Sector · Defence and military

The supplier is audited. The platform too.

A supplier to the defence industrial base answers for what it hosts and for who can reach it. That obligation passes down to the lower tiers of the chain.

What we see

  • CUI does not arrive labelled. It comes in as an attachment, a drawing or a quotation, and ends up in a shared space that was never qualified to hold it.
  • Contractual requirements are written as specific controls, not as intent. An audit asks for evidence that a control applied to a named resource on a given date.
  • Many workshops depend on software that only exists on Windows. Moving off the Microsoft stack therefore happens in layers, starting with those that carry no such constraint.
What is at stake

Compliance is evidenced. It is not declared.

01

Scope of CUI

Until the perimeter where controlled data travels is drawn, the whole information system sits inside the audit. Reducing that perimeter is the first piece of architecture work.

02

Subcontracting chain

Obligations pass to lower-tier suppliers through the contract. One link hosting with an unqualified provider affects the prime contractor’s file.

03

Single-vendor dependency

Productivity suite, directory and mail with the same provider create a dependency that some contracts no longer accept. Reversibility is built before it is demanded.

What we do

A narrow perimeter. Evidence attached.

01

Azure enclave written as code

Dedicated subscription, separated identities and logging exported outside the application perimeter, all under version control. NIST SP 800-171 controls are attached to the resources that carry them, which makes the evidence reproducible.

02

WIN TO LUX

Replacing Windows Server with Linux and Active Directory with FreeIPA, in layers, treating servers without application dependencies first. Workstations tied to proprietary engineering software are handled last or kept, with the reason written down.

03

AI agents on unclassified corpora

Production within eight weeks on documents whose sensitivity has been established before ingestion. Controlled corpora stay out of scope until the hosting has been qualified to hold them.

04

A documented Copilot decision

On some perimeters the answer is not to deploy Copilot. We produce the analysis that supports that and the list of spaces where the tool remains usable without contractual exposure.

Applicable frameworks

The texts are known. The application less so.

NIST SP 800-171

The publication sets out requirements for protecting CUI in non-federal systems. Each requirement has to map to a real configuration, not to an internal policy statement.

CMMC

The programme structures the assessment of suppliers to the US defence industrial base on their handling of CUI. The expected level depends on what the contract puts into circulation.

CLOUD Act

A company subject to US law can be compelled to produce data it holds, regardless of where the server physically sits. For a European supplier, that exposure is addressed when choosing the host, alongside operators such as OVHcloud, Scaleway, Infomaniak or Delos.

Start by seeing

No brochure. A written scoping.

We can read a contractual requirement and say what it implies on the infrastructure side, with nothing expected in return.

See your external surface