Federal organizations spend considerable effort vetting the platforms they procure. The services team implementing and monitoring those platforms often receives less scrutiny. When the work involves Controlled Unclassified Information, that gap carries real compliance risk. Most federal compliance conversations center on software: whether a platform is FedRAMP authorized, DoDIN APL approved, or listed on a contract vehicle. That scrutiny is warranted. What it sometimes misses is the services engagement beneath the platform.