Services

NIST 800-171 and CMMC compliance

NIST 800-171 Evaluation

Despite all of the talk about the upcoming CMMC requirements, NIST 800-171 is the existing standard for Aerospace suppliers holding sensitive U.S. government data. You are expected to be self-attested compliant with it today.

We can help your IT, security, and compliance staff get through the security jargon and acronym-laden alphabet soup by asking the right questions to help you understand the scope and effort needed for compliance. From there, we assist in the design of your system security plan to get your site sustainably and affordably in compliance. The results will be evidence for your CMMC certification request when those regulations take effect.

 

CMMC Evaluation

The upcoming CMMC will require Aerospace suppliers to have compliance validated by a certified independent third party auditor to one of five levels of certification. Any suppliers with federal contract information will be required to meet level one CMMC certification and with controlled unclassified information (CUI) that will be required to meet level three certification. We can help your team ascertain the appropriate level and from there get your site sustainably and affordably prepared for your audit.

 

Enclave Design

In many situations, compliance can be streamlined by consolidating sensitive data and systems into an on-site or cloud based enclave. We can help your team architect an IT and network solution that simplifies compliance and also has minimal impact to your existing workflows.

 

POA&M Management and Remediation

Audits have findings. The Plan of Action and Milestones (POA&Ms) is the blueprint for resolving those findings.  We provide a recommended remediation for each POA&M. Our goal is to provide maintainable solutions that minimize the threat vector while demonstrating continued, auditable compliance.

 

Policies and Procedures

A large component of compliance is stating in writing how you intend maintain security. We have a full set of policies and procedures available, with Aerospace considerations, so your team doesn’t have to start from scratch.

 

Book a Consultation

Aerospace Compliance for Aerospace Companies