Who we work with
CMMC consulting for defense contractors who hold CUI
Cyber DSC is a compliance advisory practice for companies in the Defense Industrial Base. We work with organizations that handle Controlled Unclassified Information and need to demonstrate NIST SP 800-171 implementation — to a contracting officer, to a prime, or to a third-party assessor.
Most of our clients are small and mid-sized contractors without a dedicated compliance team. They have a SPRS score they are not confident in, an SSP written from a template, and no clear picture of which systems are actually in scope. That is the problem we solve.
Subcontractors to primes
Flow-down clauses arrived with the contract and nobody has worked out what they require in practice.
Manufacturers and engineering firms
Controlled technical data moves through drawings, ERP systems and shop-floor equipment that was never scoped.
IT and service providers
You support defense clients and need to understand where your tooling sits inside their assessment boundary.
What we do
Readiness work, not a template pack
Compliance documents are easy to buy and hard to defend. Our work starts with what is actually happening in your environment and produces documentation that matches it.
- Scope determinationWe trace how CUI actually enters, moves through and leaves your environment, then categorize assets under 32 CFR § 170.19. The boundary is an output of that exercise, not an assumption made at the start.
- SPRS score validationWe assess against the 110 requirements in NIST SP 800-171 Revision 2 using the DoD Assessment Methodology, so the score you post is one you can support.
- SSP and POA&M that hold upA System Security Plan describing the environment you have, with named owners, and a remediation plan sequenced by impact rather than by ease.
- AI governance inside the CUI boundaryYour people are already using AI tools. We help you decide which instances can hold controlled data, and document that decision before an assessor asks. See AI in CUI environments.
Each of these runs as a fixed-scope, fixed-fee engagement with the price published up front — from a readiness assessment through SSP development, audit preparation and ongoing advisory. The full list, with what each one delivers, is on the services page.
Current status
Phase 2 is suspended. The obligation is not.
Third-party certification milestones were paused in July 2026, but DFARS 252.204-7012 safeguarding, incident reporting, SPRS posting and annual affirmation all remain in force — and government-led assessments continue. For most contractors this is the cheapest preparation window they will get. Program updates are published by the DoD CIO.
If you are not sure where you stand, the 25-question self-check takes five minutes and names the control families holding your score down. If you already know what you need, the engagements and fees are published. If you would rather talk it through first, book a call.
Cyber DSC is led by Nabiha Sofia Herradi, a Certified CMMC Professional with a law degree and fifteen years in governance, risk and compliance. Based in Jacksonville, Florida, serving defense contractors nationwide.
- CMMC-CCP
- CISM
- CISA
- CIPP/E
- CIPP/US
- LL.B (J.D.)
Next step
Most contractors find their scope is wider than they thought.
A short call, then a written read on where you actually stand against NIST SP 800-171 and what it would take to close the gap.
