Hold Department of War contracts? See the defense contractor page
Broader Federal Contractor Market

Your agency contract carries cybersecurity obligations that do not come with a program name or a scoring system.

We apply purpose-built compliance tools and practitioner-led advisory to CUI, NIST SP 800-171, FAR requirements, and agency-specific cybersecurity clauses. There is no SPRS score to post, but the same 110 requirements, the same boundary decisions, and the same evidence questions apply when an agency reviewer or a prime asks to see your program.

What your contract stacks on you

G
FAR 52.204-21Fifteen basic safeguarding requirements on any system that touches Federal Contract Information.
A
32 CFR Part 2002 / CUIHandle, mark, and protect Controlled Unclassified Information the way the issuing agency requires.
R
NIST SP 800-171The 110 requirements agencies invoke, directly or through a prime, when CUI is in scope.
D
Agency-specific clausesDHS, VA, GSA, HHS, DOE, and others each add their own cybersecurity terms, reporting timelines, and review rights.

Who this page is for

You contract with a civilian agency

Your contract references FAR 52.204-21, CUI handling, or NIST SP 800-171, and no one has told you what that means for your systems.

A prime flows 800-171 down to you

Your prime holds the federal contract and has passed the requirement, and the questionnaire, down the chain to you.

An agency added its own cybersecurity terms

Agency supplements, incident reporting windows, and review rights that sit on top of the FAR baseline.

A reviewer or a prime wants to see your program

There is no certification to point to, so your SSP, evidence, and your people's answers are the whole case.

Where federal CUI requirements stand

Outside the Department of War, cybersecurity requirements arrive contract by contract and agency by agency rather than through a single program. A government-wide FAR rule for CUI has been proposed to standardize handling and NIST SP 800-171 expectations across civilian agencies. Until it is final, what applies to you is whatever your contract and your agency's supplement say, which is exactly what the consultation reads with you.

Tools do the repeatable work. Advisory makes the calls.

Every Globe-America engagement combines purpose-built federal cybersecurity compliance tools with practitioner-led advisory support from a CMMC Registered Practitioner. Advisory hours are included in every engagement, not sold as add-ons.

What the tools handle

  • Scoping: boundary, asset inventory, and the network diagram from one model
  • Documentation: SSP, policies, and procedures generated against the requirement set
  • Evidence tracking: what is ready, what is missing, and who owns it
  • Control ownership: RACI across all 14 requirement families
  • Remediation planning: POA&M and roadmap sequenced by risk and timeline
  • Readiness monitoring: your readiness score, calendar, and posture in one view

What advisory provides

  • Interpreting what your contract clauses actually require of your company
  • Validating that an implementation is real, not just written
  • Resolving scope decisions a tool cannot make for you
  • Prioritizing risk against your contract dates and budget
  • Preparing your people for the interview, not just the paperwork
  • Determining whether your compliance position can withstand scrutiny

Built on the Cyber G.A.R.D.™ Framework

Four phases, in order. Scoping mistakes invalidate everything downstream, so Govern comes first and Defend comes last.

G

Govern the Boundary

Contract and agency clause review, CUI and FCI scope, asset inventory, the network boundary diagram, and who owns the decisions inside it.

A

Align Evidence

SSP, policies, procedures, and artifacts mapped to the 800-171 requirement or agency clause that calls for each one, so the documentation matches reality.

R

Reinforce Implementation

Controls verified operational, gaps remediated, remediation sequenced by risk and contract timeline.

D

Defend the Assessment

Evidence tested, staff rehearsed for the interview, and a realistic go/no-go before an agency reviewer or a prime asks.

Ways to engage

Every engagement starts with a consultation, and the consultation fee credits in full toward whatever comes next. Standalone tools can be purchased outright.

Advisory engagements

Tools unlocked plus included advisory hours. Consultation required first.
Bronze: Compliance FoundationOne-time. 8 to 12 advisory hours. Score, boundary, policies, roadmap.
$15K to $32K
Silver: Readiness & GovernanceThree-year cycle. 16 to 24 hours a year. Evidence, RACI, mock interviews.
$52K to $72K
Gold: Continuous Compliance OversightMonthly retainer. 8 to 20 hours a quarter. Posture stays current.
$5K to $12K/mo

Client tool portal

Where engagement clients work.

Twenty-seven browser-based tools across Bronze, Silver, and Gold access levels, unlocked by the access code your advisor provides. Nothing installs, nothing connects to your network, and you keep every file you produce.

Complimentary free toolsFive open-access tools, including the Cyber G.A.R.D.™ Self-Assessment. No login, no email, no cost.
Use the free tools

Bring your contract and your agency's supplement. Leave knowing what applies, your gaps, and your timeline.

Sixty minutes with Eddie White, CMMC Registered Practitioner, 20-year U.S. Air Force veteran, and the person who runs every engagement personally. The fee credits in full if you continue.

Globe-America Consulting, Inc. is a Service-Disabled Veteran-Owned Small Business in Dallas-Fort Worth, Texas.