Defense contractors under SSA, Proxy, SCA, or Board Resolution agreements manage their ECP, TCP, AOP, annual GSC reports, and DCSA inspection prep in Word documents and SharePoint folders. FulcrumFOCI changes that — structured, auditable, always inspection-ready.
Your ECP, TCP, AOP, FLP, and Visitation Plan live in version-controlled Word documents — until someone edits the wrong copy.
The GSC chair's annual compliance certification to DCSA is a hard requirement. No system tracks it — until your IS Rep asks for it.
Personnel changes, ownership shifts, and new foreign national access all require timely DCSA notification. Without a system, they get missed.
When DCSA announces a vulnerability assessment, your FSO scrambles to reconstruct a year's worth of artifacts in 48 hours.
From initial SF-328 submission through annual DCSA inspection — and every event in between.
Version-controlled ECP, TCP, AOP, FLP, and Visitation Plan — templated per your specific mitigation agreement type. Approval routing and DCSA submission package generation included.
Guided wizard producing the 32 CFR 117.11 annual compliance report. Pre-populates from your Dataverse records. Routes to GSC chair for digital certification. Deadline tracking included.
Structured annual self-inspection workflow per NISPOM 117.7(g)(2). Checklist-driven with finding management, corrective action tracking, and SMO certification generation.
Foreign national visit requests, pre-visit TCP compliance checks, escort assignment, visit logging, and AOP-required visit history. External portal for visitor self-service.
Foreign travel pre-briefing requests, interaction reports for contact with foreign nationals, AOP-linked logs, and automated DCSA notification when reportable thresholds are met.
Real-time DCSA inspection readiness score, upcoming certification deadlines, overdue items by owner, visit volumes, open change events, and self-inspection finding status.
Classified and CUI contract log, program access records, bilateral disclosure agreements, DD-254 tracking, and subcontractor FOCI applicability assessments.
Monitors and logs all events requiring DCSA notification — ownership changes, KMP transitions, new foreign affiliations, security incidents. Auto-generates notification drafts with regulatory citations.
All tiers deploy into your existing Microsoft tenant — Azure Government or GCC High. No shared infrastructure. Your data never leaves your boundary.
Each add-on is an independent subscription layer applied on top of any base tier.
For companies seeking their initial Facility Security Clearance. Guided SF-328 completion, FOCI determination workflow, sponsoring contract tracking, FCL package assembly checklist, and timeline management through DCSA processing.
For cleared facilities. Personnel Security Clearance (PCL) roster management, DISS/NBIS submission tracking, classified material accountability log, storage container inventory, open storage area documentation, and Standard Practice Procedures (SPP) management.
For facilities with a classified information system (CIS). ISSM/ISSO role tracking, system authorization artifact management (ATO, IATT, SSP), continuous monitoring log, media destruction records, and IS self-inspection checklist per 32 CFR 117.
FulcrumFOCI deploys directly into your existing Azure Government or GCC High Power Platform environment. All data stays inside your boundary. No FedRAMP obligation on Fulcrum. Your existing CMMC compliance posture is unaffected.
Fulcrum provisions and manages a dedicated Azure Government tenant for your organization. Per-customer isolation. Mirrors the CMMC enclave model already familiar to cleared contractors.
Pricing is not displayed publicly. Submit below and a Fulcrum advisor will respond within one business day.
A Fulcrum advisor will respond within one business day. You can also reach us at info@fulcrumadvisory.us.