Compliance
NIST SP 800-171 and DFARS
If your contracts carry DFARS 252.204-7012, you already owe these controls — whatever happens to CMMC. This is the work of finding out where you actually stand and closing the distance.
What the clause actually requires
DFARS 252.204-7012 requires you to implement the 110 security requirements of NIST SP 800-171 across 14 families, report cyber incidents to DIBNet within 72 hours, and flow the same clause down to subcontractors unaltered.
CMMC assesses those same requirements against 320 assessment objectives. The framework is the measuring instrument; 800-171 is the thing being measured, and it is contractual whether or not anyone turns up to check.
That distinction matters more than usual right now. CMMC Phase II was suspended on 13 July 2026, so third-party certification is on hold — but the clause was untouched, and the weight moved onto the self-assessment score and the affirmation a named person signs in SPRS.
What the engagement produces
A gap analysis
Every control assessed against what you actually have, not what the policy says you have. The output is a list of what is met, what is partially met, and what is not.
A System Security Plan
The document describing how your environment meets each requirement. It is yours, it is the first thing any assessor asks for, and it has to survive being read closely.
A POA&M
A plan of action with milestones for everything not yet met — what will be done, by whom, and by when. A credible one is worth more than an optimistic one.
What people get wrong
Treating the score as the goal. A high SPRS score you cannot evidence is a liability, not an achievement — particularly now, when the affirmation carries more weight than it did and the Department of Justice's Civil Cyber-Fraud Initiative did not pause.
Assuming the provider owns it. A substantial share of 800-171 is organisational — training, screening, physical access, policy your people actually follow. No technology partner can do those for you. Our shared responsibility matrix sets out the usual split across all 14 families.
Stopping because Phase II is paused. Every plausible outcome of the review still requires these controls. Unwinding an enclave and rebuilding it later costs more than maintaining one.
Where this leads
Most engagements start here and continue into CMMC Level 2 readiness or a move to GCC High if CUI is in scope. If your contracts only involve FCI rather than CUI, the lighter obligation under CMMC Level 1 and FAR 52.204-21 may be all you owe — and we would rather tell you that than sell you the larger engagement.
Find out where you stand
We offer a free CMMC gap assessment for qualifying contractors — where you actually are against the 110 controls, and which of them are yours rather than ours.
Schedule a call