NIST SP 800-171 Revision 2 and Revision 3 Consulting From Certified Experts.

Every Kieri consultant is formally trained on the requirements specified in NIST SP 800-171, and certified to assess compliance to NIST SP 800-171 as a CMMC assessor. Engagements are flexible and based on your needs.

Guidance on NIST SP 800-171 R3

Who is requiring NIST SP 800-171 R3

Why Kieri for NIST SP 800-171 R3 Consulting

With years of experience consulting and assessing on NIST SP 800-171 R2, we have the solid foundation to get you there for R3.

Experienced in Field

Our company was founded to consult on NIST SP 800-171 Revision 2. We’ve helped over 600 companies with their goal of compliance. We are deeply familiar with the new revision of that NIST standard and have built a complete set of the documents necessary for a compliant security program.

Multiple forms of engagement

Start with an engagement reviewing your current revision 2 program with recommended actions for revision 3 as the output. Get a block of time and meet on a cadence to get guidance. Start fresh with the Revision 3 version of the KCD and hours to help you with edits and aligning your internal compliance program. The option is yours.

No Ongoing Subscription Required

We want to help you be self-sustaining with compliance, not dependent on an ongoing engagement with a recurring cost. You can always come back and re-engage for more time.

Read More on the Revisions

What Changed and What It Means for You

NIST SP 800-171 Revision 2 and Revision 3 labels for CMMC consulting services

Consulting Services for Every Stage

Program and Status Review, Then Plan

Steps in a NIST SP 800-171 Revision 3 compliance program review
Consulting focus areas for NIST SP 800-171 Revision 3 compliance

Kieri Compliance Advisory

Full Preparation Project

An end-to-end engagement for organizations that want a plan, a schedule, and an expert alongside them until they are ready for assessment.

Scoping is Key

Identify the information that needs protection to the NIST SP 800-171 Revision 3 standard, and how it flows through your environment. Document the corresponding scope and defining boundaries. Get this right first.

Documentation and Evidence

Adapt your existing documentation, or create something unique where it makes sense. Then ensure you have the evidence and ability to demonstrate you are executing your program as planned.

Implementation Guidance

Whether the guidance you need is on technical implementation, or the necessary administrative controls and internal training necessary for compliance, we can help. Revision 3 is significantly different, use our expertise to get there efficiently.

Executive Support

We calculate the resources compliance will take and help you present that case to leadership. We can often recommend cheaper and simpler solutions than the ones on the table.

Handoff to Your Team

Kieri is not a managed services provider. We explain the reasoning behind every document and control as we go, so your team can keep running the program without us.

What Sets Our Consulting Apart

Practical
Scoping

We have been advocating for common sense assessments and practical scoping since the early days of CMMC. Security requirements have to work alongside the business.

Plain
Answers

We explain how we interpret gray areas and what we have seen pass in real assessments, rather than repeating the language of the requirement back to you.

 

Experienced
Consultants

Kieri keeps 20+ certified assessors on staff and has supported 400+ organizations through NIST SP 800-171 and CMMC work. The person guiding your preparation knows what actually holds up in a real assessment.

“In our own compliance journey of trying to figure out what we are required to do, even with consultants that helped us along the way, the MOST useful resource that we have found to date has been the KCD.”

Melissa Kimball

, Director

University of Maine

“My team and I have been using the KCD for about a week now, and I have to say, it’s been a breath of fresh air compared to our previous approach. It has made several processes much easier for us, and for that, we’re truly grateful. You have a fantastic product that far exceeds our expectations.”

Daniel Martinez

, Director of Cybersecurity

nDepth Security

“In our own compliance journey of trying to figure out what we are required to do, even with consultants that helped us along the way, the MOST useful resource that we have found to date has been the KCD.”

Melissa Kimball

, Director

University of Maine

“My team and I have been using the KCD for about a week now, and I have to say, it’s been a breath of fresh air compared to our previous approach. It has made several processes much easier for us, and for that, we’re truly grateful. You have a fantastic product that far exceeds our expectations.”

Daniel Martinez

, Director of Cybersecurity

nDepth Security

You Buy the Hours You Need

Consulting engagements vary by organization size, system complexity, and how much documentation already exists. We scope the work with you first, then quote it. There is no recurring program to buy into before we start.

FAQ

Yes. Every Kieri consultant is a Certified CMMC Assessor. The guidance you get comes from people who sit on the other side of real assessments and know what evidence holds up.

No. We do not provide both consulting and formal CMMC assessment to the same client, and we consider the sale of compliance documentation templates to be consulting. We can provide a list of assessment organizations with good track records on request.

No. You buy the hours you need for the work in front of you. A retainer is available if you want ongoing access to an advisor, but it is an option rather than a condition.

Most start with a scoping conversation and a review of your existing documentation. From there we work through requirements with your team, record what is missing on a Plan of Action, and keep going until you are ready.

The underlying NIST SP 800-171 requirements and the DFARS 252.204-7012 clause have not changed, and contractors are still expected to maintain and post a self-assessment score. Preparation work you do now carries forward.

Yes. At our core we are a NIST SP 800-171 readiness and assessment company. CMMC is the Department of War program built on top of that standard, and we work with organizations on both.

Organizations that deploy Kieri​

Ready to Start Your CMMC Preparation?

Ready to Start
Your CMMC Preparation?

Work with Certified CMMC Assessors who perform real assessments. Start with a document review or scope a full preparation project. Over 400 organizations supported to date.