NIST SP 800-171 · CMMC Readiness · Northern Virginia

Know where you actually stand.

Fixed-price gap assessments for small defense subcontractors. Every finding mapped to the published NIST assessment objectives, every score calculated the way DoD calculates it, every claim checkable by your own people.

The SPRS scale — where most subcontractors think they are, and where they are

The DoD scoring methodology runs from −203 to 110. Most owners don't know the floor is negative. Most who self-reported a 110 have never calculated their real number — and a senior executive affirms that number to the federal government every year.

The Situation · August 2026

The certification rollout paused. Your obligations didn't.

In July 2026, DoD suspended the CMMC Phase 2 rollout pending a program review. Some subcontractors read that as a reprieve. Read the fine print instead.

DFARS 252.204-7012

The requirement never moved

NIST SP 800-171 has been a contractual requirement since 2017. The pause suspended the third-party verification rollout, not the clause sitting in your contracts today. Primes continue to flow it down regardless of CMMC's status.

SPRS Affirmation

Self-attestation risk went up

With no mandatory outside assessor, your self-reported SPRS score is the legal record — and a named executive at your company affirms it annually. DOJ's Civil Cyber-Fraud Initiative pursues contractors whose scores don't match reality. An inaccurate score is a False Claims Act problem with your signature on it.

Prime Flowdowns

Primes are filling the vacuum

Primes must verify their supply chain before award, and several now demand evidence on their own timelines — some giving suppliers under 90 business days to produce it. Fixing gaps now, on your schedule, is the inexpensive version of this work.

Engagements

Three ways in. Fixed price, every time.

No hourly billing, no scope creep, no surprise invoices. Half up front, half on delivery.

I
Baseline Compliance Scan

A structured working session with your IT lead or MSP, run through our assessment tooling. You leave knowing your real SPRS score and your ten most consequential gaps.

  • Calculated SPRS score, DoD methodology
  • Findings summary by control family
  • Top-ten gap register
  • One-hour executive readout
$750Starting · 2 week delivery
II
Full Gap Assessment & Roadmap

All 110 controls assessed against the NIST SP 800-171A assessment objectives with direct evidence review — configurations, policies, screenshots — not self-reported answers. The core engagement.

  • Complete 110-control gap report
  • Evidence citation on every finding
  • Prioritized remediation roadmap, costed
  • SPRS scoring worksheet, math shown
  • Two readout sessions
$2,500Starting · 4–5 week delivery
III
Assessment, SSP & POA&M

Everything in the full assessment, plus the documentation an assessor asks for first: a drafted System Security Plan, a working Plan of Action & Milestones, and starter policies for your largest documentation gaps.

  • Full gap assessment & roadmap
  • Drafted System Security Plan
  • Drafted POA&M, SPRS-mapped
  • Starter policy set
  • 30-day follow-up session
$6,000Starting · 7–9 week delivery

For reference: consultancy readiness engagements commonly start near $10,000, and a full third-party C3PAO assessment runs $30,000–$70,000. Blackpine is a deliberately lean practice — the pricing reflects overhead, not corners.

Method

Don't trust the resume. Check the work.

Blackpine is a young practice, and pretending otherwise would be a bad start to a relationship built on honest assessment. So the methodology is designed to be verified, not believed.

Public standards only

Scored against published objectives

Every control is assessed against the NIST SP 800-171A assessment objectives and scored with the DoD SPRS methodology — both public documents. Nothing proprietary stands between you and verifying a finding.

Evidence, cited

Every finding shows its work

A failed control cites the specific objective it fails and the specific evidence reviewed. Your IT lead, your MSP, or a future assessor can check any line of the report independently. That transparency is the product.

Purpose-built tooling

ComplyScan under the hood

Assessments run on ComplyScan, scoring software built in-house specifically for 800-171 Rev 2, paired with manual evidence review. We know exactly what the tooling does because we wrote it — no black-box vendor platform.

Your data stays yours

We never take custody of CUI

Assessment evidence is about your environment — configurations, policies, screenshots — never the controlled information itself. Your CUI does not leave your systems during an engagement, by design.

Judge the deliverable before you pay for one.

Request the full sample gap assessment report — a complete engagement deliverable prepared for a model contractor. Read it, hand it to your IT person, and decide if the work speaks for itself.

Request sample report
The Practice

A deliberately lean practice.

Blackpine exists because the smallest companies in the Defense Industrial Base are priced out of compliance help — and they make up nearly three-quarters of it.

The firms doing this work well charge more than a fifteen-person machine shop can justify. The ones charging less often sell checkbox questionnaires that wouldn't survive contact with a real assessor. Blackpine sits in the gap on purpose: rigorous methodology, small-company pricing, and a report you can independently verify instead of a brand name you're asked to trust.

The practice is led by its founder — a U.S. Army National Guard Signal Support Systems Specialist and cybersecurity management student at Virginia Tech, based in the Haymarket–Gainesville corridor, who built the assessment tooling personally. That means engagements are done by the person whose name is on the work, not delegated to whoever was available.

Founded2026 · Northern Virginia
FocusNIST SP 800-171 Rev 2 readiness for 10–50 person defense subcontractors
BackgroundU.S. Army Signal Corps (VA ARNG) · Cybersecurity Management & Analytics, Virginia Tech
ToolingComplyScan — in-house 800-171 scoring and gap engine
CoverageManassas · Chantilly · Gainesville · Warrenton · Fredericksburg · Winchester
Engagement modelFixed price · on-site available throughout NoVA
Straight Answers

The questions owners actually ask.

CMMC is paused. Why would we do this now?

The pause stopped the third-party certification rollout. It didn't touch DFARS 252.204-7012, which has required NIST 800-171 in your contracts since 2017, and it didn't touch the SPRS affirmation your executive signs annually — which DOJ actively enforces. The program review is expected to conclude with third-party assessment returning in some form. Closing gaps now, on your own timeline, costs a fraction of closing them under a prime's deadline later.

Why should we trust a new practice?

You shouldn't — not on faith. Request the sample report and judge the work directly. Every finding maps to a published NIST assessment objective and cites the evidence behind it, so anyone technical on your side can verify the assessment line by line. Trust in this engagement comes from checkability, not from a logo or a partner's bio.

Why not hire an established firm?

If you have $15,000 or more budgeted and want a national brand on the cover page, you should — and we'll say so on the call. In practice, firms at that tier rarely want a fifteen-person subcontractor as a client, and the work lands with their most junior analyst anyway. Blackpine gives you the same framework and the same assessment objectives at a price that leaves budget for the part that matters: actually fixing the gaps.

Will this get us CMMC certified?

No, and be wary of anyone who implies otherwise. Blackpine is not a C3PAO and does not issue certifications of any kind. What you get is an honest picture of your current state, your real SPRS score, and a costed path to closing your gaps — the groundwork that makes any future certification effort faster and cheaper.

How do we know the report is accurate?

Because it's built to be checked. Findings are scored against the published 800-171A objectives and the public DoD scoring methodology, with the evidence for each conclusion cited in the report. If anything is wrong, you'll be able to see exactly where — and we'd rather you catch it than an assessor.

Begin

Start with the sample report.
Or a fifteen-minute call.

contact@blackpinecompliance.com

One line about your company and your prime relationships is enough. The sample report and scheduling link come back within one business day.

BasedHaymarket, Virginia
ServingNorthern Virginia & the DC-metro DIB
ResponseWithin one business day
LinkedInBlackpine Compliance Advisory

Required reading, in plain terms. Blackpine Compliance Advisory LLC is an independent readiness and gap assessment practice. Blackpine is not a CMMC Third-Party Assessment Organization (C3PAO), is not accredited by the Cyber AB, and is not authorized to issue CMMC certifications or official compliance determinations of any kind. Assessments do not constitute certification, accreditation, or a guarantee of compliance with NIST SP 800-171, DFARS 252.204-7012, the CMMC program, or any contractual requirement. Findings reflect professional judgment based on information and evidence provided by the client as of the assessment date. Implementation of recommendations does not guarantee any particular score or outcome in any subsequent self-assessment, third-party assessment, or government audit. Clients remain solely responsible for their compliance obligations, for the accuracy of any score or affirmation submitted to SPRS, and for all representations made to the U.S. Government or to prime contractors.