Audit-Ready CUI & NIST 800-171 Training
Built for Your DoD Contract.

Custom live training that walks your team through CUI handling, all 110 NIST SP 800-171 controls, DFARS 252.204-7012 obligations, and CMMC 2.0 Level 2 readiness — taught by a working compliance assessor.

DFARS 252.204-7012
NIST SP 800-171
CMMC 2.0 Level 2
DoD Assessment Methodology

Custom training from $3,995 · Tailored to your CMMC level · Response within 1 business day

What your team learns in one focused session

A 3-hour live training tailored to your CUI categories, your CMMC level, and your specific compliance gaps. We don't run boilerplate slides — we build a session around your actual contract obligations.

1

CUI Fundamentals

What Controlled Unclassified Information actually is, the difference between CUI Basic and CUI Specified, the categories your DoD contract pulls in, and how the ISOO CUI Registry governs the program. We cover banner markings, cover sheets, and limited dissemination controls in plain language.

2

NIST SP 800-171 Implementation

Walk through the 110 security requirements across all 14 control families — Access Control, Audit and Accountability, Configuration Management, Incident Response, and the rest. We map each requirement to your environment and identify which controls you've implemented, which need work, and which need compensating controls in your POA&M.

3

DFARS 252.204-7012 & Cyber Incident Reporting

The Safeguarding Covered Defense Information clause is the contractual mechanism that makes NIST 800-171 enforceable. We cover what triggers the 72-hour reporting clock, how to file through the DoD DIBNet portal, what forensic preservation requires, and the flow-down obligations to your subcontractors.

4

CMMC 2.0 Level 2 Readiness

How CMMC 2.0 Level 2 assessment differs from a NIST 800-171 self-assessment, what evidence a C3PAO will demand, how the DoD Assessment Methodology scoring works, and exactly what to post to the Supplier Performance Risk System (SPRS) per DFARS 252.204-7019. We finish with a realistic remediation timeline.

5

System Security Plan & POA&M

The SSP is the single document that every assessor opens first. We cover the structure assessors expect, how to document each of the 110 requirements, the right level of detail, and how to track unimplemented requirements in a defensible Plan of Action and Milestones. Audit-ready, not check-box.

6

Real-World CUI Scenarios

The questions assessors actually ask. The mistakes contractors actually make. Live Q&A on your specific CUI handling workflows, your supply chain, your subcontractor management, your incident response runbook. We adapt this section to whatever your team needs most.

Carl B. Johnson

Taught by Carl B. Johnson

NIST 800-171 Assessor, CMMC RP, 20+ Years DoD Compliance Experience

Carl is a working NIST 800-171 Assessor and author of several CUI, compliance, and ITAR books, whitepapers, and playbooks used by hundreds of DoD contractors. He has spent more than two decades helping DoD prime contractors and subcontractors stand up audit-ready compliance programs — building System Security Plans, leading Plan of Action and Milestones remediation, and walking teams through the DoD Assessment Methodology before SPRS scores get posted.

Every training Carl runs is informed by what he sees inside contractor environments week after week: where teams genuinely struggle with CUI marking, which NIST controls trip up actual assessments, how DFARS 252.204-7012 reporting plays out under pressure, and what a C3PAO looks for in CMMC Level 2 evidence. The training is practical because the work is practical.

Built for DoD Contractors at Every Tier

Prime Contractors

Defense industrial base primes carrying DFARS 252.204-7012 down to subcontractors. Train your program offices, your security team, and your contract managers in one coordinated session.

Subcontractors at Every Tier

Small and mid-sized subs who handle CUI under flow-down obligations from a prime. We focus on what you actually need to implement at your scale — without burning budget on enterprise-grade overkill.

Aerospace & Engineering Firms

Teams handling Controlled Technical Information (CTI), engineering drawings, and export-controlled data subject to ITAR or EAR. We cover the Specified rules that go beyond CUI Basic.

IT & Cybersecurity Service Providers

MSPs and MSSPs serving the defense industrial base who need their own teams compliant — and who advise contractor clients on NIST 800-171 implementation and CMMC Level 2 prep.

Request Custom Training

Tell us about your team. Carl B. Johnson reviews every request personally and sends back a tailored proposal and invoice within 1 business day. Custom training from $3,995.

Your Company
We're built for businesses — please use your company email address.
Training Needs
Billing Information

For your invoice. Terms: Due on receipt.

By submitting, you agree to be contacted about your training request. We respond within 1 business day.

Frequently Asked Questions

What is NIST SP 800-171?

NIST Special Publication 800-171 is the foundational standard for protecting Controlled Unclassified Information on contractor systems. It defines 110 security requirements across 14 control families that DoD contractors must implement under DFARS 252.204-7012 and that form the technical basis for CMMC 2.0 Level 2 certification.

What is the difference between CMMC and NIST 800-171?

NIST 800-171 is the technical standard — the rulebook of 110 security requirements you must implement. CMMC is the DoD assessment and certification program — the exam that verifies you have those controls in place. You implement NIST 800-171 to pass a CMMC Level 2 assessment.

Who needs CUI and NIST 800-171 training?

Any DoD contractor or subcontractor handling Controlled Unclassified Information needs CUI and NIST 800-171 training — primes, subs at every tier, and individual employees with CUI access. DFARS 252.204-7012 and CMMC 2.0 Level 2 mandate it as part of compliance.

How long is the training session?

Custom CUI & NIST 800-171 training runs approximately 3 hours and is tailored to your team's CMMC level, the CUI categories you handle, and your specific compliance gaps.

Do participants receive a certificate of completion?

Yes. All participants receive a certificate of completion that serves as audit-ready documentation of CUI and NIST 800-171 training compliance for DFARS and CMMC assessments.

What does "custom" actually mean?

We adapt the agenda, examples, scenarios, and Q&A to your contract obligations, your CUI categories, your CMMC target level, and the gaps your team needs to close. No boilerplate slides.

What Defense Contractors Say