-22 (Driving Efficient Acquisition of AI) were issued April 3, 2025 and replaced the rescinded M-24-10 and M-24-18. M-25-21 governs how agencies use AI; M-25-22 governs how they buy it. Together they are the current binding guidance for federal AI programs.

What are the live buying triggers for agencies right now?

Four obligations create work: designating and empowering a Chief AI Officer, publishing and maintaining a public AI use-case inventory, applying minimum risk-management practices to every high-impact AI use case, and writing Responsible AI evaluation criteria into solicitations and contracts. Each one requires documented artifacts an agency can defend, which is where subcontracted support gets bought.

What are the deadlines under M-25-21?

Agencies had 60 days from April 3, 2025 to identify a Chief AI Officer, 180 days to publish an AI strategy, and 365 days to bring high-impact AI use cases into compliance with the minimum risk-management practices or stop using them. Use-case inventories are refreshed annually. Those recurring compliance and inventory cycles keep the demand live rather than one-time.

What does M-25-22 change about AI acquisition?

It pushes agencies toward performance-based acquisition for AI, requires vendor terms that protect government data and avoid vendor lock-in, and expects Responsible AI requirements to appear in the requirement documents themselves - not as an afterthought at award. Primes bidding AI work are increasingly evaluated on the governance package, not just the model.

What counts as a high-impact AI use case?

AI whose output serves as a principal basis for decisions with a legal, material, safety, or rights-affecting consequence for the public. Those use cases carry the heaviest obligations: pre-deployment testing, AI impact assessment, ongoing monitoring, human oversight, and a documented determination. Getting the determination right is what keeps obligations right-sized.

How does Cijara Group support these requirements?

We lead with program management and FAR/DFARS compliance, then apply AI governance inside that discipline. Deliverables are the artifacts a contracting officer can accept: high-impact AI determinations, use-case inventory support, risk-management plans mapped to the NIST AI RMF, model documentation, and human-oversight runbooks - sized so an agency carries only the controls that actually apply.

NAICS Codes

Where we play.

Cijara Group subcontracts under seven NAICS codes covering federal management consulting, computer systems and IT services, professional services, and management training. Tap any code for capabilities, agencies served, and contract vehicles.

See all NAICS codes →

Why Cijara

The sub you'd want if you were the prime.

Built for primes, not against them

We exist to make your delivery easier. No prime-side ambitions, no channel conflict - your client relationship stays yours.

Small-business subcontracting support

Aligned to FAR 52.219-9 small-business subcontracting plan goals and supplier-diversity reporting needs.

Senior bench, lean overhead

Direct access to principals on every engagement. No multi-layer markups, no junior-staff bait-and-switch.

Conflict-free, cleared posture

Clear teaming agreements with ROFR. Active management of OCI exposure across our network of W-2 commitments.

Leadership

Irma Chilin, MBA - Managing Principal & Co-Founder

Irma Chilin is the Managing Principal, Co-Founder, and majority owner of Cijara Group. She brings more than 15 years inside the banking regulatory function - managing examinations from within the institution, with regulators across the table.

She leads Cijara's banking-regulatory and BSA/AML practice, spanning exam and issue management, RCSA and risk-control design, and internal audit across global institutions.

Joshua Reh - Principal & Co-Founder

Joshua Reh is a Principal and Co-Founder of Cijara Group. He brings 15+ years inside the model risk, operational risk, AI governance, and enterprise data management functions at major financial institutions - building and operating the programs regulators and internal risk committees rely on.

He leads Cijara's model risk management and AI governance practice, bringing operator-grade experience to federal primes managing complex regulatory and technology requirements.

Engage

Let's discuss your scorecard goals.

Capability statement, past performance summary, and teaming agreement templates available on request.

Use your full name or preferred contact name.

We will use this address for follow-up.

Include a country code if you are outside the U.S.

Select one or more areas where you need support.

We will use this information to respond to your capability inquiry.

Prefer email? Write us at contact@cijaragroup.com.

Charlotte, North Carolina · UEI GFAVPG24N4V3