DEFENSE INDUSTRIAL BASE

Prove your CUI is protected to CMMC 2.0, before your contract depends on it.

SIEGE runs as a persistent adversary against your environment, emulating the nation-state actors that systematically target the Defense Industrial Base for controlled unclassified information (CUI). It validates the 110 NIST SP 800-171 controls behind CMMC Level 2 the way an assessor, and an attacker, actually tests them: by trying to reach your CUI and proving whether your safeguards hold.

See the Compliance Crosswalk
01
THE ATTACK PATH

This is how the breach actually happens.

FIG.01: ADVERSARY PATH / DEFENSE INDUSTRIAL BASEAGENT ACTIVE
INGRESST1566SpearphishingFOOTHOLDT1078Valid accountsLATERALT1021Remote servicesPRIV ESCT1068Domain escalationCROWN JEWELIMPACTcui-fileshare-01
From a contractor inbox to your CUI repository. SIEGE walks the path an adversary takes to your controlled unclassified information, and shows you exactly where it breaks.
02
THE THREAT

Who's actually coming for you.

The DIB is a standing target for foreign intelligence services seeking U.S. defense technology and CUI. SIEGE emulates how these actors actually operate, as documented in U.S. Government advisories.

Volt Typhoon · PRC
State-Sponsored Espionage
U.S. Government advisories have warned that PRC state-sponsored actors pre-position in U.S. defense and critical-infrastructure networks using living-off-the-land techniques. SIEGE replays these stealthy TTPs against your controls to prove what actually detects them.
APT41 · China
Defense Technology Theft
Dual espionage-and-financial groups chain supply-chain compromise and credential theft to reach defense IP and CUI. SIEGE pressure-tests the exact routes to your protected data.
T1195 · Supply Chain
Subcontractor & Supply-Chain Risk
Adversaries breach smaller, less-defended suppliers to reach prime contractors. SIEGE validates the trust relationships and segmentation between your environment and your partners.
03
THE MANDATE

CMMC asks one question of every defense contractor. SIEGE answers it.

CMMC 2.0 and its underlying frameworks all ask the same thing: can you prove your controls actually protect CUI? SIEGE produces the evidence once and maps it to every requirement your assessor and contracting officer review.

MandateRequirementSIEGE Evidence
CMMC 2.0 Level 2Assessment against NIST SP 800-171 (110 controls)Adversarial validation that each control family holds under attack
NIST SP 800-171 Rev 2Protect CUI across 14 control familiesMapped, exploit-ranked evidence per family
DFARS 252.204-7012Safeguard CDI; 72-hour incident reportingProven detection and response along real attack paths
DFARS 252.204-7019/7020SPRS self-assessment scoreDefensible, evidence-backed scoring, not a paper estimate
NIST SP 800-172Enhanced protections against the APTValidation against advanced-persistent-threat tradecraft
04
THE PROOF

Built under DARPA. Validated by DoD.

★ DEVELOPED UNDER DARPA CASTLE PROJECT ★ DOD VALIDATED ★ TRUSTED BY US DEFENSE & INTELLIGENCE ★

When SIEGE confirms your CUI is protected, that finding carries the weight of the DARPA CASTLE program and operational validation across DoD and U.S. Government environments. For your assessor, your contracting officer, and the programs you support, it is the most credible evidence a defense contractor can present, proof your safeguards hold, not a self-attestation.

05
THE MATH

What a failed assessment actually costs.

~220,000
Companies across the Defense Industrial Base expected to fall under the CMMC program.
110
NIST SP 800-171 security requirements behind CMMC Level 2, every one a place to fail an assessment.
No score, no award
Without a compliant SPRS score and CMMC status, DoD contracts are off the table.

Sources: DoD CMMC Program rulemaking (32 CFR Part 170); NIST SP 800-171 Rev 2; DFARS 252.204-7012 / 7019 / 7020 / 7021.

06
FREQUENTLY ASKED

Questions teams ask before a SIEGE engagement.

What is CMMC 2.0 and who needs it?
CMMC 2.0 (Cybersecurity Maturity Model Certification) is the U.S. Department of Defense program that verifies defense contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Most contractors handling CUI must meet Level 2, which is an assessment against the 110 security requirements of NIST SP 800-171. SIEGE validates those requirements adversarially, proving the controls actually work, not just that they exist on paper.
How does SIEGE help with CMMC and NIST SP 800-171?
SIEGE runs as a continuous adversary against your environment, attempting to reach your CUI the way a real attacker would. It maps every finding to the relevant NIST SP 800-171 control family and CMMC practice, ranks gaps by true exploitability, and produces dated, assessment-ready evidence your C3PAO assessor and contracting officer can rely on.
Is SIEGE testing safe for production defense networks?
Yes. SIEGE runs in simulated or mirrored environments and never touches production systems, so there is no downtime or disruption to ongoing contract work.
How is SIEGE different from a standard penetration test for CMMC?
A penetration test is a point-in-time snapshot. SIEGE runs continuously, uses AI agents trained on real DoD tradecraft, and was developed under the DARPA CASTLE program, so its findings carry provenance no commercial pen test can match, and your evidence stays current as your environment changes.

See SIEGE walk an adversary to your CUI.

Twenty minutes. We'll map a real attack path to a CUI repository and show you the assessment-ready evidence your C3PAO expects, no slideware.

Back to All Sectors