Section 847 Ready • DCSA Inspectable • Deployed in Your Tenant

The Only Platform Built for
FOCI Compliance

Defense contractors under SSA, Proxy, SCA, or Board Resolution agreements manage their ECP, TCP, AOP, annual GSC reports, and DCSA inspection prep in Word documents and SharePoint folders. FulcrumFOCI changes that — structured, auditable, always inspection-ready.

37,740 Companies entering FOCI oversight under Section 847
155+ Days average DCSA processing time — preparation matters
0 Purpose-built FOCI compliance platforms before this one

FOCI compliance is a manual, high-stakes liability

📄

Documents scattered across SharePoint

Your ECP, TCP, AOP, FLP, and Visitation Plan live in version-controlled Word documents — until someone edits the wrong copy.

Annual GSC deadlines missed

The GSC chair's annual compliance certification to DCSA is a hard requirement. No system tracks it — until your IS Rep asks for it.

🚨

Changed conditions go unreported

Personnel changes, ownership shifts, and new foreign national access all require timely DCSA notification. Without a system, they get missed.

🔍

Inspection prep is a fire drill

When DCSA announces a vulnerability assessment, your FSO scrambles to reconstruct a year's worth of artifacts in 48 hours.

FulcrumFOCI covers every phase

From initial SF-328 submission through annual DCSA inspection — and every event in between.

01

Pre-FOCI / No FCL

  • SF-328 assessment and gap analysis
  • FOCI risk scoring (ownership mapping)
  • Mitigation agreement selection wizard
  • FCL sponsorship readiness checklist
  • Section 847 applicability assessment
Add-on: FCL Acquisition Module
02

FOCI Mitigation Active

  • ECP / TCP / AOP / FLP document library
  • GSC formation and member tracking
  • Visitation Plan and visit request workflow
  • PCL roster and insider threat log
  • Standard Practice Procedures (SPP) builder
  • Contract / CUI registration log
Add-on: FCL Possession Module
03

Annual Compliance Cycle

  • Self-inspection workflow (32 CFR 117.7(g)(2))
  • SMO annual certification generator
  • GSC compliance report (32 CFR 117.11)
  • DCSA vulnerability assessment prep
  • Corrective action tracking and closeout
  • Audit trail and artifact export package
04

Changed Condition Events

  • Ownership / M&A change triggers
  • KMP / FSO / ITPSO changes
  • New classified contract registration
  • Foreign national access events
  • Security incident initial and final reports
  • DCSA notification workflow and log
Add-on: Classified Computing Module

Every artifact. Every workflow. One place.

📋

FOCI Document Library

Version-controlled ECP, TCP, AOP, FLP, and Visitation Plan — templated per your specific mitigation agreement type. Approval routing and DCSA submission package generation included.

SharePoint • Power Pages • Power Automate

Annual GSC Report Builder

Guided wizard producing the 32 CFR 117.11 annual compliance report. Pre-populates from your Dataverse records. Routes to GSC chair for digital certification. Deadline tracking included.

Model-Driven App • Power Automate • Dataverse
🔍

Self-Inspection Manager

Structured annual self-inspection workflow per NISPOM 117.7(g)(2). Checklist-driven with finding management, corrective action tracking, and SMO certification generation.

Model-Driven App • Power BI • Dataverse
👤

Visitor Management

Foreign national visit requests, pre-visit TCP compliance checks, escort assignment, visit logging, and AOP-required visit history. External portal for visitor self-service.

Canvas App • Power Pages • Power Automate
✈️

Travel & Interaction Requests

Foreign travel pre-briefing requests, interaction reports for contact with foreign nationals, AOP-linked logs, and automated DCSA notification when reportable thresholds are met.

Canvas App • Power Automate • Dataverse
📊

Compliance Dashboard

Real-time DCSA inspection readiness score, upcoming certification deadlines, overdue items by owner, visit volumes, open change events, and self-inspection finding status.

Power BI Embedded • Dataverse • Azure Monitor
📁

Contract & CUI Register

Classified and CUI contract log, program access records, bilateral disclosure agreements, DD-254 tracking, and subcontractor FOCI applicability assessments.

Model-Driven App • Dataverse • SharePoint

Changed Condition Tracker

Monitors and logs all events requiring DCSA notification — ownership changes, KMP transitions, new foreign affiliations, security incidents. Auto-generates notification drafts with regulatory citations.

Power Automate • Dataverse • Teams Alerts

Start with FOCI. Scale to your full security program.

All tiers deploy into your existing Microsoft tenant — Azure Government or GCC High. No shared infrastructure. Your data never leaves your boundary.

FulcrumFOCI Core
Tier 1
Essential FOCI compliance management for SSA, Proxy, SCA, or Board Resolution companies
  • FOCI document library (ECP, TCP, AOP, FLP)
  • Annual GSC report wizard
  • Changed condition tracker
  • Self-inspection workflow
  • DCSA inspection readiness dashboard
  • Audit trail and artifact export
Request Pricing
Fulcrum Full Suite
Tier 3
Platform plus an internal AI assistant grounded on your FOCI documents and DCSA policy guidance
  • Everything in Tier 2
  • Copilot Studio AI agent (Teams)
  • RAG over your ECP/TCP/NISPOM
  • Azure OpenAI GPT-4o (your tenant)
  • Natural language FOCI Q&A
  • AI-assisted annual report drafting
  • Policy gap identification
Request Pricing

Premium Add-On Modules

Each add-on is an independent subscription layer applied on top of any base tier.

Add-On A

FCL Acquisition Module

For companies seeking their initial Facility Security Clearance. Guided SF-328 completion, FOCI determination workflow, sponsoring contract tracking, FCL package assembly checklist, and timeline management through DCSA processing.

Add-On B

FCL Possession Module

For cleared facilities. Personnel Security Clearance (PCL) roster management, DISS/NBIS submission tracking, classified material accountability log, storage container inventory, open storage area documentation, and Standard Practice Procedures (SPP) management.

Add-On C

Classified Computing Module

For facilities with a classified information system (CIS). ISSM/ISSO role tracking, system authorization artifact management (ATO, IATT, SSP), continuous monitoring log, media destruction records, and IS self-inspection checklist per 32 CFR 117.

Your tenant. Your data. Your control.

Managed Enclave

Fulcrum provisions and manages a dedicated Azure Government tenant for your organization. Per-customer isolation. Mirrors the CMMC enclave model already familiar to cleared contractors.

Ready to make DCSA inspections a non-event?

Pricing is not displayed publicly. Submit below and a Fulcrum advisor will respond within one business day.

Request received.

A Fulcrum advisor will respond within one business day. You can also reach us at info@fulcrumadvisory.us.