Firewalla Purple SE
Gigabit firewall with VLAN segmentation, intrusion detection, and an audit log you can hand an assessor — no monthly fee. The single best move most small shops can make.
CMMC isn't optional anymore. This is the exact stack a veteran-run shop uses to lock down its network, satisfy the controls, and stay eligible for DoD work — without an enterprise budget or a six-figure consultant.
On July 13, 2026, the Department of Defense suspended CMMC Phase 2 and opened a 60-day review. The third-party C3PAO certification mandate scheduled for Nov 10, 2026 is paused. What hasn't changed: Phase 1 self-assessment requirements remain in effect, and you must still meet NIST 800-171 and protect FCI/CUI. What this means for you →
Each product below maps to a control family your assessment actually grades. Build the layers, document them, keep the contract.
Control what touches your network. A real firewall logs and segments — the ISP box can't.
SC / System & CommsEncrypted, versioned, recoverable data — so ransomware or a dead drive never ends a contract.
MP / Media ProtectionPhishing-proof MFA and managed credentials — the controls assessors fail people on most.
AC · IA / Access & IDSanitize, shield, and account for every device that stores or moves controlled data.
PE / Physical ProtectionNo faceless template mill. This is the exact stack and paperwork a small defense contractor uses to get audit-ready — from people who've done it, not resold it.
Defense-world discipline, not marketing gloss. We speak the language of the contracts you're trying to keep.
Every recommendation maps to a real NIST 800-171 control. We run our own SPRS score with these same tools.
The kit documents the full 800-171 control set — a completeness guarantee you control, not a "you'll pass" promise nobody can make.
We tell you what a consumer firewall does and doesn't do (it's not FIPS-validated). Fit over commission — every time.
The tools below secure you. This gets you documented and compliant — the part that actually wins and keeps the contract. A done-for-you CMMC / NIST 800-171 kit: SSP, the 20 required policies, a POA&M template, and your SPRS scorer.
DoD paused the Level 2 C3PAO third-party certification mandate in July 2026 pending a 60-day review. Self-assessment is still required and already in solicitations — staying audit-ready is still how you keep the contract.
Same finish line — assessment-ready, documented, eligible. The difference is what it costs you to get there.
| DIY with the BASTION Kit | Hire a Consultant | Do Nothing | |
|---|---|---|---|
| Out-of-pocket cost | $2,995 one-time | $116k–$138k avg for a small shop | $0 now — then lost awards |
| Time to assessment-ready | Weeks, on your schedule | 2–4 months + their backlog | Never |
| SSP + 20 required policies | ✓ Included, editable | ✓ Billed hourly | ✗ |
| SPRS score + POA&M | ✓ Included | ✓ | ✗ |
| Still yours after the audit | ✓ Lifetime updates | ✗ Re-engage & re-pay | ✗ |
| Audit-ready for self-assessment now | ✓ Documented and ready | Maybe — if slots open | ✗ Exposed if the mandate returns |
Get the kit → Check my SPRS score free →
Preparation that gets you audit-ready for a fraction of consultant fees — not a substitute for the C3PAO audit itself.
Your first control and your best dollar. Segmentation and logging the ISP router simply can't do.
Gigabit firewall with VLAN segmentation, intrusion detection, and an audit log you can hand an assessor — no monthly fee. The single best move most small shops can make.
Firewall, network controller, and NVR in one rack unit. The dashboard bigger contractors already standardize on when they add seats.
Fanless appliance for a self-hosted pfSense/OPNsense firewall. Total control and full logging for the shop that wants zero black boxes in its boundary.
Encrypted, versioned, recoverable. The control that turns a ransomware hit from a lost contract into a Tuesday.
Encrypted volumes, versioned snapshots, and off-site sync — a private, auditable backup target that no subscription can lock you out of.
NAS-rated drives built for 24/7 duty. Buy in pairs and mirror them — redundancy is what "recoverable" actually means on paper.
Hardware-encrypted, rugged, pocket-sized. Your encrypted off-site copy that satisfies the "protect media in transit" line item.
MFA and managed credentials — the control family assessors fail small shops on more than any other.
Phishing-proof hardware MFA that directly satisfies the multifactor requirement. Buy one per user plus spares for the safe.
Managed credentials with the access logs and provisioning you can show an assessor. Pairs with the YubiKey. The FedRAMP authorization is on the Government Cloud edition — commercial Keeper Business is a different SKU and doesn't carry it.
Sanitize, shield, and account for anything that stores or moves controlled data.
Old drives are a breach in a drawer. Standalone NIST-standard wipe before any device is reused, returned, or retired — with a log to prove it.
Fully blocks cell, GPS, WiFi, and Bluetooth — device control for travel, teardown, or any endpoint that needs to go dark instantly.
Cheap insurance against contactless badge, card, and CAC skimming. The one pick everyone on the team should carry.
Hardware locks the network; software monitors it and covers the human layer. These do the heavy lifting — and keep protecting you every month.
Managed credentials, access logs, and provisioning that stand up to an assessor — the gov-grade identity backbone. Buy the Government Cloud edition, not commercial Keeper: the FedRAMP authorization is on that SKU specifically.
End-to-end encrypted email and file sharing built for CUI — the small-contractor standard for protecting controlled data in transit and at rest.
Yes — an assessor grades whether your System Security Plan accurately documents how you meet each of the 110 NIST 800-171 controls, not who typed it. A well-built DIY SSP that maps to every control and reflects what you actually do stands up exactly like a consultant's. What fails people is missing evidence and vague policies — which is why the kit includes an evidence checklist and 20 editable policies, not just a template.
For most contracts right now, no — and this changed recently. On July 13, 2026, DoD suspended CMMC Phase 2 and opened a 60-day review, pausing the Level 2 C3PAO third-party certification mandate that had been set for November 10, 2026. Level 1 and many Level 2 requirements are still met by a self-assessment you submit to SPRS — and those still apply. The third-party requirement could return in modified form after the review, so the smart move is to stay audit-ready: the kit gets you there, and if a C3PAO is ever needed you walk in with the paperwork already done.
The kit does the 80% that's document-and-policy work — the part consultants bill the most hours for. A small shop averages $116k–$138k going fully outsourced. You're paying for the deliverables (SSP, policies, POA&M, SPRS scorer, evidence checklist), not a person's hourly rate. If you later want a human to review it, you buy that as a targeted add-on — not a six-figure engagement.
No — and anyone who tells you a Firewalla or UniFi box is FIPS 140-2 validated is wrong. Consumer/prosumer firewalls give you real, gradeable value: network segmentation, logging, and boundary control. But the FIPS-validated encryption boundary assessors expect around CUI is a separate question (Fortinet/SonicWall/WatchGuard territory). We tell you exactly which control each product supports so you don't get surprised in an assessment.
Now. Self-assessment requirements are already in solicitations and remain in force. In July 2026 DoD suspended the Phase 2 C3PAO third-party mandate for a 60-day review — so the November 10, 2026 deadline is paused — but your obligation to meet NIST 800-171, submit an SPRS score, and protect FCI/CUI did not go away. If the third-party requirement returns, there are still fewer than 100 authorized assessors for 100,000+ firms, so the shops that stayed ready win. Starting early is still the entire advantage.
A complete System Security Plan, the 20 required policies (editable), a POA&M template, an SPRS self-assessment scorer, and an evidence checklist that maps to every control — plus lifetime updates as the rules change. It's the documented compliance layer; the hardware and software on this page are what the SSP describes you using.
Plain-English breakdowns of the controls, costs, and paperwork — written by a working practitioner, not a marketing team.
Scope CUI into a small segmented enclave and cut your assessment cost 40–60%.
Read the guide → cmmc costThe honest line items behind the $116k–$138k quotes — and the DIY path.
Read the guide → vendor supply chain riskThe six federal exclusion lists, and how to check a supplier against them before you buy.
Read the guide → nist sp 1326The five research areas the government uses to investigate a supplier, in plain English.
Read the guide → best firewall for cmmcFirewalla, Protectli, or UniFi — matched to your shop size, with the FIPS truth.
Read the guide → sprs scoreHow the 110-to-−203 scale works, and what a negative score tells a prime.
Read the guide →Free tools, no signup: 800-171 ↔ 800-53 Crosswalk · FOCI Screener · SPRS Estimator · What Changes in Rev 3 — the calculations run in your browser.
Before you buy any tool or hardware, run the same 15-minute check the government uses to vet its suppliers — Section 889, FASCSA, DFARS 7012 hosting, TAA, and the six official lists to verify against. One printable page.