Full Report
Learn how MSPs/MSSPs can identify if a client is a DoD contractor handling CUI.
Analysis Summary
# Best Practices: Identifying DoD Industrial Base Clients Handling CUI
## Overview
These practices address the critical need for Managed Service Providers (MSPs) and MSSPs to accurately identify clients within the Department of Defense (DoD) supply chain. Failure to identify these clients leads to significant legal and financial risks, as companies handling Controlled Unclassified Information (CUI) are subject to strict DFARS and CMMC regulatory requirements that exceed standard commercial security packages.
## Key Recommendations
### Immediate Actions
1. **Conduct "Eagle Eye" Site Audits:** Review client websites for military imagery (F-35s, special forces), "Industries Served" sections, and specific defense-related quality markers (ITAR, AS9100).
2. **Public Award Search:** Query the client’s legal name on **USASpending.gov** to verify direct federal contracts and historical award amounts.
3. **Review Purchase Orders (POs):** Request copies of current POs or task orders to look for specific "Flow-down" clauses, particularly **FAR 52.204-21** and **DFARS 252.204-7012**.
### Short-term Improvements (1-3 months)
1. **Standardize Intake Questionnaires:** Update sales and onboarding forms to include questions regarding ITAR registration and Nadcap accreditation.
2. **Implement Managed ISPM:** Deploy Internal Security Policy Management (ISPM) tools to begin mapping technical controls to the 110 requirements of NIST SP 800-171.
3. **Client Education:** Inform clients that "commercial-off-the-shelf" (COTS) exemptions are rare and that subcontracting for a "Prime" (e.g., Boeing, Lockheed) usually mandates CMMC compliance.
### Long-term Strategy (3+ months)
1. **Establish a Shared Responsibility Matrix:** Develop a formal document (utilizing tools like DEFCERT) that defines which NIST 800-171 controls the MSP manages versus which the client owns.
2. **Audit Internal Operations:** Ensure the MSP’s own access controls and data handling meet the scrutiny required to manage CUI environments.
3. **Sensitive Data Mode Implementation:** Configure security tools to use "Sensitive Data Mode" or logical separation to handle client data without the high cost of full FedRAMP authorization where applicable.
## Implementation Guidance
### For Small Organizations
- Focus on identifying the presence of CUI via simple keyword searches in contracts.
- Prioritize the 15 basic safeguarding requirements of FAR 52.204-21.
### For Medium Organizations
- Implement automated tools to track compliance against NIST 800-171.
- Utilize public directories (Nadcap, DDTC) to verify the status of aerospace and defense subcontractors.
### For Large Enterprises
- Formalize a CMMC Level 2 assessment preparation plan.
- Establish dedicated enclaves for DoD-related work to limit the scope of CMMC assessments.
## Configuration Examples
- **NIST 800-171 Mapping:** Configure Managed EDR/ISPM tools to alert on the 55 (out of 110) requirements that can be automated, such as unauthorized software execution or credential rotation failures.
- **Logical Separation:** Set up Huntress or similar agents in "Sensitive Data Mode" to ensure no CUI is inadvertently ingested into the MSP's support systems, maintaining compliance without full FedRAMP overhead.
## Compliance Alignment
- **DFARS 252.204-7012:** Safeguarding Covered Defense Information.
- **NIST SP 800-171:** Protecting CUI in Nonfederal Systems.
- **CMMC 2.0:** Cybersecurity Maturity Model Certification.
- **ITAR:** International Traffic in Arms Regulations.
- **FAR 52.204-21:** Basic Safeguarding of Covered Contractor Information Systems.
## Common Pitfalls to Avoid
- **The "Commercial" Myth:** Assuming a client isn't a defense contractor because they sell a commercial product (e.g., bolts, software). If it’s used in a defense system, CUI may still be present.
- **Ignoring Subcontracts:** Focusing only on direct government awards; many CUI holders are 2nd or 3rd-tier subcontractors who never appear on USASpending.gov.
- **Checklist Mentality:** Treating CMMC as a one-time checklist rather than an ongoing operational model.
## Resources
- **USASpending[.]gov:** For tracking direct federal awards.
- **DDTC ITAR Registration:** To verify defense article manufacturing status.
- **NIST SP 800-171 Framework:** The underlying technical standard for CUI protection.
- **DEFCERT Shared Responsibility Matrix:** For MSP/Client duty separation.