Cyber Swiss
Army Knife Squad

Services / Compliance and audit

CMMC and NIST 800-171 readiness

Gap assessment, hardening and documentation for defense and federal supply-chain work — including GCC High, CUI boundaries and ITAR handling. The unglamorous part is the evidence, and that is where most assessments are won or lost.

What usually gets in the way

  • No clear boundary around where CUI is stored and processed.
  • Controls implemented but with no evidence an assessor accepts.
  • Commercial Microsoft 365 in use where GCC High is required.
  • SSP and PoA&M either missing or long out of date.
  • Subcontractor flow-down obligations not addressed.
  • An assessment date fixed before the work has started.

How we approach it

  • Define and document the CUI boundary and data flows.
  • Assess each control family and record the real state, not the intended one.
  • Plan and support migration to GCC High where the requirement demands it.
  • Write the SSP and maintain a PoA&M that tracks genuine progress.
  • Build evidence packages mapped control by control.
  • Prepare your team for what the assessor will actually ask.

What you end up with

  • A defensible CUI boundary you can explain in one diagram.
  • An SSP and PoA&M that stand up to review.
  • Evidence assembled before the assessment, not during it.
  • A realistic view of readiness and the work still outstanding.

Start with a conversation

Tell us where you are with cmmc and nist 800-171 readiness and we’ll tell you what it actually takes.