NIST 800-171 and CMMC readiness for submarine industrial base suppliers
I ran compliance inside the Electric Boat supply chain for 8 years. Now I do it for suppliers your size.
Gap assessment, System Security Plan, and a defensible SPRS score in three weeks. Fixed fee. Delivered by the person who did the work, not a team learning it on your budget.
Verifiable track record
- 8 years
- NIST 800-53/171, DFARS, and CMMC compliance in the GD Electric Boat supply chain
- CISSP, CCSP
- ISC2 certified. CompTIA SecurityX and CySA+, both DoD 8140 baseline
- 7 tools
- Production security and compliance applications, built and secured in-house
- 3 weeks
- Kickoff to delivered SSP, POA&M, and SPRS score
The problem
A DFARS clause showed up in your contract. Nobody at your company owns compliance. Your MSP handles the firewall but not the paperwork. The one consultant who called back quoted six figures and eight months.
DoD is expected to begin putting mandatory CMMC Level 2 requirements into applicable contracts in November 2026. At that point a supplier without a defensible SSP and SPRS score is not carrying a compliance risk. They are an ineligible bidder.
Why me
Eight years on the side of the table that asks.
I administered these regulations from the inside.
Five years as Cybersecurity Compliance Manager at Unisys supporting the General Dynamics Electric Boat account, three before that as a security engineer on the same account through DXC. NIST 800-53 and 800-171, DFARS, CMMC, SOX. Recurring audits, control validation, remediation governance, and biweekly risk briefings to the CIO.
I know what an assessor actually asks for.
The difference between a control that is implemented and a control you can prove was implemented is where small suppliers lose. I spent years on the side of the table that asks.
I built the tooling.
POA&M Tracker, AIBOM Studio, SecBaseline, and four other production applications, all mine, all live, all free to use. That is why three weeks is a real timeline rather than a promise.
You work with me.
Not an account manager, not a junior analyst. Direct access, fixed fees, scope agreed before anything starts.
I will tell you if you do not need me.
If your flowdown does not reach you or your existing SSP holds up, I will say so.
What I do
Three offers. Fixed fees. Visible prices.
NIST 800-171 Readiness Sprint
$7,500 flat · 3 weeks
All 110 controls assessed, a System Security Plan that matches reality, a POA&M with owners and dates, and an SPRS score you can defend.
See what’s included →AI Governance Package
$6,500 flat · 2 weeks
AI system inventory, usage policy, and risk assessment mapped to NIST AI RMF and ISO/IEC 42001, plus EU AI Act applicability analysis.
See what’s included →Fractional Security and Compliance Lead
from $4,000/mo
Senior security ownership without a senior security salary.
See what’s included →
Tools, free, no signup
Seven production applications. Six featured here.
- SecBaselineSTIG and CIS findings in plain English, mapped to NIST 800-53secbaseline.com ↗
- POA&M TrackerRMF-focused POA&M and continuous monitoring managementpoamtracker.com ↗
- AIBOM StudioAudit-ready AI Bills of Materials for NIST AI RMF and ISO 42001aibom.studio ↗
- Attack BranchSTRIDE threat models and attack trees from a system descriptionattackbranch.com ↗
- Phishing SonarPhishing triage with client-side PII redaction and STIX 2.1 exportphishingsonar.com ↗
- Bump In The LogLog timelines mapped to MITRE ATT&CKbumpinthelog.com ↗
Use them without talking to me. If they are useful, you know how I think.
Common questions
NIST 800-171, CMMC, and SPRS, answered.
When does CMMC Level 2 become mandatory?
DoD is expected to begin putting mandatory CMMC Level 2 requirements into applicable contracts in November 2026. From that point, a supplier without a defensible System Security Plan and SPRS score is an ineligible bidder, not just a compliance risk.
Is this the same as CMMC certification?
No. Formal CMMC certification is performed only by an authorized C3PAO. The Readiness Sprint gets you ready for that assessment, or gets your self-assessment to a place you can defend. It is readiness preparation, not a certification assessment.
What is an SPRS score?
SPRS is the Supplier Performance Risk System, where DoD contractors post their NIST 800-171 self-assessment score. I calculate yours per DoD methodology with the arithmetic shown, so you can explain any number to a prime or an assessor.
Do I need this if I have a DFARS 252.204-7012 clause in my contract?
If DFARS 252.204-7012 flows down to you and you receive or generate CUI, you are already obligated to implement NIST 800-171. If your flowdown does not actually reach you, or your existing SSP holds up, I will tell you so.
How long does a NIST 800-171 readiness assessment take?
Three weeks from kickoff to a delivered System Security Plan, POA&M, and SPRS score. Week one is scoping and boundary definition, week two is the control-by-control assessment, week three is drafting and the executive readout.
How much does it cost?
The NIST 800-171 Readiness Sprint is $7,500 flat, split 50% at kickoff and 50% on delivery. No hourly billing and no change orders unless you change scope. For context, a C3PAO assessment itself runs $30,000 to $150,000.
Not sure whether any of this reaches you?
Twenty minutes, no pitch. Tell me what showed up in your contract and I will tell you what it actually requires.