CMMC Level 2NIST SP 800-171Built for small defense contractors
Assessment Ready Federal Compliance
Federal cybersecurity readiness, engineered: CMMC Level 2, NIST SP 800-171, DFARS, and FedRAMP-related obligations, delivered as a working program instead of a blank page.
JumpStart Fed gets small defense contractors organized and assessment-ready. The hard part is already built: a structured program of controlled documents, implementation guidance, and evidence expectations, mapped to every requirement of NIST SP 800-171. You deploy it, work it, and walk into your assessment with a system, not a scramble.
The snapshot is free and launching soon. Scoping calls are live now, with the person who builds these programs.
§ 01 · Why now
The pause didn't pause the rules
In July 2026, DoD suspended the third-party assessment deadline while a task force reviews the CMMC program. It did not suspend DFARS 252.204-7012, NIST SP 800-171, or the self-assessments contracts require at award — and primes are still flowing requirements down.
Since the CMMC acquisition rule took effect, new DoD solicitations can require a current CMMC self-assessment as a condition of award. Phase one is not coming. It is here.
companies make up the defense industrial base counted in the CMMC rulemaking, and DoD's newer acquisition estimates run past 300,000. If you handle CUI, Level 2 applies, whatever your headcount.
is the largest of the Justice Department's False Claims Act cybersecurity settlements with defense contractors so far, one of several. Misstating compliance is a legal risk now, not just a contracts risk.
What the review changes is the gate, not the ground: the requirements any reformed assessment would measure against — the 110 controls of NIST SP 800-171 — are already in your contracts today. And if third-party assessments return in their current form, a pool of roughly one hundred authorized C3PAOs will serve everyone at once. The pause is preparation time, if you use it. We are using it too: JumpStart submitted written comment to the reform RFI.
§ 02 · The program
What engineered means
Not a dashboard that watches you. Not a consultant's blank template. A compliance program that already exists, ready to be deployed and worked by a shop with no security team.
A 93-step program
From kickoff to assessment-ready in a defined sequence. Every step says what to do, who owns it, and what evidence it produces. You always know where you are and what comes next.
Controlled documents with real content
Your SSP, policies, plans, and registers arrive as working documents: sections drafted, instructions in place, roles and approval fields, revision history, operational columns, and evidence references. Not empty shells.
Traced to the framework
Every document and step traces to the requirements it satisfies. When your assessor asks how you meet a control, the answer is on paper, with the evidence referenced beside it.
All 110 requirements, across 14 control families
Requirement counts vary dramatically by family. Access Control alone carries 22. Personnel Security has 2. The program is weighted the way the framework is, so your effort lands where assessors look.
One segment per control family, sized by requirement count, per NIST SP 800-171 rev. 2, the version CMMC Level 2 assesses against. See the family-by-family breakdown on the program page.
§ 03 · The operating model
Compliance should behave like a managed system, not a document scramble
Readiness comes from disciplined implementation, clear ownership, and defensible evidence. The program moves you through four states, in order.
-
Obligation
Your contracts and your CUI decide what applies. The program starts by fixing scope: which systems, which people, which requirements.
Scope fixed -
Implementation
Work the 93 steps. Deploy the controlled documents, assign owners, and put the practices they describe into daily operation.
In operation -
Evidence
Every step states the evidence it should produce. You collect it as you go, referenced from the documents, ready to show.
On file -
Readiness
You walk into assessment with a complete SSP, a managed POA&M, and evidence on file. Your C3PAO assesses. You are prepared.
Assessment-ready
From here, an authorized C3PAO performs the assessment
We hand off a complete SSP, a managed POA&M, and evidence on file. The certification decision belongs to your independent assessor, and we are careful about that line. Read the full operating model.
§ 04 · Deployment
We meet you where your data lives
Two ways to run the same program. The differentiator is choice, not ideology.
Runs fully local
JumpStart Fed runs on your own machines. CUI stays on hardware you control, inside the boundary you already defend. That keeps a cloud service out of your CUI handling story, and the FedRAMP question that comes with one off your plate.
Connected version
A connected deployment built on AWS and Okta is coming, for teams that already run that stack and want managed identity and storage. Same program, same controlled documents, different home.
§ 05 · Substance
Real structure, honestly stated
JumpStart Fed is new, and we would rather show you the program than invent a customer counter. These numbers describe what you actually deploy.
Kickoff to assessment-ready in one defined sequence.
Every NIST SP 800-171 requirement, traced to documents and evidence.
Effort weighted the way the framework weights it.
Documents arrive written: sections, roles, approvals, evidence references.
One integrated management system: an ISO/IEC 27001 foundation carrying the federal, privacy, and cloud overlays your contracts actually invoke. It keeps working after the assessment instead of gathering dust as a binder.
§ 06 · Next step
Two ways to start. Both are free.
Book a scoping call
Thirty minutes with the person who builds these programs. Bring your contract situation and rough headcount. Leave knowing your scope, a realistic timeline, and what an engagement would look like. No runaround.
Book a scoping callReadiness snapshot
A free, fast answer to the question every contractor starts with: where do I actually stand against the 110 requirements? Launching soon. Leave your email and be first in line.
Get notified at launch