AccuSights
Partners
Book my 30-minute demo

Government & Defense Contractors · Cybersecurity, compliance and GRC, in plain English

A pause is not a pardon. Be ready before the queue forms.

The Department paused the Phase 2 certification mandate on July 13, 2026. DFARS 7012, the 72-hour incident clock, SPRS score posting and Phase 1 self-assessments all kept running, and primes still ask. We get you to 110 with a defensible SSP, a clean POA&M and, if you want it, a CUI enclave that shrinks your scope.

Practitioner-led, CRISC and CISAFrom $6,000Enclave partner for CUI

The test is scored against CIS Controls v8.1 IG1 and the CIS Community Defense Model. You see your score immediately, then we talk if you want to.

A story we hear too often

The 40-person machine shop that is one link in a national supply chain

the owner of a precision machine shop that makes parts for a prime’s missile program

Frank’s shop in Rockford makes forty-one parts. Nobody outside the program knows what they go into, and Frank likes it that way. Forty people, three shifts when the prime is busy, and a drawing package marked CUI that arrives by email because that is how the prime sends it.

A Tuesday in September. The prime’s supplier-security team calls: a leak site is advertising files from ‘a Midwest defense machine shop,’ and the sample includes a drawing with the program number on it. Frank does not know yet whether it is his.

In the version that becomes a national-security story, it is his. The drawings sat on a shared drive with the office email, the CAM vendor’s remote-access box was never patched, and the 72-hour DFARS 7012 clock started three days ago without anyone knowing. The prime suspends the supplier, and the SPRS score Frank posted is now a false statement.

In Frank’s version, the CUI never touched the shared drive. It lives in the enclave, the remote-access box was patched the week the vulnerability was published, and the engineer on watch can show the prime, that afternoon, which files left. None did. The sample belongs to another shop. Frank sends the prime his SSP and his incident log by five.

A leak site is advertising files from ‘a Midwest defense machine shop,’ and the sample includes a drawing with the program number on it.

What changes the ending

  1. CUI contained in an enclave, away from the office email and the shared drive (NIST 800-171 3.1 and 3.13; CIS Control 3, Data Protection)
  2. Remote-access and vendor connections inventoried and patched against the CISA Known Exploited Vulnerabilities list (CIS Controls 7 and 15)
  3. A 72-hour incident reporting procedure rehearsed, with logs that show what left and what did not (NIST 800-171 3.6; CIS Controls 8 and 17)
Show me this running for my business

The questions owners are afraid to ask

Ask them anyway. Here are the answers.

We are a 40-person shop. Why does a breach here become a national-security story?

Because a drawing package for a missile or an aircraft part is exactly what a foreign intelligence service wants, and small suppliers are the easiest place to get it. The prime knows that, which is why the supplier-security call comes to you and not to their CISO.

What does Governance, Risk and Compliance mean for a shop our size?

Governance, Risk and Compliance (GRC), simplified for a supplier, means one control set (NIST 800-171), one place the evidence lives (the SSP and the enclave), one person who owns it, and a rehearsed 72-hour procedure. No consulting army, no six-month discovery, and a score you can defend to a prime.

If we find out we were breached, what happens in the first 72 hours?

You contain, you preserve the logs, you determine which CUI was touched, and you report to DIBNet within 72 hours of discovery with a medium-assurance certificate you already hold. Shops that have rehearsed this do it in a day; shops that have not miss the clock and learn about it from the prime.

What you hold, and why someone wants it

Your data protection needs, by the data.

Controlled Unclassified Information: drawings, specifications, program data

The data a foreign service wants and a contract requires you to protect under DFARS 7012. An enclave, NIST 800-171 controls and access limits protect it.

The SSP, POA&M and SPRS score

A posted score with no evidence behind it is a false statement to the government. A documented assessment and a current SSP protect you.

The shop-floor network and controllers

Unpatchable controllers on the office network are the path from a phishing email to a stopped spindle. Segmentation protects them.

Remote access and vendor connections

The CAM vendor’s box and the VPN nobody patched are how 38% of manufacturing breaches begin. Inventory and patching protect them.

Employee records, payroll and supplier payments

Business email compromise does not care that you are a defense supplier. MFA and call-back verification protect them.

110
NIST SP 800-171 controls your contracts still require today, with a 72-hour incident clock that never paused
Source: DFARS 252.204-7012; NIST SP 800-171 Rev 2
~100
authorized C3PAOs for more than 100,000 defense companies, the capacity gap the Department cited when it paused Phase 2
Source: DoD CIO statement, July 13, 2026 (reported by DefenseScoop and Federal News Network)
61%
of manufacturing breaches involved ransomware, and 61% involved a third party. Vulnerability exploitation opened 38% of them
Source: Verizon 2026 Data Breach Investigations Report, Manufacturing snapshot

What applies to you

The rules, in one page, with the dates that matter.

CMMC 2.0 (32 CFR Part 170, 48 CFR DFARS rule)
US Department of War (DoD)
Level 1 and Level 2 self-assessments in applicable solicitations since November 10, 2025; certification is a condition of award under DFARS 252.204-7021.
Phase 2 (C3PAO certification, due November 10, 2026) suspended July 13, 2026 pending a Reform Task Force report due to the CIO within 60 days, on or about September 13, 2026.
DFARS 252.204-7012
DoD
NIST SP 800-171 Rev 2 compliance, 72-hour cyber incident reporting to DIBNet, FedRAMP Moderate-equivalent cloud for CUI.
Rev 2 remains the contractual baseline under Class Deviation 2024-O0013; Rev 3 is not yet adopted.
DFARS 252.204-7019 and 7020
DoD
A current NIST 800-171 self-assessment score posted in SPRS (range -203 to 110), and DoD access to assess.
FedRAMP (Consolidated Rules 2026)
GSA FedRAMP PMO
Cloud services handling federal data; Rev 5 authorizations sunset December 31, 2028.
CJIS Security Policy 6.0
FBI
Contractors handling criminal justice information: stronger identity, MFA, cloud and encryption controls.
Full compliance expected by October 1, 2027.

Verified September 2026 from the regulators' own publications. We map all of it to one control set so evidence is produced once.

A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. We help interpret the requirements, scope what applies, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify.

The threat picture

What actually goes wrong, and what we do about it.

  • Losing a bid because the SPRS score is stale, unsupported by an SSP, or lower than the prime expects.
  • CUI scattered across personal email, consumer cloud and unmanaged laptops, multiplying the assessment scope.
  • A 72-hour reporting obligation your team has never rehearsed.

It happened to businesses like yours

A ransomware attack on Collins Aerospace’s MUSE check-in software over the weekend of September 19, 2025 forced Heathrow, Brussels and Berlin airports onto manual check-in for days; ENISA confirmed ransomware and the supplier is an RTX subsidiary.

September 2025 · Wikipedia summary with ENISA confirmation

The Akira ransomware gang claimed a September 2025 breach at BK Technologies, a publicly traded maker of radios for police, military and government agencies, the kind of small supplier a prime depends on.

September 2025 · Comparitech

Public incidents, listed to show the pattern, never to shame a victim.

Protect, for a defense business

We protect your people, every device, the servers and the website. Day and night.

  • We protect your employees’ inboxes, where the spoofed prime and the fake supplier invoice arrive.
  • Every laptop, engineering workstation and front-office PC, inside and outside the enclave.
  • The server, the file share and the enclave holding CUI, with logs that show what moved.
  • The shop-floor network, segmented so an infected office PC cannot reach a controller.
  • The cloud apps: Microsoft 365 GCC or GCC High, the enclave, ERP, remote access and the prime’s portals.
  • Day and night, with an AI agent that contains a threat in seconds and a named human engineer watching, and a 72-hour reporting procedure ready.

Think of it as a per-employee service, like payroll. Except that this is the one corner that, if you cut it, can empty the account and take the business with it. We have your back.

How Protect works →

Where we start

Cybersecurity and Data Protection Assessment for Defense Suppliers

Governance, Risk and Compliance (GRC), simplified for a supplier: one control set, one evidence home, one owner, one rehearsed 72-hour procedure. Built on the CIS Controls v8.1 IG1 and mapped to NIST SP 800-171, scoped from what a supplier stands to lose: the contract, the clearance of trust with the prime, and the program.

  • CUI scoping and data-flow map: where controlled data lives, moves and can be contained (NIST 800-171; CIS Controls 1, 2 and 3)
  • Inventory of every controller, workstation, server, remote-access path and cloud service, including the CAM vendor’s box (CIS Controls 1, 2 and 15)
  • Shop-floor segmentation plan and enclave recommendation: Microsoft 365 Commercial, GCC, GCC High or an encrypted CUI enclave (CIS Control 12)
  • Account audit: shared logins, ex-employee access, MFA on email, ERP, remote access and the enclave (CIS Controls 5 and 6)
  • 72-hour DFARS 7012 incident procedure written and rehearsed, with the logs to support it (CIS Controls 8 and 17)
  • Defensible SPRS estimate, distance to 110 and a ranked remediation plan that feeds the Gap Readiness package with the work credited
Start with the 3-minute test

Packages

Built for defense businesses, with the price on the page.

CMMC Level 2 Gap Readiness Package

A fixed-scope package for defense suppliers who need a defensible SPRS score, an SSP a C3PAO will accept and a remediation path that fits a small company.

From $6,000published price
3 to 5 weeks to the delivered gap assessment, SSP and POA&M
Details →

CMMC Self-Assessment and SPRS Score Calculation

The simplest step a defense supplier can take this quarter: a guided self-assessment against all 110 controls, the DoD scoring methodology applied correctly (1, 3 and 5-point weights, from -203 to 110), the quick wins that move the score most, and a number you can post in SPRS and defend to a prime..

Fixed feescoped in 30 minutes
1 to 2 weeks
Details →

Mock Audit Package: SOC 2, HIPAA or CMMC

We run your audit before your auditor does: the same evidence requests, the same interviews, the same sampling, the same findings language.

Fixed feescoped in 30 minutes
1 to 3 weeks depending on framework and scope
Details →

Governance, Risk and Compliance (GRC), simplified

The discipline the largest institutions run, sized for a business that cannot hire a department for it.

Governance, Risk and Compliance is how a bank or a hospital system decides what to protect, proves it is protected, and shows a regulator the evidence. We ran it for those institutions. We now run it for the 30-person supplier, the medical practice and the defense subcontractor, because that is where the supply chain is thinnest and where a breach does the most damage, sometimes to more than one company.

Governance

Who owns security, which policies are real, and what the owner signs. One page, not a binder.

Risk

What could stop the business, ranked by likelihood and cost, refreshed as the threats change, not once a year.

Compliance

The evidence a regulator, a prime contractor or a customer asks for, produced once and kept current every day.

A defense contractor with 40 people is a link in a national supply chain. A breach there is not a small-business story; it is a national-security one. The same is true, at a smaller scale, for the accounting firm that holds 900 client returns and the clinic that holds 12,000 patient records.

Questions owners ask

Straight answers.

CMMC Phase 2 is paused. Should we wait?
No. Phase 1 self-assessments, DFARS 7012, 7019 and 7020 are in force, primes are flowing requirements down now, and the reform task force is reviewing cost and assessor capacity, not the underlying NIST 800-171 obligation. Contractors that use the pause to reach 110 with a clean SSP win the contracts when the queue forms.
What is a good SPRS score?
The scale runs from -203 to 110. Level 2 self-assessment requires 110, or a conditional status at 88 or above with a POA&M for eligible items, and every 1-point item met. Our free check estimates where you stand; the gap package produces the defensible number.
Are you a C3PAO?
No, and we say so plainly. We are the readiness partner that gets you through a C3PAO assessment the first time: gap assessment, SSP, POA&M, remediation, enclave and a mock assessment run the way the assessor will run it.

People also search: CMMC consultant near me · CMMC gap assessment in Chicago · for a 40-person defense machine shop · for a Rockford precision manufacturer · NIST 800-171 help for small suppliers · CMMC readiness for an engineering firm · for a subcontractor to a major prime · CUI enclave setup in the Midwest

Never too big or too small

Let's talk about your cyber anxieties. Thirty minutes with an engineer.

3-min test