CUI Handling Statement & Customer Responsibility Matrix

Effective date: September 22, 2026

1. 1. What KollGuard is, in CMMC terms

KollGuard is a readiness and continuous-monitoring tool. It helps a defense contractor attest NIST SP 800-171 requirements, compute an SPRS score, scope an assessment, and export a System Security Plan, POA&M and Shared Responsibility Matrix. It also watches the contractor's vendors against the FedRAMP Marketplace and DFARS flow-down expectations.

KollGuard is not a CUI system and is not inside your CUI boundary:

  • KollGuard stores findings, attestations, scores, scope metadata and vendor metadata. It never stores Controlled Unclassified Information (CUI), ITAR/EAR technical data, or classified information.
  • KollGuard does not process, store or transmit CUI on your behalf, so it is not a cloud service provider under DFARS 252.204-7012(b)(2)(ii)(D) and the FedRAMP Moderate-equivalency requirement in that clause does not apply to it.
  • Under the DoD CMMC Level 2 Scoping Guide, KollGuard is at most a Contractor Risk Managed Asset and is normally documented as out of scope. List it that way in your asset inventory and SSP, citing this statement.

KollGuard is not FedRAMP authorized and does not claim to be. Nothing KollGuard produces is a certification, an authorization, or an assessment result. SPRS, the CMMC eCMS and your C3PAO are the systems and parties of record.

2. 2. Guardrails KollGuard enforces

  • Free-text fields on the CMMC surfaces (scope inventory, system profile, attestation notes, implementation statements, POA&M entries) reject text carrying CUI marking banners (CUI//, CONTROLLED//, (CUI), NOFORN, FOUO, distribution statements, ITAR/EAR markings).
  • Every CMMC input reminds the operator never to paste CUI.
  • Scanners are read-only and store findings, not content: no source code, database rows or documents are retained.
  • Evidence is linked by URL to your own systems. Uploaded vendor documents are for vendor due diligence and must not contain CUI.
  • All customer data is hosted in the United States (AWS us-east-2 via Supabase), encrypted in transit and at rest, with a hash-chained audit log.

3. 3. Customer Responsibility Matrix

Because KollGuard is outside the CUI boundary, no 800-171 requirement is inherited from KollGuard. The right-hand column describes KollGuard's own platform security so you can risk-manage the tool; the middle column is what stays with you for your CUI environment.

800-171 familyYou (CUI environment)KollGuard (platform, outside the boundary)
AC Access ControlImplement and attest 3.1.x for the enclave.Role-based access, tenant isolation via row-level security, MFA, SSO/SCIM on Enterprise.
AT Awareness & Training3.2.x for enclave users.Staff security training; no customer obligation.
AU Audit & Accountability3.3.x for the enclave; our audit log can evidence monitoring activities.Hash-chained, tamper-evident audit log of every tenant action; exportable.
CM Configuration Management3.4.x, including the asset inventory (our scope inventory is a working copy; your SSP is the record).Infrastructure as code, reviewed pull requests.
IA Identification & Authentication3.5.x for the enclave.Supabase Auth with MFA; tenant-scoped API keys.
IR Incident Response3.6.x, including the DFARS 7012 72-hour DoD report (your obligation).Incident notification to affected customers per the Terms; not a 7012 reporting party for your CUI.
MA Maintenance3.7.x.Managed platform.
MP Media Protection3.8.x; CUI never leaves the enclave onto KollGuard.Not applicable (no CUI media).
PE Physical Protection3.10.x for your facilities.Inherited from AWS for our platform; irrelevant to your enclave.
PS Personnel Security3.9.x.Background-checked staff; least-privilege production access.
RA Risk Assessment3.11.x; scan findings and vendor gaps feed your risk assessment.Continuous vulnerability scanning of the platform.
CA Security Assessment3.12.x; SSP / POA&M / SRM exports are drafts you own and finalise.SOC 2-aligned platform controls.
SC System & Communications3.13.x for the enclave.TLS 1.2+, encryption at rest, US hosting.
SI System & Information Integrity3.14.x; findings can evidence flaw-remediation tracking.Platform patching and monitoring.

4. 4. Your obligations

  1. Do not enter CUI into KollGuard: describe systems and controls, link to evidence held in your CUI environment.
  2. Record KollGuard in your asset inventory and SSP as a Contractor Risk Managed or out-of-scope asset, with this statement as the justification.
  3. Treat KollGuard outputs (SSP, POA&M, SRM, SPRS estimate) as drafts to be validated by your Affirming Official and, at Level 2, your C3PAO.
  4. The DFARS 252.204-7012 incident report and the annual affirmation under 32 CFR 170.22 stay with your Affirming Official; KollGuard only reminds.

5. 5. Contact

Security questions: security@kollguard.com · Trust Center: kollguard.com/security