For the defense industrial base

The requirement arrived. The company that received it has no security department.

Read the constraint before the pitch: we hold neither a FedRAMP authorization nor a FedRAMP certification, so a scope that carries Controlled Unclassified Information into an external service is not one we can serve today. What we can help with sits on the other side of that line — and knowing exactly where the line falls for your contracts is worth more than most of what gets sold into this sector.

What a flow-down clause looks like when it lands on a company of eighty people

A clause arrives in a contract from a prime. It references obligations that assume an organisation with a security function, a documented system boundary, an asset inventory, and somebody whose job is compliance. The company receiving it has a machine shop, an accounting system, an engineer who also runs the network, and a quarter to respond in.

The first honest problem is scope. Nobody is certain which files, which folders, which emails and which machines actually hold the data the clause is about. The drawings came in by email, were saved to a share, were copied to a laptop for a job, and were sent to a supplier. There is no map, and building one is a project nobody has budget for.

The second is that two different obligations get treated as one. Basic contract information and controlled information carry different requirements, and a supplier who assumes the stricter one applies everywhere buys controls they do not need — while a supplier who assumes the looser one applies everywhere has an exposure they do not know about.

The third is the cost shape. The controls that satisfy a serious assessment are largely fixed cost: they do not scale down for a company with one contract. So the smallest suppliers face close to the largest bill, and some of them conclude, quietly and rationally, that the defense work is no longer worth keeping.

And there is a market of vendors who understand all of this and are selling into the fear. Some of what is offered is genuinely useful. Some of it is a certification claim that does not mean what a supplier reading it will think it means.

You cannot protect a boundary you have not drawn

Most suppliers cannot say with confidence which of their systems hold Federal Contract Information, which hold Controlled Unclassified Information, and which hold neither — and every requirement, cost estimate and assessment outcome depends on that answer.

This is the finding underneath most of the cost. A supplier who cannot draw the boundary has to treat the whole company as in scope, and treating the whole company as in scope is what turns a manageable obligation into an existential one. The single highest-value piece of work available to most suppliers is drawing that line accurately.

Drawn accurately, the picture usually improves. A large share of systems turn out to hold neither category and can be excluded with evidence. Another share holds only basic contract information, where the requirements are the basic safeguarding ones and a self-assessment applies. The genuinely controlled data is often concentrated in fewer places than feared — and that concentration is the thing that makes an enclave affordable rather than absurd.

Drawn inaccurately in the optimistic direction, the outcome is an assessment finding. Drawn inaccurately in the pessimistic direction, the outcome is a company spending on controls for systems that never needed them, which is the quieter failure and probably the more common one.

What is being offered here is help with the first part — the map, the flow, and where contract data actually moves — and an honest statement of where we cannot go. Both halves matter. A vendor who will not tell you where their own limit is has not given you information you can plan with.

What a supplier gets, stated without inflation

Knowing where contract data actually is — measured by an observed inventory of systems, shares and paths holding each category, against a starting point where no map existed.

Systems that can be excluded from scope with evidence — measured by the count of systems evidenced as holding neither category, with the basis recorded for an assessor.

The two obligations kept apart — measured by each in-scope system mapped to the specific data category it holds, rather than to a single blanket assumption.

The size of the boundary you would have to protect — measured by systems and users inside the proposed boundary, before and after the map is drawn.

Where controlled data leaves the boundary today — measured by observed paths out — mail, portable media, supplier exchange — enumerated rather than estimated.

Operational work that has nothing to do with the boundary — measured by elapsed time and waiting in quoting, scheduling, quality and supplier management, measured outside the controlled scope.

any assessment outcome, any compliance determination, and any representation that using this service satisfies a contractual requirement. We are not an assessor, we do not hold a CMMC certification, and no vendor can make you compliant by being purchased. Your obligations attach to you under your contracts, and an assessor will evaluate your environment rather than our marketing.

Where this can operate, and where it cannot

It can operate against the parts of your business that hold no controlled information: quoting, scheduling, supplier management, quality follow-up, customer communication, and the administrative flow around a job. That is genuine operational ground and for most suppliers it is where the time is actually going.

It can help observe where contract data moves, in order to draw the boundary — a read-only exercise, scoped and agreed in advance, whose output is evidence you own.

It cannot host, process or transit Controlled Unclassified Information for you today. The requirement that governs a cloud service provider handling that data is a FedRAMP Moderate equivalency standard, and we hold neither a FedRAMP authorization nor a FedRAMP certification. That sentence is the reason to trust the rest of the page rather than an exception to it.

Where your enclave already exists and is operated by a provider who does meet the requirement, this stays outside it. There is no configuration that moves it inside, which is the correct design.

What we hold, and what we do not

We hold neither a FedRAMP authorization nor a FedRAMP certification, and we do not hold a CMMC certification. Those are different claims from each other and both answers are no. A supplier being sold either one should ask to see it, because in this sector the claim is checkable and the checking is somebody’s job.

A SOC 2 Type II independent CPA attestation is in progress and no report exists yet. When one does, it will be described as held rather than in progress, and the change will be made by a person who knows it changed.

Operational access is not permission to train. Your data — including drawings, quotes and supplier terms, none of which you would want in a competitor’s hands — does not become material improving anything serving another organisation. In a sector where your customers and your competitors overlap, that boundary is the precondition for the conversation.

Every consequential action carries a receipt naming its authority and time, exportable by you. For a supplier building an evidence file, a record produced during the work is worth considerably more than a narrative assembled for an assessor afterwards.

Your prime, your assessor, and your own contracts lead

The reviewer who matters most is not ours to satisfy — it is your assessor, and eventually your prime’s supply-chain security team. What they will look at is your environment and your evidence, so the useful thing a vendor can give you is evidence you own rather than assurances about themselves.

The distinction to hold on to through every vendor conversation this year: basic contract information and controlled information carry different requirements, and the level of assessment differs with them. Any document that treats them as one thing is either simplifying for a reader who cannot afford the simplification, or does not know.

Bring your contracts lead into the first conversation. The scope question is a contracts question before it is a technology question, and getting it wrong in either direction is expensive.

Draw the boundary first. It is the work with the highest return.

A read-only mapping exercise across the systems you believe may hold contract data, producing an evidenced inventory of what holds which category — with nothing moved, nothing changed, and no controlled data leaving your environment.

This is the phase that changes the economics for most suppliers, and it is deliberately the phase that does not require trusting us with anything sensitive. It is observation, scoped and agreed in advance, and the output is a document you own.

Several suppliers should stop there. If the map shows the controlled data is concentrated in three systems, the right next step is an enclave conversation with a provider who meets the requirement for that data — and we would tell you so, because the alternative is selling you something that leaves you non-compliant.

Where the map shows a large operational surface that holds no controlled data — quoting, scheduling, supplier follow-up, quality — that is where this can help, and it can start without touching the boundary at all.

Questions buyers actually ask

Are you CMMC certified?

No, and neither is any vendor in a way that transfers to you. CMMC obligations attach to your organisation and an assessor evaluates your environment, so no purchase makes a supplier compliant. What a vendor can legitimately affect is whether the environment being assessed is smaller and better evidenced — which is why the boundary map is the first piece of work rather than a product.

Can you hold our CUI?

No. A cloud service provider handling that data has to meet a FedRAMP Moderate equivalency standard, and we hold neither a FedRAMP authorization nor a FedRAMP certification. Controlled information stays inside your boundary or with a provider who meets the requirement, and there is no configuration here that changes that. If a vendor answers this question with a qualified yes, ask them which authorization they hold and at what impact level.

Then what is left that you can actually do for us?

Two things. First, the read-only boundary map — which for most suppliers is the highest-return work available, because treating the whole company as in scope is what makes the obligation unaffordable. Second, the operational surface that holds no controlled data at all: quoting, scheduling, supplier follow-up, quality actions. For most shops that is where the elapsed time actually goes, and it has been ignored because compliance absorbed all the attention.

We are considering exiting defense work. The overhead is more than the margin.

That is a legitimate business conclusion and some suppliers should reach it. What usually distorts it is that the overhead is estimated against an assumed scope rather than a measured one, and the assumed scope is almost always the whole company. Draw the boundary first. If the number still does not work afterwards, you will be exiting on the basis of a real figure — and that is a better decision either way.

Our prime is asking for our score. We do not have the evidence to support one.

Then the evidence is the work, and it starts with knowing which systems are in scope — a score computed against a scope you cannot evidence is a liability rather than an answer. The mapping exercise produces an inventory with the basis recorded per system, in a form you own and can hand to an assessor. What it does not do is produce the score for you or represent that any score is correct; that determination is yours.