Research Domain

Cybersecurity and Attestation

Research on control implementation, evidence sufficiency, and the exposure created when attested posture exceeds documented reality.

NIST SP 800-171 · CMMC · DFARS 252.204-7012 · CUI · FCA

Domain Statement

What this domain covers

The durable question in contractor cybersecurity is not which verification regime applies but whether documented posture substantiates what has been attested. Research in this domain examines evidence sufficiency, control-implementation reality, and the enforcement exposure that arises when the two diverge.

Analytic questions

  • Does documented posture substantiate what has been attested?
  • What evidence is sufficient to make an attestation defensible under examination?
  • Where do control-implementation gaps concentrate, and why?
  • How does enforcement exposure change as verification mechanisms change?

Methods Applied

  • Control-implementation assessment
  • Evidence-chain analysis
  • Scoping and boundary definition
  • Enforcement exposure modeling

Related Advisory

Standards


Publications

Published work in this domain

Your Subcontractor’s Engineer Does Not Exist

What a North Korean placement inside a defense contractor costs a company that did nothing wrong — and what converts it from a victim into a respondent. Identity verification that fails against a purchased genuine identity, ITAR deemed-export exposure, the sanctions question, and attestation. Cross-links: Export Controls, Threat Finance & Sanctions.
SB-2026-04 · 9 Aug 2026

The Export Rule Controls Your Data. It Never Tells You How to Protect It.

Where a cybersecurity obligation actually comes from when an export-control regulation controls your information but prescribes no control set. 10 CFR Part 810, the CUI framework, and why applicability is a contract question, not a question about the data.
SB-2026-02 · 30 Jul 2026

The Deadline Went Away. The Obligations Did Not.

What the July 2026 CMMC Phase II suspension changed, what it did not change, and what a contractor remains responsible for under representations already made.
SB-2026-01 · 20 Jul 2026

Further publications in preparation

Additional research in this domain currently exists within the WP-2026 corpus, published independently under CC BY 4.0. A curated Sanctir edition — conformed to the published analytic standard, individually indexed, and citable by DOI — is in preparation.

Back to the research library