Government cloud services and GovCon infrastructure.
Federal and Department of Defense requirements, including CMMC, FedRAMP, DFARS 252.204-7012, CUI handling, FOCI, export control, and data sovereignty, shape whether a contractor’s cloud infrastructure and CRM can process covered information or support a sale to an agency. Lightbridge Cloud is an independent readiness advisor that maps each applicable requirement to the right starting point.
If you are evaluating cloud infrastructure or a CRM as a government contractor, here is what actually matters.
Most cloud buying decisions come down to cost and capability. A government contractor carries a third variable: whether the workload is allowed to sit where it sits, whether the data it holds is Controlled Unclassified Information, and whether the contract that funds the work requires a specific authorization, assessment, or certification before that workload can go live. Skipping this variable does not make it go away. It surfaces later, in a pre-award survey, a C3PAO assessment, or a lost bid.
Lightbridge Cloud built this page as a map, not a rewrite of the material. Each card below links to the real guide or the real advisory service. This page's job is to get you to the right one quickly, whether you already know the acronym you need or you are starting from a plain question about what your contract actually requires.
Where to start, by situation.
You are bidding on, or already hold, a DoD contract.
Start with the free readiness assessment, then move to CMMC readiness advisory. Most DoD awards that touch Controlled Unclassified Information will require CMMC Level 2, built on the same NIST 800-171 controls behind your DFARS clause.
Free CMMC readiness assessment →You sell a cloud product or SaaS offering to a federal agency.
Start with FedRAMP readiness. Authorization is granted to the cloud offering, not to an advisory firm, so the work is scoping the baseline and building the evidence a 3PAO and an agency will accept.
FedRAMP readiness →You need to know which cloud region or platform to actually use.
Start with GovCloud and Impact Levels. The right environment, AWS GovCloud, Azure Government, GCC High, or a commercial region, follows from the data category and Impact Level, not from vendor preference.
GovCloud and Impact Levels →You are not sure what any of this means yet.
Start with the CUI guide. Controlled Unclassified Information is the data category that triggers most of these obligations, so understanding what counts as CUI clarifies which regime actually applies to you.
What is CUI? →Authorization and readiness advisory.
These are the three engagements Lightbridge Cloud runs directly. Each prepares an organization for an assessment or authorization performed by an independent third party, not by Lightbridge itself.
CMMC Compliance Readiness
For defense contractors and subcontractors in the Defense Industrial Base. Scoping, NIST 800-171 gap assessment, SSP and POA&M development, and C3PAO assessment preparation across CMMC 2.0 Levels 1 through 3.
Learn more →FedRAMP Readiness Advisory
For a cloud product or service sold to federal agencies. Baseline selection (Low, Moderate, High), NIST 800-53 gap assessment, SSP development, and 3PAO assessment preparation ahead of an Agency ATO.
Learn more →GovCloud and Impact Levels
For deciding where a workload actually needs to run. Maps data categories to DoD Impact Levels (IL2 through IL6) and to AWS GovCloud, Azure Government, and GCC High.
Learn more →The regulatory landscape, explained.
See the full guide index →Vendor-neutral guides to the acronyms and categories that shape a GovCon cloud decision, published as reference, not as a pitch for any single platform. This section is a curated subset; the full guide index covers additional guides, including FIPS 140, C-SCRM, DoD Zero Trust, and CMMC asset scoping.
DFARS and NIST 800-171
The contract clause, the 110-control standard, the SPRS self-assessment score, and how they ladder up to CMMC.
Read the guide →FOCI and FOCI Mitigation
How DCSA reviews Foreign Ownership, Control or Influence under 32 CFR Part 117, and the mitigation instruments from a Board Resolution to a Voting Trust.
Read the guide →CUI Explained
What Controlled Unclassified Information actually is, the NARA CUI Registry categories, Basic versus Specified, and how marking and handling work.
Read the guide →Salesforce Government Cloud
Can CUI live in Salesforce? Commercial Salesforce versus Government Cloud versus Government Cloud Plus, and the FedRAMP baseline each one carries.
Read the guide →ITAR vs EAR
Export-control basics for a contractor moving technical data through cloud systems: ITAR versus EAR, deemed exports, and where cloud access decides exposure.
Read the guide →Data Sovereignty vs Data Residency
Why legal jurisdiction and the CLOUD Act outrank the physical location of a disk, and the controls that actually enforce sovereignty.
Read the guide →BYOK vs HYOK Encryption
Who holds the key material and who can decrypt, compared across bring-your-own-key, hold-your-own-key, external key stores, and provider-managed keys.
Read the guide →Cloud and GovCon Glossary
A single index of the acronyms across this hub, IL2 through IL6, SPRS, POA&M, SSP, FOCI, BYOK/HYOK, and more, each linked back to the guide that covers it in depth.
Read the guide →SBOM for Defense Contractors
What a Software Bill of Materials is, how EO 14028 and the NIST SSDF inform federal software-security expectations, and what a defense contractor delivering software needs to produce or request one.
Read the guide →Cloud compliance is half the program. The accounting side lives at Lightbridge ERP.
A government contractor's compliance surface is not only where data lives. It also includes DCAA-compliant cost accounting, indirect rate structures, timekeeping, and the incurred cost submission, all of which run through the ERP system rather than the cloud environment. Lightbridge ERP runs vendor-neutral ERP selection and delivery for government contractors, across platforms including Deltek Costpoint, Unanet, and NetSuite.
See ERP for government contractors for that side of the program, and the ERP practice's DCAA-compliant accounting guide for the finance detail.
Lightbridge Cloud advises. It does not certify.
Lightbridge Cloud is an independent, vendor-neutral cloud advisory firm. It accepts no vendor kickbacks and carries no reseller quotas, so a recommendation to use AWS GovCloud, Azure Government, or GCC High follows from your data category and contract obligations, not a partner-tier incentive. Lightbridge helps organizations build readiness against CMMC, FedRAMP, and related federal requirements. It does not itself hold a CMMC certification or a FedRAMP authorization, is not a C3PAO or 3PAO, and does not perform the certifying assessment. Those determinations rest with the accredited assessor and the authorizing agency.
This page is general information, not legal, audit, or accounting advice. Regulations such as DFARS, NIST SP 800-171, CMMC, FedRAMP, ITAR, EAR, and DCAA requirements change over time. Verify any specific clause, threshold, or timeline against the official source, including acquisition.gov, fedramp.gov, NIST, the DoD CIO and OUSD(A&S), the NARA CUI Registry, DCSA, and, for export controls, DDTC and BIS. AWS, GovCloud, Microsoft, Azure, Salesforce, Deltek, Costpoint, and Unanet are trademarks of their respective owners; Lightbridge Cloud is independent and is not affiliated with, endorsed by, or a partner-tier reseller of these vendors.
Government contracting cloud compliance: frequently asked questions
- What does a government contractor need from a cloud provider that a commercial buyer does not?
- A commercial cloud buyer optimizes for cost, performance, and integration. A government contractor carries the same requirements plus a compliance layer: which Impact Level a workload falls under, whether Controlled Unclassified Information is in scope, whether DFARS 252.204-7012 or a FedRAMP authorization applies, and whether foreign ownership or export-control rules constrain who can touch the environment. Getting the compliance layer wrong can jeopardize a contract award or an audit, not just a budget line.
- Is Lightbridge Cloud FedRAMP authorized or CMMC certified?
- No, and it is worth being precise about why. FedRAMP authorization is granted to a specific cloud service offering, not to an advisory firm, and CMMC certification is issued to the organization being assessed by an accredited C3PAO, not to its advisor. Lightbridge Cloud is an independent readiness advisor: it helps contractors and cloud offerings prepare for these authorizations and assessments. It does not itself hold a FedRAMP authorization or a CMMC certification, and it is not a C3PAO or 3PAO.
- Where should I start: CMMC, FedRAMP, or GovCloud?
- It depends on what you are trying to do. If you are a defense contractor or subcontractor performing on a DoD award, start with CMMC readiness. If you sell a cloud product or service to a federal agency, start with FedRAMP readiness. If your question is simpler, which region or government cloud environment a workload should run in, start with GovCloud and Impact Levels. The four starting points below map to the four most common situations a contractor lands in.
- Does this hub cover my ERP and accounting system too?
- Not directly. Cloud infrastructure and CRM compliance, the subject of this hub, is a different scope than DCAA-compliant cost accounting, indirect rate structures, and incurred cost submissions on the finance side. That work belongs to the Lightbridge ERP practice, which runs vendor-neutral ERP selection and delivery for government contractors on platforms such as Deltek Costpoint, Unanet, and NetSuite. See ERP for government contractors for that side of the program.
- What is the difference between DFARS, NIST 800-171, CMMC, and FedRAMP?
- DFARS 252.204-7012 is the contract clause that obligates a defense contractor to safeguard covered information. NIST SP 800-171 is the 110-control standard that clause points to. CMMC adds independent verification on top of that same standard for defense contractors. FedRAMP is a separate program that authorizes cloud service offerings, built on NIST SP 800-53 rather than 800-171, for sale to federal agencies generally, not only the Department of Defense. The DFARS and NIST 800-171 guide walks through how the first three connect.
- Do these requirements apply if I am a subcontractor, not a prime?
- Often yes. Safeguarding and reporting obligations under DFARS 252.204-7012 generally flow down through the supply chain, so a subcontractor handling Controlled Unclassified Information can inherit close to the same duties as the prime contractor above it. Applicability always turns on the specific clauses in your contract or subcontract, so treat the contract itself, and acquisition.gov, as the authoritative source rather than assuming your tier exempts you.
- How does a CRM like Salesforce fit into GovCon cloud compliance?
- A CRM that stores Controlled Unclassified Information, export-controlled technical data, or other sensitive federal information falls inside the same scoping exercise as any other system: it needs to sit in an environment that matches the required Impact Level, and access to it needs to respect FOCI and export-control boundaries. Lightbridge Cloud advises on Salesforce alongside AWS GovCloud, Azure Government, and GCC High as part of the same vendor-neutral GovCloud and Impact Levels assessment. See the Salesforce Government Cloud guide for how commercial Salesforce, Government Cloud, and Government Cloud Plus differ on that scoping question specifically.
- Why does vendor neutrality matter for GovCon cloud advisory?
- Much of the compliance guidance a contractor finds is published by the platform vendor or reseller that stands to sell the environment, which tilts the framing toward what they sell. Lightbridge Cloud accepts no vendor kickbacks and carries no reseller quotas, so a recommendation to use AWS GovCloud over Azure Government, or a Level 2 self-assessment over third-party verification, follows from your data category and contract obligations rather than a partner-tier incentive.
Get a GovCon cloud readiness assessment.
We scope your data, map it to the right Impact Level and authorization path, and build a defensible readiness plan, vendor-neutral throughout.