DFARS 252.204-7012 NIST SP 800-171 SPRS CMMC Level 2

Your DoD contracts come with 110 controls attached.
We make you defensibly compliant, at a fixed fee.

Fixed-fee compliance for DoD contractors with 25 to 500 employees: NIST SP 800-171 done completely, an SPRS score you can sign, and CMMC Level 2 ready the day assessments resume.

In plain terms: the government requires you to prove your company protects the technical data your defense customers send you. We build that proof, and it holds up when someone checks.

$45,000 fixed · 16 weeks · 4 written guarantees · Price on the page
Cyber-AB Registered Practitioner · E&O Insured · Advice is all we sell · EN / ES delivery

Not ready for the full program? The Defense Compliance Diagnostic is $7,500 for the founding cohort, credited in full within 90 days. Or take the two-minute fit check first.

§ 02 Regulatory status (verified July 2026)
SUSPENDED
CMMC Phase 2 third-party certification requirement (DoD pause, July 13, 2026; program review concludes ~fall 2026).
STILL MANDATORY
  • ·DFARS 252.204-7012
  • ·All 110 NIST SP 800-171 controls
  • ·Current SPRS score
  • ·Annual executive affirmations
  • ·Prime flowdowns
STILL ENFORCED
DOJ False Claims Act settlements: $507K (small contractor, June 2026)  ·  $875K (Georgia Tech)  ·  $8.4M (Raytheon).

Dated, sourced, and kept current. Check it against anything a vendor tells you: DoD pause memo · DOJ settlement · DFARS 252.204-7012 text

§ 03 The problem

Half the supply chain heard "suspended" and stopped.
Their obligations didn't.

0
Controls you're attesting to today
0
Of the 76,598 contractors who need Level 2 have finished, at most
$0
DOJ settlement, June 2026
$0
SecureFort fixed fee

The July 13 pause did not touch DFARS 7012, the 110 controls, your SPRS score, or the affirmation your executive signs. DOJ is settling cases against contractors whose scores didn't survive audit. One company your size settled for $507,144 weeks before the pause. Government assessors scored it at minus 170, on a scale where full compliance is 110. Someone signed the number it had reported instead.

76,598 contractors need Level 2 under DoD's own rulemaking estimate; fewer than 1,500 have finished. When the review concludes, the queue forms behind the contractors who used the quiet months.

Three ways to buy this work: boutiques ($65K to $150K+, quoted after a sales process), template mills (why most contractors arrive unprepared), and your MSP (essential, but they shouldn't grade their own homework). There's a gap in the middle: senior-led, independent, fixed-fee. That's SecureFort.

§ 04 The program

The Defense
Compliance Program.

NIST SP 800-171, complete. CMMC Level 2, ready. Sixteen weeks, one fixed fee. Full SSP, 19 policies authored to your environment, control-by-control evidence register (110), POA&M with owners and dates, SPRS score you can sign, week-15 readiness review, C3PAO-ready handoff. Senior-led interviews and readouts throughout.

What you get, in eight documents
01
System Security Plan

All 110 controls, narratives built to your environment.

02
19 policies, environment-specific

Authored to your tooling and your people, not templates.

03
Evidence register

Every control mapped to the document an assessor asks for.

04
POA&M

Named owners, real dates, board-ready.

05
SPRS score you can sign

The number, the basis, the paper trail.

06
Week-15 readiness review

Residual gaps flagged, options priced, decisions logged.

07
C3PAO handoff package

Everything packaged, plus assessor selection guidance.

08
30-day Q&A window

Post-engagement questions answered without a new SOW.

Week 1–2
CUI mapping and scoping

Interviews across engineering, IT, HR, and operations. Where CUI enters, where it moves, where it lives. First cut of scope and enclave options.

Week 3–4
Gap analysis, all 110 controls

Scored gap analysis against each of the 110 NIST 800-171 controls. Defensible SPRS position established. First executive readout.

Week 5–6
SSP v1.0 authoring

Full System Security Plan drafted against your real environment. Control-by-control narratives. Delivered at week 8 as the milestone tied to your second payment.

Week 7–8
Nineteen policies authored

Policies written to your environment, not templates: access control, incident response, media protection, personnel security, and the rest of the AC through SI families.

Week 9–11
Evidence register (110 controls)

Working with your IT team or MSP to collect and index the evidence each control requires. Screenshots, configs, tickets, logs, memos. Nothing left as "trust me."

Week 12–13
POA&M and remediation coordination

Named owners, real dates, and prioritized remediation of any residual gaps. We coordinate; your IT team or MSP executes.

Week 14–15
Readiness review

Full mock walk-through of your package as an assessor would see it. Residual gaps flagged, options priced, decisions documented.

Week 16
C3PAO handoff

Handoff package assembled, C3PAO selection guidance provided, executive readout delivered. Thirty-day Q&A window opens.

Weeks 1–4
Discovery & scoping
CUI mapping, scoping interviews, scored gap analysis against all 110 controls, defensible SPRS position, first executive readout.
Weeks 5–8
SSP & policies
Full SSP drafted against your environment. Nineteen policies authored to your organization. SSP v1.0 delivered week 8 as the milestone tied to the second payment.
Weeks 9–13
Evidence & POA&M
Evidence register across all 110 controls. POA&M with named owners and real dates. Remediation coordination with your IT team or MSP.
Weeks 14–16
Readiness & handoff
Mock walk-through, C3PAO-ready handoff package, executive readout, and a 30-day post-engagement Q&A window.
Fixed fee, sixteen weeks, four written guarantees.
See pricing and compare ↓
§ 05 Four written guarantees

Contract language,
not marketing copy.

All four guarantees appear verbatim in every SOW. We'll send it to your counsel before you sign anything.

01 · Guarantee

No Handoff

The senior consultant you meet leads start to finish: every interview, judgment call, readout, and final QA. Specialists may assist under the lead's review; your named lead never changes without written agreement, or you terminate with a prorated refund of fees paid.

02 · Guarantee

Audit-Quality

If a formal assessment within 12 months finds a material defect in a document we wrote, we correct it at no charge. We stand behind every page we deliver. What we don't guarantee: an assessor's judgment, or remediation that wasn't finished after we left.

03 · Guarantee

Week-4 Walk-Away

Five business days after the Phase 1 readout to exit. Walk away and the engagement reprices to the Diagnostic: you pay $7,500, keep the gap report and scoping memo, and the rest of your deposit comes back within ten business days. Committing early never costs more than being cautious.

04 · Guarantee

Readiness Validation

When your remediation is done, we come back: one full re-score across all 110 controls and a written go or no-go, before you spend a dollar on a C3PAO. One pass, within 120 days of handoff, included in the Program. You'll know you're ready before anyone official asks.

§ 06 Independence

We sell advice.
Full stop.

No software licenses. No enclave subscription. No managed IT. No assessment arm. Your MSP is essential: they implement and run the controls. We're the independent layer that documents that work and makes it stand up to assessors, primes, and auditors.

MSPs like working with us: we make their engineering look as good on paper as it is in the rack. And because we sell no tooling and no services beyond advice, our recommendations have nothing behind them but the assessment.

Custody

We don't need your CUI, so we never take it. No possession, no storage, no transmission: our deliverables describe your environment, they don't contain your data. On the rare occasion we need to see CUI at all, we view it inside your systems, under your credentials, and nothing leaves. It's written into the SOW.

§ 07 The fit check

Do you actually need us?
Six questions.

Built for DoD contractors handling CUI, 25 to 500 employees. Not for primes with in-house teams or Level 1-only shops. Six questions, two minutes, no email, nothing recorded. Designed to tell you the truth, including "you don't need us."

Question 1 of 6 Do you do DoD work?
Q1

Do you do DoD work today? Prime, sub, or an active contract vehicle.

Q2

Does your contract include DFARS 252.204-7012, or have you received a compliance letter from your prime?

Q3

Do you handle CUI: Controlled Unclassified Information (drawings, specs, ITAR, technical data)?

Q4

How many employees?

Q5

Where does your SPRS score stand right now?

Q6

Who owns compliance inside the company?

Result

You don't need us.

If you don't currently do DoD work, DFARS and NIST 800-171 don't apply to you. Bookmark the page if that changes. Otherwise, this is time back.

Result

Probably CMMC Level 1.

Level 1 is an annual self-assessment against 15 FAR-based safeguarding requirements. Most small shops handling FCI (not CUI) can do this without outside consulting. Book a free 15-minute call and we'll confirm; we won't sell you work you don't need.

Book the free 15-min call
Result

Likely Level 2, below our size band.

If drawings, specs, or technical data flow to you, you are Level 2 no matter your headcount. Our fixed-fee program is built for contractors with 25 to 500 employees, so we are probably not your most cost-effective option. Book 15 minutes and we will point you toward right-sized help, free.

Book the free 15-min call
Result

Level 2, with attestation exposure.

You're likely handling CUI, and your SPRS score is missing, stale, or unowned. That is exactly the exposure DOJ is settling: signatures on numbers that didn't survive audit. Start with the Defense Compliance Diagnostic ($7,500 founding-cohort price, credits in full toward the Program within 90 days), or book a call.

Result

Level 2, get assessment-ready.

You're on the right side of the score, with someone owning compliance. Now it's about getting your SSP, evidence register, and POA&M in a shape a C3PAO will accept. That's the Defense Compliance Program: $45,000, sixteen weeks, four written guarantees.

Result

Probably too big for us.

Above 500 employees you likely have the internal muscle (or the enterprise Big-4 relationships) that make our fixed-fee model the wrong fit. Book a call anyway: we'll be honest and point you at someone better suited.

Book a 30-min referral call
§ 08 The path

From Diagnostic to Defensible.

The Diagnostic is the Program's first phase, sold on its own. Its findings carry straight forward, nothing repeated, nothing re-billed, the fee credits in full. After certification, an ongoing partnership keeps you defensible year over year.

Know where you stand · 2 weeks

Defense Compliance Diagnostic

$10,000 founding cohort: $7,500 until the five spots fill

Scored gap analysis across all 110 controls, defensible SPRS position, prioritized roadmap, exec readout.

Credits in full toward the Program within 90 days.

For teams that don't yet know where they stand.

Get contract-ready · 16 weeks

Defense Compliance Program

$45,000 founding cohort: $35,000 until the five spots fill

SSP, nineteen policies, evidence register, POA&M, readiness review, C3PAO handoff. Four written guarantees, in contract language.

First-year Affirmation Renewal at half rate for direct Program clients.

For teams that already know they're going all the way: one contract, one start date.

Ongoing maintenance

Compliance Partner

Affirmation Renewal
$15,000 /yr

The annual re-score behind next year's executive affirmation. For contractors up to roughly 150 employees.

First year: $7,500 for direct Program clients.

Full Retainer
$4,500 /mo

Continuous coverage for contractors above 150 employees or with multiple prime relationships.

The number your executive signs next year should be as defensible as the one they signed this year. Two ways to keep it that way.

Multi-site, multi-CAGE, or above roughly 250 employees? Scoped individually, typically $65,000 to $75,000. Book a call; we'll size it in 30 minutes.

Founding cohort · 5 spots. Closes December 31, 2026 or when the five spots fill, whichever comes first. While spots last: the Program at $35,000 instead of $45,000, and the Diagnostic at $7,500 instead of $10,000, in exchange for a written case study and a testimonial only if you're happy.

Price-lock promise. The price on this page is the price. If it ever changes, this page changes first.

§ 09 See the work before you buy

The methodology,
in your hands.

Sample gap-assessment report. Read it, share it with your IT lead or counsel, judge the depth yourself.

  • 16 pages: a fictional 58-person machine shop assessed end-to-end, from a self-reported 104 to an assessed minus 44, with the full 110-control scoring table and the remediation math back to 110.
  • The exact deliverable our Diagnostic clients receive, populated end-to-end. Not a lead magnet: the depth is the same as the paying product.
  • Delivered by email. One follow-up at most. Unsubscribe anytime.

Free SPRS Sanity-Check. A 20-minute self-scoring worksheet: find out whether the score in SPRS is one your executive should be affirming.
Download it now (PDF, 5 pages). No email, no form, no follow-up.

Request the sample report

Prefer not to fill a form? Email us directly.

§ 10 Who you'll work with
Julio Ryan, Principal and Founder, SecureFort
Founder FIG. 02
Principal & Founder

Julio Ryan

Eight years of cybersecurity risk and compliance consulting across regulated industries. The framework names change; the work is the same: translating what your IT team actually does into control narratives an external assessor will accept.

Working with SecureFort means you talk to the same person from first discovery call through final readout. No account team. No mid-stream handoff.

  • Cyber-AB Registered Practitioner (RP). Verify the listing yourself in the CMMC Marketplace.
  • NIST-based control assessments, audit readiness, and remediation programs, from mid-market companies to enterprise.
  • Hundreds of control interviews and assessor-facing documents behind the methodology on this page.
  • Readiness only. We build the package; an independent C3PAO conducts the assessment. That separation protects you.
  • Delivery in English and Spanish, including working sessions and shop-floor rollouts that train your production crew on CUI handling.
§ 11 Common questions

Common questions,
plainly answered.

CMMC Phase 2 was just suspended. Shouldn't we wait? +

Wait on the certification booking, sure. Waiting on readiness is the expensive mistake: your DFARS 252.204-7012, NIST 800-171, and SPRS obligations are in force today (that is what DOJ enforces). Everything we build is NIST 800-171 work that holds value under any review outcome, and when certification resumes the ready contractors get assessed first.

Our MSP says they can handle CMMC. +

They're essential; they implement. But the party attesting to compliance should not be the party selling the IT it is attesting to. We work alongside your MSP; we sell nothing else.

Can you guarantee we pass the assessment? +

No one credible guarantees an assessor's judgment. We guarantee our documents: if a formal assessment within 12 months finds a material defect in something we wrote, we correct it at no charge. That covers our work product, not remediation that wasn't finished or changes made after handoff.

What exactly is the Readiness Validation? +

When you've closed out the remediation we scoped, we re-score you across all 110 controls and put it in writing: ready to schedule, or not yet, and exactly why. One pass, within 120 days of handoff, included in the Program. It's a checkpoint, not a second engagement. If you want us alongside you through the whole fix window, that's Remediation Support, quoted separately. If your remediation window runs past 120 days, we extend the validation by written agreement.

How long does the Diagnostic really take, start to finish? +

About a month, door to door, and we would rather you hear that from us. One to two weeks for your team to gather the evidence checklist and sit the interviews (we send the checklist and scheduler the day you book, and your MSP will do most of the artifact lifting), then ten business days of assessment on our clock, ending in the executive readout. No clock starts until your artifacts are in and your interviews are done.

If we do the Diagnostic first, are we paying for the same work again in the Program? +

No. The Diagnostic's scoped gap analysis, SPRS position, and roadmap become the Program's starting inputs; the fee credits in full and nothing is re-billed. The Program still runs sixteen weeks, because its pace is set by your team's decisions and changes, not by our analysis speed. Diagnostic clients spend the first month validating and going deeper instead of starting cold, which is why their Programs tend to land on schedule.

Is SecureFort a C3PAO? +

No. SecureFort is a readiness practice. The formal Certified Third-Party Assessment Organization (C3PAO) assessment is conducted by a separate, independent firm; we help you engage the right one after your readiness package is complete. This separation is required by the CMMC program and protects the integrity of the assessment.

What's the payment structure? +

Depends on what you buy. The Diagnostic is 100% at booking. The Program is 50% at kickoff and 50% at week 8, tied to SSP v1.0 delivery, with no change orders. Affirmation Renewal is billed annually; the Full Retainer is monthly ACH on a 6-month initial term. All ACH or wire, and every SOW goes to your counsel before you sign anything.

What are the founding cohort terms? +

The founding cohort is the first five Program clients. They pay $35,000 (vs. $45,000 standard), and while spots remain the Diagnostic is $7,500 (vs. $10,000 standard). In exchange we ask for a written case study and a testimonial, only if you're happy. First come, first served, until the five spots are filled.

We only need CMMC Level 1. Do you help with that? +

Level 1 is an annual self-assessment against 15 basic safeguarding requirements (FAR 52.204-21). If that is all you need, we'll confirm it in a free 15-minute call and point you at the FAR 52.204-21 checklist. We will not sell you work you don't need.

Why fixed fee instead of hourly? +

Hourly billing creates the wrong incentives. Fixed fee aligns them: a complete, assessor-ready package delivered in sixteen weeks. If we run long, that is our problem to absorb, not your invoice to swallow.

Why start now if certification is paused? +

Enforcement is happening today under DFARS and the False Claims Act. Readiness takes sixteen weeks. When certification resumes the queue forms behind the contractors who used the quiet months. The reason to start now is enforcement and runway, not deadline math.

What if our IT team can't implement the technical controls? +

We scope technical implementation out of our engagement, but we partner with technical implementation firms and MSPs who can execute alongside us. We coordinate; they execute.

§ 12 Talk to us

Thirty minutes.
No pitch.
We'll tell you if you don't need us.

Your contract exposure, your real SPRS position, whether this is even your priority right now. Not the right fit? We'll say so and point you to someone better suited.

Founding cohort · 5 spots · Four written guarantees · Fixed fee, published price