NIST 800-171 Penetration Testing, Risk Assessments, and Compliance Gap Assessments, tailored to your company and designed to help you validate compliance with DFARS, ITAR, and NIST 800-171.

We can help you ensure NIST 800‑171 compliance

NIST 800-171 Risk Assessment

A risk assessment will evaluate the effectiveness of your entire security program and test your internal and external defenses using real-world attack scenarios.

NIST 800-171 Compliance Gap Assessment

A controls gap assessment is designed to test your organization against each of the NIST 800‑171 security controls and prepare your organization for audit.

NIST 800-171 Penetration Test

Designed to fully meet the requirements of NIST 800‑171, our network and web application penetration testing will validate the effectiveness of your security program by testing it against real-world attack scenarios.

Continuous Monitoring

We work with your technical teams to help develop a plan to meet your continuous monitoring requirements, and help you stay on top of your 30-60-90 day patch cycles.

Custom Framework Mapping

NightLion has developed proprietary compliance framework mapping tools to help your organization satisfy multiple audits without wasting redundant business resources.

Managed Security Programs

We will work with you and your organization to develop a technology agnostic managed security program to help satisfy control requirements.

Have questions? We are ready to schedule your free consultation

Contact us today

In The Media

Bloomberg interview with Founder Vinny Troia

ITAR, DFARS, & 800‑171 For Controlled Unclassified Information (CUI)

If you’re a service provider to the U.S. federal government – whether to civilian agencies or the Department of Defense (DoD) – your information systems must meet requirements as specified in the Federal Acquisition Regulation (FAR) or the Defense Federal Acquisition Regulation Supplement (DFARS). You may also need to comply with the requirements of the International Traffic in Arms Regulations (ITAR) or the Export Administration Regulations (EAR)

— Data from A Higher Education Information Security Council 2016

Cybersecurity Blog

The latest news and insights into the world of cybersecurity

Case Study

Medical & Healthcare Industry

Night Lion provides IT audit and security control validation for Managed IT provider Specializing in Medical and Healthcare Systems