We define the CUI boundary, specify the controls in the language the assessment objectives use, and record who owns which objective. Your team or your provider builds to that specification. We then validate what was delivered and prepare the evidence an assessor will ask for.
Third-party assessment. The C3PAO requirement that was set to begin in November 2026 is on hold pending a reform task force review, and solicitations carrying Phase 2 language are being amended.
Everything that actually protects the data. DFARS 252.204-7012 still applies. NIST SP 800-171 is still the standard. SPRS scoring and annual affirmations are still due. FedRAMP Moderate equivalence for cloud-held CUI still applies.
A false SPRS score was always a False Claims Act exposure and still is. Primes are still flowing down their own requirements on their own timeline. The suspension bought time to do the work properly. It did not remove the work.
A prime sends a questionnaire, or a clause lands in a contract, and the honest internal answer is that nobody can say yet what the score covers or how it was reached.
There is a number in SPRS. It was produced quickly, under deadline, against a boundary that was never written down, and the person who produced it has often moved on.
System Security Plans written to satisfy a request tend to claim controls the configuration does not enforce. The distance between the document and the running system is the whole problem, and it is a common one.
We define the CUI boundary and write the basis for the line we draw. Then a full assessment against all 110 requirements at the objective level, a score you can defend, and a Plan of Action that names owners and dates.
Identity and conditional access, endpoint coverage, controlled-data discovery, segmentation and enclave design, access review cycles, and incident response. Written as specifications your team or your provider builds to, with a shared responsibility matrix recording who owns which objective.
We review what was delivered against what was specified, then establish the evidence cycle: an artifact per control, on a cadence, with a named owner. The record should accumulate as a byproduct of operating rather than as a project the month before an assessment.
The ones that come up most often before a scoping call.
Yes. The 800-171 obligation, the DFARS clause, the SPRS score and the annual affirmation all survive the pause untouched. The reform task force is reviewing how the program assesses, not whether the underlying standard applies. Every organization that treats the pause as a reprieve will restart from behind.
No, and no consultant can. Certification comes from an accredited C3PAO. We prepare the environment and the evidence and stay on the other side of that line. We also do not build what we assess, for the same reason: a firm that configures a control and then attests that it works has graded its own homework.
For a small supplier with a contained boundary, commonly six to twelve months from scoping to assessment-ready. The variable is rarely the controls. It is how much of the environment has to change, and how much evidence history has to accumulate before an assessment window opens.
Whether CUI is confined to an enclave or spread across your whole enterprise. That single decision drives cost more than any other, because everything in scope has to meet the standard, be documented, and generate evidence.
If CUI reaches you, yes. Flow-down does not stop at the first tier. Primes are increasingly asking for evidence rather than assertions, and they are asking earlier in the award cycle.
Yes, and we prefer to. Scoping conversations get useful quickly, and the useful part usually involves details you should not be discussing without one.
© 2026 CARMhaus Consulting LLC. All rights reserved. Cybersecurity · Assurance · Risk Management
We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.