CMMC & NIST 800-171

CMMC and NIST 800-171 compliance for defense contractors who don't want to become compliance experts

If you hold DoD contracts, or sell to a prime that does, DFARS 252.204-7012 has been sitting in your paperwork for years. Maybe you submitted a SPRS score back when your prime first asked and haven't looked at it since. Maybe you never submitted one and you know it. And now CMMC language is showing up in new solicitations and flow-downs, and the quotes you're getting from national compliance firms attach very large numbers to very vague scopes.

Book a 30-Minute Compliance Conversation

Or maybe you’re not in defense work yet, and CMMC is the wall between you and contracts you want to win. Same wall, better timing: it’s a lot cheaper to build an environment right the first time than to retrofit one under deadline.

You’re not behind because you’re careless. You’re behind because you run a business, and this material is written like it’s trying to keep you out.

We do this work for contractors in Macon and Warner Robins, in plain language, with prices explained before the work starts. The owner is the person you’ll actually be talking to.

Book a 30-Minute Compliance Conversation

No cost, no pitch deck. We'll tell you where you actually stand.

Where CMMC actually stands (updated July 2026)

Short version: the certification got suspended. The requirement didn’t.

CMMC became a binding contract requirement in November 2025. Then in July 2026, the Department suspended the Phase II rollout, the part where third-party certification assessments were going to become mandatory in contracts, and launched a 60-day review of the whole program. If you saw a headline that said “CMMC is dead,” that’s the story it garbled.

Here’s what’s still fully in force, per the Department’s own announcement: Phase I self-assessments, DFARS 252.204-7012, and NIST 800-171, now enforced through your self-reported SPRS score and “select government-led assessments.” Read that last part again. The score you filed is the compliance record, and the government reserved the right to show up and check it. A padded score was a liability when a scheduled assessor was coming. It’s arguably a bigger one when the check is a spot check.

Whatever comes out of the review, it will sit on top of 800-171, because 7012 isn’t going anywhere and the data still has to be protected. Implement the standard for real and the acronym changes stop mattering to you.

Where most contractors actually stand

We’ll say the quiet part. A lot of SPRS scores in the system are 110s that were typed in, not earned. Everyone in the supply chain knows it, including the DoD, which is a big part of why CMMC exists. The Department of Justice has already pursued False Claims Act cases over misreported scores, so an inaccurate submission isn’t a paperwork problem anymore.

A first careful assessment against all 110 controls usually lands far below what the company self-reported. That’s normal. It’s not a character flaw, and it’s fixable. What’s not fixable is pretending, because enforcement didn’t go away in July 2026. It turned into spot checks, and spot checks don’t send a save-the-date.

800-171 is an infrastructure job

Most of what’s sold under the CMMC banner is documentation: a policy binder, an SSP template, a findings report with your logo on the cover. You need the documents, and we write them. But a System Security Plan describes an environment. Somebody still has to build that environment, and then run it every day so it stays true when your business changes.

That’s where CoreSouth comes in. We build infrastructure that works, and we build it secure. We spend our days hardening identity and endpoints and segmenting the networks behind them, including for businesses that answer to PCI DSS auditors, where the tolerance for hand-waving is zero. NIST 800-171 doesn’t ask for anything exotic. It describes what a well-run environment already looks like: controlled access, monitored systems, patched software, documented change. Build the environment right and the 110 controls stop being a checklist you chase. They become a description of how your IT already works. The DoD’s July 2026 announcement said the goal now is “tangible cyber hygiene rather than administrative overhead.” We’ve been building that way all along.

For contractors under DFARS 7012, that means your compliance program and your IT operation are the same thing, run by the same people, instead of two vendors pointing at each other when the assessor asks a hard question.

What we do

1. NIST 800-171 gap assessment

Fixed scope, fixed price, all 110 controls measured against your actual environment (not a questionnaire your office manager fills out). You walk away with a SPRS score you can submit without holding your breath, and a remediation plan with priorities and real cost estimates attached to each item. Not “implement multifactor authentication” as a line item. What it costs and how long it takes, control by control.

If you’ve been avoiding SPRS because you don’t know what an accurate score would reveal, this is the way through. This is our NIST 800-171 assessment for Middle Georgia contractors, and it’s built to be the last assessment you need before remediation starts.

2. Remediation and implementation

An assessment tells you what’s broken. We’re an IT company first, so we fix it. That’s the difference between us and most of the compliance firms quoting this work: they assess, hand you a findings report, and sell you advisory hours. We do the implementation.

That includes:

  • Microsoft 365 GCC migration planning and management, when your CUI handling requires it
  • Entra ID and Intune hardening to meet the access control and configuration requirements
  • Written policies and a System Security Plan that describe how your business actually operates, not a template with your logo pasted on
  • Evidence collection along the way, so assessment prep isn’t a fire drill

We’ve spent 18 years building and securing IT infrastructure, and we do compliance implementation work today (PCI DSS environments, NIST-aligned hardening). This is engineering work. We treat it that way.

3. Ongoing compliance leadership

An 800-171 program isn’t a project you finish. Your SPRS score has to stay true after you file it, and your policies have to keep matching the environment as it changes. Somebody also has to answer when your prime sends a security questionnaire.

We provide that as a fractional service: a named person at CoreSouth who owns your compliance program. Not a portal, not a rotating cast. One person who knows your environment and keeps your documentation current, so you’re ready whether the next question comes from your prime or a government-led assessment.

4. A second opinion on any CMMC quote

If you’ve already received a quote from a national CMMC consultant and something about it felt off, send it to us. We’ll review it for free, no obligation, and tell you what’s real scope and what’s padding. If the quote is fair, we’ll tell you that too, and you’ll have lost nothing but thirty minutes.

We offer this because we’ve seen what’s being quoted to small contractors in Georgia, and some of it is hard to defend. If a firm is still quoting you certification prep as if nothing changed in July 2026, that’s worth a second look on its own.

Book a 30-Minute Compliance Conversation

Why a local IT company instead of a national compliance firm

The national firms know the framework. Most of them have never racked a server or written an Intune policy, so their engagement ends where your actual work begins. You get a gap report and a goodbye.

We’re based in Macon. Warner Robins is twenty minutes from us, and most of the contractors we’re built for are inside that same circle. If your work runs through Fort Eisenhower, Moody, or another Georgia installation instead, we’re a drive, not a flight, and there aren’t many firms doing this work in the state at all. When we do defense contractor IT support near Robins AFB, “support” means the person who assessed your environment is the same company hardening it, and you can put a face to the name. If something breaks the week before your assessment, we’re not a ticket queue in another time zone.

Search for a CMMC consultant near Warner Robins and you’ll mostly find national firms with a Georgia landing page. We’re actually here. Our owner, John-Mark Smith, has spent 18 years doing the infrastructure work these controls describe.

One more thing we’ll say plainly: we won’t take the engagement if we’re not the right fit. If your situation calls for a specialist we can’t be, we’ll tell you in the first conversation.

Start with a conversation, not a contract

Thirty minutes, no cost, no pitch deck. Bring whatever you have: a contract with the DFARS clauses in it, or the quote that made your eyes water. We’ll tell you whether you’re a Level 1 or Level 2 situation and what shape your SPRS obligation is in. You’ll leave knowing roughly what the path looks like. If the honest answer is “you’re closer than you think,” you’ll hear that too.

Book a 30-Minute Compliance Conversation

Frequently asked questions.

Didn't the DoD just suspend CMMC?

Part of it, yes. In July 2026 the Department suspended Phase II, the rollout stage where third-party certification assessments were going to become mandatory in contracts, and opened a 60-day review of the program. Phase I self-assessments are still required, DFARS 7012 is still in every affected contract, and NIST 800-171 is still the standard, now enforced through your self-reported SPRS score and select government-led assessments. So the certification is paused. The requirement to protect the data never was. We keep this page updated as the review plays out.

What is a good SPRS score?

A perfect score is 110. Every unmet 800-171 control deducts points (deductions range from 1 to 5 per control), and the scale runs all the way down to negative 203. So "good" depends on where you're starting, but the only score worth having is an accurate one. A self-reported 110 that wouldn't survive an assessment is a legal liability, not an asset. Most contractors' first careful assessment lands well below 110, and that's fine. The score is a starting line. The remediation plan is what matters.

Do I need CMMC Level 1 or Level 2?

It depends on what data touches your business. If you only handle Federal Contract Information (FCI), you're in Level 1 territory: an annual self-assessment against 15 basic safeguarding requirements, which is still required today. If you handle Controlled Unclassified Information (CUI), the standard is NIST 800-171, all 110 controls, with your score filed in SPRS. Third-party Level 2 certification assessments are suspended as of July 2026 while the DoD reviews the program, but the underlying obligation didn't move. Not sure which you are? Check your contracts for the 252.204-7012 clause and look at what your prime actually sends you. Technical drawings and specs are often CUI even when nobody stamped them clearly. We sort this out in the first conversation.

What does CMMC certification actually cost?

Right now, possibly nothing, because third-party certification assessments are suspended while the DoD reviews the program. Before the suspension, the Level 2 assessment by a certified third-party assessor (C3PAO) commonly ran $30,000 to $60,000 for a small contractor, and some form of verification will likely return. The cost that never went away is implementation: actually meeting the 110 controls of NIST 800-171. A 20-user shop already on Microsoft 365 with decent practices might have a modest remediation bill. A shop that needs a GCC migration plus a dozen technical controls will spend more. If a firm quoted you certification prep before July 2026, the scope just changed. Our second-opinion review is free, and this is a good month to use it.

Can my current IT company handle this?

Maybe, and it's a fair question to ask them directly. Have they read NIST 800-171? Can they produce a System Security Plan and a POA&M? Do they understand how to scope a CUI enclave? If they're good at day-to-day IT but new to this framework, that's not a reason to fire them. We work co-managed engagements where your existing IT keeps doing what they do well and we own the compliance program. What you can't afford is an IT provider who says "we've got it" and finds out otherwise during your assessment window.

What is DFARS 7012 and does it apply to me?

DFARS 252.204-7012 is the contract clause that has required defense contractors to implement NIST 800-171 since 2017. If it's in your contract, it applies, and it has since the day you signed. It also requires reporting cyber incidents to the DoD within 72 hours, and it requires that any cloud service storing your covered defense information meets FedRAMP Moderate equivalency (this is where the Microsoft 365 GCC conversation usually starts). The companion clauses, 7019 and 7020, are what require your SPRS score to be on file and current. The July 2026 CMMC suspension didn't touch any of this.

How long does it take to get compliant with NIST 800-171?

For a 10 to 50 user contractor with real gaps, plan on six to twelve months from gap assessment to a defensible SPRS score with the technical work behind it. A GCC migration alone takes careful planning, and policies need time to become practice. The suspension of third-party assessments doesn't buy that time back, because your score is on file now and government-led assessments don't come with scheduling courtesy. If the review ends and verification returns, the contractors who used this window to implement will be bidding while everyone else scrambles.