Veteran-Owned Small Business  ·  Serving the Defense Industrial Base Nationwide
DFARS 7012  ·  NIST 800-171  ·  Compliance as a Service  ·  IT Buildout

Security is the practice.
Compliance is the goal.
Certification is the byproduct.

CMMC will keep changing. Your obligation to protect CUI under DFARS 252.204-7012 and NIST SP 800-171 won't — it's been the law of your contracts since 2016. iEA builds real compliance that survives every pause, rebrand, and reform — so whatever CMMC becomes, you're already ready. Every certified assessment we've led: a perfect 110.

6 / 6
L2 engagements
110
every certified assessment
0
failed assessments
0
POA&Ms
// Track Record

A Perfect Record, On Purpose

Across every CMMC Level 2 engagement we've taken on — from photonics R&D labs to precision manufacturers — the outcome has been the same: zero failed assessments, zero POA&Ms, every finding closed before assessment day. Not after.

6 / 6
engagements certified or posted
110
perfect score in every certified assessment
0
POA&Ms — every finding closed before assessment day
2 wks
most recent client: 88 posted to SPRS

Photonics & AI defense R&D firm

From zero IT department to CMMC L2 certified — full hands-on build, mock assessment, official assessment passed.

Fully remote defense software company

End-to-end: strategy, implementation, mock assessment, official assessment — passed.

Defense manufacturer (vCISO model)

Their team executed under our guidance. Passed the official assessment with no issues.

Defense engineering services firm

SSP, policies, and procedures fully authored by iEA, with technical guidance matched to their environment. Passed clean.

Precision tooling manufacturer

vCISO services through mock and official L2 assessments. No issues, no findings.

Defense technology firm

88 posted to SPRS in two weeks. iEA now manages their compliance environment end to end.

// What We Do

Three practices. One standard: flawless.

From your first DFARS clause to a fully managed security program, iEA operates as your compliance and technology partner — advisory, execution, and operations under one roof.

PRACTICE / 01

DFARS, NIST & CMMC Advisory

Real compliance with DFARS 252.204-7012 first — certification-ready by construction, run by practitioners who have never lost an assessment.

  • Gap assessments against NIST SP 800-171
  • SSP development, policies & procedures
  • Evidence discovery & assessment packaging
  • Mock assessments — assessor methodology
  • Official C3PAO assessment support
  • SPRS scoring & submission
PRACTICE / 02

Compliance as a Service

Your entire compliance program, run as a service — executive-level leadership and hands-on operations without the executive headcount.

  • vCISO leadership & security strategy
  • Continuous compliance management
  • Solution architecture & engineering
  • Microsoft 365 GCC / GCC High administration
  • Google Workspace, Jamf & Intune management
  • Network, on-prem & infrastructure operations
PRACTICE / 03 Signature

Zero-to-IT Buildout

Our signature practice: startups with no IT at all, taken to a fully operational — and certified — IT department. Then you choose:

  • We run it — iEA operates your IT & compliance end to end
  • You take the mantle — complete documentation handover
  • Recruiting support to hire the right person to carry it forward
  • Proven: taken clients from zero IT to CMMC L2 certified
Sectors We Serve
Photonics & AI R&D Defense Software Defense Manufacturing Precision Tooling Engineering Services Defense Technology DIB Startups
// Know the Rules

CMMC is making headlines. Your obligations haven't changed.

In 2026 the Pentagon suspended CMMC Phase II and opened a reform review — the latest twist in a program that has been paused and rebranded before. The headlines are breathless. The law is calmer: what actually binds you as a defense contractor has been stable for a decade.

Still in force

DFARS 252.204-7012

The clause in your contracts since 2016: safeguard Controlled Unclassified Information and report cyber incidents rapidly. It has never been paused — not once, under any administration.

Still in force

NIST SP 800-171

The 110 security requirements behind every version of CMMC. Whatever the verification program becomes, this is the standard your environment is measured against.

Still in force

SPRS Self-Attestation

CUI contractors still self-assess and report their score, signed by a senior official — and False Claims Act exposure for inflated scores is untouched. With third-party checks paused, accuracy matters more, not less.

Still in force

ITAR & Export Control

Export-controlled technical data still has to be protected — no memo, pause, or reform review changes that obligation.

A decade of pauses. The foundation never moved.

2016

DFARS 7012 takes effect

Protecting CUI to the NIST 800-171 standard becomes a contractual duty. It has never gone away.

2020

CMMC 1.0 launches

Five levels, mandatory third-party assessments for everyone.

2021

Paused. Reviewed. Relaunched.

New leadership halts CMMC 1.0 and rebuilds it as CMMC 2.0 — three levels, self-assessments allowed.

2024–25

CMMC becomes binding regulation

32 CFR Part 170 and the acquisition rule finalize; the phased rollout begins.

2026

Phase II paused — reform review opens

Third-party enforcement is suspended for review. The duty to protect CUI? Fully intact, exactly as it was the week before.

Every administration rebrands the verification. None has ever touched the foundation. Build to the foundation — NIST 800-171, implemented for real — and you're ready for whatever CMMC becomes. That's why at iEA, compliance is the goal and certification is the byproduct. The companies that keep momentum through the pause will be at the front of the line when it ends.
// THE iEA DIFFERENCE

Where everyone else says no, we find a way.

Most compliance shops hand you a mandatory migration quote. We're solution architects first: we design a path to compliance on the stack you already run — and recommend changes only when absolutely necessary.

Microsoft 365 GCC / GCC High Google Workspace On-Prem & Hybrid Jamf Intune Apple & MDM Fleets

Commercial cloud, government cloud, on-prem, or a mix — we architect compliance around your environment, not the other way around.

// After Certification

Certification is day one. Then you choose who carries the mantle.

A perfect score only matters if it holds. Every iEA engagement ends with a deliberate decision — and we're built to deliver both answers.

Option 01 — We Carry It

Compliance as a Service

iEA stays on as your security and compliance department — continuous compliance, managed operations, and vCISO leadership as a predictable service.

  • Continuous control monitoring & evidence upkeep
  • Managed M365 GCC/GCC High, Google Workspace, MDM & infrastructure
  • Always assessment-ready — no scramble at renewal
Option 02 — You Carry It

Take the mantle

We specialize in clean handoffs: your program, fully documented and transferred to an in-house team we help you build.

  • Complete documentation of everything we built
  • Recruiting & vetting support to hire the right person
  • Transition guidance until your team runs it with confidence
// How We Work

The engagement lifecycle.

01

Discovery

A conversation about your contracts, your CUI footprint, and your timeline. No charge, no pressure — just a clear read on where you stand.

02

Assessment & Roadmap

We assess your environment against every applicable control and deliver a prioritized, plain-English roadmap with a defensible scope.

03

Remediation & Buildout

We close the gaps — technical fixes, policies, SSP, evidence — working alongside your team, your MSP, or building your IT operation from scratch.

04

Certification

A full mock assessment against assessor methodology, then support through your official assessment and SPRS posting. Every finding closed before assessment day.

05

Sustainment or Handover

iEA stays on as your managed security partner — or executes a fully documented handover and helps you hire the right person to carry it forward.

// Why iEA

Practitioner-led. Assessment-proven.

  • A perfect record — 6/6 CMMC Level 2 engagements certified or posted, a 110 in every certified assessment, zero POA&Ms.
  • Credentialed where it counts — CISSP and CMMC Certified Professional (CCP): certified in both security practice and the CMMC ecosystem itself.
  • Hands-on-keyboard execution — deep Microsoft 365/GCC administration, Apple/MDM fleets, and network infrastructure. We fix, not just advise.
  • Forged in the mission — a veteran-owned small business founded by a U.S. Army Airborne veteran who understands the defense mission from the inside.
  • Built for the whole journey — from zero-IT startups to established contractors; we build, operate, or hand over with full documentation.
// About Us

What does iEA stand for?

People ask, and the honest answer starts a generation back. My father ran his own business — IEA Inc., the Instituto de Enseñanza Automotriz, a school where he taught people the automotive trade. He didn't just fix machines; he taught others to master them, so they could build livelihoods of their own. That school has since closed — but what it stood for didn't.

When I started this company, I took up his letters on purpose. He taught people to master their machines. We teach companies to master theirs. The trade changed from engines to networks — the teaching never did. Same letters, same mission, carried forward.

implement.
we build it — hands on keyboard
Educate.
we transfer it — documented and taught
Assure.
we prove it — and keep it provable
The E has always stood for education

Led from the front.

Manny, Owner and Lead Consultant of iEA CyberSec

Manny

Owner / Lead Consultant
CISSP CMMC CCP XVIII Airborne Corps 2× OIR Deployments

I've always had a passion for helping people — it's a big part of why I served. I wanted to be part of something greater than myself. I spent five years in the U.S. Army as Airborne Artillery with XVIII Airborne Corps, including two deployments to Iraq and Kuwait in support of Operation Inherent Resolve. The Army is also where I discovered a natural aptitude for IT — and I leaned all the way in.

Since then I've had the opportunity to work inside great companies, and what that experience taught me is exactly what growing small businesses need. Here's what I believe: we read the NIST controls and overcomplicate the implementation. Compliance doesn't have to be hard, and it shouldn't be a cost dump — done right, it makes your company genuinely stronger. That's the problem I love solving. And nothing beats standing up an IT department from day one — automated processes, solid documentation, real procedures — built so cleanly that one day we hand the mantle to your internal team and it just keeps running.

I've worked with plenty of consultants over my career, and I know the stigma — the ones who engineer reasons to stick around and stretch a paycheck. I built iEA to be the opposite. The best consultants leave the place better than they found it, stay exactly as long as they're needed or wanted, and make sure everything they built can be carried forward without them. We'll always be a phone call or an email away — but our measure of success is you succeeding without us, so we can move on to helping the next small business get there too.

— Manny, Owner & Lead Consultant

Manny during his U.S. Army service, in uniform before the American flag
Then — Airborne Artillery, XVIII Airborne Corps.
2× deployed, Operation Inherent Resolve.
Now — Owner / Lead Consultant, iEA CyberSec.
Same mission: defend what matters.

Enforcement pauses. Obligations don't.

The contractors who keep momentum through the pause will be first in line when it ends. Book a free consultation — we'll give you a clear read on where you stand, what real compliance will take, and whether we're the right fit.

Book a Free Consultation