Skip to content

Shared Responsibility

GovConHouse is a toolbox for your compliance program. It is not your compliance program, and it is not a certification authority. This page explains exactly where GovConHouse’s work ends and yours begins, for every compliance framework the platform touches, with a concrete example for each.

For every framework below, GovConHouse prepares the analysis, evidence, and paperwork; you (or your organization’s authorized official) review, sign, and submit it. GovConHouse never submits anything to a government system, an assessor, or a customer on your behalf, and never holds a certification for you.

  • Your certifications. Scores, control states, evidence, and exports produced by the platform are material for your own assessments, not certifications GovConHouse holds on your behalf. GovConHouse holds none of its own either; see Not supported.
  • Your determinations. Classification labels, control-implementation assertions, and risk decisions are yours to make and defend to your assessor.
  • Your flow-downs. Obligations that flow down to your subcontractors and suppliers are yours to pass down. The platform does not sign flow-downs for you.
  • Your submissions. SPRS scores, CMMC affirmations, and FedRAMP OSCAL exports are yours to validate before submitting to the government or an assessor. SPRS and CMMC submissions go through PIEE with your organization’s own credentials. The in-app submit route returns an honest 503 (“live SPRS submission is disabled”) because the platform does not transmit to PIEE; see the SPRS Scoring page.
  • Runs the tools that compute outputs from your inputs: SPRS scoring per the DoD methodology, CMMC control-state tracking, FAR/DFARS clause checking against a real clause catalog, and FedRAMP OSCAL export.
  • Encrypts uploaded evidence files at rest with Fernet when the operator sets FERNET_KEY (free and open source), and CUI-marked contract fields at the application layer when CUI_ENCRYPTION_KEY is set. When a key is not set, the platform stores plaintext and logs that state instead of claiming otherwise. See the matrix for the exact key commands.
  • Keeps your company’s compliance data isolated from other tenants. CMMC assessment rows are scoped to your company (a row exists only with your supplier id attached, since the 2026-09-29 clean-split fix), SPRS scores are computed only from your own control rows, and cross-tenant reads return 404 by design, with IDOR regression tests covering pipeline, proposals, awards, sentinel runs, fabric posture, and audit events. Known limitation, on record: the legacy cmmc_control_states table holds pre-2026-09-20 rows with no supplier id; tenant-scoped readers filter them out, and quarantining them is queued cleanup.
  • Processes data through its own service providers (hosting, AI processing, and payments) under your agreement with GovConHouse.

The platform tooling does not cover every framework, and the platform itself holds no certifications. In product copy and in these docs, unsupported means unsupported:

  • StateRAMP and GovRAMP: no catalog, no assessment, no export exists in the platform.
  • NIST CSF self-assessment: no Functions, Categories, Subcategories, or Tier model exists. (CSF appears only as a tag label.)
  • Third-party or government assessment records: CMMC assessment rows can be self-assessed with your evidence; the platform cannot record a C3PAO or DIBCAC result as the source of a control status.
  • Platform certifications: GovConHouse holds no SOC 2, ISO 27001, FedRAMP, or CMMC certification. Any page on this site that says otherwise is a bug; report it.
  • Live SPRS submission: the platform computes and exports; it does not post to PIEE. See the SPRS Scoring page.

Every responsibility, every party, one owner per cell: see the Shared Responsibility Matrix.

GovConHouse does Tracks your implementation status against all 110 NIST SP 800-171 controls, scores it against the DoD Assessment Methodology, and generates a POA&M for anything not yet MET.
You do Review every control’s evidence, correct anything the platform got wrong, and have your C3PAO (or your own self-assessment, for Level 1) conduct the actual certification assessment.
Example GovConHouse shows AC.L2-3.1.1 as MET based on your MFA configuration evidence. Your assessor still independently verifies that evidence during your C3PAO assessment
GovConHouse does Generates a System Security Plan (SSP) skeleton from your control implementations, tracks POA&M items with owners and deadlines, and exports OSCAL packages in the format 3PAOs and agencies expect.
You do Complete and validate the SSP narrative, engage a 3PAO for the actual assessment, and submit through the government’s own FedRAMP process.
Example GovConHouse exports an OSCAL-formatted SSP for your cloud service offering. That file is a head start on the paperwork, it is not, and does not claim to be, a FedRAMP Authorization to Operate. GovConHouse itself holds no FedRAMP authorization of its own. See FedRAMP Export for what the export does and does not mean.
GovConHouse does Calculates your SPRS score using the real DoD scoring methodology from your control implementation data.
You do Have your organization’s senior official review and personally affirm the score before it’s submitted to SPRS, this affirmation is a legal attestation by a named individual at your company, not by GovConHouse.
Example GovConHouse computes a score of -15 based on your current control gaps. Your senior official reviews the underlying control data, agrees it’s accurate, and is the one who logs into SPRS and submits it under their own name and authority.
GovConHouse does Maps your policies, controls, and risks to the NIST 800-171 catalog and surfaces gaps.
You do Own the actual policy content and the risk-acceptance decisions behind it.
Example The platform flags that your incident response policy doesn’t cover a required element. You (or your compliance lead) write the actual policy language
GovConHouse does Tracks the compliance requirements tied to your GSA Schedule (TAA, Section 508, price list currency, etc.) and flags what’s coming due.
You do Maintain the actual compliance posture and respond to your GSA Contracting Officer directly

Denied-parties / third-party risk screening

Section titled “Denied-parties / third-party risk screening”
GovConHouse does Screens the partners and suppliers you enter against OFAC, BIS, and debarment lists you configure.
You do Make the actual go/no-go decision on any match, and maintain your own due-diligence file, a screening hit from the platform is a starting point for review, not an automatic legal determination.

Every framework above has a real government or assessor process behind it, and every one of those processes requires a named, accountable person at your organization to sign or submit. A software platform cannot stand in for that signature, and a platform that implied it could would be overclaiming exactly the kind of certification authority it doesn’t hold. This is why every generated document, score, and export in GovConHouse is framed as material for your review, not a finished, submittable artifact on its own.