Managed Security · CMMC & NIST SP 800-171

Readiness proves a control exists. An assessor asks whether it runs.

Several 800-171 requirement families are not satisfied by a documented policy. Monitoring, audit logging, incident response and awareness are judged on whether they operate continuously and produce records. Cyberneza scopes and implements; Huntress-backed managed security operates the parts that have to run every day.

The gap

Documentation-only controls are where self-assessments overstate.

Written, not operating

An SSP can accurately describe an intended control while nothing in the environment performs it. That distinction is invisible in a document review and obvious in an assessment interview.

No evidence trail

Requirements that call for review, analysis and response expect artifacts — records showing the activity happened, repeatedly, over time. A tool that was installed but never watched produces none.

Scored optimistically

SPRS scoring rewards implemented practices. Where a control is scored as met on the strength of a policy, the score does not survive contact with an assessor, and the correction lands late.

What managed security supports

The requirement families that need something running.

Audit & Accountability (AU)

Centralized collection, retention and review of audit records across endpoints, identity and cloud services, with reporting that demonstrates the review actually occurs.

Managed SIEM →

System & Information Integrity (SI)

Continuous endpoint monitoring, malicious-code detection, and monitoring of inbound and outbound communications traffic for attack indicators.

Managed endpoint security →

Incident Response (IR)

Detection and analysis capability feeding an incident-handling process, with investigated incident reports and remediation guidance that give the process something to act on.

Incident response →

Identification & Authentication (IA)

Detection of credential misuse, session hijacking and adversary-in-the-middle activity — the attack classes that defeat multi-factor authentication rather than going around it.

Identity security →

Awareness & Training (AT)

Managed security-awareness and phishing-simulation delivery with completion records, which is the form the evidence usually has to take.

Security awareness →

Cyberneza’s part

Scoping the CUI boundary, deciding which assets are in scope, mapping what each capability does and does not evidence, and writing it into the SSP accurately rather than optimistically.

SSP, POA&M & SPRS →

Managed security supports the evidence behind these practices. It does not by itself make a practice compliant, and no tool or provider can declare a requirement met — that determination belongs to your self-assessment or your C3PAO.

Why this matters now

Attacks on manufacturing rose 88% year over year.

Huntress analysed activity across more than 4.6 million endpoints and 9.4 million identities during 2025. Two findings land directly on the defense industrial base: attacks against manufacturing were up 88%, and abuse of remote monitoring and management tooling — the software small suppliers rely on for IT support — rose 277%. Adversary-in-the-middle activity accounted for 18.9% of identity threats, a technique that bypasses multi-factor authentication rather than defeating it.

The reason that matters for an 800-171 programme is specific: RMM abuse and AiTM both look like authorized activity. They are detected by reviewing behaviour over time, which is exactly the capability a documentation-only control does not provide.

Source: Huntress 2026 Cyber Threat Report. Figures are Huntress’s. Our read on what it means for defense contractors →

How it sequences

Assess first. Operate what the assessment found.

1. Scope and assess

Establish the CUI boundary and the in-scope asset set, then assess the current state against the practices. Managed security is scoped to what the assessment actually found, not sold ahead of it.

2. Remediate and implement

Close the gaps that need configuration or architecture work, with Cyberneza developing the guidance and your team executing through change control.

3. Operate and evidence

Move monitoring, logging, detection and awareness into continuous operation, and keep the records the assessment will ask for.

Working out which practices need something running?

We can review your current scope, SSP and POA&M and identify which requirements are documented but not operating.

Supported platforms, features, response actions, integrations and licensing depend on the selected Huntress service and current product availability. Cyberneza is an authorized Huntress reseller.