We keep grant-funded programs funder-ready so you keep the grant. Contract boilerplate is not a certification demand — most of it means verify your vendors or produce an evidence pack.
“FedRAMP and GovRAMP are badges for the companies you buy software from — your job is to verify theirs, not earn your own.”
“The frameworks that land on your desk are NIST 800-171 flow-down, CMMC if you touch DoD data, and SOC 2 if you handle data for others.”
Federal / DoD pass-through
“Contractor shall comply with NIST SP 800-171”
A written 800-171 program if CUI is in scope — SSP, POA&M, and annual affirmation. Without CUI, this often means a self-attestation, not a 3PAO assessment.
Who is obligated: Your organization
State / federal RFPs
“Offeror must demonstrate FedRAMP-compliant infrastructure”
Your cloud vendors must be FedRAMP-authorized — not you. Your job is to verify and document their status.
Who is obligated: Your vendors (you verify)
SLED contracts
“Vendor must meet state cloud security standards (GovRAMP / StateRAMP)”
Same as FedRAMP, at the state level. Check whether the contracting agency participates in GovRAMP.
Who is obligated: Your vendors (you verify)
Most foundations and many state grants
“Provide evidence of a security program”
A questionnaire or attestation plus an evidence pack (policies, access reviews, training records) — not a certification.
Who is obligated: Your organization
Health / data-handling orgs
“Comply with applicable laws re: data protection”
HIPAA if you are a covered entity or business associate; state breach-notice laws; CCPA-style rules if you hold California resident data.
Who is obligated: Your organization
DoD / GSA
“Subcontractors subject to the same terms”
Flow-down: vendors who touch the same data need the same verification chain (GSA CUI rule, effective Jan 5, 2026).
Who is obligated: Your vendors, documented by you
Federal / state contracts
“Cyber incident notification within 72 hours”
A written incident-response plan with a notification SLA — and a drill in the last 12 months.
Who is obligated: Your organization
Many state agencies
“Maintain cybersecurity insurance”
A policy in force with stated minimum limits, plus renewal proof for the funder.
Who is obligated: Your organization
Which framework actually lands on your desk
Framework
Applies when
Obligated
NIST 800-171
CUI is in scope on a federal contract or flow-down
Your organization
CMMC 2.0
DoD contract with CUI (Level 2) or FCI (Level 1)
Your organization; a 3PAO assesses Level 2 (Phase 2 deadline Nov 2026)
SOC 2
You act as a service org / data intermediary for partners or beneficiaries
Your organization; a CPA audits
GovRAMP / state RAMP
You buy cloud services used in state work
Your vendors — not you
FedRAMP 20x
You buy cloud services used in federal work
Your vendors — not you
HIPAA
Covered entity or business associate
Your organization
Decoder rules
Never read a clause as stricter than it is. Over-reading sells fear; grant budgets are not fear-shaped.
Never read it looser than it is. If CUI flows, 800-171 is real and CMMC Level 2 may follow (Nov 2026).
Every clause maps to: obligation → who is obligated (org vs vendor) → evidence → deadline.
Paste a clause into the scorecard agent (choose “Decode a clause”) for a draft reading.
Last Myle advises and prepares. We do not certify, authorize, or act as a 3PAO or CPA firm. Agents draft; a named consultant reviews every client-facing deliverable. We do not take custody of your evidence or CUI — data stays in your tenant. Talk to a human.