Services / Compliance and audit
CMMC and NIST 800-171 readiness
Gap assessment, hardening and documentation for defense and federal supply-chain work — including GCC High, CUI boundaries and ITAR handling. The unglamorous part is the evidence, and that is where most assessments are won or lost.
What usually gets in the way
- No clear boundary around where CUI is stored and processed.
- Controls implemented but with no evidence an assessor accepts.
- Commercial Microsoft 365 in use where GCC High is required.
- SSP and PoA&M either missing or long out of date.
- Subcontractor flow-down obligations not addressed.
- An assessment date fixed before the work has started.
How we approach it
- Define and document the CUI boundary and data flows.
- Assess each control family and record the real state, not the intended one.
- Plan and support migration to GCC High where the requirement demands it.
- Write the SSP and maintain a PoA&M that tracks genuine progress.
- Build evidence packages mapped control by control.
- Prepare your team for what the assessor will actually ask.
What you end up with
- A defensible CUI boundary you can explain in one diagram.
- An SSP and PoA&M that stand up to review.
- Evidence assembled before the assessment, not during it.
- A realistic view of readiness and the work still outstanding.
Start with a conversation
Tell us where you are with cmmc and nist 800-171 readiness and we’ll tell you what it actually takes.