Federal & Defense / FOCUSED SERVICE

NIST SP 800-171

Mapping where sensitive information lives, a scoped gap assessment against NIST 800-171 with the DoD scoring method, SSP and POA&M, and your score submission.

WHAT THIS SERVICE ADDRESSES

The challenge behind the engagement.

This service is for a contractor that must protect sensitive government information and post a security score for it. We find that information first: which contracts require it, which data counts, where it sits across mail, file storage, engineering tools, and business systems, and what flows to subcontractors. We choose the architecture, a walled-off enclave, your whole enterprise, or a hybrid, and gather evidence that any cloud service holding the information meets the required protection level. We assess all 110 requirements against their objectives and apply the DoD scoring method, then note where the newer edition differs so fixes made now hold up later. We write the system security plan and remediation plan and align your incident response to the fast reporting and evidence-preservation duties your contract sets. We never promise a score; it reflects what is in place.

WHEN THIS IS THE RIGHT FIT

Manufacturers, engineering firms, and research organizations that received a requirement from a prime or a solicitation asking for a security score, often with sensitive information already sitting in everyday cloud email and file tools and no current plan in place.

THE WORK BEHIND THE SERVICE

What we do.
What you can use.

Find the information and choose the architecture

We begin with your contracts and the requirements they flow down, then trace the sensitive information through email, file storage, engineering and design tools, and business systems into a clear data-flow map. With that map we decide enclave, enterprise, or hybrid, list every cloud service that touches the information, and gather the protection-level evidence your contract requires for each.

Score the 110 requirements the DoD way

Requirement by requirement we test the objectives across how people sign in, how devices are managed, how threats are detected, how logs are kept, and how encryption is validated, then apply the DoD scoring method to reach your score. We note where the newer edition’s wording differs so the fixes you make now hold up later.

Deliver the plan, remediation, and score record

You receive the data-flow map, a scoping memo, an objective-level gap report with your projected score, the system security plan, a dated remediation plan, a policy set, and a roadmap ordered by point value. We support your score submission, prepare control owners for a government-led assessment, and retest fixes with dated evidence.

IS THIS THE RIGHT ENGAGEMENT?

Who it’s for.
When you need it.

BEST SUITED FOR
  • Manufacturers and engineering firms that received a 7012 flowdown from a prime
  • Research organizations holding CUI in commercial Microsoft 365 with no current SSP
  • Contractors that must post a Basic Assessment score under DFARS 252.204-7020
  • Suppliers choosing between a GCC High enclave and an enterprise-wide boundary
WHEN IT’S TIME TO ENGAGE
  • A solicitation asks for an SPRS score you have never calculated
  • A prime demands proof that CUI is protected before awarding work
  • A DIBCAC Medium or High assessment is scheduled for your systems
  • Cyber incident reporting duties apply and no response plan is documented
AGREED AROUND YOUR ENVIRONMENT

What the scope can include.

  • Find the sensitive information across contracts, mail, file storage, and business systems

  • Choose the architecture, enclave, enterprise, or hybrid, and set provider responsibilities

  • Gather protection-level evidence for every cloud service that holds the information

  • Assess all 110 requirements against their objectives with the DoD scoring method

  • Review the newer edition so new controls are designed to its structure

  • Align incident response to the fast reporting and evidence-preservation duties

TRANSPARENT PRICING

What it typically costs.
One rate: $150/hour.

Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.

Small
$7,500–$15,000

Under 50 employees, one office, mostly cloud tools

About 50–100 hours
Mid-size
$15,000–$27,000

50–250 employees, mix of cloud and on-site systems, up to three locations

About 100–180 hours
Large
$27,000–$48,000

250+ employees, several sites, engineering or manufacturing systems in scope

About 180–320 hours
WHAT MOVES THE PRICE
  • Where sensitive defense information lives and how many systems touch it
  • Number of employees and locations
  • Existing documentation and security tooling
  • Outside IT providers whose controls must be accounted for
TYPICAL TIMELINE

4–6 weeks for small firms; 8–12+ weeks for larger, multi-site organizations

No third-party fee is required for a self-assessment score; if a contract later requires CMMC certification, the C3PAO is paid separately.

Get a fixed quote for your scope

Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.

TANGIBLE DELIVERABLES

What you take forward.

  • Data-flow map and scoping memo naming every system and provider that touches the information
  • Gap report with objective-level results and a projected score
  • System security plan, remediation plan, policy set, and a roadmap ordered by point value
  • Score submission record and preparation notes for a government-led assessment

Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.

SERVICE-SPECIFIC QUESTIONS

Before we get started.

Which edition applies, and when will that change?

The earlier edition today. The standards body has published a newer edition, but the government contract clause still points to the earlier one until that changes, and the certification program relies on the same edition. The newer edition reorganizes the requirements and adds agency-set parameters, and the government has published its parameter choices as a signal that a move will eventually come. We assess and score you against the edition your contract requires today and note where the newer wording differs, so the controls you build now will not need rework.

How is this different from CMMC Level 2 readiness?

Same 110 requirements, different obligation. This service covers the duty written into your contract: protect the information, report incidents quickly, keep a current plan, and post a score that can fall below zero. CMMC Level 2 adds a formal program on top: sorting your assets, scoring by a fixed method, limits on what can sit unfinished, annual affirmations, and eventually a third-party certification. If you have never scored yourselves, start here; if you already post a score and expect a certification requirement, our CMMC Readiness service picks up from this baseline.

REFERENCE POINTS
START AT THE SOURCE

Let’s find your next move.

A focused conversation. A clear scope. A practical path to stronger security.

Let’s talk security