
Data Governance & CUI Advisory
Advisory for government contractors navigating CUI and the federal regulatory landscape.
About Us
InfoCompli is a Montana-based advisory practice focused on how organizations identify, protect, and govern sensitive information, with deep specialization in Controlled Unclassified Information (CUI). The practice is led by a security professional with more than twenty years in federal information security, including work at the origin of the government's CUI program and across the defense industrial base.The regulatory landscape is shifting, and the forthcoming CUI FAR rule is set to reshape what contractors are expected to do. Organizations need more than checklist compliance. They need to understand what their data actually is, where the obligations really fall, and how to build governance that holds up as the rules evolve. That is the work InfoCompli does.

Services
CUI & Data Governance Advisory
Helping organizations answer the questions that come before compliance. What information do we actually hold? What is genuinely CUI, and what has been over-scoped? Where do the obligations fall, and who made that determination? This foundational work of proper scoping, boundary definition, and data-governance structure is what makes every downstream requirement manageable rather than overwhelming.Contract & Requirements Analysis
Federal contracts rarely state plainly what they require. Obligations are distributed across the FAR, agency supplements, and incorporated clauses, and they interact in ways that dictate specific courses of action. InfoCompli reviews contracts and solicitations to map those requirements, identify how they fit together, and translate them into clear direction, including one of the most consequential and frequently muddied questions in federal work: what actually counts as CUI under a given contract, and what that determination obligates you to do.Regulatory Readiness
Preparing organizations for the specific regimes that apply to them, including the forthcoming CUI FAR rule and CMMC. Gap analysis, remediation planning, and documentation support, grounded in an understanding of where each requirement comes from and what it is actually trying to accomplish.Security Program Support
Senior security-program expertise without a full-time hire, including Facility Security Officer (FSO) and Assistant FSO services, program development, self-inspection support, and ongoing program management for cleared and compliance-driven organizations.
Speaking
Rachel L. Bassford, Founder & Principal of InfoCompli, speaks on CUI, data governance, and the practical realities of federal compliance.UpcomingHigher Education Breakout
CS5 East · October 2026 · National Harbor, MD · Lead PresenterYou Can't Protect What You Haven't Governed: The Determination Problem Underneath Every CUI Scoping Decision
CMMC Midwest · October 2026 · Tulsa, OK · PresenterPastWhat Not to Miss When Scoping CUI in Your Environment
CMMC Day (DIB Cyber Certification Series) · College Park, MD · May 2026 · PresenterThe FSO's True Role in CUI Execution
NSI Conference · April 2026 · PresenterDCSA, FOCI, FSOs, & CUI
CUI-CON · February 2026 · Orlando, FL · PresenterThe CCP Illusion: Where Certification Ends and Experience Begins
CS5 East (Official Conference of the Cyber AB) · National Harbor, MD · October 2025 · PanelistCMMC Mock Assessment
With Fernando Machado, Cybersec Investments · CS5 East · National Harbor, MD · October 2025 · Joint presenterNew to CUI and CMMC? What to Know From a Practitioner, Not a Vendor
NCMS Conference · June 2025 · Presenter