// Government & Defense

Built for the
Defense Industrial Base.

CMMC, NIST SP 800-171, and ITAR compliance programs designed by practitioners who understand the unique obligations, threat landscape, and operational constraints of defense contractors.

CMMC 2.0

Mandatory for all DoD contracts involving CUI. C3PAO assessments are now active. Organizations without a compliant program risk contract loss.

DFARS 252.204-7012

Requires adequate security per NIST SP 800-171 and mandates rapid reporting of cyber incidents to the DoD Cyber Crime Center.

ITAR / EAR

Export control violations carry criminal liability and debarment risk. Compliance must be integrated with your cybersecurity program — not siloed.

01

CMMC Readiness

CMMC 2.0Level 2Level 3C3PAO Prep

Project-based

CMMC compliance is a contractual requirement for organizations in the Defense Industrial Base handling Controlled Unclassified Information. We guide you from initial gap assessment through remediation, evidence collection, and C3PAO audit readiness — with a program designed to satisfy assessors and actually improve your security posture. We have direct experience with the self-assessment and third-party assessment pathways.

Frameworks & Regulations

CMMC 2.0 · NIST SP 800-171 Rev 2 · DFARS 252.204-7012

Scope Includes

  • CMMC Level 2 & Level 3 gap assessment and scoring
  • System Security Plan (SSP) development and review
  • POA&M development and milestone tracking
  • CUI boundary scoping and data flow mapping
  • Evidence collection and documentation packages
  • C3PAO assessment preparation and mock assessments
  • SPRS score calculation and submission guidance

02

NIST SP 800-171 Compliance

NIST 800-171CUIDFARSDIB

Project-based

NIST SP 800-171 forms the foundation of CMMC Level 2 and is a direct contractual requirement under DFARS for any organization handling Controlled Unclassified Information. We help organizations understand their current compliance posture, develop a credible remediation plan, and build the documentation infrastructure required by assessors and the DoD.

Frameworks & Regulations

NIST SP 800-171 Rev 2 · NIST SP 800-53 · DFARS 252.204-7012

Scope Includes

  • Full 110-control gap assessment across all 14 domains
  • System Security Plan (SSP) development
  • Plan of Action & Milestones (POA&M) management
  • CUI identification, scoping, and handling procedures
  • Configuration management and access control implementation support
  • Audit and accountability log coverage mapping
  • SPRS self-assessment scoring and submission

03

ITAR / DFARS Compliance

ITAREARDFARSExport Control

Project-based

ITAR and EAR compliance is a legal obligation for companies that manufacture, export, or broker defense articles and services. Non-compliance carries criminal liability, debarment risk, and potential loss of export privileges. We help organizations understand their ITAR obligations, implement compliant processes, and integrate export control requirements with their broader cybersecurity program.

Frameworks & Regulations

ITAR (22 CFR 120-130) · EAR (15 CFR 730-774) · DFARS 252.204-7012

Scope Includes

  • ITAR applicability assessment and commodity jurisdiction analysis
  • Technical data control program design
  • Foreign national access controls and visitor procedures
  • DFARS cybersecurity clause gap assessment
  • Integration of ITAR controls with CMMC/800-171 programs
  • Employee training program design for export compliance
  • Voluntary self-disclosure preparation support

04

Defense Security Assessments

DIBNIST 800-53Supply ChainDefense

Project-based

Security assessments for defense contractors require understanding the unique threat landscape, classification requirements, and regulatory obligations of the DIB. Our defense assessments go beyond standard commercial frameworks to account for nation-state threat actors, supply chain integrity requirements, and the intersection of physical and cyber security common in defense environments.

Frameworks & Regulations

NIST SP 800-53 · NIST SP 800-161 · CMMC 2.0

Scope Includes

  • DIB-specific threat modeling and risk assessment
  • NIST SP 800-53 control assessments for federal suppliers
  • Supply chain risk management (SCRM) program design
  • Defense subcontractor flow-down requirements review
  • Insider threat program assessment
  • Physical and cyber security convergence review

Working toward CMMC or managing ITAR obligations?

Let's talk through your specific situation and timeline.

Get in Touch