AI Readiness and Responsible Decision Advisory for Defense Contractors and DIB Suppliers

Every AI decision, with the evidence behind it.

Inventory. Classify. Decide. Evidence.

AI Governance Advisors (AIGA) is a senior-led, platform-neutral advisory that helps U.S. defense contractors and Defense Industrial Base (DIB) suppliers govern their use of AI where it meets Controlled Unclassified Information (CUI), CMMC and DFARS obligations.

We find the AI tools and features already in use, map where they could touch CUI, help you decide what can proceed and on what conditions, and build the evidence your CMMC advisers, primes and customers will ask for. We lead the AI governance workstream. Certification, assessment and technical security testing stay with your C3PAO, CMMC adviser or RPO, and MSSP.

We work with CISOs, GRC and compliance leads, CMMC program managers, security leaders and the executives accountable for customer readiness.

When defense contractors bring us in

Defense contractors come to us when they have a specific question and a date attached.

"Our prime sent a questionnaire asking how we use AI. What do we say?"

A prime or customer questionnaire that needs answers you can support.

"We're scoping for CMMC. Are our AI tools in scope?"

A scoping decision where AI assistants, plugins or embedded features may reach CUI.

"Someone may be using AI with CUI. How do we find out and what do we allow?"

AI use around CUI that nobody has formally approved or ruled out.

"A new contract flows down DFARS requirements. Does our AI use hold up?"

A DFARS flow-down expectation from a prime or a contract.

"The board, a customer or a new AI workflow is raising questions we can't answer yet."

An executive, customer or rollout question that needs a defensible yes, no or "yes, if."

AI is reaching defense contractors through copilots, plugins and features built into tools you already license, often faster than scoping, policy and records can keep up. CMMC scoping follows the data, not the product. The questions that matter: which AI can reach CUI, where prompts and outputs go, who approved each use, and what record shows it. We close that gap without stopping useful AI work.

How we work: Inventory > Classify > Decide > Evidence

1

1. Inventory

Which AI tools, plugins, embedded features, models and vendors are in use, including unapproved use?

You get: AI inventory and AI bill of materials (AI-BOM), use-case and vendor inventories

2

2. Classify

Which uses can reach CUI or contract data, where does the data go, and how much review does each need?

You get: AI/CUI map, data-flow notes, risk-tier rubric, risk register

3

3. Decide

What can proceed, on what conditions, and under whose authority?

You get: Approve, approve with conditions, restrict, prohibit or escalate, with a named owner and a review date

4

4. Evidence

What record supports the decision and shows it is enforced?

You get: Executive decision memo, CMMC evidence mapping, evidence index, prime or customer response pack, roadmap

What you receive

Each engagement produces working records your team owns and keeps current, not a slide deck.

Illustrative sample: AI/CUI decision record

Ways to work with us

Every engagement has a fixed scope agreed in writing, with a set number of tools, use cases or business units, named deliverables, and stated assumptions and exclusions. We share fees after a short scoping call.

Start here

Section 1513 / CMMC for AI Diagnostic

A bounded diagnostic of your AI use around CUI: AI-BOM, AI/CUI map, evidence gaps and executive decision memo

Core

CMMC for AI Readiness Assessment

A risk register, NIST AI RMF assessment, CMMC evidence mapping addendum and roadmap

When a deadline or customer review is coming

DIB AI Evidence Buildout

Expanded inventories, governance artifacts, prime and customer response materials, and coordination with your CMMC partners

Ongoing

Readiness Cadence Retainer

Intake of new AI tools, evidence refresh, decisions, issue tracking and executive reporting. Available once a baseline is in place and you have a named internal owner

What we do, and what stays with your C3PAO, CMMC adviser and MSSP

Who owns it

  • CMMC certification assessment: An authorized C3PAO (or DCMA DIBCAC for Level 3)
  • CMMC control implementation, SSP and POA&M: Your CMMC adviser or Registered Practitioner Organization (RPO)
  • Technical security configuration and testing: Your MSSP or IT and security team
  • Legal advice, contract and flow-down interpretation: Your counsel and contracting officer
  • SPRS scores and annual affirmations: Your affirming official

AIGA's role

  • CMMC certification assessment: We prepare the AI inventory, decisions and evidence index your team presents
  • CMMC control implementation, SSP and POA&M: We supply the AI inventory, AI/CUI map and decision records they reference
  • Technical security configuration and testing: We define what each AI decision needs confirmed and record the result
  • Legal advice, contract and flow-down interpretation: We flag the questions and organize the facts
  • SPRS scores and annual affirmations: We keep the AI-related evidence current so the affirmation rests on records

CMMC, DFARS and Section 1513: where things stand (as of October 2026)

CMMC program rule

DoD's CMMC program rule (32 CFR Part 170) took effect December 16, 2024. CMMC Level 2 is built on the 110 security requirements of NIST SP 800-171 Rev. 2. AI tools are scoped the same way as any asset that processes, stores or transmits CUI.

DFARS CMMC rule

The DFARS rule that puts CMMC into contracts (48 CFR Parts 204, 212, 217 and 252) took effect November 10, 2025, with a phased rollout originally scheduled through November 2028. Phase 2 and later milestones are on hold during the suspension described below.

Phase 2 suspension

On July 13, 2026, DoD suspended the CMMC Phase 2 requirements scheduled for November 10, 2026, put pending and future CMMC implementation milestones on hold, and began a review. During the suspension, solicitations may include only Level 1 (Self) or Level 2 (Self) requirements. Phase 1 self-assessment requirements and DFARS 252.204-7012 remain in effect. As of October 2026, the outcome of the review had not been announced.

DFARS 252.204-7012

The clause still requires NIST SP 800-171 safeguarding, cyber incident reporting, and cloud services for covered defense information that meet the FedRAMP Moderate baseline or its equivalent.

FY2026 NDAA Section 1513

Public Law 119-60, enacted December 18, 2025, directs DoD to develop an AI/ML security framework built on the NIST SP 800 series and existing frameworks, including CMMC, and to amend the DFARS so that contractors that develop, deploy, store or host covered AI/ML for DoD implement the framework. The statute sets no implementation deadline. No published framework or DFARS rule is yet known.

FY2026 NDAA Section 1532

Bars DoD contractors, subject to waivers, from using AI developed by DeepSeek or High Flyer (and related entities) in performing a DoD contract. An accurate AI inventory is how you show you comply.

How these rules apply to your contracts is a question for your counsel and contracting officer. We help you build the records that answer it.

Regulatory context last reviewed: October 8, 2026.

Questions defense contractors ask about AI and CMMC

Who helps defense contractors get ready for CMMC when they use AI tools?

AIGA leads the AI governance workstream: finding every AI tool and feature in use, mapping where each one could touch CUI, deciding which uses can proceed and on what conditions, and keeping the evidence your CMMC and DFARS work needs. RPOs and CMMC advisers handle control implementation, the SSP and POA&M. MSSPs configure and test technical controls. An authorized C3PAO performs third-party certification assessments. AIGA is not a C3PAO or RPO and does not certify or assess CMMC compliance.

We use AI tools and handle CUI. What do we need to do for CMMC?

Treat AI tools like any other asset. In practice: (1) inventory every AI tool, plugin and embedded AI feature, including unapproved use; (2) map which ones can reach CUI and where prompts and outputs go; (3) decide for each use whether it is approved, approved with conditions, restricted or prohibited, and name an owner; (4) ensure your SSP, policies, training and evidence reflect those decisions. DFARS 252.204-7012 obligations remain in effect. AIGA's Section 1513 / CMMC for AI Diagnostic produces the AI inventory, AI/CUI map, evidence gaps and executive decision memo.

Is an AI tool in scope for our CMMC assessment?

It can be. CMMC scoping follows the data, not the product. If an AI assistant, plugin or embedded feature can process, store or transmit CUI — for example by reading a document library or mailbox that holds CUI — it belongs in the scoping conversation with your RPO or adviser. If your policies and configuration are meant to keep CUI out of a tool, that choice still needs to be documented and enforced. AIGA builds the AI inventory and AI/CUI map your team needs for that conversation. The scoping decision belongs to you and your CMMC advisers; assessment determinations belong to your assessor.

What is Section 1513 of the FY2026 NDAA, and does it apply to us?

Section 1513 (Public Law 119-60, enacted December 18, 2025) directs DoD to develop a cybersecurity and physical security framework for AI/ML technologies acquired by the Department, building on the NIST SP 800 series and CMMC, and to amend the DFARS so covered contractors implement it. Covered contractors are those that develop, deploy, store or host covered AI/ML under a DoD contract. No implementation deadline is set; no published framework or DFARS rule is yet known as of October 2026. If you only use AI tools internally, CMMC and DFARS 252.204-7012 already apply to any AI use that touches CUI. Whether Section 1513 applies to a given contract is a question for your counsel and contracting officer.

Our prime sent a questionnaire asking how we use AI. What should we send back?

Send answers you can support with records. Primes increasingly ask which AI tools you use, whether any touch CUI or contract data, how use is approved and monitored, and how requirements are flowed down. A current response pack typically covers your AI inventory, which tools are approved for which data, the conditions on each, who owns the decisions, how employees are trained, and what is still open with dates. AIGA builds that pack from your inventory and decision records, and you decide what to send. AIGA does not attest on your behalf. Contract and flow-down interpretation stays with your counsel.

Is CMMC still happening after the Phase 2 suspension?

Yes, in part. On July 13, 2026, DoD suspended CMMC Phase 2 requirements, put later implementation milestones on hold, and started a review. Solicitations may include only Level 1 (Self) or Level 2 (Self) requirements during the suspension. Phase 1 self-assessment requirements remain in place, baseline compliance with NIST SP 800-171 Rev. 2 will be enforced through self-assessments and selected government-led assessments, and DFARS 252.204-7012 remains in effect. As of October 2026, DoD had not announced the outcome of the review. AI use that touches CUI is still covered by the safeguarding requirements you already have. Check current DoD guidance and your contracts before relying on any timeline.

Is AIGA a C3PAO or a CMMC RPO? Can AIGA certify us?

No. AIGA is not a C3PAO or a CMMC Registered Practitioner Organization, and it does not certify, assess or attest to CMMC compliance. AIGA does not provide legal advice or perform cybersecurity or penetration testing. AIGA leads the AI governance workstream: the AI inventory, AI/CUI mapping, risk decisions, and the evidence and response materials that your RPO or adviser, your MSSP and your assessor can use. Certification, assessment and technical testing stay with those partners.

Can we use ChatGPT, Copilot or other AI assistants with CUI?

Whether you can depends on the specific product, how and where it is hosted, how it is configured, and what your contracts require. A blanket answer isn't possible. DFARS 252.204-7012 requires that cloud services used to handle covered defense information meet the FedRAMP Moderate baseline or its equivalent. Consumer and personal AI accounts sit outside your controls entirely. The workable approach is a decision for each use: which tool, which data, which environment, what conditions, and who approved it. Your MSSP or IT provider confirms the environment and configuration. AIGA helps you make and record the decision, set the conditions, and keep your inventory, policies and evidence consistent with it.

Who you'll work with

Senior-led, every engagement

AIGA is led by its two co-founding principals, who scope and deliver every engagement themselves.

See the Team Bios.

Platform-neutral advisory

We don't sell or require any AI or compliance software. Every decision and every artifact stays with you.

We work alongside the CMMC providers you already have — C3PAOs, RPOs, MSSPs — or the ones you choose. We lead the AI governance workstream so your other partners can focus on what they do best.

Who we work with

CISOs & Security Leaders

We map AI risk to your security posture and give you defensible decisions backed by evidence.

GRC & Compliance Leads

We produce the artifacts your CMMC program needs: inventory, map, risk register, evidence index.

CMMC Program Managers

We close the AI governance gap so your scoping, SSP and evidence reflect actual AI use.

Executives & Boards

We help you reach a defensible yes, no or "yes, if" on the AI questions customers and primes raise.

Bring us one AI question that has a deadline

Tell us which AI tools or uses you are weighing, what is driving the timing (a prime questionnaire, a CMMC scoping decision, a new contract, or a board or customer question), and who you are already working with (C3PAO, RPO or adviser, MSSP). We will come back with a fixed-scope Section 1513 / CMMC for AI Diagnostic proposal with named deliverables, assumptions and exclusions, and a clear handoff to your CMMC partners.

Copyright © 2026 AI Governance Advisors (AIGA) | www.aigovadvisors.ai - All Rights Reserved.