Research only

DoD contractors and defense manufacturers

Explore the policy documents and regulatory sources relevant to this industry. Assessment checks for this profile are in development.

Research listings are separate from implemented scans. No quote or assessment is available for this profile yet. Public uploads must contain no patient data or other restricted information.

Documents to review

  • System security planResearch document type
  • Incident response planResearch document type
  • Plan of action and milestonesResearch document type
  • Technology control planResearch document type

Scope questions

Industry alone does not establish legal applicability. Confirm location, activities, role, data and relevant thresholds.

  • Where does the organization operate, and which regulator, license, permit or contract governs the activity?
  • Which business activities, data types and organization roles does the document describe?
  • Do the relevant thresholds or exceptions change which requirements apply?

Unknown answers stay unresolved. Document detection does not answer these questions for you.

A fictional example to explore

This short policy outline demonstrates the document's structure and research questions. It is a navigation example; scans for this profile are not available yet.

PDF pages are counted exactly. DOCX and TXT use the disclosed word-count estimate, so the same policy can have different billable page counts.

Regulations and frameworks to explore

These are research candidates for this profile. Confirm the exact organization and activity before concluding that a rule applies.

Research only

CMMC, DFARS, and NIST SP 800-171 contract requirements

32 CFR Part 170 · DFARS 252.204-7012 · NIST SP 800-171 as contractually applicable · DFARS 252.204-7021

Check the actual DoD contract clauses, FCI/CDI/CUI, system boundary, required CMMC level and assessment obligations. DFARS 252.204-7012 covers safeguarding and cyber-incident duties; 252.204-7021 and 32 CFR Part 170 address CMMC. Under 7012(b)(2)(ii)(D), external cloud services handling covered defense information need FedRAMP Moderate-equivalent security and specified incident/evidence duties. This is separate from general FedRAMP scope; ordinary commercial hosting is not automatically covered.

Jurisdictions: US-FEDERAL

Research applicability questions
  • Does an applicable contract contain the cited safeguarding or cyber clause?
  • Will your systems process, store or transmit federal contract information in contract performance?
  • Will the uploaded package contain Controlled Unclassified Information or covered defense information?
  • Which CMMC level and assessment type are specified in the solicitation or contract?
  • What CMMC assessment level and assessment/affirmation requirements does the actual solicitation or contract specify?
Research only

NIST Cybersecurity Framework 2.0

NIST CSWP 29

Voluntary cybersecurity risk-management framework for organizations of any size or sector. Customer contracts may request alignment; it is not a law or a certification. Map the selected profile and desired outcomes; do not score optional framework alignment as a legal violation.

Jurisdictions: GLOBAL

Research applicability questions
  • Has your organization or a customer selected a NIST CSF profile or outcomes to evaluate?
  • Does a customer contract, regulator or internal policy require a particular CSF profile or outcome set?
Research only

Export Administration Regulations compliance program

15 CFR Parts 730-774

EAR scope depends on items, software/technology, destination, end user/use and relevant US-person activities. BIS export-compliance program guidance supports internal controls but does not determine a transaction’s classification, license or exception. Restricted/export-controlled materials require an approved processing environment; this family is not an ITAR assessment.

Jurisdictions: US-FEDERAL · GLOBAL

Research applicability questions
  • What items/technology, destinations, end users and end uses are involved, including any reexport or transfer?
  • Which EAR classification, restrictions, license or exception and US-person activity conditions apply?