Blue Vault: NIST 800-17 Landing Zone Accelerator for AWS GovCloud
Deep Blue Cloud Computing · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
The requirement to protect Controlled Unclassified Information has not changed. NIST SP 800-171 has been the contractual baseline under DFARS 252.204-7012 since 2017 and remains in force under every CMMC scenario, including the July 2026 suspension of Phase 2 third-party certification. Blue Vault builds your environment to the standard itself, so your security posture holds no matter what the certification mechanism becomes.
Defense contractors handling Controlled Unclassified Information (CUI) need more than a secure AWS environment; they need one an assessor can walk through.
Show the rest of the publisher’s description (10 more lines)
Blue Vault is a fixed-scope professional services engagement from Deep Blue Cloud Computing that deploys a CMMC Level 2-ready multi-account landing zone in AWS GovCloud (US). Every architectural decision maps to the 110 practices of NIST SP 800-171 Rev 2, the technical foundation of CMMC Level 2. The result is an environment that is technically compliant at launch and designed to stay compliant as your organization grows and DoD assessment requirements evolve.
What is included:
A fully deployed CUI enclave with hard account isolation enforced through Service Control Policies. A Plan of Action and Milestones (POA&M) template, CUI boundary diagram, and operational runbook.
Infrastructure & Security Framework: AWS Services Used
- Blue Vault automates the deployment and continuous governance of your cloud architecture by natively integrating and configuring the following core AWS services:
- Governance & Operations: AWS Control Tower (orchestration and baseline controls), AWS Organizations (account structure and Service Control Policies), and AWS Config (continuous configuration and compliance monitoring).
- Identity & Security Posture: AWS IAM Identity Center (centralized SSO and permission sets), AWS Security Hub (security findings aggregation with automated checks against CIS and NIST standards), Amazon GuardDuty (managed threat detection).
- Centralized Logging & Auditing: A dedicated Amazon S3 log archive coupled with AWS CloudTrail and Amazon CloudWatch Logs for aggregated, cross-account audit trails.
- Enterprise Networking: AWS Transit Gateway for hub-and-spoke multi-account networking, combined with AWS Network Firewall and Amazon Route 53 Resolver for centralized egress filtering and hybrid DNS routing.
- Data Protection & Secrets: AWS Key Management Service (KMS) for customer-managed encryption keys across accounts, and AWS Secrets Manager for secure storage and automated rotation of credentials.
Highlights
Highlighted by the publisher on AWS Marketplace.
Evidence, not intentions All 110 NIST SP 800-171 Rev. 2 security requirements deployed, instrumented and evidenced, with the artifacts your self-assessment and SPRS score rest on handed over at close.
A CUI boundary that survives review CUI workloads isolated at the account level. Service control policies, KMS and AWS Network Firewall enforce the boundary continuously, so your scope stays provable rather than asserted.
Fixed scope, fixed clock Three engagement tiers, delivered in as few as 20 business days, purchasable through AWS Marketplace in AWS GovCloud (US) and eligible for drawdown against your AWS private pricing commitment. No open-ended SOWs.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Sources
Linked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

