NIST 800-171 and CMMC help for small manufacturers
If you make parts that end up in defense work, your customers may already be asking about NIST 800-171 or CMMC. Even if you don't, bigger customers are sending security questionnaires that ask the same kinds of questions. This page explains what's involved and how we help, in plain English.
What these are, briefly
- NIST SP 800-171 is a set of security requirements for companies that handle Controlled Unclassified Information (CUI), such as certain drawings and specs from defense contracts.
- CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense program that checks whether contractors actually meet those requirements. The level you need depends on the information you handle and what your contract says.
- Customer questionnaires from non-defense customers often borrow from the same requirements.
Sources: NIST SP 800-171 Rev. 2, the version defense contracts and CMMC Level 2 currently use, and Rev. 3 (NIST CSRC); CMMC program (DoD CIO). The CMMC timeline is changing; we'll tell you where it stands when we talk.
How we help
- Find out what applies. We look at your contracts and the data you handle, so you know whether you need CMMC at all, and at what level.
- Gap review. We compare how you work today against the requirements and give you a prioritised list.
- Fix the IT side. MFA, access control, logging, encryption, backups and the rest of the technical controls, set up and maintained.
- Write it down. Help with your System Security Plan and the policies that go with it.
- Stay compliant. Ongoing monitoring and evidence, so next year isn't a scramble.
What we are, and aren't
We help you get ready and stay ready. We're not a CMMC Third-Party Assessment Organization (C3PAO), and we don't certify you; an accredited assessor does that.
Start with the scope
The first useful question is "what do we actually have to protect, and where is it?" Our readiness assessment answers that, and keeping CUI in a smaller part of your network can cut the cost of everything that follows.
The technical controls overlap heavily with what insurers ask for. See cybersecurity and insurance readiness.
Not sure where you stand?
Our Manufacturing Cyber-Risk & Insurance Readiness Assessment gives you a written, plain-English picture of your security, backups and insurance gaps, with a fixed quote to fix them, valid for 30 days.
Get the Assessment or call (800) 619‑5494 Send us your customer's questionnaire