Holdfast Cyber is a veteran-owned advisory firm that takes Detroit-metro defense suppliers from gap assessment to certification-ready — and keeps them there — against NIST SP 800-171 and CMMC 2.0.
~20 questions · under 3 minutes · indicative estimate, no login
Veteran-Owned Small Business · Serving the Defense Industrial Base
The Department of Defense is phasing certification requirements into its contracts. As those clauses take effect, primes are passing them straight to their subcontractors — and a defensible SPRS score, System Security Plan, and POA&M are becoming table stakes for staying on the bid list.
Most small and mid-sized suppliers don't have a compliance department. They have an operations or IT lead absorbing NIST 800-171 — fourteen control families deep — on top of a full-time role.
Holdfast Cyber closes that gap without asking you to build a team for it: one accountable point of contact and a clear path from where you are today to certification-ready.
When a prime needs a certified partner and your documentation isn't ready, the award doesn't wait. Readiness is now a prerequisite to compete — not a nice-to-have you handle after you win.
Each engagement is built on your actual environment — never boilerplate templates dropped into a new logo.
Baseline your environment against NIST SP 800-171 and produce a defensible SPRS self-assessment score.
Details →A System Security Plan that reflects how your business actually runs, paired with an actionable POA&M.
Details →All fourteen 800-171 control-family policies plus IR and CM plans, written to your operations.
Details →Continuous monitoring and evidence discipline so readiness is maintained, not rebuilt annually.
Details →Evidence packaging and hands-on preparation for your self-assessment or C3PAO engagement.
Details →Senior security and compliance guidance without a full-time hire on the payroll.
Details →A disciplined engagement model that moves you from an honest starting position to a maintained state of readiness — with defined deliverables at every phase.
We measure your environment against NIST 800-171, calculate your SPRS score, and hand you a prioritized remediation roadmap. You leave this phase knowing exactly where you stand — before committing to the work.
Policies, System Security Plan, and POA&M are built and mapped to your environment, alongside incident response and configuration management plans and hands-on support closing control gaps.
Continuous monitoring and evidence discipline keep readiness a maintained state rather than an annual scramble — and keep you prepared to support the certifying assessment whenever it comes.
Holdfast Cyber is led by a career governance, risk, and compliance practitioner with more than fifteen years spanning U.S. Coast Guard port security, CISO and VP-level security roles, and principal GRC consulting across a portfolio of defense and commercial clients.
That track record is the standard your engagement is held to: an 8-for-8 first-time ISO 27001 certification rate with zero critical findings. No account handoffs, no call center — the same senior practitioner from first call to final evidence package.
Meet the Firm
A gap assessment tells you exactly where you stand against NIST 800-171 today, and what it takes to be certification-ready. No obligation to continue.
Request a Gap Assessment