Cybersecurity consulting and NIST SP 800-171 compliance for defense contractors
Cyber RST Consulting helps companies protect Controlled Unclassified Information (CUI), meet NIST SP 800-171 and 800-172 requirements, and prepare to do business with the US Government and the Department of War (DoW).
Cybersecurity Consulting Services
Every engagement is delivered by certified consultants who hold current, active DoW security clearances.
NIST SP 800-171 and 800-172 compliance
We assess your current controls, build or update your System Security Plan (SSP) and Plan of Action and Milestones (POA&M), and guide remediation so you are ready for CMMC assessment.
Penetration testing
Authorized, scoped testing of your networks, systems, and applications, with every finding ranked by risk and paired with a specific fix.
Physical security assessments
An on-site review of access control, visitor procedures, camera coverage, network closets, and how CUI is stored and handled.
eMASS support and training
Help building, organizing, and maintaining Risk Management Framework authorization packages in eMASS, plus training so your team can keep them current.
Cybersecurity training
On-site and virtual training built around your team’s roles, covering security awareness, threat reporting, and proper handling of CUI.
Training program assessments
A review of your existing cybersecurity training program against current DoW requirements, with a clear list of what to keep, fix, and add.
Who We Help
We work with organizations that handle sensitive government information or want to start competing for federal and DoW contracts.
Defense Contractors and Subcontractors
Companies in the Defense Industrial Base that handle CUI and must meet DFARS and CMMC requirements.
Small Businesses Entering Federal Work
Firms preparing for their first DoW or federal contract that need a compliance baseline from day one.
Organizations with In-House Training
Firms preparing for their first DoW or federal contract that need a compliance baseline from day one.
Teams working in eMASS
System owners and security staff who manage RMF authorization packages and need hands-on support.
How an engagement works
-
Step 1
Consultation
We start with a conversation about your business, the contracts you hold or are pursuing, the kinds of sensitive information you handle, and any deadlines you are working against.
What’s included- Review of current and upcoming contract requirements
- Discussion of the CUI and systems in scope
- A clear proposed scope and next steps
-
Step 2
Assessment
We evaluate your current security posture against NIST SP 800-171, 800-172, or the requirements that apply to you, through interviews, documentation review, technical testing, and on-site walkthroughs.
What’s included- Control-by-control gap analysis
- Review of policies, SSP, and POA&M
- Findings ranked by risk and impact
-
Step 3
Roadmap
You get a prioritized plan that shows what to fix first, what each fix involves, and who owns it, so leadership can make informed decisions about time and budget.
What’s included- Prioritized remediation plan
- Updated System Security Plan and POA&M
- Estimated level of effort for each item
-
Step 4
Implementation and training
We work alongside your team to close the gaps, then train your staff so the improvements hold up day to day and through future assessments.
What’s included- Hands-on remediation support
- Role-based training for your team
- Preparation for CMMC or government assessment
Frequently Asked Questions
Plain answers to the questions we hear most often from contractors.
-
NIST SP 800-171 is a set of security requirements from the National Institute of Standards and Technology for protecting Controlled Unclassified Information (CUI) in non-federal systems. Contractors that handle CUI for the Department of War are generally required to implement it.
-
NIST SP 800-171 is the baseline for protecting CUI. NIST SP 800-172 adds enhanced requirements for CUI tied to critical programs or high-value assets, aimed at defending against advanced persistent threats.
-
The Cybersecurity Maturity Model Certification (CMMC) program verifies that contractors have implemented required security practices. CMMC Level 2 is built on the NIST SP 800-171 requirements, and Level 3 adds requirements drawn from NIST SP 800-172.
-
The Enterprise Mission Assurance Support Service (eMASS) is the DoW’s web-based system for managing cybersecurity authorization packages under the Risk Management Framework (RMF). We help teams build, organize, and maintain those packages.
-
Both. Physical security assessments are performed on-site. Training, compliance support, and many assessment activities can be delivered virtually.
-
Send us a message through our contact page or email consulting@cyberrst.com. We’ll schedule a conversation to understand your needs and recommend next steps.