NIST 800-171 & CMMC 2.0 COMPLIANCE CONSULTING
// THE PROBLEM
If your business handles Controlled Unclassified Information as a DoD subcontractor, CMMC 2.0 isn't optional paperwork, it's a condition of staying in the supply chain. Most small manufacturers don't have a compliance department. They have someone wearing five hats, one of which just became "figure out 110 security controls."
A lot of what gets sold into this space is a binder of policy documents that describe a network nobody actually built. That gap is what an assessor finds, and it's what closing it for real requires someone who understands both the framework and the shop floor it has to run on.
// HOW IT WORKS
- Gap Assessment: every one of the 110 NIST 800-171 controls checked against what's actually in place, not what a policy claims, delivered as a written report costed against what closing each gap takes.
- SSP & POA&M Development: the System Security Plan and Plan of Action & Milestones a C3PAO or your prime contractor will actually ask to see, matched to your real environment.
This is advisory and documentation work: what the controls require, where you stand against them, and what closing each gap takes. Implementation, the actual network segmentation, hardware, and configuration work, is scoped and quoted separately once the assessment defines what's needed.
// INFORMED BY DIRECT EXPERIENCE
This isn't framework theory read off a page. The assessment and documentation are informed by direct, hands-on experience designing a CUI enclave for a DoD subcontractor pursuing CMMC 2.0 Level 2 / NIST 800-171 Rev 2, real segmentation, identity and access controls, and documentation written as the system was built. That background is what separates a useful gap assessment from a checklist.
// WHO THIS IS FOR
Small manufacturers, machine shops, and other subcontractors in the DoD supply chain who need a clear, honest read on where they stand against NIST 800-171 and CMMC 2.0, and the documentation a C3PAO or prime contractor will actually ask to see, without hiring a full compliance department.
// FAQ
What's the difference between NIST 800-171 and CMMC 2.0?
NIST 800-171 is the underlying set of 110 controls. CMMC 2.0 is the DoD certification program that verifies you meet them. Getting CMMC-ready means implementing NIST 800-171.
Do you build the compliant network, or just tell us what's needed?
This engagement is advisory and documentation: the gap assessment and the SSP/POA&M. Implementation is scoped and quoted as separate work once the assessment identifies what's actually needed.
Can a small shop get useful guidance here without a big compliance firm?
Yes. A large firm brings process and paperwork; this brings someone who understands the framework and the shop floor it runs on.
What does a gap assessment produce?
A written report checking all 110 controls against what's actually in place, each gap costed against what closing it takes.