CMMC and NIST 800-171
CMMC compliance consultant for defense contractors
We help defense suppliers implement NIST SP 800-171, document it in a system security plan, calculate an accurate SPRS score and prepare for CMMC assessment. You get a realistic plan that holds up whichever way the program moves next.

For the defense supply chain
Scoped for manufacturers and suppliers handling FCI and CUI
Remediation in house
Engineers for identity, network, endpoint and logging controls
Top virtual CISO services company
Recognized by Cyber Security Review
CMMC 2.0 compliance
What CMMC and NIST 800-171 require
The Cybersecurity Maturity Model Certification (CMMC) program verifies that Department of Defense contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). CMMC 2.0 has three levels, and the level in your contract depends on the information you handle.
For most suppliers that handle CUI, the standard behind CMMC is NIST SP 800-171. DFARS 252.204-7012 already requires you to implement it, and the DoD assessment methodology turns your implementation into an SPRS score that you post in the Supplier Performance Risk System.
The three levels
CMMC levels at a glance
Your contracting officer sets the level and assessment type in the solicitation.
Program status
Where CMMC stands as of 2026
CMMC is being phased into DoD contracts. The program rule (32 CFR Part 170) took effect in December 2024, and the acquisition rule (48 CFR) took effect on November 10, 2025. That started Phase 1, in which contracts can require Level 1 and Level 2 self-assessments.
Phase 2 was scheduled to begin on November 10, 2026 and would have made third-party (C3PAO) Level 2 certification a condition of award for many contracts. On July 13, 2026, the Department suspended Phase 2 and the later phases and set up a CMMC Reform Task Force to review the program. During the review, new requirements are limited to Level 1 and Level 2 self-assessments. As of late September 2026, the task force’s recommendations have not been made public.
What has not changed
- DFARS 252.204-7012 and NIST SP 800-171 still apply to contracts that involve CUI
- Phase 1 self-assessment requirements remain in place
- You still need a current SPRS score and a senior official’s affirmation
- Contractors can still choose a voluntary C3PAO assessment
The work to implement 800-171 is the same whether your eventual assessment is a self-assessment or a C3PAO assessment. We recommend continuing it. Requirements change, so confirm the CMMC level and assessment type for each contract with your contracting officer.
What’s included
NIST 800-171 compliance and CMMC Level 2 assessment readiness
CUI scoping
We map where FCI and CUI flow and draw the smallest defensible assessment boundary.
Gap assessment
Each 800-171 requirement is tested against your environment, with gaps ranked by score impact and effort.
SPRS score
We calculate your score using the DoD assessment methodology so what you post is accurate and defensible.
System security plan
A system security plan (SSP) that describes how each requirement is met in your environment.
POA&M
A plan of action and milestones for open items, with owners and dates you can meet.
Remediation
Our engineers can implement MFA, access control, logging, encryption and network segmentation.
How it works
From scoping to assessment-ready
Scope
Confirm which contracts involve FCI or CUI, which level applies and which systems are in scope.
Assess
Test all applicable requirements, calculate your current SPRS score and document gaps.
Remediate and document
Close gaps, write the SSP and POA&M and gather the evidence an assessor will ask for.
Affirm and maintain
Support your self-assessment, SPRS update and affirmation, or a C3PAO assessment, then keep controls current.
Deliverables
What you receive
FAQ
CMMC and NIST 800-171 questions
Related services
Related services
Talk to a CMMC expert
Know your SPRS score and your path to CMMC
Tell us about your DoD contracts and an advisor will reply by email to scope your 800-171 and CMMC work.
Prefer email? Write to [email protected] or call (858) 712-0040.
