Skip to content

NIST SP 800-171 Rev 2

Your 800-171 evidence,in one record.

Overwatch 7Six keeps every file mapped to the requirement it supports, assigned to an owner, and stamped with the date it was last validated. All 110 requirements. All 14 families. One record you can stand behind.

Fifteen minutes against all 110 requirements. No account, and we never receive the result unless you send it to yourself.

Vigilant. Autonomous. Mission Ready.

Requirements tracked
110Requirements tracked
Requirement families
14Requirement families
CUI files accepted
0CUI files accepted
Organization per tenant
1Organization per tenant

The problem

Small defense suppliers are asked to meet serious security requirements without the staff, budget, or process maturity to manage readiness cleanly.

Regulatory update · July 13, 2026

The Department of War suspended CMMC Phase II, the third-party assessment requirement (C3PAO at Level 2, DIBCAC at Level 3) that was due to take effect November 10, 2026. A CMMC Reform Task Force was given 60 days to deliver recommendations. That period closed in September 2026, and no change to contractual obligations has been published. Phase I self-assessment, NIST SP 800-171 Rev 2 reporting, SPRS scores, annual affirmations, and DFARS 252.204-7012 are unchanged. Self-assessed evidence still has to hold up.

Source · U.S. Department of War release, July 13, 2026 · Reviewed September 17, 2026

110 / 14

NIST SP 800-171 Rev 2 requirements, across 14 families. CMMC Level 2 requirements are identical to them

Source · 32 CFR § 170.14(c)(2); NIST SP 800-171 Rev 2

-203 to 110

SPRS score range. Each unmet requirement deducts 1, 3, or 5 points, with partial credit only where the methodology names it

Source · NIST SP 800-171 DoD Assessment Methodology v1.2.1, June 24, 2020

180 days

To close out every POA&M item after a Conditional CMMC Status, confirmed by a closeout assessment. Miss it and the Conditional status expires

Source · 32 CFR § 170.21

$52M / 9

Recovered in cybersecurity False Claims Act settlements in FY2025, across nine cases

Source · Outside-counsel analysis of DOJ FY2025 FCA statistics. DOJ's own release does not break out the cybersecurity figure

They don't know what systems are in scope for CUI.

Evidence is scattered across email, SharePoint, tickets, screenshots, cloud portals, and MSP reports.

Their MSP says “we handle security,” but nobody can prove which controls are covered.

Their SSP is incomplete, stale, or written in consultant language nobody owns.

POA&M items exist informally, with no clear owner or deadline attached.

Executives don't know what readiness means in contract-risk terms.

Technical teams don't know what evidence an assessor will expect to see.

SPRS scoring feels disconnected from the day-to-day remediation work.

Satisfying a NIST SP 800-171 control takes evidence: a config export, a ticket, a policy document, a log, mapped to the specific control and assessment objective it supports, with an owner and a validation date attached. Most defense contractors can point to their tools. Fewer can produce that evidence on request, in the format an assessor needs.

Three modules

Each one answers a question you will be asked about your self-assessment.

Compliance

Where do we stand?

All 110 requirements grouped by family, each with a status, an owner, the date it was last validated, and how many files back it up. The header counts the requirements holding zero evidence.

Mail

What is due?

The annual affirmation due date sits first. Open POA&M items sort by target date, and anything inside 30 days is marked. A planned assessment appears only once one is scheduled.

Agent

What is missing?

An assistant that reads your evidence metadata against NIST SP 800-171A assessment objectives and cites the objective identifier behind every observation. It reports what exists and what does not.

How the record gets built

01

Upload

Attach a file to the requirement it speaks to. Confirm it holds no CUI. The file lands in storage scoped to your organization and nowhere else.

02

Map

Every file carries the requirement it supports, who uploaded it, and when. Plain-language intent sits next to each requirement so the mapping is deliberate.

03

Validate

Log a validation and the record stamps the date and the person. Six months later you can still answer who checked this, and when.

04

Affirm

Open POA&M items sort by target date. The affirmation card carries the next due date. Nothing depends on a calendar reminder someone forgot to set.

What this is

Compliance infrastructure that turns security activity into assessor-ready evidence.

Overwatch 7Six doesn’t promise certification. The strongest language here is readiness, evidence, defensibility, assessment preparation, control implementation, and accountability.

Overwatch 7Six is

  • A readiness operations system for CMMC 2.0 Level 2 / NIST SP 800-171
  • A contract-readiness platform for defense supply chain companies
  • An evidence organization and control accountability system
  • A bridge between executives, internal IT, MSPs, assessors, and technical operators
  • A vendor-neutral record that accepts evidence from any system, with no agent to install
  • A way to convert security activity into assessor-usable artifacts

Overwatch 7Six is not

  • A generic GRC dashboard
  • A one-click CMMC certification tool
  • A replacement for a C3PAO assessment
  • A cloud-only, Microsoft-only, or Defender-only product
  • A consultant marketplace with a software wrapper
  • A static spreadsheet replacement with prettier screens

The federal lifecycle

Six stages from first scope to the affirmation that keeps status current. Overwatch 7Six doesn’t replace this process, it organizes the evidence you carry through every stage of it.

010203040506
  1. 01 · Scope

    Identify which systems and data touch FCI or CUI. That determines the required CMMC level.

    32 CFR § 170.19

  2. 02 · Assess

    Self-assessment for Level 1 or Level 2 (Self), or a C3PAO or DIBCAC assessment for Level 2 (C3PAO) and Level 3.

    32 CFR §§ 170.15–170.18

  3. 03 · Score

    SPRS score submitted. A Level 2 POA&M item cannot exceed 1 point, with one named exception at 3 points for non-FIPS-validated CUI encryption.

    DFARS 252.204-7019/7020; 32 CFR § 170.21(b)

  4. 04 · Conditional

    180 days to close out the POA&M, confirmed by a closeout assessment. Miss it and the Conditional CMMC Status expires.

    32 CFR § 170.21

  5. 05 · Final

    Certified status. Valid for 3 years for a C3PAO or DIBCAC assessment.

    32 CFR §§ 170.16–170.17

  6. 06 · Affirm

    An affirming official reaffirms continuous compliance in SPRS every year the status stays current.

    32 CFR § 170.22

AI doctrine

AI assists. Humans own the claim.

AI reduces friction. It doesn’t get to create unsupported claims on your behalf.

The assistant reads your evidence index, never your evidence. File names, the requirement each maps to, statuses, and validation dates reach the model. The contents of an uploaded file are never read and never sent.

Good AI uses

  • Naming the assessment objectives with no evidence against them
  • Citing the NIST SP 800-171A objective ID behind every gap it reports
  • Flagging evidence that has gone stale against its validation date
  • Ordering gaps by what a self-assessment surfaces first
  • Turning open POA&M items into the questions an assessor will ask
  • Reading the evidence index and saying what is missing from it

Bad AI uses

  • Inventing evidence
  • Claiming compliance without proof
  • Generating final SSP language without review
  • Creating fake control implementation statements
  • Replacing assessor judgment
  • Replacing customer sign-off
“Handoff rule: AI can assist, but every assessment-facing claim must trace back to evidence the customer can defend.”

Scope boundary

This system takes no CUI

Overwatch 7Six holds evidence about your controls, not the regulated data itself. Screenshots of a policy setting, a signed training roster, an asset inventory. Every upload carries a required acknowledgment, and the database refuses any evidence row that does not have it. The checkbox is not the only gate.

“I confirm this file contains no Controlled Unclassified Information (CUI). Overwatch 7Sixdoes not accept CUI.”

14 families, 110 requirements

The full catalog ships seeded. You start from the standard, not from an empty table.

Read the family guide →
  • 3.1

    Access Control

    22 requirements

  • 3.2

    Awareness and Training

    3 requirements

  • 3.3

    Audit and Accountability

    9 requirements

  • 3.4

    Configuration Management

    9 requirements

  • 3.5

    Identification and Authentication

    11 requirements

  • 3.6

    Incident Response

    3 requirements

  • 3.7

    Maintenance

    6 requirements

  • 3.8

    Media Protection

    9 requirements

  • 3.9

    Personnel Security

    2 requirements

  • 3.10

    Physical Protection

    6 requirements

  • 3.11

    Risk Assessment

    3 requirements

  • 3.12

    Security Assessment

    4 requirements

  • 3.13

    System and Communications Protection

    16 requirements

  • 3.14

    System and Information Integrity

    7 requirements

What’s at stake

An SPRS score that doesn’t match reality is a False Claims Act problem, with or without a breach.

01

Enforcement is active, not theoretical

DOJ's Civil Cyber-Fraud Initiative, running since October 2021, has settled fifteen cybersecurity-related False Claims Act cases. Nine of them closed in fiscal year 2025 alone, recovering more than $52 million out of a record $6.8 billion in total FCA recoveries.

Outside-counsel analysis of DOJ FY2025 FCA statistics. The cybersecurity breakout is not in DOJ's own release

02

Named settlements, real numbers

Georgia Tech Research Corporation and the Georgia Institute of Technology paid $875,000 on September 30, 2025. DOJ alleged no system security plan existed for the lab doing Air Force and DARPA work until at least February 2020, and that the assessment score of 98 submitted to DoD was false. Raytheon, its parent RTX, and successor Nightwing paid $8.4 million on May 1, 2025 over 29 contracts and subcontracts.

DOJ press releases, May 1 and September 30, 2025

03

The theory is misrepresentation

DOJ's own framing of these cases: they are not about being breached. They are about certifying something to the government that wasn't true. An inaccurate SPRS score creates the exposure, whether or not an incident ever happens.

31 U.S.C. §§ 3729–3733; DOJ Civil Cyber-Fraud Initiative, announced October 2021

Five of the eight Initiative settlements DOJ announced during calendar year 2025 began as qui tam suits filed by insiders. The relators in the Georgia Tech case took $201,250. The former Raytheon director of engineering who filed that case took $1,512,000. A gap between what your SSP claims and what your evidence actually shows is a liability an employee can act on, not just an assessor.

Source · Outside-counsel analysis of DOJ settlement announcements. DOJ publishes no qui tam breakout for the Initiative

Product north star

“Show me why you believe this control is implemented.”

Whoever asks, a CEO, an IT manager, an MSP, or an assessor, Overwatch 7Six should make the answer easy to find, easy to explain, and hard to fake.

The founder

Built by a compliance professional who has lived the evidence problem, not just diagrammed it.

Bradley A. Baker, Founder, Patriot 7Six LLC

Texas Veterans Commission verified veteran-owned business

Bradley A. Baker

Founder & Sole Principal, Patriot 7Six LLC

Overwatch 7Six comes out of direct experience administering the M365 tenant and Mimecast for a clinical research organization under constant regulatory audit, where access control, retention, and evidence trails were the daily work. That work showed what happens when evidence lives in someone’s inbox instead of a system built to defend it in front of an assessor. For a defense contractor, that gap is the difference between a Final CMMC status and a Conditional one that runs out the clock.

Service record

Rank
SGT / E-5
MOS
11B · Infantryman
Branch
U.S. Army · RA
Service
1996 – 2002
Discharge
Honorable
Status
Service-Connected Disabled Veteran

Civilian record

Tenure
2005 – 2026
Role
Sr. IT Application Administrator
Domain
Clinical Research
Specialty
O365 · DLP · Compliance
Degree
B.S. Information Systems Security
Honors
Honor Graduate · NTHS

Airborne-qualified infantryman with the 82nd Airborne Division, 1996–1999, earning the Expert Infantryman’s Badge. Promoted to Sergeant with the 172nd Infantry Brigade, Fort Wainwright, Alaska, 1999–2002. Two decades in enterprise IT since 2005, including SOX and FERPA-regulated environments, before founding Patriot 7Six LLC.

Stage & posture

Bootstrapped. Building. Open to the right conversations.

Capital

Bootstrapped

Solo founder, building full-time on personal capital and earned time since leaving enterprise IT in September 2026. No outside dilution to date.

Build state

Overwatch 7Six · MVP build

In active development. Not yet live. This site describes the product being built, not a shipped platform.

Posture

Selectively open

Not actively raising. Open to mission-aligned angels, veteran-network professionals, and strategic partners: VSOs, PTACs, and government contracting consultants.

Data handling

Built on cloud-native infrastructure with encryption in transit and at rest, strict tenant isolation, and role-based access control. No customer PII, CUI, or unverified regulatory claim leaves the platform for a third-party tool without the customer’s knowledge.

Questions

What is NIST SP 800-171 Rev 2?
NIST SP 800-171 Rev 2 is the security standard that sets 110 requirements across 14 families for protecting sensitive information in nonfederal systems. Each requirement has a numbered identifier, such as 3.1.1, and a companion set of assessment objectives published as NIST SP 800-171A.
Does Overwatch 7Six store CUI?
No. Overwatch 7Six does not accept Controlled Unclassified Information. Every evidence upload requires an explicit acknowledgment that the file contains no CUI, and the database rejects any evidence row without it. The acknowledgment is enforced at the data layer, not only in the interface.
What does the evidence review assistant do?
The Agent module compares your uploaded evidence metadata against NIST SP 800-171A assessment objectives and cites the specific objective identifier for every observation. It describes what evidence exists and what is missing. It does not state that a requirement passes or fails, and it does not produce a score. Your organization's self-assessment makes that determination.
What is a POA&M?
A plan of action and milestones records a requirement that is not yet met, who owns closing the gap, and the target date for closing it. Overwatch 7Six sorts open items by target date and marks anything due within 30 days.
How many requirements does Overwatch 7Six track?
All 110, grouped by their 14 families, each with a status, an owner, a last-validated date, and a count of attached evidence.

Start with the standard

Create an account and the 110-requirement catalog is waiting, scoped to your organization alone.

Create account