Live

CMMC Pulse — from the field

See the full feed →
Maps to NIST 800-171 & CMMC 2.0 · updated Jul 2026

The security a small government contractor needs to pass the assessment — and keep the contract.

CMMC isn't optional anymore. This is the exact stack a veteran-run shop uses to lock down its network, satisfy the controls, and stay eligible for DoD work — without an enterprise budget or a six-figure consultant.

Update · Jul 2026

On July 13, 2026, the Department of Defense suspended CMMC Phase 2 and opened a 60-day review. The third-party C3PAO certification mandate scheduled for Nov 10, 2026 is paused. What hasn't changed: Phase 1 self-assessment requirements remain in effect, and you must still meet NIST 800-171 and protect FCI/CUI. What this means for you →

110
NIST 800-171 controls — all mapped
Suspended
Phase 2 C3PAO paused Jul 2026 — self-assessment still required
$2,995
vs the $116k–$138k consultant path
Veteran-run
Built by people who've done it
The method

Compliance is layers — and an assessor checks every one.

Each product below maps to a control family your assessment actually grades. Build the layers, document them, keep the contract.

LAYER 01

Boundary

Control what touches your network. A real firewall logs and segments — the ISP box can't.

SC / System & Comms
LAYER 02

Backups

Encrypted, versioned, recoverable data — so ransomware or a dead drive never ends a contract.

MP / Media Protection
LAYER 03

Access

Phishing-proof MFA and managed credentials — the controls assessors fail people on most.

AC · IA / Access & ID
LAYER 04

Devices

Sanitize, shield, and account for every device that stores or moves controlled data.

PE / Physical Protection
Why builders trust BASTION

Built by a veteran-run shop that lives in these controls.

No faceless template mill. This is the exact stack and paperwork a small defense contractor uses to get audit-ready — from people who've done it, not resold it.

🎖️

Veteran-run

Defense-world discipline, not marketing gloss. We speak the language of the contracts you're trying to keep.

🛠️

Practitioner-built

Every recommendation maps to a real NIST 800-171 control. We run our own SPRS score with these same tools.

📋

Maps to all 110 controls

The kit documents the full 800-171 control set — a completeness guarantee you control, not a "you'll pass" promise nobody can make.

🤝

Honest about scope

We tell you what a consumer firewall does and doesn't do (it's not FIPS-validated). Fit over commission — every time.

Skip the guesswork

Get assessment-ready without a $30k consultant.

The tools below secure you. This gets you documented and compliant — the part that actually wins and keeps the contract. A done-for-you CMMC / NIST 800-171 kit: SSP, the 20 required policies, a POA&M template, and your SPRS scorer.

  • System Security Plan + 20 mapped policies, editable
  • SPRS self-assessment scorer & POA&M template
  • Evidence checklist that maps to every control
CMMC Level 2 DIY Compliance Kit
$2,995
one-time · lifetime updates
Get the kit →
Independently vetted · not legal advice.
Regulatory status

CMMC Phase 2 — suspended, under review

DoD paused the Level 2 C3PAO third-party certification mandate in July 2026 pending a 60-day review. Self-assessment is still required and already in solicitations — staying audit-ready is still how you keep the contract.

What changed →
Run the real math

The $2,995 kit is the cheapest way to be ready.

Same finish line — assessment-ready, documented, eligible. The difference is what it costs you to get there.

DIY with the BASTION Kit Hire a Consultant Do Nothing
Out-of-pocket cost $2,995 one-time $116k–$138k avg for a small shop $0 now — then lost awards
Time to assessment-ready Weeks, on your schedule 2–4 months + their backlog Never
SSP + 20 required policies Included, editable Billed hourly
SPRS score + POA&M Included
Still yours after the audit Lifetime updates Re-engage & re-pay
Audit-ready for self-assessment now Documented and ready Maybe — if slots open Exposed if the mandate returns

Get the kit → Check my SPRS score free →

Preparation that gets you audit-ready for a fraction of consultant fees — not a substitute for the C3PAO audit itself.

LAYER 01 · SC

Boundary protection

Your first control and your best dollar. Segmentation and logging the ISP router simply can't do.

FW-PURPLE-SETop pick

Firewalla Purple SE

Gigabit firewall with VLAN segmentation, intrusion detection, and an audit log you can hand an assessor — no monthly fee. The single best move most small shops can make.

2.5GbE ×2IDS/IPSSC.L2
Fit
$$$$$
View on Amazon →
UNIFI-UDM-PROScales up

UniFi Dream Machine Pro

Firewall, network controller, and NVR in one rack unit. The dashboard bigger contractors already standardize on when they add seats.

Rack 1U10G SFP+SC.L2
Fit
$$$$$
View on Amazon →
PROTECTLI-VP2410Full control

Protectli Vault (pfSense)

Fanless appliance for a self-hosted pfSense/OPNsense firewall. Total control and full logging for the shop that wants zero black boxes in its boundary.

Fanless4× 2.5GbESC.L2
Fit
$$$$$
View on Amazon →
LAYER 02 · MP

Backups & media protection

Encrypted, versioned, recoverable. The control that turns a ransomware hit from a lost contract into a Tuesday.

SYNOLOGY-DS923Top pick

Synology DS923+ NAS

Encrypted volumes, versioned snapshots, and off-site sync — a private, auditable backup target that no subscription can lock you out of.

4-bayAES-NIMP.L2
Fit
$$$$$
View on Amazon →
WD-RED-PRO-8TBPairs with NAS

WD Red Pro 8TB ×2

NAS-rated drives built for 24/7 duty. Buy in pairs and mirror them — redundancy is what "recoverable" actually means on paper.

7200 RPMCMR5yr warranty
Fit
$$$$$
View on Amazon →
SAMSUNG-T7-SHIELDOff-site copy

Samsung T7 Shield SSD

Hardware-encrypted, rugged, pocket-sized. Your encrypted off-site copy that satisfies the "protect media in transit" line item.

AES 256-bitIP65MP.L2
Fit
$$$$$
View on Amazon →
LAYER 03 · AC · IA

Access control & identity

MFA and managed credentials — the control family assessors fail small shops on more than any other.

YUBIKEY-5C-NFCBuy per seat

YubiKey 5C NFC

Phishing-proof hardware MFA that directly satisfies the multifactor requirement. Buy one per user plus spares for the safe.

FIDO2USB-C + NFCIA.L2
Fit
$$$$$
View on Amazon →
KEEPER-GOV-CLOUDRecurring ↻

Keeper Security Government Cloud

Managed credentials with the access logs and provisioning you can show an assessor. Pairs with the YubiKey. The FedRAMP authorization is on the Government Cloud edition — commercial Keeper Business is a different SKU and doesn't carry it.

Access logsFedRAMP HighAC.L2Gov Cloud SKU only
Fit
Subscription
See Keeper Government Cloud →
LAYER 04 · PE · MP

Device & media control

Sanitize, shield, and account for anything that stores or moves controlled data.

DRIVE-ERASER-DOCKTop pick

Secure Drive Eraser Dock

Old drives are a breach in a drawer. Standalone NIST-standard wipe before any device is reused, returned, or retired — with a log to prove it.

NIST 800-88SATA + NVMeMP.L2
Fit
$$$$$
View on Amazon →
MOS-DARKNESS-BAGField kit

Mission Darkness Faraday Bag

Fully blocks cell, GPS, WiFi, and Bluetooth — device control for travel, teardown, or any endpoint that needs to go dark instantly.

MIL-STD shield2-layerPE.L1
Fit
$$$$$
View on Amazon →
RFID-BLOCK-KITEvery badge

RFID Faraday Sleeves

Cheap insurance against contactless badge, card, and CAC skimming. The one pick everyone on the team should carry.

13.56 MHz15-packPE.L1
Fit
$$$$$
View on Amazon →
Highest-leverage layer

The subscriptions that watch the doors.

Hardware locks the network; software monitors it and covers the human layer. These do the heavy lifting — and keep protecting you every month.

KEEPER-GOV-CLOUDRecurring ↻

Keeper Security Government Cloud

Managed credentials, access logs, and provisioning that stand up to an assessor — the gov-grade identity backbone. Buy the Government Cloud edition, not commercial Keeper: the FedRAMP authorization is on that SKU specifically.

FedRAMP HighFIPS 140-3IA.L2Gov Cloud SKU only
Fit
Per seat
See Keeper Government Cloud →
PREVEIL-CUIRecurring ↻

PreVeil (Encrypted Email & Files)

End-to-end encrypted email and file sharing built for CUI — the small-contractor standard for protecting controlled data in transit and at rest.

End-to-end encryptedCUI-readySC.L2
Fit
Per seat
Get PreVeil →
Straight answers

The questions every small contractor asks first.

Will a DIY SSP actually pass an assessment?

Yes — an assessor grades whether your System Security Plan accurately documents how you meet each of the 110 NIST 800-171 controls, not who typed it. A well-built DIY SSP that maps to every control and reflects what you actually do stands up exactly like a consultant's. What fails people is missing evidence and vague policies — which is why the kit includes an evidence checklist and 20 editable policies, not just a template.

Do I really need a C3PAO?

For most contracts right now, no — and this changed recently. On July 13, 2026, DoD suspended CMMC Phase 2 and opened a 60-day review, pausing the Level 2 C3PAO third-party certification mandate that had been set for November 10, 2026. Level 1 and many Level 2 requirements are still met by a self-assessment you submit to SPRS — and those still apply. The third-party requirement could return in modified form after the review, so the smart move is to stay audit-ready: the kit gets you there, and if a C3PAO is ever needed you walk in with the paperwork already done.

Is $2,995 really enough when consultants charge six figures?

The kit does the 80% that's document-and-policy work — the part consultants bill the most hours for. A small shop averages $116k–$138k going fully outsourced. You're paying for the deliverables (SSP, policies, POA&M, SPRS scorer, evidence checklist), not a person's hourly rate. If you later want a human to review it, you buy that as a targeted add-on — not a six-figure engagement.

Do these firewalls make me "FIPS compliant"?

No — and anyone who tells you a Firewalla or UniFi box is FIPS 140-2 validated is wrong. Consumer/prosumer firewalls give you real, gradeable value: network segmentation, logging, and boundary control. But the FIPS-validated encryption boundary assessors expect around CUI is a separate question (Fortinet/SonicWall/WatchGuard territory). We tell you exactly which control each product supports so you don't get surprised in an assessment.

When do I actually need to be ready?

Now. Self-assessment requirements are already in solicitations and remain in force. In July 2026 DoD suspended the Phase 2 C3PAO third-party mandate for a 60-day review — so the November 10, 2026 deadline is paused — but your obligation to meet NIST 800-171, submit an SPRS score, and protect FCI/CUI did not go away. If the third-party requirement returns, there are still fewer than 100 authorized assessors for 100,000+ firms, so the shops that stayed ready win. Starting early is still the entire advantage.

What's actually in the kit?

A complete System Security Plan, the 20 required policies (editable), a POA&M template, an SPRS self-assessment scorer, and an evidence checklist that maps to every control — plus lifetime updates as the rules change. It's the documented compliance layer; the hardware and software on this page are what the SSP describes you using.

Free · one-page PDF

The Vendor Vetting Checklist — free download

Before you buy any tool or hardware, run the same 15-minute check the government uses to vet its suppliers — Section 889, FASCSA, DFARS 7012 hosting, TAA, and the six official lists to verify against. One printable page.

No spam. Unsubscribe anytime. No login.