Defense contractors handling CUI have one job: demonstrate that all 110 NIST SP 800-171 r2 controls are implemented, documented, and defensible. We handle the gap analysis, build your SSP and POA&M, guide remediation, and get you assessment-ready. Backed by Cy3 Security's 20-year defense cybersecurity practice and a purpose-built GRC platform that tracks every one of the 110 controls in real time.
The single most common reason contractors fail or get rescheduled is not missing technical controls - it's a System Security Plan that doesn't accurately describe the controls they already have. Under NIST SP 800-171 r2, every one of the 110 requirements must be documented with implementation details, responsible parties, and supporting policies. Assessors read your SSP line by line. Vague descriptions and undocumented systems are findings. We build documentation that holds up in the room.
Your SPRS self-attestation under DFARS 252.204-7019 is a legal representation to the federal government. If your score overstates your actual compliance posture, that is a False Claims Act problem. The DoJ has made cybersecurity misrepresentation an active enforcement priority. We calculate your real score against the NIST SP 800-171 DoD Assessment Methodology before anyone else does - so you know exactly where you stand.
DFARS 252.204-7012 requirements flow from the prime contractor down through every tier of the supply chain. Many small subcontractors in manufacturing, engineering, and logistics are in scope without realizing it. If your work touches a drawing, specification, or statement of work that contains CUI, you are required to implement all 110 NIST SP 800-171 r2 controls and document them in a compliant SSP. Your prime contractor's compliance posture depends on yours - and they know it.
A Plan of Action and Milestones is not a one-time document. Under CMMC and DFARS 252.204-7020, your POA&M must reflect current remediation status, scheduled completion dates, and responsible parties for every open finding. Most contractors treat it as a checkbox. Assessors treat it as evidence. We build and maintain a live POA&M that tracks every gap from identification through closure.
Every Cy3 Kindred engagement is backed by a purpose-built GRC platform developed by Cy3 Security and engineered by Kindred Technology Group. Your compliance posture needs to be accurate and defensible at all times - not in a spreadsheet that goes stale the day after it's built. The platform drives every deliverable we produce for you: the gap assessment, the SSP, the POA&M, and the SPRS score.
Most contractors build their SSP and POA&M in spreadsheets that go stale the moment anything changes. Our platform keeps your compliance posture synchronized with your actual environment at all times - so every deliverable we hand you reflects reality on the day your assessor reads it. That is the difference between documentation that passes and documentation that gets you rescheduled.
Cy3 Kindred is a joint practice built on Cy3 Security's 20-year defense cybersecurity background and Kindred Technology Group's engineering depth. We handle every phase of the readiness process: gap analysis against all 110 NIST SP 800-171 r2 controls, SSP and POA&M documentation, hands-on remediation, and assessment preparation — backed by a purpose-built GRC platform that keeps your compliance posture accurate and defensible.
A direct 45-minute conversation that confirms whether you handle FCI or CUI, which CMMC level applies under your specific contract language, and what your real obligations are. Many subcontractors in the Southeast are in scope without realizing it. DFARS 252.204-7012 requirements flow down through the entire supply chain. Free, no commitment.
Full assessment of your posture against all 110 NIST SP 800-171 r2 controls across all 14 families. We calculate your real SPRS score using the DoD Assessment Methodology and deliver a prioritized findings report - what you're missing, what it costs you in SPRS points, and what to fix first to maximize your score and minimize your exposure.
Advisory guidance on what to fix and how - plus hands-on technical implementation through our partner Kindred Technology Group. We prioritize remediation by SPRS point recovery so you get the most compliance improvement from every dollar spent.
Mock assessment, evidence packaging, and staff interview prep modeled on how a real C3PAO conducts their review. Most contractors who get rescheduled do so on documentation gaps and interview unreadiness - not missing controls. We close that gap before you're in the room. Includes a final review of your SSP and POA&M against the CMMC Assessment Guide criteria.
If your team uses ChatGPT, Copilot, or similar tools on work that touches CUI, those tools may fall inside your CMMC assessment boundary and must be documented in your SSP. Most readiness firms don't know how to scope this. We inventory every AI tool, map its CUI exposure to the relevant NIST 800-171 r2 controls, and build the SSP language that covers it before your assessor flags it.
A structured engagement moves through four phases: confirm your scope and obligations, assess your posture against all 110 controls, build the documentation and close the gaps, then prepare for assessment. Each phase builds directly on the last. The platform keeps everything synchronized so your documentation reflects your actual posture at every step.
A 45-minute working session with a practitioner - not a sales rep. We review your contract language, identify whether you handle FCI or CUI, confirm which CMMC level applies, and give you a straight answer on what your actual obligations are. No commitment, no pitch deck.
Our team conducts a hands-on assessment of your environment against all 110 NIST SP 800-171 r2 requirements. We calculate your real SPRS score per the DoD Assessment Methodology and deliver a prioritized findings report - what you have, what you're missing, and what to address first.
We author your System Security Plan, Plan of Action and Milestones, and the supporting security policies required by NIST SP 800-171 r2 - all based on your actual environment, not generic templates. Technical gaps get addressed by our implementation team. You work with one practice from assessment through remediation, so your documentation always reflects what you've actually built.
We run a structured mock assessment against the CMMC Assessment Guide criteria, package your evidence, and prepare your team for assessor interviews. When you walk into your C3PAO assessment, your documentation is complete, your staff knows what to expect, and your posture is defensible.
Cy3 Kindred was built by two practitioners who know the defense environment from the inside. One co-founder spent 20 years protecting Air Force and Navy systems. The other has spent 15 years building technology for government-adjacent clients and researching how institutions adopt and govern new technologies. Between them: the security depth to find real gaps and the documentation rigor to make the findings stick.
Ahmad began his cybersecurity career in the United States Air Force, where he built the foundation for two decades of protecting critical information systems. After separating from the Air Force in 2007, he continued serving the defense community as a military contractor before founding Cy3 Security - Cy3 Kindred's cybersecurity advisory partner. Through Cy3, he has delivered cybersecurity consulting and risk management to Air Force and Navy organizations, healthcare systems, and state agencies throughout Georgia and Alabama. Under his leadership, Cy3 developed the GRC platform that powers every Cy3 Kindred engagement - tracking all 110 NIST SP 800-171 r2 controls in real time and generating CUI-compliant SSPs, POA&Ms, and SPRS scores directly from live assessment data.
Redesigning Oversight for the Age of Intelligent Systems. Ahmad's published examination of governance, risk, and leadership in an era shaped by AI and autonomous technologies - the framework behind how we approach AI tool risk inside a CMMC boundary.
Dr. Kenley Obias brings the academic and applied AI research dimension that no pure-play cybersecurity firm can replicate. As an Ed.D.-credentialed AI researcher and Fulbright Specialist, he develops AI literacy frameworks, publishes peer-reviewed work on equitable AI deployment, and builds AI-powered systems for government-adjacent clients through Kindred Technology Group - Cy3 Kindred's technical implementation partner. At ASU, he serves on the AI Committee and co-leads research into applied AI in institutional settings. His active research into shadow AI risk, AI governance frameworks, and AI tool deployment in regulated environments is the methodological backbone of Cy3 Kindred's AI Boundary Assessment - grounded in evidence, not checklists.
DFARS 252.204-7012 requires contractors handling CUI to implement adequate security per NIST SP 800-171, report cyber incidents within 72 hours, and preserve images of compromised systems. Here is what those obligations mean in practice for a small defense subcontractor.
Read the guide →The DoD Assessment Methodology assigns specific point values to each of the 110 NIST SP 800-171 r2 controls. Starting from +110, each missing control deducts points. Understanding which controls carry the most weight - and which are most achievable - is the key to maximizing your score and minimizing your legal exposure.
Read the analysis →An SSP that doesn't accurately describe your implemented controls is the top reason CMMC assessments get rescheduled. We break down the five most common documentation errors small contractors make - and how each one creates both assessment failure risk and False Claims Act exposure under DFARS 252.204-7019.
Get the checklist →We respond within one business day. We don't share your information.