// DEFENCE AND CMMC · HANS STUDY

Defence industrial base compliance, with the technical work that actually holds up

CMMC 2.0 in the United States. CPCSC in Canada. NIST SP 800-171 underneath both. Independent technical advisory for defence contractors and subcontractors who need the architecture, the controls, and the documentation in a state that survives an assessment, not just an internal review.

What this is, and what it is not

This is technical advisory for defence industrial base organizations preparing for CMMC 2.0 in the US, CPCSC in Canada, or NIST SP 800-171 alignment in either country. The work focuses on the technical layer that the framework actually depends on. Network segmentation. Identity and access management. Logging and audit. Backup and recovery. Endpoint and server hardening. Boundary protection. The controls that fail an assessment when the documentation does not match what the network is doing.

This is not a paper-only compliance shop. The deliverable is an environment that holds up technically, with documentation that accurately describes it.

Where independent advisory adds value

CMMC-01

CMMC 2.0 Level 2 readiness

Architecture review against the 110 NIST 800-171 controls. Gap assessment. Remediation roadmap. Evidence and documentation preparation that matches what an assessor will actually look at.

CMMC-02

CPCSC alignment for Canadian DIB

Canadian Program for Cyber Security Certification advisory for organizations doing or pursuing defence work in Canada. Architecture, controls, and documentation aligned to the framework.

CMMC-03

NIST SP 800-171 baseline

Independent assessment against all 14 control families (Rev 2). Realistic reading on which controls are met, partially met, or not met, and a roadmap that prioritizes the ones that actually move the assessment.

CMMC-04

CUI enclave architecture

Network segmentation for controlled unclassified information. Boundary design between CUI and non-CUI environments. Practical answers for organizations where the entire network does not need to be in scope.

CMMC-05

Microsoft Windows hardening

Active Directory architecture, Windows Server hardening, Group Policy and security baselines, Microsoft 365 in CUI-aware configurations. Detailed work on the Microsoft side, where most CMMC environments live.

CMMC-06

SSP and POA&M development

System Security Plan and Plan of Action and Milestones documentation that accurately describes the environment, identifies open gaps, and stands up to the level of scrutiny an assessment applies.

Standards and frameworks in scope

Last reviewed October 2026: CMMC Phase 2 suspended July 13, 2026; CPCSC Level 1 in select contracts since summer 2026; Level 2 from spring 2027.

  • CMMC 2.0, Cybersecurity Maturity Model Certification (US DoD)
  • CPCSC, Canadian Program for Cyber Security Certification
  • NIST SP 800-171, protecting controlled unclassified information
  • ITSP.10.171, Canadian Centre for Cyber Security adaptation of NIST SP 800-171 for CPCSC
  • NIST SP 800-53, security and privacy controls for information systems and organizations
  • NIST SP 800-172, enhanced requirements for CUI
  • ITSG-33, Government of Canada IT security risk management
  • ISO/IEC 27001, information security management
  • TIA-942, data centre infrastructure standard

What field experience looks like

I have worked across federal infrastructure, defence environments, and organizations supporting Canadian and US defence supply chains. The advisory is built from NIST SP 800-171 and CMMC readiness work with small defence suppliers since 2019, the network architecture that determines what is in scope, and the operational reality of running a CUI enclave at a small or mid-size organization without taking the rest of the business offline.

For organizations that are early in the process, an architecture review and gap assessment is usually the right first engagement. For organizations close to assessment, the focus is on closing the highest-impact gaps and aligning documentation to actual technical state.

Start with the free resources

A lot of Level 1 work you can do yourself. These are free, and they're what I'd hand a client first.

Questions

Does my CMMC certificate satisfy CPCSC?

Not automatically. The programs share the NIST SP 800-171 lineage, but there is no mutual recognition. PSPC may accept a valid CMMC certification case by case at Level 1, after confirming the assessment covers the required scope.

When is CPCSC Level 1 required, and when does Level 2 start?

Level 1 has been in select contracts since summer 2026, and it's required at contract award. PSPC plans to put Level 2 into select contracts from spring 2027.

What can I do myself before hiring anyone?

A lot of Level 1 work you can do yourself. Start with CPCSC, explained, the free book, the policy builder, and the CPCSC templates and checklists.

Where does an engagement usually start?

For organizations early in the process, an architecture review and gap assessment is usually the right first engagement. For organizations close to assessment, the focus is on closing the highest-impact gaps and aligning documentation to the actual technical state.

Do you write the SSP and POA&M?

Yes. I develop System Security Plan and Plan of Action and Milestones documentation that describes the environment accurately and identifies open gaps. The aim is an environment that holds up technically, not paper-only compliance.

How is this work priced?

Architecture review, gap assessment, remediation oversight, and SSP and POA&M development are discrete engagements. Each is scoped on a call, and a written quote comes before any work starts.

Bring in independent advisory before the assessment is booked

Architecture review, gap assessment, remediation oversight, and SSP/POA&M development are all available as discrete engagements. The earliest point of engagement is also the highest-impact point.