The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

Kieri Solutions CMMC Profile: Status, Services, Cost, and Who It Fits

By The Defense Compliance Report Editorial Team — an independent trade publication on CMMC 2.0 and DIB compliance · Last verified September 2026

Kieri Solutions LLC has a Cyber AB C3PAO (CMMC Third-Party Assessment Organization) listing and sells Level 2 assessments, KCD templates, the KRA, gap analysis, and consulting. A CMMC ecosystem member that served as your preparation consultant within the past three years cannot participate in your Level 2 certification assessment. Kieri says KCD and KRA buyers must use another C3PAO.

Searching for a Kieri Solutions CMMC review? We didn't hire Kieri or test its products, so this isn't one. It's what a careful buyer needs instead:

  • what the public record shows;
  • what Kieri says about itself;
  • where Kieri's own pages disagree;
  • one table showing which Kieri purchase rules out which.

Where CMMC stands (checked September 24, 2026). Official department webpages now use Department of War (DoW), while the regulations and contract clauses still use Department of Defense (DoD). DoW suspended CMMC Phase 2 on July 13, 2026. Its CMMC page says the program "is paused in Phase 1 and may only require self-assessments at two levels." The official DARS index also lists Class Deviation 2026-O0025, Revision 3, dated September 3, 2026. The official pages we checked list no replacement Phase 2 date or public final reform-task-force report.

The July 2026 implementation memorandum directed DoW program managers and requiring activities to designate only Level 1 (Self) or Level 2 (Self), amend active solicitations containing Level 2 (C3PAO) or Level 3 requirements, and remove those requirements from existing government contracts before the next option or scheduled administrative modification. Old language may still remain in an unamended document. A prime may also impose its own supplier qualification, but that is not automatically a current DoW CMMC requirement. If the document in front of you still says Level 2 (C3PAO), get written clarification or an amendment before paying for an assessment. See what the suspension changed and what it didn't.

This page is for you if either of these is true:

  • Kieri is on your shortlist, for templates, a GCC High build, a gap analysis, consulting, or a Level 2 assessment.
  • You already bought from Kieri and want to know what that rules out.

Start somewhere else if either of these is true:

  • You only handle FCI (Federal Contract Information). That's non-public information provided by or generated for the government under a contract to develop or deliver a product or service, excluding public and simple transactional information. Level 1 is a yearly self-assessment against the 15 safeguards in FAR 52.204-21, with no C3PAO involved. The Level 1 self-assessment checklist is your page.
  • You aren't sure whether you handle CUI (Controlled Unclassified Information). That's information the government requires or permits to be safeguarded by law, regulation, or policy. Settle that first with FCI vs. CUI.

Kieri Solutions at a glance

Kieri Solutions LLC says it was established in 2015. Its founder is Amira Armond, whom Kieri describes as a Certified Lead CMMC Assessor and Provisional Instructor. It sells both sides of CMMC work: help getting ready, and the formal assessment. Many of its strongest claims are its own and can't be checked from public records, so the table below says which is which.

Your question — Short answer — How we know — What to check yourself
Your questionShort answerHow we knowWhat to check yourself
Is Kieri a C3PAO?The Cyber AB Marketplace has a C3PAO listing for Kieri Solutions LLC, and Kieri calls itself an authorized C3PAO.Cyber AB listing; Kieri's About pageWhether the live listing says "Authorized" or "Accredited," and its effective date, on the day you sign
Does it sell both assessments and readiness help?Yes. It sells formal Level 2 assessments, mock assessments, gap analysis, consulting, the KCD, and the KRA.Kieri's service pagesWhich one your paperwork actually calls for
Can it prepare you and then assess you?The rule bars an ecosystem member that served as your preparation consultant within three years. Kieri says its consulting, KCD, KRA, and standard gap analysis trigger that boundary. The Cyber AB’s CoPC recognizes a formal, results-only mock or gap assessment as conflict-free only when it gives no remediation or improvement advice.Kieri's FAQs; 32 CFR 170.8(b)(17)(ii)(G); CoPC §3.4The exact scope and Kieri's conflict decision in writing, before work starts
Are prices public?Mostly no. One Kieri article prices the KCD and KRA together at about $15,000.Kieri article, June 30, 2026A current written quote
How experienced is it?Kieri says "50+" assessments and more than 20 certified assessors averaging 21 years. Another block on the same homepage says "100+" assessments.Kieri's homepage (company-stated; the two figures conflict)The count as of a date, and the names of your assigned team
Are there independent reviews?Our September 2026 searches found Kieri's own testimonials and case studies, not a dependable body of independent customer reviews.Searches run September 24, 2026References for the exact service and team you'd buy

What we verified (September 24, 2026).

  • We read:
  • the October 2024 Federal Register final rule and 32 CFR 170.3, 170.8, 170.9, 170.17, 170.19, 170.21, and 170.22 on the eCFR;
  • FAR 52.204-21, DFARS 252.204-7012, NIST SP 800-171 Revision 2, NIST SP 800-171A, and the current DoW Level 2 scoping and assessment guides;
  • the current DoW CMMC page, the July 2026 implementation memorandum, and the official DARS entry for the September 3, 2026 Revision 3 class deviation;
  • the Cyber AB's July 15, 2026 statement, CMMC Code of Professional Conduct v2.0, CMMC Assessment Process v2.0, and Kieri's Marketplace member page;
  • Kieri's homepage, About, Team, case-study, assessment, gap-analysis, consulting, KCD, and KRA pages;
  • two dated Kieri articles.
  • We couldn't independently verify:
  • the Marketplace member page's live status label and effective date, which are JavaScript-rendered;
  • Kieri's assessment count, team-wide experience figures, product outcomes, or customer outcomes;
  • current prices beyond Kieri's own published figures.
  • We didn't: hire Kieri, buy its products, or interview its clients.

Which Kieri service are you buying, and does it rule Kieri out as your assessor?

Kieri sells two kinds of work: help getting ready, and the official test. Under the CMMC rule, a CMMC ecosystem member that served as your consultant to prepare you for any CMMC assessment within the past three years can't participate in your Level 2 certification assessment. So the first question isn't whether Kieri is good. It's which side of Kieri you're buying.

Think of a driving school that also gives road tests. You can take lessons there, or take your road test there. If they taught you, someone else gives you the test.

The rule is 32 CFR 170.8(b)(17)(ii)(G). It requires the Cyber AB's code of conduct to bar CMMC ecosystem members from a Level 2 certification assessment when they "previously served as a consultant to prepare the organization for any CMMC assessment within 3 years." That code covers firms as well as individual assessors. C3PAOs must follow it under 32 CFR 170.9(b)(2).

The CFR does not define exceptions by service label. The Cyber AB’s CMMC Code of Professional Conduct §3.4 does define a non-certification assessment—often called a mock, gap, or dry-run assessment—as not creating that conflict only when it is formal, follows the relevant assessment procedures, gives the buyer a results deliverable, and provides no recommendations, advice, or consultative information on remediation or improvement. The CoPC says the C3PAO alone is responsible for the conflict decision; neither the Cyber AB nor the CAICO will issue an advance conflict-of-interest opinion.

The CoPC’s supplemental template example also treats implementation templates, documentation, and other tools that guide preparation or remediation as advisory activity that creates an organizational conflict for the selling C3PAO. That is why KCD and KRA belong on the readiness side of the table.

If you buy this from Kieri — What Kieri says you get — Which side — Price info Kieri publishes — Can Kieri still run your certification assessment?
If you buy this from KieriWhat Kieri says you getWhich sidePrice info Kieri publishesCan Kieri still run your certification assessment?
KCD license, with or without the 25-hour customization packagePre-written policies, procedures, and an SSP for all 110 Level 2 requirements; 40+ hours of video; monthly Q&As; three sessions with Kieri assessors; 12 months of updatesReadinessQuote only; about $15,000 bundled with the KRA (June 30, 2026 article)No, under Kieri's published policy. Kieri's KCD and assessment FAQs send KCD buyers to another C3PAO.
KRA licenseBlueprint for Microsoft 365 GCC High and Windows laptops: diagrams, baseline settings, scripts, step-by-step procedures, validation checklistsReadinessQuote only; about $15,000 bundled with the KCDNo, under Kieri's published policy. Kieri's assessment FAQ sends KRA buyers to other C3PAOs.
Engineering help building the KRA40 hours of Kieri engineers working with your teamReadiness$28,000 (June 30, 2026 article)No, under Kieri's published policy. Kieri's consulting FAQ says it doesn't provide consulting and formal assessment to the same client.
Standard gap analysisReview of all 110 requirements; scoping, cloud-vendor, and CUI data-flow review; findings report; prioritized fix-it roadmapReadinessFixed-fee quoteNo, under Kieri's published policy. Kieri's gap-analysis FAQ says the standard version counts as consulting.
Observations-only gap analysisThe same review, findings only, no fix-it advice. You must ask for it up front.Non-certification assessmentFixed-fee quotePotentially, but only if the exact engagement satisfies CoPC §3.4. It must be formal, provide a results deliverable, and give no remediation or improvement advice. Get the scope and Kieri's written conflict basis before work starts.
Consulting: document review, advisor retainer, or full preparation projectSSP and document review (typically 25 hours), scoping help, fix-it guidance, advisor meetings about once a monthReadinessHourly or fixed-scope quoteNo, under Kieri's published policy. Same consulting FAQ.
Mock assessmentA practice evaluation; Kieri's description includes a prioritized remediation roadmapNon-certification assessmentQuotePotentially, but only as a true mock under CoPC §3.4. Kieri's marketed roadmap appears inconsistent with the CoPC's no-remediation-advice condition. Require a narrowed results-only scope and Kieri's written conflict basis, or use another assessor.
Formal Level 2 certification assessmentHigh-level readiness check, formal on-site assessment, findings for every assessment objective, and up to 4 hours of virtual close-out. A CMMC Status and Certificate of CMMC Status depend on the assessment result; they are not automatic.AssessmentFirm fixed-price quoteOnly if Kieri's live Marketplace status is Authorized or Accredited and its written conflict check confirms that no disqualifying preparation consulting occurred within the prior three years.

What the assessment-side readiness check can cover. Under the CMMC Assessment Process (CAP) v2.0, the C3PAO may review the SSP for completeness, accuracy, and consistency, validate the assessment scope, confirm that evidence and people will be available, and decide whether the organization is ready to begin. It does not evaluate whether implementation is adequate or sufficient, predict a successful outcome, or tell the organization how to remediate. If Kieri identifies that you are not ready, the CAP permits an explanation of why the assessment should be suspended, not remedial advice.

Assessment and affirmation cadence. A Level 2 certification assessment is due every three years when that assessment type is required. The Affirming Official affirms after the assessment and annually thereafter; failure to make the annual affirmation causes the status to lapse. A Conditional status has a maximum 180-day POA&M closeout window, and the Final status retains the original Conditional status date for its three-year term.

Terms used in the table:

  • KCD means Kieri Compliance Documentation.
  • KRA means Kieri Reference Architecture.
  • SSP means System Security Plan, the document that explains how you meet each requirement.

Two hypotheticals show how this plays out.

Say you run a 75-person machine shop. You buy the KCD, add Kieri's 25-hour customization block, and hire Kieri to help close gaps. Kieri's own FAQs say every one of those counts as consulting. Plan on a different C3PAO from day one, and budget for it now. Better than finding out after the readiness work is done.

Now say the same shop is nearly ready and wants Kieri as its assessor. It asks for an observations-only gap analysis. Kieri's FAQ says it will limit findings to observations, with no fix-it advice, if you ask up front. The label alone isn't enough: the work must also be formal, follow the relevant non-reporting assessment procedures, produce a results deliverable, and provide no remediation or improvement advice under CoPC §3.4. Get the statement of work and Kieri's written conflict basis before anyone starts.

Three quick checks before you call anyone:

  1. Does your contract, solicitation, or prime's subcontract say Level 1 (Self), Level 2 (Self), or Level 2 (C3PAO)? "Level 2" by itself isn't enough.
  2. Does it include DFARS 252.204-7012? If so, you must protect covered defense information under NIST SP 800-171, whatever happens with Phase 2. What that clause requires.
  3. Have you bought the KCD, the KRA, a gap analysis, or consulting from Kieri in the last three years?

The right use of Kieri, if any, isn't the same for every contractor. It depends on your required CMMC level, whether you handle FCI or CUI, the assessment type your paperwork names, your IT and cloud setup, and your timeline. Those same facts decide whether you need a C3PAO, an RPO/RP (Registered Practitioner Organization or Registered Practitioner), a set of templates, an MSSP (Managed Security Service Provider), or a CUI enclave. The contract clause sets your level, not a checklist.

A general answer can't settle those for you. Use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right kind of help before you request quotes. Do not submit CUI, drawings, or sensitive contract details.

If your answers to those three checks left you unsure which side of Kieri you need, or whether you need Kieri at all, map your situation before you book a sales call.

See which kind of CMMC help fits →

Where Kieri's own pages disagree

Kieri publishes substantial detail about its services. That also means some of its pages say different things. None of these proves anything is wrong, but each one is worth settling in writing before you sign.

Topic — One Kieri page says — Another Kieri page says — Get this in writing
TopicOne Kieri page saysAnother Kieri page saysGet this in writing
Assessment countHomepage stat block: "50+ Assessments," completed since CMMC went live. The consulting page says "well over 50."The same homepage's comparison block says "100+ assessments completed."How many formal Level 2 certification assessments Kieri has completed, as of what date, and what the "100+" includes
Consulting, then assessingThe consulting page says that if you want a formal assessment, "a separate Kieri team handles it."The same page's FAQ says Kieri doesn't provide both consulting and formal assessment to the same client.Whether Kieri will assess you after this exact engagement. The FAQ aligns with the rule's entity-level boundary; merely assigning a different internal team does not answer the conflict question.
Gap analysisThe gap-analysis page says the standard version includes a prioritized remediation roadmap and counts as consulting.The same page says Kieri will limit findings to "observations only" if you ask up front.The exact statement of work and Kieri's written basis that it meets CoPC §3.4: formal assessment procedures, a results deliverable, and no remediation or improvement advice.
Building the KRAThe KRA page FAQ: "Can Kieri build it for us? No."The June 30, 2026 article offers "turnkey delivery where Kieri builds everything" for an added $28,000.Whether turnkey builds are sold today and what they include. Any build work puts Kieri on your readiness side.
Mock plus certificationThe assessment page says Kieri can conduct both a mock and a certification assessment.Its mock assessment description includes a "prioritized remediation roadmap," while CoPC §3.4 bars remediation or improvement advice from a conflict-free true mock.Whether Kieri will remove the roadmap and other advice from your mock, and its written basis for later assessing you
How many C3PAOs existA May 2026 Kieri article calls Kieri "one of 54 authorized C3PAOs."The Cyber AB counted 110 authorized C3PAOs on July 15, 2026.Use the live Marketplace, not either historical count. The July snapshot was roughly double the May figure.

Is Kieri an authorized C3PAO?

Kieri says it is. The Cyber AB, the current CMMC Accreditation Body, keeps a C3PAO listing for Kieri Solutions LLC. We confirmed that the member page exists, but its current status label and effective date are JavaScript-rendered and were not exposed by the tools used for this check. Confirm both in the live Marketplace before signing.

No article, this one included, can tell you a C3PAO's status on the day you sign. The Cyber AB's Marketplace can. Here's how:

  1. Go to the Cyber AB Marketplace and search for "Kieri Solutions LLC."
  2. Confirm the organization is listed as a C3PAO and the status reads "Authorized" or "Accredited."
  3. Save a dated screenshot for your contract file.
  4. Look up each assessor Kieri names for your team.

What the two labels mean. Under the rule, C3PAOs must be authorized or accredited to run Level 2 certification assessments (32 CFR 170.9(a)). Accreditation means meeting ISO/IEC 17020, an international standard for inspection bodies. A C3PAO has to reach that within 27 months of authorization (32 CFR 170.9(b)(2)). Either current label, when the Marketplace shows the organization in good standing, permits it to run the assessment. "Applicant," "Candidate," or an in-process status does not.

What "we passed our own DIBCAC assessment" means. DIBCAC is the Defense Industrial Base Cybersecurity Assessment Center, a government assessment team. Kieri says it passed a Level 2 assessment by DIBCAC with a perfect score, using the same documents and architecture it now sells.

Every C3PAO must undergo a DCMA DIBCAC Level 2 assessment that meets the requirements for a Final Level 2 assessment. Under 32 CFR 170.9(b)(6), it doesn't result in a CMMC Status or certificate. So read Kieri's statement as its own claim about the score it achieved during a required authorization step. If accurate, Kieri's statement shows that it used the documents and architecture in its own environment; it does not show that the same materials will produce the same result in yours.

Check the people, not just the firm. A C3PAO's assessment team must include at least two Certified CMMC Assessors (CCAs), one of them the Lead CCA. A separate CCA who isn't on the team handles quality review (32 CFR 170.9(b)(12)–(13)). Kieri says its assessors are employees, not contractors. Ask for names. For more on reading a listing, see our Cyber AB Marketplace guide.

What does Kieri cost?

Kieri publishes one bundle price: about $15,000, one time, for the KCD and KRA together, in a June 30, 2026 article. Everything else is quoted after a call: the assessment, the gap analysis, consulting, and the KCD or KRA on its own. In the worked example below, Kieri's stated recurring figures exceed its stated one-time license and build figures; your actual environment and quote may differ.

What — Kieri's published figure — Time period — Source
WhatKieri's published figureTime periodSource
KCD and KRA license togetherAbout $15,000. Includes build instructions, configuration documents, 10 hours of support, and the training library.One-timeKieri article (June 30, 2026)
Engineering help building the KRA$28,000 for 40 hoursOne-timeSame article
Turnkey build by Kieri"Add $28,000," as written. The KRA page's FAQ says Kieri doesn't build it.One-timeSame article; confirm with Kieri
KCD aloneQuote only. One-time license, lifetime use, 12 months of updates.One-timeKCD page
KRA aloneQuote only. One-time license, lifetime access, future updates included.One-timeKRA page
ConsultingHourly or fixed-scope quote. No monthly contract required.Per engagementConsulting page
Gap analysisFixed-fee quotePer engagementGap analysis page
Formal Level 2 assessmentFirm fixed-price quote after a questionnaire and a callPer assessmentAssessment page
Running a KRA environment (Kieri's own estimates)Laptops about $900 each; Microsoft 365 E5 about $1,200 per user per year; help desk about $2,000 per user per year; compliance upkeep at least $30,000 per yearLaptops one-time; the rest yearlyJune 30, 2026 article

These are Kieri's own figures from dated pages. They're leads for a conversation, not quotes.

A worked example, using only Kieri's June 30, 2026 numbers. Say you run a 40-person machine shop, and 12 people work with CUI drawings. You license the KCD and KRA, buy Kieri's 40 hours of build help, and give those 12 people KRA laptops. This is arithmetic on one company article, not a quote or a total-cost estimate. It assumes Kieri's help-desk and compliance-maintenance lines are separate rather than overlapping; a written quote must confirm that.

  • One-time: $15,000 license, plus $28,000 build help, plus 12 laptops at $900 ($10,800). That's $53,800.
  • Every year after that: 12 Microsoft 365 E5 licenses at $1,200 ($14,400), plus help desk for 12 at $2,000 ($24,000), plus $30,000 compliance upkeep. That's at least $68,400 a year.
  • Assessment: not from Kieri, because you bought its readiness side. A different C3PAO quotes that separately. For what assessments generally involve, see C3PAO assessment cost.

Not included: your own staff's time. If you already pay an IT provider to support those 12 people, part of the help desk line isn't new money. GCC High licensing varies by plan; see GCC High cost and licensing.

What a comparable quote should break out, from Kieri or anyone else:

  • licenses;
  • documentation customization;
  • engineering or build labor;
  • Microsoft and other software;
  • ongoing IT or security support;
  • the formal assessment itself;
  • travel and on-site days;
  • close-out work after a Conditional status;
  • extra sites or systems;
  • cancellation and rescheduling terms.

Is there an independent Kieri Solutions CMMC review?

Not that we found. Our searches turned up three things, none of them independent, which is why this page has no star rating:

  • Kieri's own testimonials and case studies;
  • directory listings that repeat Kieri's own description;
  • content from CMMCaudit.org, whose chief editor is Kieri founder Amira Armond, according to Kieri's Team page.
Evidence — What it tells you — What it doesn't
EvidenceWhat it tells youWhat it doesn't
Kieri's testimonials and case studiesKieri publishes named customer stories and favorable quotationsThe full denominator, selection method, or how many engagements had poor outcomes. Kieri chooses and hosts them.
The Cyber AB Marketplace listingKieri's identity and C3PAO status on the day you checkAnything about quality or customer experience
CMMCaudit.org and Kieri's webinarsHow Kieri's people read the rules, which is useful for judging fitAn independent view. Kieri's Team page says founder Amira Armond is chief editor of CMMCaudit.org.
References you request from KieriFirst-person experience with the exact service and teamWhether the experience is representative; Kieri chooses which references to offer

The most useful first-person input available to a buyer may be a reference call with a company like yours that bought the same service. Treat a company-selected reference as useful but not representative. Ask:

  1. Which Kieri service did you buy: the KCD, the KRA, consulting, a gap analysis, or an assessment?
  2. What was the original price, and what was the final price?
  3. What changed after you signed?
  4. Who actually did the work?
  5. Did Kieri decline anything because of its conflict rules?
  6. If Kieri prepared you, what did your eventual assessor accept, reject, or make you change?
  7. What work was still yours after Kieri finished?

Who Kieri fits, and who should start somewhere else

Kieri's public offerings line up most directly with two situations:

  • a small-to-mid contractor with a capable in-house or part-time IT person who wants a detailed do-it-yourself playbook;
  • an assessment-ready contractor comparing formal assessors who hasn't used Kieri's readiness side.

Start with another category if you want someone to run your security for you, you only need Level 1, or you already bought Kieri's readiness side and want it to assess you.

Your situation — Kieri option that may fit — Start here instead, or compare with
Your situationKieri option that may fitStart here instead, or compare with
Your contract or prime names Level 2 (C3PAO); your SSP is done; you've had no Kieri readiness work in three yearsCompare Kieri's formal assessment with other currently Authorized or Accredited C3PAOsC3PAO list, choosing a Level 2 C3PAO
You handle CUI, have no SSP yet, have a small IT team, and want to do it yourself from worked examplesThe KCD. Plan on a different assessor.CMMC policy templates, SSP template
You want to own a Microsoft 365 GCC High setup and have a capable part-time sysadminThe KRAGCC High for CMMC
You want an expert beside you, but not a monthly managed contractKieri consulting or its advisor retainer. Use another assessor later.CMMC RPO consultants
You want someone to run your security day to dayNot Kieri; its consulting page says it isn't a managed serviceCMMC MSP guide
You want a walled-off, managed place for CUINot the KRA, which is a do-it-yourself build, not a managed enclaveCMMC enclave vs. GCC High
You do not intend to use Microsoft 365 GCC HighThe KCD may still fit (Kieri says it isn't tied to a platform). The KRA won't fit.CMMC provider categories
Your paperwork asks only for Level 1 (Self) or Level 2 (Self)You don't need a C3PAO for that award. The KCD can support a Level 2 self-assessment.Self-assessment vs. C3PAO
You don't know your level or whether you handle CUINone yet. Settle scope first.FCI vs. CUI, CMMC scoping guide

If your row pointed away from Kieri, or across two rows, the useful next step is finding which category of help fits your contract and data.

Map my CMMC path →

What is the KCD, and is it worth paying for over free templates?

The KCD is a set of pre-written policies, procedures, and an SSP. Kieri says it's based on the documents it used in its own assessment. The difference from free templates is that it comes filled in with example answers instead of blanks.

What Kieri says is in it:

  • Documents covering all 110 Level 2 requirements.
  • More than 40 hours of training video.
  • Monthly Q&A sessions and three one-on-one sessions with Kieri's certified assessors.
  • A one-time license for lifetime use, with 12 months of updates.
  • A design for organizations under 1,000 users. Kieri names 50 to 500 users as its main target.
  • Content that isn't tied to one platform.

Where it can be worth paying for. If your IT person knows your systems but not compliance language, filled-in examples, training, updates, and assessor sessions may replace substantial internal drafting and interpretation work. Because the standalone price is quote-only, compare the quote with the hours it would actually save.

Where it doesn't. Documents describe; assessors check what you actually do. A policy that says you review logs every week only helps if someone reviews them every week and keeps the record. No template can promise a pass. Kieri says it used the documents in its own assessment; that says nothing about whether they fit or pass in your environment.

Three more limits:

  • If you only handle FCI at Level 1, a 110-requirement package is probably more than you need.
  • Kieri's published policy says buying the KCD means using another C3PAO for the formal assessment.
  • The version question matters: see NIST SP 800-171 Rev. 2 vs. Rev. 3.

What is the KRA, and do you need GCC High?

The KRA is Kieri's blueprint for building a CMMC Level 2 environment on Microsoft 365 GCC High, Microsoft's government cloud offering, with Windows 10/11 laptops. Kieri's current product FAQ presents it as something your team builds and runs, although its June 30 article describes a turnkey option. You don't need GCC High to use the KCD, and CMMC does not universally require GCC High. DFARS 252.204-7012 requires a contractor using an external cloud service provider for covered defense information to ensure FedRAMP Moderate-equivalent security and specified reporting duties; it does not name GCC High. The KRA chooses GCC High as its architecture.

What Kieri says is in it:

  • network diagrams;
  • baseline settings for GCC High and Windows 11;
  • PowerShell configuration scripts;
  • step-by-step technician procedures;
  • templates for your SSP;
  • validation checklists.

The license is one-time, with lifetime access and future updates. Kieri says it works alongside on-premises equipment.

Who runs it. Kieri says the KRA is designed for a part-time sysadmin plus a virtual CISO (vCISO, an outside security lead) meeting at least once a month. Its FAQ says Kieri won't build it for you, though its consultants can work alongside your team. Its June 30 article describes a turnkey option; see the disagreement table above.

How it's designed, per Kieri. It uses locked-down laptops instead of virtual desktops. Kieri says disabling printing can help keep paper, printers, and facilities out of scope and make a virtual-only assessment possible. That is a design claim, not an automatic rule. Under 32 CFR 170.19, a Level 2 asset is out of scope only if it cannot process, store, or transmit CUI, does not provide security protections for CUI assets, and is physically or logically separated from CUI assets. An asset that falls into an in-scope category cannot be relabeled out of scope. The CMMC Assessment Process v2.0 says the C3PAO and contractor determine the virtual and in-person mix in Phase 1; environments without applicable physical or environmental controls may negate an on-site portion, but disabling printing by itself does not decide that. Validate the actual asset, facility, and assessment boundaries with the C3PAO.

Who it doesn't fit. If you have no one in-house who can follow detailed technical procedures, the KRA will sit on a shelf. Look at GCC High options with managed support, or a managed enclave.

Should you book a Kieri assessment while Phase 2 is paused?

Only if a current written requirement or a deliberate business decision calls for it. During the suspension, DoW program managers and requiring activities may designate only Level 1 (Self) or Level 2 (Self), but voluntary C3PAO assessments remain available. Old C3PAO language may still appear in an unamended solicitation, government contract, or prime document. Confirm whether it is an operative requirement, stale language awaiting amendment, or a prime's separate supplier qualification before you spend. Kieri advises contractors to keep going, and Kieri sells assessments, so weigh that advice against the document that actually governs your work.

The sources.

  • The Department of War: its CMMC page says the program is paused in Phase 1 and may only require self-assessments. Its July 2026 implementation memorandum directed amendment of active solicitations and removal of suspended C3PAO and Level 3 requirements from existing government contracts by the next option or scheduled administrative modification.
  • The Cyber AB: said on July 15, 2026 that C3PAO Level 2 certification assessments remain available.
  • Kieri: said in a July 22, 2026 post that it recommends continuing, and that no client on its assessment schedule had cancelled.

Booking can make sense when:

  • A contracting officer or prime confirms in writing that a Level 2 (C3PAO) result remains an operative condition for your award or supplier qualification. For a government CMMC requirement, ask for the amendment or modification that resolves the suspension; see flow-down requirements.
  • A prime explicitly makes a C3PAO result its own supplier qualification, even when it is not a current DoW solicitation requirement. Make sure the document says what status, scope, and date it will accept.
  • You want independent third-party assessment evidence for a business reason, understand that it may not be required for the award, and are truly ready. Ready means your SSP is complete, your controls are in place, and your evidence is current.

Hold off when:

  • You still have open gaps. An assessment isn't remediation.
  • You were booking only to beat the suspended November 10, 2026 Phase 2 date.
  • The only C3PAO language you have is stale or unresolved and no contracting officer or prime will confirm what it means.
  • You used Kieri's readiness side in the last three years. Then Kieri's published policy points you to another assessor, and the rule's conflict boundary still has to be applied to the exact work.

If you do go ahead, a Conditional status is not automatic: the score must be at least 88 points out of 110, only eligible one-point requirements may remain open except for the rule's limited encryption exception, and several named requirements can never go on the POA&M (Plan of Action and Milestones). The C3PAO closeout certification assessment must be completed within 180 days. See Conditional Level 2 status and POA&M close-out.

Before you spend on an assessment you may not need, confirm which assessment type your paperwork actually points to.

See which assessment your contract points to →

12 questions to ask Kieri before you sign

Treat the first sales call as a fact-check, not a pitch. These twelve questions pin down the role, the people, the conflict boundary, the price, and what happens if the rules change. They work just as well for any other C3PAO or readiness firm.

Don't paste CUI, drawings, credentials, export-controlled files, or sensitive contract details into any sales form or email.

  1. What is Kieri Solutions LLC's current Cyber AB status, Authorized or Accredited? Please send the live Marketplace link.
  2. Which legal entity will our agreement name, and in which role: assessment, consulting, documentation license, architecture license, or engineering help?
  3. If we buy [the KCD / the KRA / a gap analysis / a mock assessment / consulting], will Kieri still be eligible to run our Level 2 certification assessment? For a mock or observations-only gap, show in the statement of work how it meets CoPC §3.4's formal, results-only, no-remediation-advice conditions.
  4. For what dates and activities will Kieri apply the rule's three-year lookback: the purchase, customization sessions, consulting work, a mock, or later updates? What Cyber AB policy supports that treatment?
  5. Which C3PAOs do you refer KCD and KRA buyers to, and do you receive anything for those referrals?
  6. Who would be on our assessment team (the Lead CCA and the other CCAs), who would be the separate quality reviewer, and are any of them contractors rather than Kieri employees?
  7. During the CAP Phase 1 readiness check, will you limit the work to SSP completeness, accuracy, and consistency; scope; evidence availability; and readiness—without evaluating implementation adequacy or sufficiency, predicting the outcome, or giving remedial advice?
  8. What assumptions sit behind the fixed price: users, sites, CAGE codes, CMMC Unique Identifiers (UIDs), cloud services, external service providers, specialized assets, and evidence maturity? What triggers a change order or an extra day?
  9. What does the included up-to-four-hour virtual close-out cover, and is the separate rule-defined POA&M closeout certification assessment included? If not, what would it cost?
  10. What happens to our dates, deposit, cancellation rights, and price if our solicitation or contract is amended to remove or change the C3PAO requirement while Phase 2 is paused?
  11. For the KCD or KRA: how many companies or sites does one license cover? What do updates cost after the included period? Can the license transfer?
  12. How will your sales, readiness, and assessment teams receive, store, restrict access to, and delete our information?

How we built this profile

We built this profile from public records and Kieri's own pages, all checked September 24, 2026. The box near the top summarizes what we read and what we couldn't confirm.

We didn't give Kieri a score. A score needs testing, and we didn't buy, hire, or interview anyone. Kieri did not pay for, review, or approve this profile. Our Editorial & Advertising Policy explains how we handle commercial relationships, and our methodology explains how we check sources. More provider profiles are in our CMMC provider reviews and comparisons.

Frequently asked questions

Does Kieri assess companies outside its home region? Yes, according to Kieri. Its assessment page says it supports organizations throughout the United States and that its assessment teams travel nationwide. Ask how travel is priced, since it can change a fixed-price quote.

How do Kieri's quotes work? For assessments, Kieri says it sends a questionnaire about your readiness and environment, holds a review call, then sends a firm fixed-price quote. It recommends reaching out once your scope is settled and you aren't planning to add systems. Kieri also says it will guarantee your schedule if you sign and you're ready; that's a scheduling promise, not a promise about results.

How long does Kieri's work take? Kieri says a gap analysis takes a few weeks for most small to mid-sized contractors and that its formal assessment is four days on site after a high-level readiness check. It also says it may schedule a POA&M reassessment within a few days. The rule still requires the separate POA&M closeout certification assessment to be completed within 180 days, and only eligible findings can be placed on a POA&M.

Is Kieri a managed service provider? No. Its consulting page says it is not a managed service. You buy hours or a fixed scope, with an optional advisor retainer of about one meeting a month. If you want someone to run your security day to day, look at an MSP (managed service provider) or MSSP.

Does the KCD cover NIST SP 800-171 Revision 3? Kieri says the KCD license covers both Revision 2 and Revision 3. NIST has superseded Revision 2 as a publication, but the current DoW CMMC page still maps Level 2 to Revision 2's 110 requirements, and 32 CFR 170.17(c) still uses the June 2018 SP 800-171A procedures for Level 2 certification assessments. Do not replace your CMMC evidence baseline with Revision 3 unless the contract and official CMMC direction change.

Does the KRA work with on-premises equipment and shop-floor systems? Kieri says yes. Its KRA page says the architecture is compatible with on-premises equipment and manufacturing networks, and lists operational technology environments among its targets. How those systems fit your CMMC scope is still your decision to document; see our CMMC scoping guide.

Still not sure which CMMC path fits your company? Use The Defense Compliance Report's Find My CMMC Path tool to see which path and kind of help fit your contract, CUI, environment, and timeline — before you hire anyone.

Find my CMMC path →

Sources

Rules, standards, and government sources

  • 32 CFR Part 170 final rule, 89 FR 83092 (October 15, 2024): Federal Register (checked September 24, 2026)
  • 32 CFR 170.3, applicability and codified phase schedule: eCFR (checked September 24, 2026)
  • 32 CFR 170.8, Accreditation Body, including the three-year consultant conflict rule in (b)(17)(ii)(G): eCFR (checked September 24, 2026)
  • 32 CFR 170.9, CMMC Third-Party Assessment Organizations: eCFR (checked September 24, 2026)
  • 32 CFR 170.17, Level 2 certification assessment and affirmation requirements: eCFR (checked September 24, 2026)
  • 32 CFR 170.19, CMMC scoping: eCFR (checked September 24, 2026)
  • 32 CFR 170.21, POA&M requirements: eCFR (checked September 24, 2026)
  • 32 CFR 170.22, affirmation: eCFR (checked September 24, 2026)
  • FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems: Acquisition.gov (checked September 24, 2026)
  • DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting: Acquisition.gov (checked September 24, 2026)
  • NIST SP 800-171 Revision 2: NIST (checked September 24, 2026)
  • NIST SP 800-171A, June 2018 assessment procedures: NIST (checked September 24, 2026)
  • Department of War CIO, CMMC Resources & Documentation: dowcio.war.gov (checked September 24, 2026)
  • Department of War CIO, CMMC Level 2 Scoping Guide v2.13: PDF (checked September 24, 2026)
  • Department of War CIO, CMMC Level 2 Assessment Guide v2.13: PDF (checked September 24, 2026)
  • Department of War CIO, About CMMC: dowcio.war.gov (checked September 24, 2026)
  • Department of War, “Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements,” July 13, 2026: war.gov (checked September 24, 2026)
  • Department of War CIO, “Implementing Suspension of CMMC Phase II,” July 2026: PDF (checked September 24, 2026)
  • DARS, Revolutionary FAR Overhaul class-deviation index, including Class Deviation 2026-O0025 Revision 3 dated September 3, 2026: acq.osd.mil (index checked September 24, 2026)

Cyber AB

  • CMMC Code of Professional Conduct v2.0, including §§3.3-3.4 and Appendix A: PDF (checked September 24, 2026)
  • CMMC Assessment Process v2.0, including preliminary proceedings and Phase 1: PDF (checked September 24, 2026)
  • Statement on the Department of War's Suspension of CMMC Phase II Requirements, July 15, 2026: cyberab.org (checked September 24, 2026)
  • Marketplace member page, Kieri Solutions LLC: cyberab.org (checked September 24, 2026; current status label and effective date are JavaScript-rendered and must be confirmed in a live browser)

Kieri Solutions (company-stated claims)

All Kieri pages listed above were checked September 24, 2026.


About The Defense Compliance Report

The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on every claim and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.

We are not affiliated with the Cyber AB, DoD, DCMA DIBCAC, NIST, or any U.S. government agency. This page is educational research, not legal, contractual, or compliance advice. Confirm scope and applicability with a CMMC Registered Practitioner (RP) or a qualified federal-contracts attorney.

Find my CMMC path →