Skip to main content
Lightbridge Cloud A Lightbridge.ai company

Cloud guides.

Lightbridge Cloud publishes these guides as an independent, vendor-neutral reference for teams making cloud decisions: enterprise integration and platform choice, plus the compliance landscape defense and federal contractors navigate. We map workloads to the right tools and controls without reseller bias, so the explanations describe the subject as it is, not as a platform vendor would frame it.

Government contracting and compliance guides

See the GovCon hub →

DFARS and NIST 800-171

A vendor-neutral guide to DFARS 252.204-7012, the NIST SP 800-171 security requirements, SPRS self-assessment scoring, and how they ladder up to CMMC for defense contractors.

Read the guide →

FIPS 140-2 and 140-3

What FIPS 140-2 and FIPS 140-3 validation establishes, why "AES-256 encrypted" is not the same claim, and what to verify for NIST SP 800-171 requirement 3.13.11.

Read the guide →

FOCI Guide

A vendor-neutral guide to Foreign Ownership, Control or Influence: how DCSA reviews FOCI under 32 CFR Part 117 and the mitigation instruments from Board Resolution to Voting Trust.

Read the guide →

C-SCRM and NIST 800-161

A vendor-neutral guide to Cybersecurity Supply Chain Risk Management under NIST SP 800-161: supplier risk assessment, provenance and pedigree tracking, contractual flow-down, and how it connects to DFARS obligations for operationally critical support or subcontract performance involving covered defense information.

Read the guide →

DoD Zero Trust and CMMC

The DoD Zero Trust Strategy and NIST SP 800-207's zero trust concepts, mapped to CMMC and NIST SP 800-171 Revision 2 CUI environments, and where zero trust architecture informs but does not replace applicable security requirements.

Read the guide →

CUI Explained

Plain-English guide to CUI: what it is, NARA CUI Registry categories, Basic vs Specified, marking and handling, and how safeguarding maps to DFARS, NIST 800-171, and CMMC.

Read the guide →

CMMC Asset Scoping and CUI Enclave

The five CMMC Level 2 asset categories (CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, Out-of-Scope Assets) and how a CUI enclave can help narrow the assessment boundary when properly separated per the Out-of-Scope criteria.

Read the guide →

Salesforce Government Cloud

Can CUI live in Salesforce? A vendor-neutral guide to commercial Salesforce vs Government Cloud vs Government Cloud Plus, FedRAMP authorization levels, and what a defense contractor needs.

Read the guide →

ITAR vs EAR

A vendor-neutral guide to US export controls: ITAR versus EAR, deemed exports, and why cloud access, encryption, and key custody decide export-control exposure.

Read the guide →

Data Sovereignty

Data sovereignty vs residency: why jurisdiction and the CLOUD Act outrank disk location, how to classify data, and the controls (key custody, isolation) that enforce sovereignty.

Read the guide →

BYOK vs HYOK

Compare BYOK, HYOK, external key stores, and provider-managed keys: who holds key material, who can decrypt, and which model fits a sovereignty or compliance requirement.

Read the guide →

Cloud and GovCon Glossary

An index of the government-contracting cloud vocabulary covered across these guides: DFARS, CMMC, CUI, DoD Impact Levels, SSP, POA&M, FOCI, ITAR/EAR, and BYOK/HYOK.

Read the guide →

SBOM for Defense Contractors

What a Software Bill of Materials is, how EO 14028 and the NIST SSDF inform federal software-security expectations, and what a defense contractor delivering software needs to know to produce or request one.

Read the guide →

Lightbridge Cloud guides explain the rules without selling a platform.

Most cloud compliance explainers are published by platform vendors and resellers who profit when you pick their product, so the framing tilts toward what they sell. Lightbridge Cloud is an independent cloud advisory practice that recommends AWS, Azure, or GCP on workload fit, not partner incentives. These guides describe the regulations and the controls neutrally.

When you are ready to turn learning into an authorization path, the same practice runs CMMC readiness, maps workloads across GovCloud and Impact Levels, and guides FedRAMP readiness across the federal landscape. For a persona-first starting point across all of it, see the GovCon hub.

From learning to an authorization path.

When the reading is done and a real compliance decision is on the table, Lightbridge Cloud runs vendor-neutral readiness advisory that maps every workload to the right controls.