CMMC & NIST SP 800-171
You do not have to see yourself as a defense company. If a customer has flowed down DFARS 252.204-7012 - or a contract names CMMC or NIST SP 800-171 - the obligation is already yours. We scope what actually applies, close the security gaps and prepare the System Security Plan and evidence your defense supply-chain position requires.
What this actually is
"CMMC", "800-171" and "DFARS" get used interchangeably. They are not the same document, and knowing which one binds you is half the work.
110 security requirements for protecting Controlled Unclassified Information (CUI) on non-federal systems. It is not a certification. It is pulled into your contract by clause, and you meet it whether or not anyone audits you this year.
The Defense Federal Acquisition Regulation Supplement clause that obliges a contractor - and its subcontractors - to implement NIST SP 800-171 and report cyber incidents. If this clause is in your contract, the obligation is already live.
The Cybersecurity Maturity Model Certification program layers assessment on top of 800-171: self-assessment at Level 1, third-party (C3PAO) assessment at Level 2. The program rule took effect, but the Department suspended the Phase II rollout on 10 July 2026 pending a 60-day review. The underlying 800-171 obligation did not pause with it.
A System Security Plan describing how each requirement is met, and a Plan of Action and Milestones for what is not yet closed. These are the artifacts an assessor - or a prime doing due diligence - asks for first.
Who it reaches
None of these companies would call themselves a defense contractor. Each is subject to NIST SP 800-171 because of what it won and what information it handles.
What we deliver
Whether your systems actually handle CUI, and where the boundary sits. Most cost and most risk come from scoping this too wide - or discovering too late it was drawn too narrow. We establish it before you spend.
Where you stand against NIST SP 800-171, with each requirement marked met, partial or open, and the SPRS score that follows from it - so your position is a number you can defend, not a claim.
The SSP that describes how each control is met, and a realistic Plan of Action and Milestones for the rest. The documents a prime's due diligence and a C3PAO assessment both start from.
Prioritised, owned and mapped onto how your business operates - access control, incident response, media protection, configuration management - not a control set bolted on beside the work.
If you already run ISO 27001 or are heading for SOC 2, much of the evidence carries over. We map 800-171 onto what you have so you build one management system, not a parallel one for the contract.
Where the CMMC program stands, what your contract requires today versus what a level assessment will require, and how to be ready for the assessment without waiting for it to be scheduled.
Kellwick prepares you for CMMC and NIST SP 800-171. Level 2 CMMC assessments are performed by an accredited third-party assessment organisation (C3PAO); Level 1 is a self-assessment you attest to. We are not an assessor or certification body and cannot guarantee an assessment outcome.
FAQ
What actually binds you, whether it reaches you at all, and where Kellwick stops.
Because the obligation follows the contract and the information, not your self-description. A manufacturer, a software supplier, an engineering firm or a managed service provider becomes subject to NIST SP 800-171 the moment a customer flows down DFARS 252.204-7012 and CUI reaches your systems. Plenty of companies caught by this would never call themselves 'defense' - they simply won work that sits somewhere in a federal or defense supply chain. The first useful step is establishing whether CUI actually touches your systems at all; for some companies the honest answer is no, and that is worth confirming before you spend anything.
The Department suspended the Phase II rollout of the CMMC program on 10 July 2026 pending a 60-day review, so the timeline for third-party assessments being written into contracts is in flux. What did not pause is NIST SP 800-171 itself: where DFARS 252.204-7012 is already in your contract, implementing the 110 requirements, maintaining a System Security Plan and reporting cyber incidents are live obligations regardless of the CMMC assessment schedule. Treating the suspension as a reason to stop is the mistake - it is the window to get the SSP and evidence right before an assessment requirement lands.
No. Kellwick is an independent readiness advisory. Level 1 CMMC is a self-assessment you attest to; Level 2 assessments are performed by an accredited third-party assessment organisation (a C3PAO), not by us. We prepare you for that - scope, gap assessment, SSP, POA&M, remediation and evidence - and we are explicit about the boundary: we cannot issue a certificate or guarantee an assessment outcome.
A lot of the operating evidence - access control, change management, incident response, configuration and media handling - maps onto NIST SP 800-171 requirements, so you are not starting from zero. But the two are not the same shape: 800-171 is a prescriptive control set tied to a CUI boundary and an SPRS score, where ISO 27001 is a management system you certify. We map what you already produce onto the 800-171 requirements, then work only the genuine gaps, so you run one programme rather than two.
Before you spend on remediation: is CUI even in scope, what is your 800-171 position, and what does a CMMC assessment add? We start there.