Get DFARS/NIST 800-171 Compliant With cuick trac™!

Play Icon

Introducing cuick trac™

Cuick trac™ is a cost-effective, practical, turn-key solution that helps contractors and sub-contractors of the DoD receive, process and transmit controlled unclassified information (CUI).
Icon containing a piggy bank drawing


Control costs and ROI without adding to payroll
Icon containing a fast forward sign

Quick Implementation

Have access to secure and compliant environment in less than 2 weeks
Icon containing a clipboard drawing

Technical + Administrative + Physical

Full compliance program for all assessment objectives
Icon containing a contract drawing

Fulfill & Maintain Contracts

Store, process and transmit CUI with proof of continuous compliance

Who is using cuick trac™?

CMMC Certifications will require continuous compliance to compete for United States Department of Defense (DoD) contracts. Certifications will encompass five levels that range from “Basic Cybersecurity Hygiene” to “Advanced and Progressive.”
Learn More About CMMC ->
building icon


Sub-contractors utilize cuick trac™ to achieve compliance in a much shorter time period, for a fraction of the cost of doing it themselves, in order to prove an on-going compliance program for CUI.
building icon

Prime Contractors

Primes use cuick trac™ as their CUI Vendor Risk Management solution for their supply chain and lower tier suppliers.
Beryllium InfoSec logo

Powered by Beryllium

Beryllium InfoSec Collaborative is a different type of cyber security company. In our approach, cyber security is not just about information technology. It is about people too, just like your organization.
Learn More About The Company
NIST Experts
Our team is full of NIST experts. Many security standards map back to NIST, and we strongly believe NIST provides the best security frameworks to strengthen your organization's cyber security program.
Owned by Veterans
As a small business owned by veterans, we "serve" to protect your organization from current and future cyber threats, which in turn protects our nation.
We collaborate with the industry's best cyber security experts to provide industry leading solutions for your organization. The days of "we can do it all" are over. We take pride in working with other top security peers.

Frequently Asked Questions

What is cuick trac™?

Cuick trac™ at its core, is a private hosted, virtual enclave that satisfies the technical requirements of NIST SP 800-171a. The pre-configured enclave allows for better control of CUI data flow, as the data never touches the OSC’s (organization seeking certification) network. This allows for a smaller Plan of Action and Milestones (POA&M) focused on non-digital CUI (physical), and the administration of NIST SP 800-171 and CMMC Level 3 in a full compliance program engagement.

What is Controlled Unclassified Information (CUI)?

Controlled Unclassified Information (CUI) refers to unclassified information that is to be protected from public disclosure. The CUI designation replaces "sensitive but unclassified" and other similar control markings. To learn more, visit What is CUI?

What is DFARS, NIST 800-171 and CMMC?

The DFARS 252.204-7012 clause says that if you handle Controlled Unclassified Information, you shall implement NIST SP 800-171 no later than Dec 31, 2017. Since this deadline has passed, and CMMC certifications beginning in 2021, organizations within the DoD supply chain need a risk-based approach to become compliant, and more importantly, secure.

NIST SP 800-171 is the National Institute of Standards & Technology (NIST) special publication providing 110 recommended security controls for protecting the confidentiality of CUI (Controlled Unclassified Information – a subset of CDI).

The Cybersecurity Maturity Model Certification (CMMC) is the standard the Department of Defense (DoD) is using to verify the members of the Defense Industrial Base (DIB) fully meet their cybersecurity requirements, prior to contract awards.

What is an SPRS Score, and How Do I Get One?

In September, 2020, the DoD released a new interim rule, approved by the Office of Management and Budget (OMB), that requires all contractors subject to DFARS 252.204-7012 within the DoD supply chain, to have an accurate assessment on record, prior to award. The interim rule becomes a bridge between the self-assessment process of DFARS 252.204-7012/NIST SP 800-171, and the verification/certification process of CMMC. The DFARS Interim Rule helps enforce full compliance and the importance it provides to our national security.

The results of Assessments are documented in the Supplier Performance Risk System (SPRS) at https://www.sprs.csd.disa.mil/ to provide DoD Components with visibility into the scores of Assessments already completed; and verify that an offeror has a current (i.e., not more than three years old, unless a lesser time is specified in the solicitation) Assessment, at any level, on record prior to contract award.

The score submitted to SPRS is based on the NIST SP 800-171 DoD Assessment Methodology. If an organization is not able to prove requirements are met, with objective evidence, should not receive credit for that specific requirement. Cuick trac™ provides a significant increase of an SPRS score, making the path to 110 much more manageable.

How Does cuick trac™ Help Me?

Cuick trac™’s purpose is to help businesses who currently work with, or want to do work with, the Department of Defense (DoD) and federal government, to become compliant with the DFARS/NIST 800-171 and eventually the emerging CMMC requirements. It caters well to businesses who lack the bandwidth and resources to implement and manage the required controls. Those businesses need an affordable, practical and secure solution that can be implemented in a shorter amount of time. If cuick trac™ isn’t the right solution, Beryllium InfoSec Collaborative can provide and recommend other services to help organizations become, and stay, compliant.

Do I need a System Security Plan (SSP) and Plan of Actions and Milestones (POA&M) Before Utilizing cuick trac™?

No. If an organization knows it isn’t compliant, they need to focus on solutions that best fit their business. A cuick trac™ subject matter expert (SME) will help an organization identify CUI data flow, scope and boundary for free. Once the identified users in scope are using the cuick trac™ enclave, the customer and cuick trac™ conduct an assessment of the NIST SP 800-171 controls (and CMMC practices and processes using the latest version of the CMMC Assessment Guides) and create/update the SSP. All remaining gaps become the POA&M (physical and administrative controls outside of the cuick trac™ enclave, if applicable) and shortens the path to completing your plan of full implementation and on-going/continuous compliance.

What Happens If I’m Not Compliant with DFARS/NIST 800-171?

Besides the risk of failing a future CMMC certification, organizations who fail to prove that they have NIST SP 800-171 fully implemented and continuously monitored, will lose the opportunity to be awarded new DoD contract awards, and potentially face fines or loss of contract.

Who Mandates these Requirements?

The Federal government. By law, businesses handling Controlled Unclassified Information (CUI) are required to become, stay and prove DFARS/NIST 800-171 compliance in order to be awarded and keep contracts. Also, primary (prime) contractors have the right to ask for proof of compliance through SSP and POA&M audits and reviews, before selecting sub-contractors.

We Don’t Have a SIEM or Any Way to Monitor Events/Incidents/Breaches, Does cuick trac™ Do That?

Yes. Under the DFARS clause, contractors must report cyber incidents within 72 hours of them happening. That’s a difficult thing to accomplish if your business doesn’t have the personnel or resources to always be monitoring your security information and event management solution (SIEM). Cuick trac™ has a SIEM monitoring the enclave, and that information is reviewed by cuick trac™ security analysts and reviewed with cuick trac™ customers on a regular basis.

Is cuick trac™ a Software, thus Needing FedRamp Approval?

No, cuick trac™ is not a software. It’s a private hosted virtual enclave/controlled environment, referred to Infrastructure as a Service (IaaS), that keeps CUI encrypted at rest and in transit. It is not configured like a traditional cloud, thus not needing FedRamp Certification.

Does cuick trac™ Replace My IT Provider?

No. Our goal, always, is to work with as much of the customer’s current business processes that are already in place. Disruption to your business is detrimental, thus a collaborative approach will be key in regard to how CUI data is collected, stored and accessed. Cuick trac™essentially becomes the OSC’s CUI Managed Security Service Provider (MSSP). 

Request a cuick trac™ Demo

Learn why so many small to medium size defense contractors choose cuick trac™ as their DFARS 252.204-7012 & NIST SP 800-171 compliance solution.
Request your cuick trac™ demo today!