Herndon, Fairfax County, Virginia
NIST SP 800-171 and CMMC programs for Herndon contractors
We help Herndon defense contractors, aerospace and space companies and federal IT firms build and document NIST SP 800-171 and CMMC Level 2 programs. Herndon is about 18 miles from Leesburg. We work on site anywhere in the Washington DC area, and much of the program work runs remotely between visits.
NIST SP 800-171, CMMC Level 2 and ITAR programs for Herndon, VA defense, aerospace and federal IT firms, from Leesburg, about 18 miles away.
Book a 30 minute callWhy does Herndon need this work?
- Herndon shares the Dulles corridor with Reston and borders the airport, with a mix of federal IT firms, software companies, systems integrators and aerospace and space businesses.
- Space and satellite work often involves ITAR technical data alongside CUI, so programs here need export control access rules designed into the enclave from the start.
- Many Herndon firms are mid sized subcontractors with a capable IT team and no security leader, which leaves scope, the SSP and risk decisions without a clear owner.
- Herndon is a short drive from Leesburg, which makes recurring on site program reviews and evidence walkthroughs practical.
Which engagements do Herndon contractors use?
SSP and POA&M review and assessor readiness
Review of your System Security Plan and POA&M against NIST SP 800-171A, so both documents are assessor ready for CMMC Level 2.
ITAR cybersecurity program
Cybersecurity programs for ITAR controlled technical data, built on NIST SP 800-171 and DFARS 252.204-7012, from Capital Cyber.
CMMC Level 2 program leadership
Fractional CISO leadership for a CMMC Level 2 certification run, from the first assessment to the C3PAO visit.
No consultant can promise the outcome of an assessment or authorization. The assessor or authorizing official decides it.
What do Herndon contractors ask?
Are you based in Herndon?
No. We are based in Leesburg, about 18 miles from Herndon. We travel to Herndon clients for on site work.
Does space hardware work fall under ITAR?
Some does and some does not, depending on how the items are classified under the export rules. Your export compliance function decides classification, and we design the security program to protect whatever is controlled.
We have an IT team. Do we still need outside leadership?
Often an IT team is strong on operations but has no one to own scope, documentation and risk decisions. A fractional security leader fills that gap without replacing the team.
Ready to talk it through?
BOOK A CALLPick a time for a 30 minute call with the practice.
What happens in 30 minutes
- We learn about your company, the contracts you hold or are bidding on, and what is driving your timeline.
- We talk through where you stand and which engagement fits, if any does.
- If there is a fit, we follow up with a written scope. No slides.