Giga-Green Giga-Green

About Giga-Green

By Giga-Green , CMMC Consulting Team Last updated

Giga-Green is a small, U.S.-based consultancy focused entirely on CMMC readiness for DoD contractors and defense industrial base (DIB) suppliers. We help you pass CMMC Level 1, 2, and 3 assessments with defensible documentation, realistic Plans of Action & Milestones (POA&Ms), and evidence packages that survive C3PAO scrutiny.

What we do

We take you from wherever you are in your CMMC journey — no existing SSP, a POA&M full of open findings, or a certification window closing in 60 days — to assessment-ready. Every engagement is grounded in the NIST 800-series, the same framework the Department of Defense uses to evaluate you.

  • CMMC gap assessments mapped to NIST SP 800-171 controls with prioritized findings and remediation cost estimates.
  • System Security Plan (SSP) authoring written to survive assessor scrutiny.
  • POA&M creation and close-out with realistic remediation timelines that meet the 180-day CMMC Final Rule window.
  • C3PAO assessment prep including mock assessments, evidence library indexing, and interview coaching.
  • Ongoing readiness advisory for organizations that need a CMMC subject-matter expert on call.
  • CMMC Copilot AI Assistant — our purpose-built tooling to accelerate documentation and evidence work.

Who we serve

We’re built for small and mid-size DIB suppliers, typically 25 to 100 users. We specialize in remote and distributed workforces, but have vetted personnel available in multiple U.S. cities when boots-on-the-ground work is required.

Our clients are DoD contractors and subcontractors whose contracts flow down DFARS 252.204-7012 and the CMMC clauses. If you handle Controlled Unclassified Information (CUI), or expect to soon, we’re built for you.

The organizations we serve most often include:

  • Manufacturers producing components, systems, or subassemblies for DoD prime contractors — the classic DIB supplier who handles CUI as part of a Statement of Work.
  • Programmers and software firms building custom applications, embedded software, or platforms for defense programs — where source code, requirements documents, and design artifacts often qualify as CUI.
  • Government consultants and advisory firms whose deliverables to federal agencies require CMMC-aligned handling of sensitive work product.
  • Critical infrastructure operators in energy, water, transportation, and communications sectors, where CMMC alignment overlaps with sector-specific frameworks like TSA SD, NERC CIP, and NIST CSF.

How we work

We don’t sell managed IT. We consult. That distinction matters: our recommendations exist to get you assessment-ready, not to justify a monthly retainer.

Our engagement model is designed so we never house your CUI directly — you retain full control of your data and infrastructure. When we implement or advise, it happens inside your environment, on tools you own. This keeps our scope out of your assessment boundary and keeps your evidence trail clean.

Every engagement is led by a named consultant. That means:

  • The consultant on your kickoff call is the same person writing your SSP six months later.
  • We don’t oversell scope to fill seats.
  • We turn engagements around fast because there’s no internal hand-off.

Standards we align to

  • NIST SP 800-171 Rev. 2 (current CMMC Level 2 basis)
  • NIST SP 800-171 Rev. 3 (staying ahead of the transition)
  • NIST SP 800-172 (for Level 3 engagements)
  • NIST SP 800-53 (as a reference framework internally)
  • NIST SP 800-61 (Incident Handling — used internally and practiced for clients)
  • DFARS 252.204-7012 and FAR 52.204-21
  • FAR 889 / NDAA 2020 — we avoid all prohibited vendors and telecommunications equipment
  • CMMC Code of Conduct

Leadership

Portrait of William Galvin, founder of Giga-Green

William Galvin — Founder

William founded Giga-Green in 2016 with a focus on enterprise IT design and NIST 800-series security. Today he leads the CMMC consulting practice, working directly with DoD contractors on gap assessments, SSP authoring, POA&M remediation, and C3PAO assessment prep.

Portrait of Jared Finkelson, co-founder of Giga-Green

Jared Finkelson — Co-founder

Jared joined as co-founder in 2017. His work focuses on the technical implementation side of CMMC readiness — access control, encryption, monitoring, incident response engineering, and secure migration into Microsoft 365 GCC High environments.

What makes us different

  • Boutique by design. We stay small on purpose. Your engagement lead is not a project manager routing tickets — they’re the practitioner doing the work.
  • Compliance meets engineering. We blend NIST fluency with hands-on IT and security experience, so the SSP, POA&M, and evidence library we produce are things a real engineer can operate and defend.
  • Model built for CUI hygiene. Our operating model keeps us out of your CUI boundary. That’s rare for a hands-on consultancy, and it’s a deliberate design choice.
  • U.S. persons only. Every Giga-Green consultant is a U.S. citizen and passes background checks — important for contracts with citizenship or clearance flowdowns.
  • Cyber insurance carried. Table stakes, but worth stating.

Talk to us

If you’re a DoD contractor or DIB supplier working through CMMC — whether you’ve just seen your first 7012 clause or you’re 60 days out from a C3PAO assessment — we’d like to hear where you are.

Prefer to skip the form? Book a discovery call directly, or reach us at info@giga-green.com or +1 (701) 630-7188.