Overview
The requirement to protect Controlled Unclassified Information has not changed. NIST SP 800-171 has been the contractual baseline under DFARS 252.204-7012 since 2017 and remains in force under every CMMC scenario, including the July 2026 suspension of Phase 2 third-party certification. Blue Vault builds your environment to the standard itself, so your security posture holds no matter what the certification mechanism becomes.
Defense contractors handling Controlled Unclassified Information (CUI) need more than a secure AWS environment; they need one an assessor can walk through.
Blue Vault is a fixed-scope professional services engagement from Deep Blue Cloud Computing that deploys a CMMC Level 2-ready multi-account landing zone in AWS GovCloud (US). Every architectural decision maps to the 110 practices of NIST SP 800-171 Rev 2, the technical foundation of CMMC Level 2. The result is an environment that is technically compliant at launch and designed to stay compliant as your organization grows and DoD assessment requirements evolve.
What is included: A fully deployed CUI enclave with hard account isolation enforced through Service Control Policies. A Plan of Action and Milestones (POA&M) template, CUI boundary diagram, and operational runbook.
Infrastructure & Security Framework: AWS Services Used
- Blue Vault automates the deployment and continuous governance of your cloud architecture by natively integrating and configuring the following core AWS services:
- Governance & Operations: AWS Control Tower (orchestration and baseline controls), AWS Organizations (account structure and Service Control Policies), and AWS Config (continuous configuration and compliance monitoring).
- Identity & Security Posture: AWS IAM Identity Center (centralized SSO and permission sets), AWS Security Hub (security findings aggregation with automated checks against CIS and NIST standards), Amazon GuardDuty (managed threat detection).
- Centralized Logging & Auditing: A dedicated Amazon S3 log archive coupled with AWS CloudTrail and Amazon CloudWatch Logs for aggregated, cross-account audit trails.
- Enterprise Networking: AWS Transit Gateway for hub-and-spoke multi-account networking, combined with AWS Network Firewall and Amazon Route 53 Resolver for centralized egress filtering and hybrid DNS routing.
- Data Protection & Secrets: AWS Key Management Service (KMS) for customer-managed encryption keys across accounts, and AWS Secrets Manager for secure storage and automated rotation of credentials.
Highlights
- Evidence, not intentions All 110 NIST SP 800-171 Rev. 2 security requirements deployed, instrumented and evidenced, with the artifacts your self-assessment and SPRS score rest on handed over at close.
- A CUI boundary that survives review CUI workloads isolated at the account level. Service control policies, KMS and AWS Network Firewall enforce the boundary continuously, so your scope stays provable rather than asserted.
- Fixed scope, fixed clock Three engagement tiers, delivered in as few as 20 business days, purchasable through AWS Marketplace in AWS GovCloud (US) and eligible for drawdown against your AWS private pricing commitment. No open-ended SOWs.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Support
Vendor support
Deep Blue Cloud Computing provides dedicated support throughout your CMMC journey - from initial scoping through assessment readiness. Our team includes AWS-certified engineers with hands-on experience designing CUI enclaves, implementing NIST SP 800-171 Rev 2 controls, and delivering compliant landing zone architectures in AWS GovCloud. Engagements include structured knowledge transfer, technical control documentation support, and a post-deployment hypercare period to ensure your environment is stable and audit-ready before your C3PAO assessment.
Pricing for this engagement is flexible and customized based on the size of your organization, CMMC target level, existing infrastructure, and assessment timeline. Contact Brian Storch at brian.storch@deepbluecloud.io to schedule a scoping call and confirm your target assessment timeline. We respond within one business day.