Defense Supply Chain

Five-point requirements cannot wait on a POA&M.

Schedule a meeting

Defense suppliers under DFARS 7012, CMMC and NIST SP 800-171

Security built for defense suppliers

Produce the evidence behind six of the most heavily weighted NIST SP 800-171 requirements, on your own servers.

Requirements

ReqRequirementPointsARRTECH product
3.3.1Create and retain audit logs.5SIEM →
3.3.2Trace actions to individual users.3SIEM →
3.3.4Alert on audit logging failure.1SIEM →
3.3.5Correlate review, analysis and reporting.5SIEM →
3.6.1Operational incident handling.5SOAR and SIEM cases →
3.6.2Track, document and report incidents.5SOAR and SIEM cases →
3.8.7Control removable media.5DLP →
3.14.6Monitor systems and traffic for attacks.5SIEM →
3.13.11FIPS-validated cryptography for CUI.5 or 3Not claimed →

SPRS score

Close five-point NIST 800-171 gaps

In the DoD assessment method, audit logging (3.3.1), incident handling (3.6.1) and removable media (3.8.7) are each worth 5 points. Under CMMC, 5-point requirements cannot be left on a plan of action, and ARRTECH covers all three.

32 CFR 170.22

Back your SPRS affirmation with evidence

Under 32 CFR 170.22, a senior official affirms your compliance every year. ARRTECH keeps the signed logs and incident records behind each requirement you claim.

NIST SP 800-171 3.8.7

Control USB drives on the shop floor

Requirement 3.8.7 asks you to control removable media on every system that handles CUI. ARRTECH DLP approves each USB device by serial number, per person, for a set time, and a manager signs off on each exception.

DFARS 7012

Stay out of cloud scope

DFARS 252.204-7012 requires any cloud service that stores your CUI to meet the FedRAMP Moderate baseline or its equivalent. ARRTECH runs on your own servers, so it adds no cloud provider to check.

By rule

3.3.1

Create and retain audit logs. ARRTECH SIEM collects audit logs from each system and keeps them for the period you set.

3.3.2

Trace actions to individual users. ARRTECH SIEM ties each event to a named user account.

3.3.4

Alert on audit logging failure. ARRTECH SIEM alerts when a log source stops sending.

3.3.5

Correlate review, analysis and reporting. ARRTECH SIEM links events across sources into one case.

3.6.1

Operational incident handling. ARRTECH SIEM opens a case, and ARRTECH SOAR records each response step and who approved it.

3.6.2

Track, document and report incidents. ARRTECH SIEM cases and ARRTECH SOAR history form your incident record.

3.8.7

Control removable media. ARRTECH DLP allows or blocks each USB device by serial number.

3.14.6

Monitor systems and traffic for attacks. ARRTECH SIEM correlates host and network logs, and Cyberdroid AI Detection flags unusual behavior.

3.13.11

FIPS-validated cryptography for CUI. Not claimed: this stays with you.

Questions

Does it add a cloud provider to our scope?

No. ARRTECH SIEM and ARRTECH DLP run on your own servers. Assessors treat them as security tools and check them only on what they do.

Can we control USB drives on the shop floor?

Yes. ARRTECH DLP allows or blocks each USB device by its make or serial number, per person or computer, for a set time. A manager approves every exception.

Who handles an incident?

An alert in ARRTECH SIEM opens an incident in ARRTECH SOAR. A person gets up to five options by email and the playbook waits. The history becomes your incident record.

What stays with you?

Your score, your signed affirmation and FIPS-validated encryption for CUI. ARRTECH runs on your servers, so it suits a supplier with its own IT staff.

Sources

Guide

How do small defense suppliers prepare for CMMC?

Start with the heaviest-weighted NIST SP 800-171 requirements: audit logging, incident handling and removable media. These cannot wait on a POA&M.

What is an SPRS score?

The SPRS score summarizes your NIST SP 800-171 self-assessment. A senior official affirms it every year, so it needs evidence behind it.

Does a SIEM help with NIST 800-171?

Yes. A SIEM supports the audit and accountability requirements, 3.3.1 to 3.3.8, and incident tracking under 3.6.

Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Available now

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Early access

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

See every system. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.