Minimum security controls for subcontractors
~86 tokMinimum security controls for subcontractors with CUI or system access include: documented information security policy; MFA for remote and privileged access; encrypted data in transit (TLS 1.2+) and at rest; vulnerability management with critical patch SLAs of 15 days; incident notification to Aegis within 24 hours of confirmed incidents; and willingness to flow down DFARS 252.204-7012 / CMMC obligations. Subcontractors without these controls cannot process CUI.