NIST 800-171 and CMMC readiness for submarine industrial base suppliers

I ran compliance inside the Electric Boat supply chain for 8 years. Now I do it for suppliers your size.

Gap assessment, System Security Plan, and a defensible SPRS score in three weeks. Fixed fee. Delivered by the person who did the work, not a team learning it on your budget.

Verifiable track record

8 years
NIST 800-53/171, DFARS, and CMMC compliance in the GD Electric Boat supply chain
CISSP, CCSP
ISC2 certified. CompTIA SecurityX and CySA+, both DoD 8140 baseline
7 tools
Production security and compliance applications, built and secured in-house
3 weeks
Kickoff to delivered SSP, POA&M, and SPRS score

The problem

A DFARS clause showed up in your contract. Nobody at your company owns compliance. Your MSP handles the firewall but not the paperwork. The one consultant who called back quoted six figures and eight months.

DoD is expected to begin putting mandatory CMMC Level 2 requirements into applicable contracts in November 2026. At that point a supplier without a defensible SSP and SPRS score is not carrying a compliance risk. They are an ineligible bidder.

Why me

Eight years on the side of the table that asks.

  • I administered these regulations from the inside.

    Five years as Cybersecurity Compliance Manager at Unisys supporting the General Dynamics Electric Boat account, three before that as a security engineer on the same account through DXC. NIST 800-53 and 800-171, DFARS, CMMC, SOX. Recurring audits, control validation, remediation governance, and biweekly risk briefings to the CIO.

  • I know what an assessor actually asks for.

    The difference between a control that is implemented and a control you can prove was implemented is where small suppliers lose. I spent years on the side of the table that asks.

  • I built the tooling.

    POA&M Tracker, AIBOM Studio, SecBaseline, and four other production applications, all mine, all live, all free to use. That is why three weeks is a real timeline rather than a promise.

  • You work with me.

    Not an account manager, not a junior analyst. Direct access, fixed fees, scope agreed before anything starts.

  • I will tell you if you do not need me.

    If your flowdown does not reach you or your existing SSP holds up, I will say so.

What I do

Three offers. Fixed fees. Visible prices.

  • NIST 800-171 Readiness Sprint

    $7,500 flat · 3 weeks

    All 110 controls assessed, a System Security Plan that matches reality, a POA&M with owners and dates, and an SPRS score you can defend.

    See what’s included →
  • AI Governance Package

    $6,500 flat · 2 weeks

    AI system inventory, usage policy, and risk assessment mapped to NIST AI RMF and ISO/IEC 42001, plus EU AI Act applicability analysis.

    See what’s included →
  • Fractional Security and Compliance Lead

    from $4,000/mo

    Senior security ownership without a senior security salary.

    See what’s included →

Common questions

NIST 800-171, CMMC, and SPRS, answered.

When does CMMC Level 2 become mandatory?

DoD is expected to begin putting mandatory CMMC Level 2 requirements into applicable contracts in November 2026. From that point, a supplier without a defensible System Security Plan and SPRS score is an ineligible bidder, not just a compliance risk.

Is this the same as CMMC certification?

No. Formal CMMC certification is performed only by an authorized C3PAO. The Readiness Sprint gets you ready for that assessment, or gets your self-assessment to a place you can defend. It is readiness preparation, not a certification assessment.

What is an SPRS score?

SPRS is the Supplier Performance Risk System, where DoD contractors post their NIST 800-171 self-assessment score. I calculate yours per DoD methodology with the arithmetic shown, so you can explain any number to a prime or an assessor.

Do I need this if I have a DFARS 252.204-7012 clause in my contract?

If DFARS 252.204-7012 flows down to you and you receive or generate CUI, you are already obligated to implement NIST 800-171. If your flowdown does not actually reach you, or your existing SSP holds up, I will tell you so.

How long does a NIST 800-171 readiness assessment take?

Three weeks from kickoff to a delivered System Security Plan, POA&M, and SPRS score. Week one is scoping and boundary definition, week two is the control-by-control assessment, week three is drafting and the executive readout.

How much does it cost?

The NIST 800-171 Readiness Sprint is $7,500 flat, split 50% at kickoff and 50% on delivery. No hourly billing and no change orders unless you change scope. For context, a C3PAO assessment itself runs $30,000 to $150,000.

Not sure whether any of this reaches you?

Twenty minutes, no pitch. Tell me what showed up in your contract and I will tell you what it actually requires.