CMMC · NIST 800-171 readiness
for small defense manufacturers
Fast. Tailored. And it keeps you there.

Most compliance tools are a filing cabinet. We built the opposite.

You pour in answers, they sit in fields, and you still do all the hard thinking yourself. We do the thinking with you, get you ready fast, then keep you ready. Built for manufacturers who sell to the Department of Defense and don't have a security team to spare.

What actually applies to you

The rules that decide whether you keep your contracts are already in force.

The headlines are about an audit that just got paused. The requirements underneath it did not pause. Here's the real boundary.

In force right now
  • FAR 52.204-21

    15 basic safeguards for Federal Contract Information (FCI), the everyday non-public information that rides along with almost any government contract.

  • DFARS 252.204-7012

    If you handle Controlled Unclassified Information (CUI), you must meet the security standard NIST 800-171 (Revision 2) and post a score to the government's SPRS system.

On the horizon — we keep you ahead of it
  • CMMC

    The added third-party audit, the Cybersecurity Maturity Model Certification. Its rollout paused in mid-2026 and is under review. Enforced or not, the requirements above stand.

  • NIST 800-171 Rev 3 · 800-172

    The next version of the standard and a higher tier for the most sensitive work. Both already published. We build you a step ahead of them.

Why it's different

Every answer does work down the line. Nothing you tell it is a dead end.

01

Nothing is wasted

You're never asked the same question twice, and you never chase proof you don't need. It's built from your actual business, not a template someone else's compliance got poured into.

02

One connected process

You walk us through how information moves through your company once. That decides what's in scope, which decides what you're asked, which decides what proof to collect. By the end, the master document an assessor reads, your System Security Plan, has written itself from the work you already did. So has your score, and your gap list with a fix on each one.

03

It won't tell you you're fine when you're not

When it can't justify calling a system out of scope, it stops and flags it instead of letting it slide. The software proposes; a person always makes the final call. A missed gap stays invisible until an assessor finds it, so the whole thing is built to refuse that.

04

It keeps you ready

Getting to ready is a push. Staying ready is the real job. Rules change, screenshots go stale, an annual task comes due, someone reconfigures a firewall on a Tuesday. It watches for all of it, so your readiness stays a live number, not a snapshot from the day you passed.

The arc of an engagement

ScaffoldInterviewScopeProveScoreRecommendDeliver

You're not buying a one-time scramble. You're buying the machine that keeps things spinning.

Where boundaries belong.

Start with a scoping conversation. metebound.com