Research labs and universities with DoD sponsored work
How do research labs and universities protect CUI from DoD sponsored work?
By separating contracted research that involves CUI or export controlled data from fundamental research, and putting the controlled work in an enclave that meets NIST SP 800-171. Fundamental research intended for publication is generally outside these controls, but a contract that includes DFARS 252.204-7012 brings the work it covers into scope.
NIST SP 800-171, CMMC and export control programs for research labs and universities with DoD sponsored work, using enclaves to keep controlled work contained.
Book a 30 minute callWhich regulations apply?
DFARS 252.204-7012
Requires adequate security for covered defense information by implementing NIST SP 800-171, reporting cyber incidents to DoD within 72 hours, meeting cloud security requirements equivalent to FedRAMP Moderate, and flowing the clause down to subcontractors.
DFARS 252.204-7019
Requires a current NIST SP 800-171 assessment score, no more than three years old, posted in the Supplier Performance Risk System.
DFARS 252.204-7020
Gives DoD access to assess your NIST SP 800-171 implementation and requires you to confirm your subcontractors' assessments before flowing work to them.
DFARS 252.204-7021
The contract clause that puts a CMMC level into a contract and requires the matching CMMC status and annual affirmation.
NIST SP 800-171 Rev 2
The 110 security requirements for protecting Controlled Unclassified Information in contractor systems, organized into 14 families and assessed with NIST SP 800-171A.
CMMC, 32 CFR part 170
The program rule that defines CMMC Levels 1, 2 and 3, how each is assessed, the scoping rules and the annual affirmation. Level 2 maps to the 110 requirements of NIST SP 800-171 Rev 2.
ITAR, 22 CFR parts 120 to 130
Controls the export of defense articles and technical data on the United States Munitions List, including release to foreign persons inside the United States. 22 CFR 120.54 sets the conditions under which encrypted technical data is not an export.
FAR 52.204-21
Basic safeguarding of covered contractor information systems that hold Federal Contract Information. It lists fifteen basic safeguarding requirements and is the basis of CMMC Level 1.
Which clauses apply to you depends on your contracts. Read them, and take legal advice where the answer matters.
Where does the work usually get hard?
- Open academic networks, shared equipment and bring your own devices make a campus hard to scope as one environment.
- Researchers, students and visiting scholars come and go, and some are foreign persons for export control purposes.
- Contract terms sometimes add CUI or export control clauses to work the lab considered fundamental research, and nobody notices until data arrives.
- Research computing, instruments and lab systems behave like operational technology and rarely fit standard IT controls.
- Responsibility is spread across sponsored programs, IT, export compliance and principal investigators, so no one owns the whole picture.
Which engagements fit?
CUI enclave design
CUI enclave design in Microsoft Azure and M365 GCC High, with a defined authorization boundary, for defense contractors.
SSP and POA&M review and assessor readiness
Review of your System Security Plan and POA&M against NIST SP 800-171A, so both documents are assessor ready for CMMC Level 2.
ITAR cybersecurity program
Cybersecurity programs for ITAR controlled technical data, built on NIST SP 800-171 and DFARS 252.204-7012, from Capital Cyber.
vCISO and security program leadership
Virtual CISO and security program leadership for defense contractors and federal integrators, including supplier cyber readiness.
No consultant can promise the outcome of an assessment or authorization. The assessor or authorizing official decides it.
What do companies in this industry ask?
Does fundamental research fall under NIST SP 800-171?
Fundamental research intended for publication is generally not CUI. The contract decides: if it includes DFARS 252.204-7012 and the work involves covered defense information, the requirements apply to that work.
Can a university meet CMMC without bringing the whole campus into scope?
Yes. Most institutions use an enclave for controlled research, so only the people and systems working on that research are in scope.
How are foreign researchers handled under ITAR?
Release of ITAR technical data to a foreign person is an export, even inside the United States. Access to controlled projects has to account for that, under the direction of the export compliance office.
Ready to talk it through?
BOOK A CALLPick a time for a 30 minute call with the practice.
What happens in 30 minutes
- We learn about your company, the contracts you hold or are bidding on, and what is driving your timeline.
- We talk through where you stand and which engagement fits, if any does.
- If there is a fit, we follow up with a written scope. No slides.