Holdfast Cyber crest Holdfast Cyber Secure Today. Defend Tomorrow.
CMMC Readiness & Managed Compliance

CMMC readiness that holds up under audit.

Holdfast Cyber is a veteran-owned advisory firm that takes Detroit-metro defense suppliers from gap assessment to certification-ready — and keeps them there — against NIST SP 800-171 and CMMC 2.0.

~20 questions · under 3 minutes · indicative estimate, no login

Veteran-Owned Small Business · Serving the Defense Industrial Base

CISSP CISM CRISC C|CISO ISO 27001 Lead Auditor U.S. Coast Guard Veteran
The Requirement

CMMC is flowing down the supply chain

The Department of Defense is phasing certification requirements into its contracts. As those clauses take effect, primes are passing them straight to their subcontractors — and a defensible SPRS score, System Security Plan, and POA&M are becoming table stakes for staying on the bid list.

Most small and mid-sized suppliers don't have a compliance department. They have an operations or IT lead absorbing NIST 800-171 — fourteen control families deep — on top of a full-time role.

Holdfast Cyber closes that gap without asking you to build a team for it: one accountable point of contact and a clear path from where you are today to certification-ready.

Why it matters

An unscored supplier is an unqualified supplier.

When a prime needs a certified partner and your documentation isn't ready, the award doesn't wait. Readiness is now a prerequisite to compete — not a nice-to-have you handle after you win.

Services

Full-lifecycle compliance, scoped to your operation

Each engagement is built on your actual environment — never boilerplate templates dropped into a new logo.

01

Gap Assessment & SPRS Scoring

Baseline your environment against NIST SP 800-171 and produce a defensible SPRS self-assessment score.

Details →
02

SSP & POA&M Development

A System Security Plan that reflects how your business actually runs, paired with an actionable POA&M.

Details →
03

Policy & Documentation

All fourteen 800-171 control-family policies plus IR and CM plans, written to your operations.

Details →
04

Managed Compliance

Continuous monitoring and evidence discipline so readiness is maintained, not rebuilt annually.

Details →
05

Assessment Support

Evidence packaging and hands-on preparation for your self-assessment or C3PAO engagement.

Details →
06

Fractional Advisory

Senior security and compliance guidance without a full-time hire on the payroll.

Details →
The Approach

Three phases, one heading

A disciplined engagement model that moves you from an honest starting position to a maintained state of readiness — with defined deliverables at every phase.

01
Assess

Position Report

We measure your environment against NIST 800-171, calculate your SPRS score, and hand you a prioritized remediation roadmap. You leave this phase knowing exactly where you stand — before committing to the work.

Gap AssessmentSPRS ScorePrioritized Roadmap
02
Implement

Course to Compliance

Policies, System Security Plan, and POA&M are built and mapped to your environment, alongside incident response and configuration management plans and hands-on support closing control gaps.

14 Family PoliciesSSPPOA&MIR & CM Plans
03
Sustain

Hold Fast

Continuous monitoring and evidence discipline keep readiness a maintained state rather than an annual scramble — and keep you prepared to support the certifying assessment whenever it comes.

Continuous MonitoringEvidence ManagementAssessment Support
Holdfast Cyber crest
Founder-Led Delivery
GRC Practitioner · USCG Veteran
Leadership

The person who runs your assessment answers the phone during your audit

Holdfast Cyber is led by a career governance, risk, and compliance practitioner with more than fifteen years spanning U.S. Coast Guard port security, CISO and VP-level security roles, and principal GRC consulting across a portfolio of defense and commercial clients.

That track record is the standard your engagement is held to: an 8-for-8 first-time ISO 27001 certification rate with zero critical findings. No account handoffs, no call center — the same senior practitioner from first call to final evidence package.

Meet the Firm
8/8
First-time ISO 27001 certifications, zero critical findings
14
NIST 800-171 control families covered end to end
40%
Reduction in high-severity findings across managed programs
15+
Years across port security, CISO roles, and GRC consulting
Holdfast Cyber crest

Start with an honest position report

A gap assessment tells you exactly where you stand against NIST 800-171 today, and what it takes to be certification-ready. No obligation to continue.

Request a Gap Assessment
Secure Today. Defend Tomorrow.