Free Download

Download Resource

Enter your details to access this resource. No spam — just relevant GovCon compliance content.

Your information is used only to send you relevant content. Unsubscribe anytime.

You're all set

Your download is ready. A copy will also be sent to your email.

Download Now
Downloadable Guides

Fulcrum Advisory Reference Materials

Practitioner-written guides based on real GovCon environments. Enter your work email to access.

Fulcrum Advisory Capability Statement

One-page GovCon capability statement with NAICS codes, core competencies, past performance, and contract vehicle status.

FOCI Readiness Checklist

Pre-assessment checklist covering ownership structure, SF 328 triggers, DCSA documentation requirements, and 90-day timeline planning. For contractors newly subject to FOCI obligations.

GCC High vs. Commercial Azure: Service Parity Matrix

Side-by-side mapping of Azure service availability in GCC High vs. commercial. Covers AI/ML, networking, developer tools, and compliance services relevant to CMMC deployments.

View Online →
CMMC Level 2 Gap Assessment Starter Template

A structured template to begin your NIST SP 800-171 Rev 3 gap assessment. 14 control families, scoring fields, and POA&M tracking columns. Not a substitute for a professional assessment.

GCC High Licensing Decision Guide 2026

Business Premium vs. G3 vs. G5 — which license meets your CMMC level, user count, and budget. Includes the E7 commercial gap analysis and AOS-G procurement pathway.

View Online →
AI in GCC High: SSP Amendment Guide

What your System Security Plan must say when you add an AI workload to your CMMC boundary. Data flow requirements, SSP section templates, and auditor-facing documentation checklist.

Templates marked PDF/XLSX are in development and will be available Q3 2025. Online resources are live now.

Official Government Sources

Primary Reference Sources

FOCI & Industrial Security

DCSA — Defense Counterintelligence and Security Agency

Primary FOCI regulatory authority. FSO resources, SF 328 guidance, mitigation agreement templates, and facility clearance information.

dcsa.mil ↗
NISPOM — National Industrial Security Program Operating Manual

32 CFR Part 117 — the operational manual governing classified information in contractor facilities. Required reading for FSOs and cleared employees.

32 CFR Part 117 ↗
DISS — Defense Information System for Security

Personnel security clearance management system. Used by FSOs to submit requests, manage visit authorizations, and track clearance status.

DISS Portal ↗
CAGE Code Lookup — DLA

Defense Logistics Agency CAGE code lookup. Verify contractor CAGE codes, entity data, and facility information for contracting and teaming due diligence.

cage.dla.mil ↗

CMMC & Cybersecurity Compliance

CMMC AB — Cyber AB

The CMMC Accreditation Body. Find C3PAOs, Registered Practitioners, and Certified Assessors. Verify CMMC certification status of potential partners.

cyberab.org ↗
DoD CIO — CMMC Program Office

Official CMMC program information, implementation timeline, FAQs, and DoD policy memoranda. Primary source for CMMC Phase rollout updates.

dodcio.defense.gov ↗
NIST CSRC — SP 800-171 Rev 3

NIST Special Publication 800-171 Rev 3 — the 110 security requirements for protecting CUI. The technical foundation of CMMC Level 2. Also find SP 800-172 for enhanced requirements.

NIST CSRC ↗
SPRS — Supplier Performance Risk System

DoD system where contractors submit their NIST SP 800-171 self-assessment scores. Contracting officers check SPRS before award. CMMC affirmations are also recorded here.

sprs.csd.disa.mil ↗

Acquisition Regulations

FAR — Federal Acquisition Regulation

The primary set of rules governing federal acquisitions. Acquisition.gov hosts the authoritative, regularly updated text. Essential for understanding contract terms and flow-downs.

acquisition.gov/far ↗
DFARS — Defense Federal Acquisition Regulation Supplement

DoD-specific acquisition rules supplementing FAR. Includes DFARS 252.204-7012 (cybersecurity), DFARS 252.204-7021 (CMMC), and FOCI-related clauses. Updated for CMMC Phase 1 (Nov 2025).

acquisition.gov/dfars ↗
SAM.gov — System for Award Management

Federal contractor registration, opportunity search, and award data. Active SAM.gov registration is required for all federal contracting. Search contractors, view past awards, and verify socioeconomic status.

sam.gov ↗
Federal Register — DFARS/CMMC Tracking

Subscribe to Federal Register RSS feeds for real-time DFARS and CMMC rule updates. Filter by Defense Acquisition Regulations System agency. Free email subscription available.

federalregister.gov ↗

GCC High & Cloud Compliance

Microsoft GCC High Feature Availability

Official Microsoft documentation of which M365 and Azure features are available in GCC High vs. commercial. The authoritative source — check before any licensing or architecture decision.

Microsoft Learn ↗
Microsoft 365 Roadmap — GCC High Filter

Filter the official M365 roadmap by GCC High to see what's in development, rolling out, and generally available in your sovereign cloud tenant. Updated in real time by Microsoft.

M365 Roadmap ↗
FedRAMP Marketplace

Authoritative list of cloud services with FedRAMP authorization. Verify that any cloud service in your CMMC boundary has FedRAMP Moderate or High authorization before including it in your SSP.

marketplace.fedramp.gov ↗
DoD CUI Registry

The authoritative registry defining what constitutes Controlled Unclassified Information. Use this to determine CUI categories that apply to your contracts before scoping your CMMC boundary.

archives.gov/cui ↗
Live Tools on This Site

Fulcrum Advisory Live Resources

Need More Than a Checklist?

Templates get you started. A practitioner gets you through the audit.

Schedule a Call