CMMC Level 2 • NIST SP 800-171 r2 • DFARS 252.204-7012

YOUR
DFARS EXPOSURE
IS REAL.

Defense contractors handling CUI have one job: demonstrate that all 110 NIST SP 800-171 r2 controls are implemented, documented, and defensible. We handle the gap analysis, build your SSP and POA&M, guide remediation, and get you assessment-ready. Backed by Cy3 Security's 20-year defense cybersecurity practice and a purpose-built GRC platform that tracks every one of the 110 controls in real time.

20+ Years Defense Cybersecurity • NIST 800-171 • DFARS • CMMC
0
NIST SP 800-171 r2 controls required for CMMC Level 2 certification
0
control families spanning access, incident response, media protection, and more
0
authorized C3PAOs serving 80,000+ contractors in the Defense Industrial Base
<1%
of the Defense Industrial Base is currently certified at Level 2
Why Most Contractors Aren't Ready

Most contractors don't know what they're missing.
We do.

Missing Documentation - Most Common Assessment Finding

The single most common reason contractors fail or get rescheduled is not missing technical controls - it's a System Security Plan that doesn't accurately describe the controls they already have. Under NIST SP 800-171 r2, every one of the 110 requirements must be documented with implementation details, responsible parties, and supporting policies. Assessors read your SSP line by line. Vague descriptions and undocumented systems are findings. We build documentation that holds up in the room.

Inaccurate SPRS Score - False Claims Act Exposure

Your SPRS self-attestation under DFARS 252.204-7019 is a legal representation to the federal government. If your score overstates your actual compliance posture, that is a False Claims Act problem. The DoJ has made cybersecurity misrepresentation an active enforcement priority. We calculate your real score against the NIST SP 800-171 DoD Assessment Methodology before anyone else does - so you know exactly where you stand.

Supply Chain Flowdown - Every Tier Is In Scope

DFARS 252.204-7012 requirements flow from the prime contractor down through every tier of the supply chain. Many small subcontractors in manufacturing, engineering, and logistics are in scope without realizing it. If your work touches a drawing, specification, or statement of work that contains CUI, you are required to implement all 110 NIST SP 800-171 r2 controls and document them in a compliant SSP. Your prime contractor's compliance posture depends on yours - and they know it.

POA&M Management - The Ongoing Obligation

A Plan of Action and Milestones is not a one-time document. Under CMMC and DFARS 252.204-7020, your POA&M must reflect current remediation status, scheduled completion dates, and responsible parties for every open finding. Most contractors treat it as a checkbox. Assessors treat it as evidence. We build and maintain a live POA&M that tracks every gap from identification through closure.

-47
Average SPRS score for a first-time small contractor self-assessment. The maximum is +110. Below zero means missing critical controls - and a negative score is visible to every prime contractor checking the Supplier Performance Risk System before awarding a subcontract.
72
Hours to report a cyber incident to DoD under DFARS 252.204-7012. The clock starts the moment you discover a breach. Most contractors don't have the incident response documentation, contact procedures, or evidence preservation process required to meet this obligation. We build it into your SSP from day one.
110
NIST SP 800-171 r2 requirements across 14 control families - every one must be documented in your SSP with implementation details, responsible parties, and supporting evidence. Our platform tracks all 110 in real time.

Cy3 Security GRC Platform

We don't use spreadsheets.
We built the platform.

Every Cy3 Kindred engagement is backed by a purpose-built GRC platform developed by Cy3 Security and engineered by Kindred Technology Group. Your compliance posture needs to be accurate and defensible at all times - not in a spreadsheet that goes stale the day after it's built. The platform drives every deliverable we produce for you: the gap assessment, the SSP, the POA&M, and the SPRS score.

Why It Matters

Your compliance posture is only as strong as the data behind it.

Most contractors build their SSP and POA&M in spreadsheets that go stale the moment anything changes. Our platform keeps your compliance posture synchronized with your actual environment at all times - so every deliverable we hand you reflects reality on the day your assessor reads it. That is the difference between documentation that passes and documentation that gets you rescheduled.

What the Platform Produces
CUI-formatted SSP covering all 110 NIST SP 800-171 r2 requirements
DoD-standard POA&M with prioritized remediation findings
Accurate SPRS score calculated per DoD Assessment Methodology
Supporting security policies mapped to specific control requirements
Signature-ready documents for System Owner and Authorizing Official

What We Do

We don't issue the certificate.
We get you ready to earn it.

Cy3 Kindred is a joint practice built on Cy3 Security's 20-year defense cybersecurity background and Kindred Technology Group's engineering depth. We handle every phase of the readiness process: gap analysis against all 110 NIST SP 800-171 r2 controls, SSP and POA&M documentation, hands-on remediation, and assessment preparation — backed by a purpose-built GRC platform that keeps your compliance posture accurate and defensible.

📋
APPLICABILITY CHECK

A direct 45-minute conversation that confirms whether you handle FCI or CUI, which CMMC level applies under your specific contract language, and what your real obligations are. Many subcontractors in the Southeast are in scope without realizing it. DFARS 252.204-7012 requirements flow down through the entire supply chain. Free, no commitment.

🔍
GAP ANALYSIS

Full assessment of your posture against all 110 NIST SP 800-171 r2 controls across all 14 families. We calculate your real SPRS score using the DoD Assessment Methodology and deliver a prioritized findings report - what you're missing, what it costs you in SPRS points, and what to fix first to maximize your score and minimize your exposure.

🔧
REMEDIATION SUPPORT

Advisory guidance on what to fix and how - plus hands-on technical implementation through our partner Kindred Technology Group. We prioritize remediation by SPRS point recovery so you get the most compliance improvement from every dollar spent.

ASSESSMENT PREPARATION

Mock assessment, evidence packaging, and staff interview prep modeled on how a real C3PAO conducts their review. Most contractors who get rescheduled do so on documentation gaps and interview unreadiness - not missing controls. We close that gap before you're in the room. Includes a final review of your SSP and POA&M against the CMMC Assessment Guide criteria.

🔐
AI TOOL SCOPING

If your team uses ChatGPT, Copilot, or similar tools on work that touches CUI, those tools may fall inside your CMMC assessment boundary and must be documented in your SSP. Most readiness firms don't know how to scope this. We inventory every AI tool, map its CUI exposure to the relevant NIST 800-171 r2 controls, and build the SSP language that covers it before your assessor flags it.

How It Works

From first call to assessment-ready.

A structured engagement moves through four phases: confirm your scope and obligations, assess your posture against all 110 controls, build the documentation and close the gaps, then prepare for assessment. Each phase builds directly on the last. The platform keeps everything synchronized so your documentation reflects your actual posture at every step.

1
FREE CHECK

A 45-minute working session with a practitioner - not a sales rep. We review your contract language, identify whether you handle FCI or CUI, confirm which CMMC level applies, and give you a straight answer on what your actual obligations are. No commitment, no pitch deck.

2
GAP ANALYSIS + SPRS SCORE

Our team conducts a hands-on assessment of your environment against all 110 NIST SP 800-171 r2 requirements. We calculate your real SPRS score per the DoD Assessment Methodology and deliver a prioritized findings report - what you have, what you're missing, and what to address first.

3
DOCUMENTATION + REMEDIATION

We author your System Security Plan, Plan of Action and Milestones, and the supporting security policies required by NIST SP 800-171 r2 - all based on your actual environment, not generic templates. Technical gaps get addressed by our implementation team. You work with one practice from assessment through remediation, so your documentation always reflects what you've actually built.

4
ASSESSMENT PREP + HANDOFF

We run a structured mock assessment against the CMMC Assessment Guide criteria, package your evidence, and prepare your team for assessor interviews. When you walk into your C3PAO assessment, your documentation is complete, your staff knows what to expect, and your posture is defensible.

The Team

Defense security experience.
Research-backed methodology. Real results.

Cy3 Kindred was built by two practitioners who know the defense environment from the inside. One co-founder spent 20 years protecting Air Force and Navy systems. The other has spent 15 years building technology for government-adjacent clients and researching how institutions adopt and govern new technologies. Between them: the security depth to find real gaps and the documentation rigor to make the findings stick.

Co-Founder • Cy3 Kindred
AHMAD AUSTIN
Co-Founder, Cy3 Kindred • CEO, Cy3 Security • USAF Veteran

Ahmad began his cybersecurity career in the United States Air Force, where he built the foundation for two decades of protecting critical information systems. After separating from the Air Force in 2007, he continued serving the defense community as a military contractor before founding Cy3 Security - Cy3 Kindred's cybersecurity advisory partner. Through Cy3, he has delivered cybersecurity consulting and risk management to Air Force and Navy organizations, healthcare systems, and state agencies throughout Georgia and Alabama. Under his leadership, Cy3 developed the GRC platform that powers every Cy3 Kindred engagement - tracking all 110 NIST SP 800-171 r2 controls in real time and generating CUI-compliant SSPs, POA&Ms, and SPRS scores directly from live assessment data.

USAF Veteran 20+ Years Defense Cybersecurity GRC Platform Development NIST 800-171 r2 Enterprise Risk Management
The Boundaryless Enterprise

Redesigning Oversight for the Age of Intelligent Systems. Ahmad's published examination of governance, risk, and leadership in an era shaped by AI and autonomous technologies - the framework behind how we approach AI tool risk inside a CMMC boundary.

Co-Founder • Cy3 Kindred
DR. KENLEY OBIAS
Co-Founder, Cy3 Kindred • Founder, Kindred Technology Group • Assistant Professor, Alabama State University

Dr. Kenley Obias brings the academic and applied AI research dimension that no pure-play cybersecurity firm can replicate. As an Ed.D.-credentialed AI researcher and Fulbright Specialist, he develops AI literacy frameworks, publishes peer-reviewed work on equitable AI deployment, and builds AI-powered systems for government-adjacent clients through Kindred Technology Group - Cy3 Kindred's technical implementation partner. At ASU, he serves on the AI Committee and co-leads research into applied AI in institutional settings. His active research into shadow AI risk, AI governance frameworks, and AI tool deployment in regulated environments is the methodological backbone of Cy3 Kindred's AI Boundary Assessment - grounded in evidence, not checklists.

Ed.D. • AI & Educational Technology Fulbright Specialist NSF Co-PI AI Governance Research Applied AI Systems 15+ Years Gov-Adjacent Tech
Insights

What you need to understand
before your next contract renewal.

■ Guide
UNDERSTANDING DFARS 252.204-7012 AND WHAT IT REQUIRES OF YOU

DFARS 252.204-7012 requires contractors handling CUI to implement adequate security per NIST SP 800-171, report cyber incidents within 72 hours, and preserve images of compromised systems. Here is what those obligations mean in practice for a small defense subcontractor.

Read the guide
■ Analysis
HOW THE SPRS SCORING METHODOLOGY ACTUALLY WORKS

The DoD Assessment Methodology assigns specific point values to each of the 110 NIST SP 800-171 r2 controls. Starting from +110, each missing control deducts points. Understanding which controls carry the most weight - and which are most achievable - is the key to maximizing your score and minimizing your legal exposure.

Read the analysis
■ Checklist
THE SSP DOCUMENTATION TRAP: WHAT GETS CONTRACTORS RESCHEDULED

An SSP that doesn't accurately describe your implemented controls is the top reason CMMC assessments get rescheduled. We break down the five most common documentation errors small contractors make - and how each one creates both assessment failure risk and False Claims Act exposure under DFARS 252.204-7019.

Get the checklist
Common Questions

What contractors ask us most.

If your contract or subcontract requires you to handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) - even a single drawing, specification, or statement of work - you are in scope. CMMC requirements flow down from prime contractors to all tiers of the supply chain under DFARS 252.204-7012. Many small subcontractors in manufacturing, engineering, and logistics are in scope without realizing it. The free CMMC readiness consultation takes 45 minutes and answers the question definitively based on your actual contract language.
CMMC Level 1 applies to contractors that handle Federal Contract Information (FCI) only. It requires implementation of 15 basic safeguarding requirements from FAR 52.204-21 and allows annual self-attestation. CMMC Level 2 applies to contractors that handle Controlled Unclassified Information (CUI). It requires implementation of all 110 security requirements from NIST SP 800-171 r2 across 14 control families and requires a third-party assessment by an authorized C3PAO for most contracts. Level 2 is where the vast majority of defense subcontractors fall - and where the documentation burden is most significant.
Level 1 and some Level 2 contracts allow self-attestation under DFARS 252.204-7019. But self-attesting an inaccurate score creates False Claims Act liability. The DoJ has made cybersecurity misrepresentation an active enforcement priority, and primes are increasingly using SPRS scores as informal pre-qualification filters before extending subcontract invitations. A low or absent score costs you contract opportunities, not just compliance points. We calculate your real score before you submit anything.
A C3PAO (Certified Third-Party Assessment Organization) is the only entity authorized to issue an official CMMC certificate. We handle gap analysis, SSP and POA&M documentation, remediation guidance, and assessment preparation. Think of it this way: the C3PAO is the exam. We're the prep course. You need both. We don't compete with C3PAOs — we work alongside them and can refer you to a partner assessor once you're ready.
Under NIST SP 800-171 r2 and the CMMC Assessment Guide, your SSP must document all 110 security requirements with: the implementation status of each requirement (implemented, planned, or not applicable), a description of how each requirement is satisfied, the system boundary and all in-scope assets, supporting policies and procedures, and the responsible party for each control. Vague language like "we use best practices" is not acceptable. Our platform generates the SSP directly from your Control Board data, ensuring every control entry is specific, accurate, and consistent with your actual posture.
It depends on your starting posture. A Level 1 engagement (FCI only, 15 controls) can be completed in 30 to 60 days. A Level 2 engagement starting from a low SPRS score typically takes 4 to 9 months from gap analysis to assessment-ready status. The most significant variable is the number of open findings and the complexity of the remediation required. Our platform tracks every gap from identification through closure so you always know exactly where you stand.
Get Started

Book a Free CMMC Readiness Consultation

What happens next
We'll reach out within one business day to schedule your free 45-minute CMMC Readiness Consultation. That call answers three questions: Do you handle FCI or CUI? Which CMMC level applies to your contracts? What is your real exposure right now? No sales pressure, no commitment.
Service Area
Georgia • Alabama • South Carolina
Tennessee • North Carolina • Florida

Remote engagements available nationwide.
Based In
Montgomery, Alabama • Atlanta, Georgia
Our founding team has been serving the Southeast defense and government market since 2009.
Why It Matters
DFARS 252.204-7012 applies to every contractor handling CUI - regardless of company size or contract value. Your SPRS self-attestation is a legal representation to the federal government. An inaccurate score creates False Claims Act exposure. We make sure your score reflects your actual posture before you submit anything.

We respond within one business day. We don't share your information.