For Federal, VA, DoD, Healthcare & Critical Infrastructure

The Evolution of Physical Security Is a Layered Solution.TSS Group Delivers All Three Layers.

Edge devices. Network layers. Human interaction. Most integrators sell you one layer and hope the others work. TSS Group designs, deploys, and maintains all three as a single, integrated system — under one contract, one team, and one point of accountability.

98%
of IoT device traffic is unencrypted
$3.9M
average cost to remediate a single cyberattack
41B+
connected IoT devices globally by 2025
53%
of medical devices have critical vulnerabilities
CVE-Verified SDVOSB Prime|UEI: VC8RJQ1TTGV5| NDAA §889 Compliant| Scottsdale, AZ — Serving Nationwide

The Core Concept — Read This First

Physical security has evolved. A decade ago, you bought cameras from one vendor, badge readers from another, and called it a system. Today, your cameras are on your network. Your badge readers are on your network. Your building controllers, HVAC, elevators, and medical devices are on your network. The line between physical security and cybersecurity has disappeared.

The integrator who sells you cameras but cannot secure the network they run on is not delivering security. They are delivering equipment. The evolution of physical security is a layered solution — edge devices, network layers, and human interaction — designed, deployed, and maintained by one team under one contract.

The plain-English version:

Think of a high-security office building. Layer 1 is the armed guard at the front desk checking IDs. Layer 2 is the secure, private hallway that ensures only authorized people can travel from the lobby to the offices. Layer 3 is an invisible key that knows exactly who you are — the door unlocks as you approach, your computer recognizes you when you sit down, and the system locks your station when you step away. You never fumble for keys. But the system always knows the right person is in the right seat.

The Architecture

Three Layers. One Solution.

Each layer solves a different problem. Together, they close every gap. TSS Group is the single prime who delivers all three.

Layer 1

Edge Devices

The Physical Layer

Cameras, readers, sensors, controllers, and electrified hardware. The things you can touch. The things that see, sense, and control access to your facility.

Dive into Layer 1
Layer 2

Network Layers

The Transport Layer

Zero Trust architecture, cryptographic microsegmentation, and encrypted transport. The invisible layer that makes your edge devices and data invisible to attackers.

Dive into Layer 2
Layer 3

Human Interaction

The Identity Layer

Persistent authentication, passwordless identity, and session continuity. The layer that knows who is at the keyboard — every second they are logged in, not just when they badge in.

Dive into Layer 3
Layer 1 — The Physical Layer

Edge Devices

1

Sensors Are Not Security

A camera records. A reader grants entry. A sensor detects motion. None of them, alone, make your facility secure. Security happens when these devices are designed as one system — not procured from three different vendors and hoped to work together.

2

NDAA Section 889 Is Not Optional

If your facility has federal funding, federal contracts, or federal tenants, your security equipment must be NDAA Section 889 compliant. Banned equipment cannot be installed — not even for commercial clients, because the ban is expanding. Every device must be verified before purchase.

3

Power and Pathway Determine Cost

The cheapest quote is usually the one that did not visit your site. A $500-per-door estimate becomes $3,500 when the installer discovers there is no cable pathway, no power within 50 feet, and the door frame needs modification. Site survey first. Then quote.

4

Interoperability Is the Real Deliverable

Your video system must talk to your access control. Your access control must talk to your intrusion detection. Your intrusion detection must talk to your building management. If they are siloed, you have purchased equipment — not security.

Questions a Smart Buyer Should Ask Any Integrator

  1. Q1.Did you survey our site before quoting, or is this a price-sheet estimate?
  2. Q2.Are all proposed devices NDAA Section 889 compliant? Can you prove it?
  3. Q3.How will the video, access control, and intrusion systems share data and events?
  4. Q4.What is the power and cable pathway plan for each device location?
  5. Q5.Who commissions the system — the same team that designed it, or a subcontractor?
Layer 2 — The Transport Layer

Network Layers

1

Zero Trust Means Verify Everything, Always

Traditional security trusts the network inside the perimeter. Zero Trust trusts nothing. Every device, every connection, every request is verified continuously — regardless of whether it originates inside or outside your facility. This is now federal law under Executive Order 14028.

2

Microsegmentation Stops Lateral Movement

When a breach happens, the attacker moves laterally — from device to device, searching for valuable data. Cryptographic microsegmentation wraps each device and workload in its own encrypted enclave. A compromised camera cannot reach your patient records. A breached HVAC controller cannot touch your access control.

3

98% of IoT Device Traffic Is Unencrypted

Cameras, card readers, building controllers, medical devices — most of them send data in the clear. Any attacker on the network can see it, intercept it, or replay it. The network layer encrypts data in motion at the link layer, making your devices and their data invisible to unauthorized monitoring.

4

Overlay, Not Rip-and-Replace

A proper Zero Trust network layer overlays your existing infrastructure. No hardware replacement. No network rebuild. No new certifications for your staff. It protects what you already have — legacy systems, new systems, IT, OT, IoT — without disruption.

Questions a Smart Buyer Should Ask Any Integrator

  1. Q1.Does your Zero Trust solution operate at Layer 2 (data link) or only Layer 3 (network)?
  2. Q2.Can you microsegment OT and IoT devices that cannot host agents or lack IP addresses?
  3. Q3.How does the solution overlay our existing infrastructure without hardware replacement?
  4. Q4.Is the solution FIPS 140-3 validated and does it hold a federal Authority to Operate (ATO)?
  5. Q5.How do you handle devices that cannot be taken offline for patching or agent installation?
Layer 3 — The Identity Layer

Human Interaction

1

Identity Is the New Perimeter

Security no longer stops at the door. Once a user badges into a room, the real question begins: who is at the keyboard? Badge readers grant entry to a space. They do not verify the person behind the workstation. The human interaction layer ensures the person at the keyboard is exactly who they claim to be — every second they are logged in.

2

Session Continuity Eliminates MFA Fatigue

Traditional multi-factor authentication verifies once at login, then trusts the session. Persistent authentication verifies continuously and invisibly. When the authorized user steps away, the session locks. When they return, it resumes. No repeated prompts. No MFA fatigue. No helpdesk calls for password resets.

3

Shared Workstations Without Compromise

In hospitals, clinics, and federal facilities, workstations are shared. The human interaction layer binds identity to the session — not the machine. When Nurse A sits down, she sees her session. When Nurse B sits down, she sees hers. Individual accountability is maintained without forcing each user to log in from scratch every time.

4

Physical and Logical Audit Trail Unified

A badge-in at the door and a login at the keyboard are usually two separate logs in two separate systems. The human interaction layer unifies them. You see, in one record, that Dr. Smith badged into Room 312 at 9:14 AM and accessed the electronic health record system at 9:14 AM. One audit trail. One source of truth.

Questions a Smart Buyer Should Ask Any Integrator

  1. Q1.How does this layer verify identity after the initial login — and is it invisible to the end user?
  2. Q2.Can you demonstrate shared workstation handling without compromising individual accountability?
  3. Q3.If our network connection drops, does this layer still keep the facility operational?
  4. Q4.What is the measurable impact on Time-to-Task — how many minutes do staff save daily?
  5. Q5.Does this solution provide a unified audit log linking physical movement to logical session activity?

The TSS Difference

Why TSS Group Is the Total Solution

Most integrators deliver one layer and subcontract the rest. TSS Group delivers all three layers under one contract — no handoffs, no knowledge gaps, no finger-pointing.

One Team, All Three Layers

The engineers who design your edge device layout are the same engineers who architect your Zero Trust network and configure your persistent authentication. No knowledge handoff. No subcontractor gaps.

SDVOSB Prime Contractor

TSS Group holds the contract. We perform the work. We do not broker it, rebadge it, or hand it off. ≥51% veteran direct labor. Self-performing. Same team from site survey through long-term support.

Compliance Built In

NDAA Section 889. NIST SP 800-207. FIPS 140-3. CMMC. EO 14028. Every device verified before purchase. Every architecture designed for your compliance framework. No banned equipment, ever.

Site Survey First, Then Quote

We do not quote from a price sheet. We visit your facility, assess your cable pathway, power availability, door hardware, and network infrastructure — then give you a real number, not a range.

Same-Team Continuity

The team that deploys your system maintains it. Long-term. Manufacturer warranties remain intact. No rotating subcontractors who have never seen your facility before.

Federal-Grade, Commercial-Ready

We serve VA, DoD, healthcare, and critical infrastructure — and commercial clients across the United States. Federal compliance standards applied to every project, regardless of client type.

The Integration Promise

When you buy cameras from Vendor A, access control from Vendor B, and network security from Vendor C, you have purchased equipment — not security. When something goes wrong, Vendor A blames Vendor B. Vendor B blames Vendor C. And you are left holding the bag.

TSS Group eliminates the finger-pointing. One contract. One team. One point of accountability. When your video system needs to trigger an access control lockout, it works — because the same engineer designed both. When your network segmentation needs to isolate a compromised camera, it works — because the same architect specified the enclave. That is what "total solution" means.

Common Questions

Answers to Every Objection

Every reason to buy one layer instead of three, answered honestly.

Compliance & Standards

Every layer maps to specific federal standards. TSS Group designs for compliance from day one — not as an afterthought.

StandardApplies ToWhat It Means
NDAA Section 889All edge devicesProhibits banned telecommunications equipment (cameras, recorders, network gear). All TSS-installed equipment is verified compliant before purchase.
NIST SP 800-207Network + Identity layersZero Trust Architecture standard. Requires continuous verification, least-privilege access, and explicit trust validation for every request.
FIPS 140-3Network layerFederal cryptographic module validation standard. The highest encryption certification for US government and DoD use.
Executive Order 14028All layersFederal mandate requiring Zero Trust architecture across government supply chains. Agencies must move toward ZTA.
CMMCAll layersCybersecurity Maturity Model Certification for DoD contractors. Layered security supports Level 3+ compliance.
FIPS 201 / PIV-CACIdentity layerFederal personal identity verification standards for high-assurance access. Supports PIV/CAC credential integration.
HIPAA / HITECHIdentity layerHealthcare privacy and security. Requires audit trails of who accessed what patient data, and when. Unified physical-logical logging supports compliance.
TIC 3.0Network layerTrusted Internet Connections framework for secure federal network boundaries.

Due Diligence

15 Questions to Ask Any Security Integrator

Print this. Bring it to your next vendor meeting. If they cannot answer all 15, they are not delivering a layered solution.

1

Edge Devices — The Physical Layer

  1. 1.Did you survey our site before quoting, or is this a price-sheet estimate?
  2. 2.Are all proposed devices NDAA Section 889 compliant? Can you prove it?
  3. 3.How will the video, access control, and intrusion systems share data and events?
  4. 4.What is the power and cable pathway plan for each device location?
  5. 5.Who commissions the system — the same team that designed it, or a subcontractor?
2

Network Layers — The Transport Layer

  1. 1.Does your Zero Trust solution operate at Layer 2 (data link) or only Layer 3 (network)?
  2. 2.Can you microsegment OT and IoT devices that cannot host agents or lack IP addresses?
  3. 3.How does the solution overlay our existing infrastructure without hardware replacement?
  4. 4.Is the solution FIPS 140-3 validated and does it hold a federal Authority to Operate (ATO)?
  5. 5.How do you handle devices that cannot be taken offline for patching or agent installation?
3

Human Interaction — The Identity Layer

  1. 1.How does this layer verify identity after the initial login — and is it invisible to the end user?
  2. 2.Can you demonstrate shared workstation handling without compromising individual accountability?
  3. 3.If our network connection drops, does this layer still keep the facility operational?
  4. 4.What is the measurable impact on Time-to-Task — how many minutes do staff save daily?
  5. 5.Does this solution provide a unified audit log linking physical movement to logical session activity?

For Technology Partners

Why Vendors Partner With TSS Group

If you manufacture edge devices, network security platforms, or identity solutions — TSS Group is the integrator who can deliver your technology as part of a complete layered solution.

SDVOSB Set-Aside Access

TSS Group opens the federal market. 38 U.S.C. § 8127 gives VA and DoD agencies a congressionally-mandated preference to award sole-source contracts to verified SDVOSB firms up to $4M. Your technology, delivered through a vehicle agencies are required by law to consider first.

All-Three-Layers Capability

Most integrators specialize in one layer. TSS Group delivers edge, network, and identity. When you partner with us, your technology is positioned as part of a complete solution — not a standalone component competing on price.

Same-Team Engineering

Our engineers design, deploy, and maintain. No subcontractor handoff. Your product is installed and commissioned by technical staff who understand the full architecture — not a cable puller reading a manual for the first time.

Federal Compliance Pipeline

NDAA, FIPS, ATO, CMMC, NIST — we navigate the compliance maze so your technology reaches federal buyers without procurement friction. Every deployment is compliance-documented from site survey through commissioning.

TSS Group does not white-label or rebrand partner technology. We integrate it, deploy it, and stand behind it — with our name on the contract and our engineers on the site. If you build technology that belongs in a layered physical security solution, we want to talk.

Start a Partnership Conversation

Request a Site Survey

No-obligation site survey for qualified opportunities. Our technical team will assess your facility and recommend an integrated, layered security solution — not a price-sheet estimate.

Cory Franek, President

TSS Group LLC — Scottsdale, Arizona