Not a defense contractor? See the federal contractor page
Defense Industrial Base

Your Department of War contract carries clauses that decide whether you can bid, keep, and defend the work.

We apply purpose-built compliance tools and practitioner-led advisory to DFARS, SPRS, NIST SP 800-171, and CMMC. The tools handle the repeatable work. The advisory hours make the judgment calls that decide whether your position holds up in front of a prime, a Third-Party Assessment, or a Government Assessment.

What your contract stacks on you

G
DFARS 252.204-7012Safeguard covered defense information and report cyber incidents within 72 hours.
A
DFARS 252.204-7019 / 7020Score all 110 NIST SP 800-171 requirements and post it to SPRS before award.
R
NIST SP 800-171The 110 security requirements your SSP, POA&M, and evidence have to satisfy.
D
DFARS 252.204-7021 / CMMCLevel 1 or Level 2, self-assessed or verified by a Third-Party Assessment, and affirmed annually.

Who this page is for

You hold or subcontract on a DoW contract

The 7012, 7019, 7020, and 7021 clauses are in your contract or your prime's, and your prime is asking what your SPRS score is.

You handle FCI or CUI

Federal Contract Information puts you at Level 1. Controlled Unclassified Information puts you at Level 2 and the full 110 requirements.

You have a SPRS score you do not fully trust

It was posted quickly, or by someone else, and you are affirming it annually under the False Claims Act.

An assessment or a prime's review is on the calendar

Self-assessment, Third-Party Assessment, or a DIBCAC Government Assessment: the documentation and the interviews both have to hold.

Where the CMMC program stands

CMMC Phase 2 was suspended on July 13, 2026 and a Reform Task Force is reviewing the program. Phase 1 remains fully in force: Level 1 and Level 2 self-assessment requirements still appear in solicitations, 32 CFR Part 170 is unchanged, and prime flow-down did not move. What changed is the date an external assessor arrives, not what you have to implement. Engagements are sequenced against your actual contract dates during the consultation.

Tools do the repeatable work. Advisory makes the calls.

Every Globe-America engagement combines purpose-built federal cybersecurity compliance tools with practitioner-led advisory support from a CMMC Registered Practitioner. Advisory hours are included in every engagement, not sold as add-ons.

What the tools handle

  • Scoping: boundary, asset inventory, and the network diagram from one model
  • Documentation: SSP, policies, and procedures generated against the requirement set
  • Evidence tracking: what is ready, what is missing, and who owns it
  • Control ownership: RACI across all 14 requirement families
  • Remediation planning: POA&M and roadmap sequenced by risk and timeline
  • Readiness monitoring: your SPRS score, calendar, and posture in one view

What advisory provides

  • Interpreting what your contract clauses actually require of your company
  • Validating that an implementation is real, not just written
  • Resolving scope decisions a tool cannot make for you
  • Prioritizing risk against your contract dates and budget
  • Preparing your people for the interview, not just the paperwork
  • Determining whether your compliance position can withstand scrutiny

Built on the Cyber G.A.R.D.™ Framework

Four phases, in order. Scoping mistakes invalidate everything downstream, so Govern comes first and Defend comes last.

G

Govern the Boundary

Contract clause review, CUI and FCI scope, asset inventory, the network boundary diagram, and who owns the decisions inside it.

A

Align Evidence

SSP, policies, procedures, and artifacts mapped to the 800-171 requirement that calls for each one, so the documentation matches reality.

R

Reinforce Implementation

Controls verified operational, gaps remediated, POA&M sequenced by SPRS point value and contract timeline.

D

Defend the Assessment

Evidence tested, staff rehearsed for the interview, and a realistic go/no-go before a prime, an assessor, or DIBCAC arrives.

Ways to engage

Every engagement starts with a consultation, and the consultation fee credits in full toward whatever comes next. Standalone tools can be purchased outright.

Advisory engagements

Tools unlocked plus included advisory hours. Consultation required first.
Bronze: Compliance FoundationOne-time. 8 to 12 advisory hours. Score, boundary, policies, roadmap.
$15K to $32K
Silver: Readiness & GovernanceThree-year cycle. 16 to 24 hours a year. Evidence, RACI, mock interviews.
$52K to $72K
Gold: Continuous Compliance OversightMonthly retainer. 8 to 20 hours a quarter. Posture stays current.
$5K to $12K/mo

Client tool portal

Where engagement clients work.

Twenty-seven browser-based tools across Bronze, Silver, and Gold access levels, unlocked by the access code your advisor provides. Nothing installs, nothing connects to your network, and you keep every file you produce.

Complimentary free toolsFive open-access tools, including the Cyber G.A.R.D.™ Self-Assessment. No login, no email, no cost.
Use the free tools

Bring your contract. Leave knowing your level, your gaps, and your timeline.

Sixty minutes with Eddie White, CMMC Registered Practitioner, 20-year U.S. Air Force veteran, and the person who runs every engagement personally. The fee credits in full if you continue.

Globe-America Consulting, Inc. is a Service-Disabled Veteran-Owned Small Business in Dallas-Fort Worth, Texas.