What applies in this sector
Descriptions are of the published requirements, not claims about outcomes.
Regimes in play
- CMMC Contractual requirement
- NIST CSF Voluntary framework
- ISO 27001 Certifiable standard
- SOC 2 Attestation examination
One control base
Mapped once, evidenced once, and maintained between assessments.
What shapes security decisions here
For contractors, security requirements arrive through the contract rather than from a regulator. DFARS clauses require safeguarding of covered defense information in line with NIST SP 800-171, along with rapid reporting of cyber incidents to the Department of Defense.
The Cybersecurity Maturity Model Certification program adds verification. Depending on level, requirements may be met by self-assessment or by assessment from an authorized third party, which means system security plans and plans of action have to be accurate and current rather than assembled at bid time.
Requirements also flow down. A prime contractor will pass obligations to subcontractors, and a subcontractor that cannot evidence compliance becomes a problem for the prime's own position.
Risks that behave differently in this sector
Not a general threat list. These are the exposures that need a different response here than they would elsewhere.
-
Eligibility, not just exposure
The immediate business risk is often commercial rather than technical: an inaccurate self-assessment score or an unclosed plan of action can cost an award.
-
Scope creep of controlled information
Controlled unclassified information spreads into email, file shares and endpoints that were never in the assessed boundary, quietly enlarging what has to be protected.
-
Rapid incident reporting duties
Reporting obligations run on short clocks, and the organization has to be able to determine what happened and report it inside that window.
-
Supply chain flow-down
Obligations you accept must be passed on and evidenced by your own subcontractors, whose maturity varies considerably.
Regulatory and contractual pressure
General descriptions of published requirements. Which of them apply to a particular organization is the first question an engagement answers.
- NIST SP 800-171
- Security requirements for protecting controlled unclassified information in non-federal systems.
- DFARS safeguarding and reporting clauses
- Contractual safeguarding obligations and rapid reporting of cyber incidents to the Department of Defense.
- CMMC
- The program under which contractors demonstrate the required level of implementation, by self-assessment or third-party assessment depending on level.
- System security plans and plans of action
- Documentation of implementation status and remediation, which must reflect the environment as it currently exists.
What leadership raises with us
- A prime contractor has flowed down requirements the organization cannot yet evidence.
- A system security plan exists but no longer matches the environment it describes.
- Plans of action carry items that have been open for years with no owner.
- Bid eligibility now depends on an assessment nobody internally owns.
- Controlled information has spread beyond the boundary that was originally assessed.
What prompts an engagement
- A contract or solicitation has introduced a CMMC level requirement.
- A prime contractor has requested evidence of NIST SP 800-171 implementation.
- A self-assessment score is due, or an existing score is out of date.
- A new award will bring controlled unclassified information into the environment for the first time.
- An assessment identified gaps that have not been closed.
Leadership first, then the program work
Engagements in this sector usually begin with vCISO leadership: an accountable owner who can establish what applies, decide what matters most, and report on it to the people who carry the obligation.
Services this sector draws on most
- Regulatory and Framework Readiness Readiness for the frameworks and regulations that genuinely apply to you, NIST CSF, ISO 27001, SOC 2, CMMC, HIPAA, PCI DSS and SOX-related IT controls, with the evidence maintained between assessments.
- Security Program Assessment A documented picture of what your security program actually covers, measured against a recognized framework, with the gaps ranked by business consequence.
- Security Policy, Standards and Awareness Policies written to match how your organization actually operates, with the standards that make them workable and the training that makes them understood.
- Incident Readiness and Response Planning A response plan that names decision makers, defines escalation and notification paths, and has been tested with the executives who would have to use it.
- Cloud Security Architecture and Governance Design and governance for cloud environments: what the provider secures, what remains yours, and how you keep track of a platform that changes underneath you.
Frameworks that apply here
- CMMC and NIST SP 800-171
- Defense contractors and their supply chain, where flow-down clauses make this an eligibility issue rather than a compliance preference.
- NIST Cybersecurity Framework
- Any organization wanting a defensible, comparable baseline. Frequently requested by customers and insurers as a reference point.
- ISO/IEC 27001
- Organizations whose customers or markets expect a certified management system, often alongside or instead of SOC 2.
- SOC 2
- Technology and service companies whose enterprise customers require evidence of a controlled environment.
Questions from government and Defense Contractors leaders
General questions about the vCISO role are answered on the vCISO page.
Does Heights perform CMMC assessments?
No. At the levels requiring third-party assessment, that work is performed by an authorized assessor organization, and the separation between preparing and assessing is deliberate.
Heights prepares your organization: establishing scope, implementing and documenting the requirements, producing an accurate system security plan, and closing plan-of-action items before an assessment is scheduled.
How do we reduce what falls in scope?
By deciding deliberately where controlled information is allowed to live, and enforcing that boundary, often through a defined enclave rather than by protecting the entire estate to the same standard.
Scoping is usually the highest-leverage decision available. It is also the one most often made implicitly, by allowing controlled information to spread wherever it is convenient.
Our plan of action has items open from two years ago. Is that a problem?
Yes. A plan of action is a commitment with dates attached, and long-open items suggest either that the remediation was never resourced or that the plan was written to satisfy a form rather than to be executed.
The practical response is to re-baseline honestly: close what can be closed, re-scope what was unrealistic, and assign owners and dates that will actually hold.
Talk through your obligations in Government and Defense Contractors.
Bring the requirements you are working to and what is currently in place. You will get a straight view of where the material gaps are and what it would take to close them.
Or reach us directly at (407) 908-7001 or info@heightscg.com.