NIST SP 800-171 · CMMC Readiness · Northern Virginia
Fixed-price gap assessments for small defense subcontractors. Every finding mapped to the published NIST assessment objectives, every score calculated the way DoD calculates it, every claim checkable by your own people.
The SPRS scale — where most subcontractors think they are, and where they are
The DoD scoring methodology runs from −203 to 110. Most owners don't know the floor is negative. Most who self-reported a 110 have never calculated their real number — and a senior executive affirms that number to the federal government every year.
In July 2026, DoD suspended the CMMC Phase 2 rollout pending a program review. Some subcontractors read that as a reprieve. Read the fine print instead.
NIST SP 800-171 has been a contractual requirement since 2017. The pause suspended the third-party verification rollout, not the clause sitting in your contracts today. Primes continue to flow it down regardless of CMMC's status.
With no mandatory outside assessor, your self-reported SPRS score is the legal record — and a named executive at your company affirms it annually. DOJ's Civil Cyber-Fraud Initiative pursues contractors whose scores don't match reality. An inaccurate score is a False Claims Act problem with your signature on it.
Primes must verify their supply chain before award, and several now demand evidence on their own timelines — some giving suppliers under 90 business days to produce it. Fixing gaps now, on your schedule, is the inexpensive version of this work.
No hourly billing, no scope creep, no surprise invoices. Half up front, half on delivery.
A structured working session with your IT lead or MSP, run through our assessment tooling. You leave knowing your real SPRS score and your ten most consequential gaps.
All 110 controls assessed against the NIST SP 800-171A assessment objectives with direct evidence review — configurations, policies, screenshots — not self-reported answers. The core engagement.
Everything in the full assessment, plus the documentation an assessor asks for first: a drafted System Security Plan, a working Plan of Action & Milestones, and starter policies for your largest documentation gaps.
For reference: consultancy readiness engagements commonly start near $10,000, and a full third-party C3PAO assessment runs $30,000–$70,000. Blackpine is a deliberately lean practice — the pricing reflects overhead, not corners.
Blackpine is a young practice, and pretending otherwise would be a bad start to a relationship built on honest assessment. So the methodology is designed to be verified, not believed.
Every control is assessed against the NIST SP 800-171A assessment objectives and scored with the DoD SPRS methodology — both public documents. Nothing proprietary stands between you and verifying a finding.
A failed control cites the specific objective it fails and the specific evidence reviewed. Your IT lead, your MSP, or a future assessor can check any line of the report independently. That transparency is the product.
Assessments run on ComplyScan, scoring software built in-house specifically for 800-171 Rev 2, paired with manual evidence review. We know exactly what the tooling does because we wrote it — no black-box vendor platform.
Assessment evidence is about your environment — configurations, policies, screenshots — never the controlled information itself. Your CUI does not leave your systems during an engagement, by design.
Request the full sample gap assessment report — a complete engagement deliverable prepared for a model contractor. Read it, hand it to your IT person, and decide if the work speaks for itself.
Blackpine exists because the smallest companies in the Defense Industrial Base are priced out of compliance help — and they make up nearly three-quarters of it.
The firms doing this work well charge more than a fifteen-person machine shop can justify. The ones charging less often sell checkbox questionnaires that wouldn't survive contact with a real assessor. Blackpine sits in the gap on purpose: rigorous methodology, small-company pricing, and a report you can independently verify instead of a brand name you're asked to trust.
The practice is led by its founder — a U.S. Army National Guard Signal Support Systems Specialist and cybersecurity management student at Virginia Tech, based in the Haymarket–Gainesville corridor, who built the assessment tooling personally. That means engagements are done by the person whose name is on the work, not delegated to whoever was available.
The pause stopped the third-party certification rollout. It didn't touch DFARS 252.204-7012, which has required NIST 800-171 in your contracts since 2017, and it didn't touch the SPRS affirmation your executive signs annually — which DOJ actively enforces. The program review is expected to conclude with third-party assessment returning in some form. Closing gaps now, on your own timeline, costs a fraction of closing them under a prime's deadline later.
You shouldn't — not on faith. Request the sample report and judge the work directly. Every finding maps to a published NIST assessment objective and cites the evidence behind it, so anyone technical on your side can verify the assessment line by line. Trust in this engagement comes from checkability, not from a logo or a partner's bio.
If you have $15,000 or more budgeted and want a national brand on the cover page, you should — and we'll say so on the call. In practice, firms at that tier rarely want a fifteen-person subcontractor as a client, and the work lands with their most junior analyst anyway. Blackpine gives you the same framework and the same assessment objectives at a price that leaves budget for the part that matters: actually fixing the gaps.
No, and be wary of anyone who implies otherwise. Blackpine is not a C3PAO and does not issue certifications of any kind. What you get is an honest picture of your current state, your real SPRS score, and a costed path to closing your gaps — the groundwork that makes any future certification effort faster and cheaper.
Because it's built to be checked. Findings are scored against the published 800-171A objectives and the public DoD scoring methodology, with the evidence for each conclusion cited in the report. If anything is wrong, you'll be able to see exactly where — and we'd rather you catch it than an assessor.
One line about your company and your prime relationships is enough. The sample report and scheduling link come back within one business day.
Required reading, in plain terms. Blackpine Compliance Advisory LLC is an independent readiness and gap assessment practice. Blackpine is not a CMMC Third-Party Assessment Organization (C3PAO), is not accredited by the Cyber AB, and is not authorized to issue CMMC certifications or official compliance determinations of any kind. Assessments do not constitute certification, accreditation, or a guarantee of compliance with NIST SP 800-171, DFARS 252.204-7012, the CMMC program, or any contractual requirement. Findings reflect professional judgment based on information and evidence provided by the client as of the assessment date. Implementation of recommendations does not guarantee any particular score or outcome in any subsequent self-assessment, third-party assessment, or government audit. Clients remain solely responsible for their compliance obligations, for the accuracy of any score or affirmation submitted to SPRS, and for all representations made to the U.S. Government or to prime contractors.