NIST CSF, 800-171 & CMMC Compliance Readiness
Know your real gap against NIST CSF 2.0, NIST SP 800-171, and the CMMC Level 1/Level 2 baseline before a customer questionnaire, a self-assessment submission, or a C3PAO certification assessment finds it for you. Control-by-control, with the citation and the evidence behind every answer.
This is an advisory readiness service. A readiness score is a measure prepared by My CISO Partner; it is not a self-assessment submission to the Supplier Performance Risk System, and it is not a CMMC certification, which only an accredited C3PAO can issue.
One versioned catalog across the frameworks that actually govern your contracts.
NIST CSF 2.0's six Functions, NIST SP 800-171 Rev 2 and Rev 3's control catalog with its crosswalk, and the CMMC Level 1 and Level 2 program baseline are each expressed as an assessable control library with the original citation preserved — never paraphrased into something that drifts from the source. We work through every applicable control with your team: what it asks, what you have, what evidences it, and what closes the gap.
- Requirement text is kept verbatim from the source publication, with organization-defined parameters and assessment objectives tracked as their own record — not summarized into something that can quietly drift from what 800-171 actually says.
- A crosswalk between 800-171 Rev 2 and Rev 3, so a program that started under one revision can see exactly how its record maps onto the other before deciding to move.
- The CMMC Level 1 and Level 2 baseline is populated from the authoritative published requirement set — no invented controls, and no Level 3 content, since the Level 3 requirement set has not been finalized.
- A readiness score that distinguishes compliance status, evidence sufficiency and remediation status — with the calculation shown, never a bare percentage.
Organizations with a framework obligation on the calendar.
Defense contractors & subcontractors
Organizations handling Controlled Unclassified Information under a DFARS clause, preparing for a CMMC Level 1 self-assessment or a Level 2 C3PAO certification assessment.
Companies adopting NIST CSF as their security baseline
Boards and executives who've chosen NIST CSF 2.0 as the common language for the security program, and need to know where the program actually stands against it.
Suppliers to defense and federal primes
Subcontractors asked by a prime contractor to demonstrate 800-171 or CMMC readiness as a condition of the relationship, ahead of any formal government requirement.
Leadership and counsel
CEOs, boards and general counsel who need the position stated in plain language, with the citation behind every statement.
The gap you find yourself is cheaper than the one a C3PAO finds.
Requirement text that's drifted
A summarized control description that no longer matches the actual publication. Requirement statements here are verbatim, with the citation shown.
Evidence that can't be produced
A control marked "implemented" until an assessor asks for the record. Every control carries what an assessor examines, what was received, and when it expires.
Rev 2 vs. Rev 3 confusion
A program that doesn't know which 800-171 revision it's actually being held to. The crosswalk shows exactly how a Rev 2 record maps onto Rev 3.
Organization-defined parameters left undefined
800-171 leaves some parameters for you to set — a password length, a review interval. Undefined parameters are a finding, not a silent gap.
Findings without owners
A gap noted in a report and never closed. Every finding has a rating, an owner, a due date and a remediation plan, and closed findings can't be quietly edited.
A framework the board doesn't understand
"Are we CMMC ready?" needs a number and a plan, not a shrug. The executive dashboard shows readiness by domain, without pretending to issue a certification we can't.
Ten stages, one traceable chain.
From the first conversation to the executive report, every stage leaves a record you can follow back: framework → domain → requirement → control → evidence → assessment → finding → remediation.
- Scope is set from your framework choice (CSF, 800-171 Rev 2/Rev 3, or the CMMC Level 1/Level 2 baseline), your contract obligations and your CUI footprint — controls that don't apply are recorded as out of scope with the reason, never silently dropped.
- Each control is recorded as Compliant, Partially Compliant, Non-Compliant, Not Applicable or Not Assessed — the assessor's vocabulary, not a certification determination — with evidence requested, received and rated for sufficiency.
- The readiness score weights each control, discounts it by evidence sufficiency, and deducts for unresolved critical and high findings — the weighting is configuration, and every step is shown.
- Issued results are frozen. A final assessment cannot be edited or reopened; a changed position is a new assessment, so history is never rewritten.
Not one framework stretched to fit three names.
NIST CSF 2.0
All six Functions and every Category and Subcategory of the 2.0 Core, usable as a standalone baseline or alongside a compliance-specific framework.
NIST SP 800-171 Rev 2
The control catalog governing programs already operating under the prior revision, with a path to see how the record maps onto Rev 3.
NIST SP 800-171 Rev 3
The current control catalog, with organization-defined parameters and assessment objectives tracked per requirement, and the Rev 2 crosswalk.
CMMC Level 1
The Foundational-level baseline for organizations handling Federal Contract Information, populated from the authoritative published requirement set.
CMMC Level 2
The Advanced-level baseline aligned to 800-171 for organizations handling Controlled Unclassified Information, ahead of a self-assessment or a C3PAO certification assessment.
CMMC Level 3 not yet published
The Expert-level requirement set has not been finalized by the Department of Defense. No Level 3 baseline is seeded, so nothing here can be mistaken for an authoritative Level 3 control.
What you receive.
- A scoped, control-by-control assessment record with the original NIST/CMMC citation preserved for every requirement.
- An evidence register: every request, version, review decision, validity period and expiry, with an access ledger.
- A findings register with rating, priority, owner, due date and a remediation plan per finding.
- The readiness score with its domain breakdown and the full calculation shown.
- An executive report — scope, score, readiness by domain, priority findings, evidence position, remediation plan and limitations — and board briefing content.
- A client portal showing assessment status, released findings, outstanding evidence and delivered reports.
Never paraphrased into drift.
Every requirement keeps its exact published text and citation. Plain-English summaries exist for audit planning, but the underlying publication controls — always, not just when it's convenient.
Start without an engagement.
Our free, browser-based CSF 2.0 Tracker walks all 106 Subcategories across all six Functions — yours to keep, no account required, and a natural first step before a full readiness engagement.
Ownership after the assessment.
Readiness is not a one-time exercise. Our Fractional CISO service carries the program forward through re-assessment as revisions and contract terms change.
Questions, answered directly.
No. It is an advisory readiness engagement. A CMMC Level 2 certification can only be issued by an accredited third-party assessment organization (a C3PAO); a Level 1 status is a self-assessment your organization submits itself. What we deliver is the gap analysis, evidence and remediation plan that gets you ready to go into either process with confidence, not the certification itself.
That depends on your contract language and DoD guidance timing. We can assess against Rev 2, Rev 3, or both, and the crosswalk shows exactly how a Rev 2 record maps onto Rev 3 controls so a later move isn't a rebuild from zero.
Not yet. The Department of Defense has not finalized the Level 3 requirement set, so no Level 3 baseline is seeded in our platform. We won't assess against a control set that doesn't officially exist yet, and we'll add it once it's published.
Named, senior consultants perform the assessment and make every judgement. Where an AI assistant is enabled for an engagement, everything it produces is labelled AI GENERATED — HUMAN REVIEW REQUIRED and cites only records already in the assessment; it cannot change a status, close a finding, or make any compliance determination.
A framework needs policies behind it, not just controls.
Our policy library includes NIST CSF-aligned sample policies among 228 templates spanning governance, risk, privacy, operational and compliance requirements — a starting point for the documentation an assessor or a contracting officer will ask to see alongside your control evidence.
Start with the free CSF tracker.
Fifteen minutes gives you a first read on where your program stands. A consultant follows up to scope the full readiness engagement against the framework your contracts actually require.