CARMhaus Consulting
Home
Services
  • Security Architecture
  • Readiness Assessment
  • Security Leadership
  • Third-Party Risk
Industries
  • Defense and Aerospace
  • Manufacturing and OT
  • Healthcare
  • Financial Services
Frameworks
  • CMMC Level 2
  • NIST SP 800-171
  • SOC 2
  • ISO 27001
  • HIPAA
  • SOX ITGC
Approach
About
Contact
CARMhaus Consulting
Home
Services
  • Security Architecture
  • Readiness Assessment
  • Security Leadership
  • Third-Party Risk
Industries
  • Defense and Aerospace
  • Manufacturing and OT
  • Healthcare
  • Financial Services
Frameworks
  • CMMC Level 2
  • NIST SP 800-171
  • SOC 2
  • ISO 27001
  • HIPAA
  • SOX ITGC
Approach
About
Contact
More
  • Home
  • Services
    • Security Architecture
    • Readiness Assessment
    • Security Leadership
    • Third-Party Risk
  • Industries
    • Defense and Aerospace
    • Manufacturing and OT
    • Healthcare
    • Financial Services
  • Frameworks
    • CMMC Level 2
    • NIST SP 800-171
    • SOC 2
    • ISO 27001
    • HIPAA
    • SOX ITGC
  • Approach
  • About
  • Contact
  • Home
  • Services
    • Security Architecture
    • Readiness Assessment
    • Security Leadership
    • Third-Party Risk
  • Industries
    • Defense and Aerospace
    • Manufacturing and OT
    • Healthcare
    • Financial Services
  • Frameworks
    • CMMC Level 2
    • NIST SP 800-171
    • SOC 2
    • ISO 27001
    • HIPAA
    • SOX ITGC
  • Approach
  • About
  • Contact
110 controls. Assessed honestly.

NIST SP 800-171 Compliance Consulting

A self-assessment score you can defend, a System Security Plan that describes the system you actually run, and Plans of Action written to close rather than roll forward. Our principal has taken an environment to 110 of 110 controls with zero open items.

Review your 800-171 position

A score you can defend, not a score you can post

The number is the easy part

The number is the easy part

The number is the easy part

Anyone can produce a self-assessment score. The question an assessor, a prime, or a DIBCAC reviewer asks is what the number was measured against, and whether the system still looks like that.

Objectives, not controls

The number is the easy part

The number is the easy part

The 110 requirements expand into 320 assessment objectives. A control marked met at the requirement level frequently fails at the objective level, and that is where scores collapse under review.

Plans of Action that close

The number is the easy part

Plans of Action that close

A Plan of Action is a commitment with a date attached. We write them to be closed, not carried forward, because carried-forward items are the ones that get read as bad faith.

Where this usually starts

A prime is asking for a position

A prime is asking for a position

A prime is asking for a position

Somebody upstream wants your score, and the number currently in SPRS came from a process nobody can now reconstruct in enough detail to defend it.

An assessment window is opening

A prime is asking for a position

A prime is asking for a position

Self-assessment, third party, or a government review. The sensible move is to know what will be found while there is still room to act on it.

The plan has stopped moving

A prime is asking for a position

The plan has stopped moving

The same items sit on the Plan of Action cycle after cycle. This is almost always an ownership problem rather than a technical one, and naming it as such is usually the unlock.

What we do

Assess against the objectives

Assess against the objectives

Assess against the objectives

All 110 requirements tested at the objective level, evidence sampled rather than asserted, with a written basis for every determination so the position survives staff turnover.

Specify what closes the gap

Assess against the objectives

Assess against the objectives

Identity, logging, media protection, configuration baselines and access review cycles, written as specifications your team or your provider can build to, with each requirement traced to a named owner.

Establish the evidence cycle

Assess against the objectives

Establish the evidence cycle

Each control gets an artifact, a cadence and an owner. That is what turns a point-in-time score into a position you can hold when somebody asks about it eighteen months from now.

What a full engagement produces

A System Security Plan that matches reality

A System Security Plan that matches reality

A System Security Plan that matches reality

Written against the system you run, not the system you intended. Clause-numbered and control-mapped so an assessor can trace a claim to a configuration.

A defensible SPRS score

A System Security Plan that matches reality

A System Security Plan that matches reality

With the working papers behind it, so you can answer how it was derived a year from now when the person who ran the assessment has moved on.

A Plan of Action with owners and dates

A Plan of Action with owners and dates

A Plan of Action with owners and dates

Sequenced by risk and by what unblocks the most other items, not alphabetically by control family.

An evidence register

A Plan of Action with owners and dates

A Plan of Action with owners and dates

What gets produced, how often, by whom, and where it lives. The register is what survives staff turnover.

Questions we get asked

The ones that come up most often before a scoping call.

110 of 110 with no open Plans of Action is the position that ends the conversation. We have taken an environment there. Short of that, what matters is that the score is honest and the remaining items have dates somebody owns.


NIST SP 800-171 is the control standard. CMMC is the program that verifies you meet it. The controls are the same either way, which is why the CMMC assessment pause does not change the underlying work.


Often, as a starting point. The common failure is that it was written to satisfy a request rather than to describe a system, so it claims controls the configuration does not enforce. We read it against the environment and tell you which parts hold.


We document it honestly, implement a compensating control where one exists, and put it on the Plan of Action with a date. Assessors are considerably more forgiving of a known gap with a plan than of a control claimed and not operating.


Yes, and that is usually the right structure. They know the environment and they hold the keys. We bring the control interpretation and the evidence discipline, write the work in terms they can execute, and review what they deliver. Keeping the specification and the build in separate hands is deliberate.


© 2026 CARMhaus Consulting LLC. All rights reserved. Cybersecurity · Assurance · Risk Management

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

Accept