Cybersecurity for people who build things.
Protect your intellectual property, meet CMMC, and win the contracts that require security proof.
Protect what keeps you building
You are running a manufacturing operation, not a cybersecurity company. OrbitalFire helps smaller manufacturers protect against threats, comply with CMMC and other requirements, and gain a competitive edge.
If you are in the DOD supply chain, CMMC is part of the picture, and we have been helping manufacturers through the changing requirements for years. If defense contracts are not your world, the fundamentals are the same: cybersecurity built for your scale, without the complexity.
Manufacturing solutions overview (PDF)What we help with
The path to certification, in order
Know where you stand
A NIST SP 800-171 gap assessment, control by control and scored, with findings ranked by risk rather than by control number.
Write it down properly
System Security Plans and Plans of Action that match how your shop actually runs, rather than filled in from a template.
Close the gaps
In priority order, at a pace your people can absorb around production, with your own IT making the changes.
Submit your SPRS score
Where we have performed your assessment, we transpose the score into the Supplier Performance Risk System for you.
And running alongside it
Training your people will finish
Awareness Training and Phishing Testing, which several 800-171 control families require outright.
Your suppliers, and your primes
Third Party Risk Management for the flow-down obligations you inherit and the ones you pass down yourself.
Ready before the call comes
Incident response planning, including the 72 hour DOD reporting obligation.
Someone who owns it
A vCISO keeping the roadmap moving between certification cycles, so it does not stall the week after the assessment.
We can also coordinate with your region's MEP center on grant opportunities, and speak for you in the conversations with primes where compliance timelines get negotiated.
CMMC, and what our RPO standing means
OrbitalFire is a Cyber-AB Registered Provider Organization, one of the first firms designated an RPO, and our team includes Registered Practitioners authorized to advise on the standard.
For manufacturers being asked to comply with CMMC requirements from their vendors and customers, we help you work out what level of CMMC is required, then take you through readiness end to end. And we keep you current as the requirements move.
The scenario required us to work through a credible cybersecurity event with the ambiguity, competing priorities, and cascading consequences that would exist in an actual incident. That was valuable not only from a cybersecurity standpoint, but also as an exercise in leadership communication, prioritization, and decision-making under pressure.

Do we need CMMC if we do not hold a defense contract?
Not usually. CMMC applies to DOD contracts and to the supply chain underneath them, so if you supply a company that holds one, the requirement generally flows down to you. Outside that, customers still ask for proof on their own questionnaires, which is a different and usually lighter bar.
What level of CMMC applies to us?
It depends on what you handle. Level 1 covers Federal Contract Information and is a self-assessment. Level 2 covers Controlled Unclassified Information and is built on NIST SP 800-171. Most smaller manufacturers land at one of those two, and working out which is the first thing we do.
Does OrbitalFire certify us?
No, and we could not. A Registered Provider Organization prepares you. The assessment itself is performed by an accredited third party, and keeping those two roles apart is what makes the preparation worth anything.
Does our whole business have to be in scope?
It depends. As part of the Assessment we will scope which systems and which people touch Controlled Unclassified Information. We will recommend the best approach for your organization.
Who submits our SPRS score?
Where we have performed your assessment, we transpose the score into the Supplier Performance Risk System for you. We can also coordinate with your region's MEP center on grant opportunities.
A contract just named NIST 800-171. What is the first thing to do?
Read the clause and find out which obligation you actually have. A DFARS 252.204-7012 requirement to meet NIST 800-171 is a different job from a CMMC level written into the contract. Then have a gap Assessment done against the controls. That gives you the score and the plan the rest of the process asks for.
Tell us about your business.
A half-hour conversation about what you're being asked for and where you actually stand. If we can help, you'll have a proposal usually within a day.
Not ready to talk? Check your readiness in five minutes and see where to start.
