NIST SP 800-171 Rev 2 · CMMC Level 2 readiness
A fixed scope gap assessment against all 110 requirements. You get a score you can actually defend, a written plan for the gaps, and a list of things you can fix yourself before you spend another dollar with me.
Who this is for
A prime sent you a flow down clause and you're not sure what it obligates you to do.
Somebody asked for your SPRS score and you had to look up what that meant.
You handle drawings, specs, or technical data for defense work and nobody has ever mapped where those files live.
Your IT support keeps the network running. Nobody was ever hired to run a compliance program.
You've been quoted a large recurring contract and you'd rather know the size of the problem first.
You have shop floor equipment that can't be patched and every provider you've talked to has hand waved past it.
Scope
Most of the confusion in this market comes from providers being vague about which of these they're selling. So here it is on the front page.
Process
Roughly two weeks, remote, with two calls on your calendar. Everything else happens on my time.
Thirty minutes, free. What's in your contracts, whether you handle CUI or only FCI, and which level actually applies. If the answer is Level 1, I'll tell you, and this ends here.
I talk to the people who touch government work, meaning the estimator, the engineer, and the quality lead. I trace how a drawing arrives, where it lands, who opens it, and what leaves the building with it. You get a data flow map most owners have never seen.
Every asset gets categorized: in scope, security protection, risk managed, specialized, or out. Shop floor equipment is handled as the specialized asset category it is. Not ignored, and not over scoped into a problem you don't have.
This is where the money is savedFirewall rule base, segmentation, remote access, identity and MFA coverage, endpoint posture, share permissions on the directories holding your drawings, logging, and backup. Real engineering review, not a questionnaire.
Met, not met, or partially met, each with evidence recorded. Requirements satisfied by policy get the same treatment as the technical ones, which is where most shops discover entire families sitting at zero.
Your score, the arithmetic behind it, and the projected score after the first round of fixes. You leave with a list of things you can close yourself this week at no cost, and a fixed quote for the things you can't.
Deliverables
The report outlives the engagement. That's the point. It's the thing you show when somebody asks how you know where you stand.
Price
Comparable gap assessments from registered provider organizations generally run five to eight thousand dollars for a business this size. I'm below that because I'm one engineer with no sales team and no overhead to cover, not because the work is smaller.
The price doesn't move based on endpoint count or how bad the findings turn out to be. If the scope is genuinely larger than a shop your size, meaning multiple sites, a second domain, or something I couldn't have anticipated on the intro call, you'll hear that before I start rather than after.
Remediation, if you want it, gets quoted as fixed scope after you've seen the report. You're under no obligation to buy it, and the report is just as useful if you hand it to somebody else.
Who does the work
I'm Arwin Singh. I run Spatix Networks, and I do the assessment myself. The same person on the intro call is the one reading your firewall config and sitting on the findings call.
My background is network security engineering, not compliance consulting. Over a decade in enterprise networking, dual CCNPs, and senior level work in OT and industrial control environments. That last part matters more than it sounds. The reason CMMC gets expensive for manufacturers is almost always bad scoping around shop floor equipment, and that's a judgment call you want made by somebody who has actually worked on those networks.
What that means in practice is that the findings are engineering findings. A compliance consultant can tell you requirement 3.13.1 is not met. I can tell you why your boundary doesn't exist, which of your controls is actually load bearing, and which finding could take the company down regardless of what it costs you in points.
Questions
Part of it did. Phase 2, the stage requiring a third party assessor for certain Level 2 contracts, was suspended in July 2026 while a task force reviews the program.
What wasn't suspended: the self assessment requirement, the annual affirmation signed by a named officer at your company, and DFARS 252.204-7012, which has been in defense contracts since 2017. Primes also set their own supplier requirements for their own risk reasons, and nothing in that memo tells them to drop anything.
The government stepped back. Whether your prime did is a different question, and it's the one that decides your contract.
No, and no. A C3PAO conducts the official certification assessment, and by design they're barred from consulting or remediating for a company they might later assess. That separation exists so your auditor isn't grading their own work.
This is the other half of the ecosystem: readiness, gap identification, and remediation. If a firm advertises both, ask them who is actually doing your certification assessment and when.
Possibly not. If you only handle Federal Contract Information and never touch CUI, you're likely looking at Level 1. That's fifteen requirements and an annual self assessment, not 110.
That's the first thing the intro call sorts out, and it's free. If the answer is Level 1, I'll say so and you won't hear a pitch. Your contracting officer can also confirm which level your contract requires, at no cost to you.
No. Most shops this size either have one person wearing the IT hat alongside another job, or an outside provider handling break fix. Either is normal and neither changes the assessment.
I'll need someone who can grant access and answer questions about how the business actually operates. That person doesn't need to be technical.
Read level access to the systems in scope, granted by you, under a signed engagement letter that spells out exactly what's authorized and what isn't. No credential harvesting, no active exploitation, nothing outside the agreed scope.
The report itself describes weaknesses in a defense supplier's environment, so it's handled as sensitive. Encrypted delivery, a defined retention period, and no identification of your company in any case study or content without written permission.
They usually are the first time, and a negative score is the normal starting position for a shop that has never done this. It isn't a grade and I don't deliver it like one.
What matters is the delta. You'll get a projected score showing where a defined amount of work puts you, and the first tranche of that work is usually free and takes an afternoon.
That's expected, and it isn't the blocker people assume. CNC controllers, CMMs, test equipment, and legacy HMIs fall under the specialized asset category. Documented and risk managed rather than fully controlled.
The failure mode I see is providers who either ignore shop floor equipment entirely or insist the whole environment has to be rebuilt around it. Neither is correct, and getting this call right is usually the difference between a four figure remediation and a five figure one.
A security assessment asks whether you're safe. A gap assessment asks whether you can prove it. Different question, different standard, different deliverable.
If you have no compliance obligation, the network security assessment is the right one and it costs less. If a prime is asking for a score, you want this one.
Start here
Tell me what your prime asked for and roughly what your environment looks like. If this isn't the right thing for you, that's a two minute answer and you'll have it.