CMMC 2.0 readiness and NIST 800-171 compliance consulting for DoD contractors nationwide. Backed by 15+ years in cybersecurity, direct DoD experience, and hands-on CMMC assessor certification.
The Department of Defense has formally embedded CMMC requirements into contracts. Non-compliance means lost contracts — and potential legal liability. Understanding your level is the first step.
17 practices aligned to basic safeguarding of Federal Contract Information (FCI). Annual self-assessment.
110 practices aligned to NIST 800-171. Handles Controlled Unclassified Information. Triennial third-party assessments required for critical programs.
110+ practices based on NIST 800-171 and select 800-172 requirements. Government-led assessments for the most sensitive programs.
I'm Neal Fennimore, founder of XNOR LLC and a Lead Certified CMMC Assessor with over 15 years securing enterprise and government environments.
Most recently, I served as a Digital Service Expert at the Defense Digital Service, where I was the technical lead for the Pentagon's bug bounty program, helped audit ATO processes across multiple platforms, and integrated security solutions into cloud infrastructure.
As IT Security Director at a DoD contractor, I led CMMC compliance efforts firsthand — hardening on-prem and Azure infrastructure, deploying security systems, and building business continuity programs that meet federal requirements.
I hold an MS in Cybersecurity from NYU (CyberFellow program) and carry the full CompTIA security stack alongside ISACA's LCCA, CCA, and CCP designations.
Recognized voice in cybersecurity and authentication.
From NIST 800-171 gap analysis to mock assessments, XNOR provides end-to-end readiness support for defense contractors pursuing CMMC certification.
Pre-assessment evaluations led by a Lead Certified CMMC Assessor, measuring your practices against CMMC Level 1 and Level 2 requirements — so you walk into your C3PAO assessment with no surprises.
Learn more →Thorough review of your current security posture against NIST 800-171 controls, with a prioritized remediation roadmap before your formal assessment.
Learn more →Design and implementation guidance for Zero Trust architectures aligned to DoD and NIST frameworks — on-prem, Azure, or hybrid environments.
Development of System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), and all supporting policies required for CMMC compliance.
Learn more →Hardening of cloud infrastructure to meet CMMC and FedRAMP alignment requirements, including SIEM integration, VLAN segmentation, and MDM policy.
Custom cybersecurity training programs and tabletop exercises designed for defense contractor teams navigating CMMC requirements for the first time.
Tools I built to help defense contractors understand and track their compliance posture before a formal assessment.
A free, browser-based tool to walk through all 110 controls across 14 NIST SP 800-171 R2 families. Track your implementation status, view your running SPRS score, and generate a compliance summary — all stored locally in your browser with no account required.
Every credential active and maintained — because the threat landscape doesn't stand still.
Quick answers to the questions defense contractors ask most about CMMC 2.0, NIST 800-171, and the assessment process.
CMMC 2.0 (Cybersecurity Maturity Model Certification) is the Department of Defense's framework for verifying that contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Any company in the defense supply chain — primes and subcontractors alike — will need to meet the CMMC level specified in their contracts.
Level 1 covers 17 basic safeguarding practices for FCI and allows annual self-assessment. Level 2 requires all 110 NIST SP 800-171 controls for handling CUI, and most contracts involving CUI require a triennial third-party assessment by a C3PAO.
Most small and mid-sized contractors need 6 to 18 months to reach Level 2 readiness, depending on their starting posture. A gap analysis early in the process gives you a realistic timeline and a prioritized remediation roadmap.
Your SPRS (Supplier Performance Risk System) score reflects your self-assessed implementation of NIST SP 800-171, ranging from -203 to a perfect 110. DoD contracting officers can view it, and an accurate score is required under DFARS 252.204-7019/7020.
No — official Level 2 certification assessments are conducted by authorized C3PAOs. XNOR provides consulting, gap analysis, remediation support, and mock assessments led by a Lead Certified CMMC Assessor so you walk into your C3PAO assessment fully prepared.
Whether you're starting from scratch or preparing for a formal assessment, let's talk through where you stand and what it takes to get compliant.
Thanks for reaching out. Neal will be in touch within 1–2 business days.