Additional Consulting Services
Once your FSO program is solid, we help you build capability in the adjacent areas DCSA increasingly evaluates during compliance reviews.
As a Service-Disabled Veteran-Owned Small Business (SDVOSB), we bring the same hands-on, boutique attention to CUI and ITAR programs that we bring to FSO consulting.
CUI Programs Under NISPOM
The NISPOM states that unless contractual requirements call for CUI protection, it’s out of scope for security reviews. But the DD Form 254 is a contractual requirement, and CUI program actions are increasingly identified in detail in its narrative sections. If you’re a defense contractor, education facility, or lab on a government contract, we help you build a CUI program that works for you and demonstrates compliance.
Whether your requirement comes from NISPOM or CMMC, we help you meet it. Organizations that handle Controlled Unclassified Information must meet clear expectations under NIST SP 800-171, NISPOM, and federal agency guidance. Even if you don’t need a full technical implementation, every organization must demonstrate clear governance, repeatable processes, documented policies, staff awareness, and evidence of oversight.

Our approach is built on three pillars: processes, workbooks, and training. We facilitate working groups to pinpoint exactly where CUI and ITAR information shows up in your daily workflow, then build the program around it using proprietary tools like our CUI Identification Aid, CUI Catalog, CUI Protection Guidance, and ITAR/CUI Control Officer Workbook, alongside our established FSO Workbook and Gold Standard Criteria methodology.
This is a DIY solution at heart: we develop the tools, facilitate the working sessions, and train your team to run the program themselves. We meet with your team on your schedule to provide updates, answer questions, and reinforce how the program applies day to day.
What’s included:
- CUI identification, scoping, and boundary definition
- Comprehensive policies and handling standards
- Organization-wide and role-based training, including for CUI control officers
- CUI Self-Inspection Program and Public Release Review Process
- Vendor and subcontractor requirements
- Incident response procedures for CUI exposure
- Facilitated CUI working groups and tabletop exercises
- Integration into contracts, QA, and other audit areas
- Assessment-ready documentation
CMMC evaluation requires establishing a CUI program that goes beyond a technical environment to protecting CUI at rest, in transit, and in physical form, including identification, training, disposition, and secure handling as CUI moves into new products. Whether you already have internal IT or an MSP handling technical controls, or you’re building the administrative foundation first, we tailor the engagement to where you are.
Outside Director Appointment
Companies under an SCA or SSA may be required to appoint an Outside Director: an independent board member focused on national security interests. Where required, the number of Outside Directors must equal or exceed Inside Directors under an SCA, and must exceed Inside Directors under an SSA.
It’s one of the toughest parts of a FOCI mitigation agreement to fulfill, and we’re prepared to serve in that capacity. If you need help meeting this requirement, let’s talk.

Export Compliance (ITAR)
Being NIST or CMMC compliant isn’t enough. Contractors handling export-controlled information under ITAR and CUI still have to identify, mark, document, and protect it wherever it resides.
We solve ITAR compliance challenges, including CUI and FGI considerations, using the same proprietary process we bring to CUI work, built around our ITAR/CUI Control Officer Workbook and tailored training. Whether you’re developing a protected network or moving to a protected cloud, we build the program around it:
- Information identification, marking, and documentation
- Countermeasures application and public release review
- Policies, procedures, and required training
- Risk-based self-inspections
- Technology controls and distinguishing basic vs. applied research

Protecting Research and Development (NSPM-33)
U.S.-funded scientific research increasingly needs protection from undue foreign influence, including exploitation of the open university research environment and intellectual property theft. We help institutions develop and execute a research protection program, train staff and researchers, and write the supporting policies and procedures so universities can confidently pursue government research, including work involving foreign students, while keeping protected information secure.

Proposal Specific Protection Plans (PSPP)
SBIRs, BAAs, and similar opportunities often require a Proposal Specific Protection Plan as part of the response. We’ve written protection plans across the DoD and its contractor base, and we can prepare yours for submission and refine it once awarded, covering all five required sections: introduction and POCs, technology element identification, threat and vulnerability assessment, countermeasures and risk mitigation, and response/recovery/ support.

NISPOM Deep Dive
Explore Jeff Bennett’s full library of NISPOM training, books, and resources at NISPOM Central.
Visit NISPOM Central