Official government references, downloadable guides, and curated tools for FOCI, CMMC, DFARS, and GCC High compliance programs.
Practitioner-written guides based on real GovCon environments. Enter your work email to access.
One-page GovCon capability statement with NAICS codes, core competencies, past performance, and contract vehicle status.
Pre-assessment checklist covering ownership structure, SF 328 triggers, DCSA documentation requirements, and 90-day timeline planning. For contractors newly subject to FOCI obligations.
Side-by-side mapping of Azure service availability in GCC High vs. commercial. Covers AI/ML, networking, developer tools, and compliance services relevant to CMMC deployments.
View Online →A structured template to begin your NIST SP 800-171 Rev 3 gap assessment. 14 control families, scoring fields, and POA&M tracking columns. Not a substitute for a professional assessment.
Business Premium vs. G3 vs. G5 — which license meets your CMMC level, user count, and budget. Includes the E7 commercial gap analysis and AOS-G procurement pathway.
View Online →What your System Security Plan must say when you add an AI workload to your CMMC boundary. Data flow requirements, SSP section templates, and auditor-facing documentation checklist.
Templates marked PDF/XLSX are in development and will be available Q3 2025. Online resources are live now.
Primary FOCI regulatory authority. FSO resources, SF 328 guidance, mitigation agreement templates, and facility clearance information.
dcsa.mil ↗32 CFR Part 117 — the operational manual governing classified information in contractor facilities. Required reading for FSOs and cleared employees.
32 CFR Part 117 ↗Personnel security clearance management system. Used by FSOs to submit requests, manage visit authorizations, and track clearance status.
DISS Portal ↗Defense Logistics Agency CAGE code lookup. Verify contractor CAGE codes, entity data, and facility information for contracting and teaming due diligence.
cage.dla.mil ↗The CMMC Accreditation Body. Find C3PAOs, Registered Practitioners, and Certified Assessors. Verify CMMC certification status of potential partners.
cyberab.org ↗Official CMMC program information, implementation timeline, FAQs, and DoD policy memoranda. Primary source for CMMC Phase rollout updates.
dodcio.defense.gov ↗NIST Special Publication 800-171 Rev 3 — the 110 security requirements for protecting CUI. The technical foundation of CMMC Level 2. Also find SP 800-172 for enhanced requirements.
NIST CSRC ↗DoD system where contractors submit their NIST SP 800-171 self-assessment scores. Contracting officers check SPRS before award. CMMC affirmations are also recorded here.
sprs.csd.disa.mil ↗The primary set of rules governing federal acquisitions. Acquisition.gov hosts the authoritative, regularly updated text. Essential for understanding contract terms and flow-downs.
acquisition.gov/far ↗DoD-specific acquisition rules supplementing FAR. Includes DFARS 252.204-7012 (cybersecurity), DFARS 252.204-7021 (CMMC), and FOCI-related clauses. Updated for CMMC Phase 1 (Nov 2025).
acquisition.gov/dfars ↗Federal contractor registration, opportunity search, and award data. Active SAM.gov registration is required for all federal contracting. Search contractors, view past awards, and verify socioeconomic status.
sam.gov ↗Subscribe to Federal Register RSS feeds for real-time DFARS and CMMC rule updates. Filter by Defense Acquisition Regulations System agency. Free email subscription available.
federalregister.gov ↗Official Microsoft documentation of which M365 and Azure features are available in GCC High vs. commercial. The authoritative source — check before any licensing or architecture decision.
Microsoft Learn ↗Filter the official M365 roadmap by GCC High to see what's in development, rolling out, and generally available in your sovereign cloud tenant. Updated in real time by Microsoft.
M365 Roadmap ↗Authoritative list of cloud services with FedRAMP authorization. Verify that any cloud service in your CMMC boundary has FedRAMP Moderate or High authorization before including it in your SSP.
marketplace.fedramp.gov ↗The authoritative registry defining what constitutes Controlled Unclassified Information. Use this to determine CUI categories that apply to your contracts before scoping your CMMC boundary.
archives.gov/cui ↗Live feed of Microsoft 365 features in development and rolling out for GCC High. Updated daily via the Microsoft Roadmap API. Filterable by status.
Open Tracker →Live DFARS, CMMC, FOCI, and NIST regulatory updates sourced daily from the Federal Register, DCSA, DoD CIO, and NIST CSRC. Filtered for the defense industrial base.
Open Watch →Service-by-service comparison of Azure capabilities available in GCC High vs. commercial. AI/ML, developer tools, networking, and compliance services — with CMMC relevance notes.
Open Map →Templates get you started. A practitioner gets you through the audit.