Black Knight Risk Management has been certified as a HUBZone small business by the U.S. Small Business Administration. The firm already holds Service-Disabled Veteran-Owned Small Business certification federally, along with Service-Disabled Veteran-Owned Business and Minority-Owned Business Enterprise certification in New York State.

Certifications are easy to list and easy to ignore. The reason this one is worth an announcement is that it changes what a contracting officer is permitted to do, not just what we can claim.

What the certification enables

HUBZone status opens four distinct mechanisms, and each one implies a different conversation:

  • Sole source award. A contracting officer may award directly without competition when the requirement falls within the applicable threshold and the officer reasonably expects a fair price. This is the most direct path from a working relationship to a contract.
  • Set-aside competition. Requirements may be reserved for HUBZone competition, where the field is smaller and the evaluation is focused.
  • Price evaluation preference. In full and open competition, a HUBZone small business receives a price evaluation preference against large business offerors.
  • Subcontracting goal credit. Prime contractors carry HUBZone subcontracting goals. Adding our firm to a team improves goal attainment while adding governance and regulatory depth to the technical volume.

Dollar thresholds and preference mechanics are set by regulation and adjust over time. We confirm current figures against the Federal Acquisition Regulation and SBA guidance rather than quoting numbers from memory.

Why this matters for the work itself

Most small firms state their certification and then wait. That is a mistake, because contracting officers are not obligated to volunteer a pathway they have not been asked about. If you are working a requirement in technology governance, cybersecurity risk, AI governance, or regulatory readiness, the useful question is whether it can be met through a HUBZone or SDVOSB sole source or set-aside. That is a faster conversation to have before a solicitation is written than after.

We should also be plain about what a certification is not. It gets a firm into the room. It does not do the work, and it is not a reason to hire anyone. What we bring is judgment built on the regulator's side of the table: examination scoping, supervisory conclusions, and finding remediation through validated closure, at both the state and federal level.

Certifications get us into the room. Judgment is what wins the work. We try never to let the first do the job of the second.

Where we fit

Our practice covers eight areas under one umbrella: technology governance, cybersecurity risk, AI governance, cloud governance, operational risk, regulatory readiness, executive advisory, and technology procurement advisory. In practice that means examination readiness, finding remediation, governance program alignment, board risk translation, and executive education.

For agencies, the entry point is usually a modernization program that has outrun its governance, or an artificial intelligence deployment nobody has yet figured out how to defend. For prime contractors, it is a technical bid that needs governance and regulatory depth to be credible to the people evaluating it.

Our entity identifiers, NAICS codes, and full certification detail are on the government page, organized for buyers who need them.