Your tech is ready for defense work. Is your paperwork?
Before you can win or keep a defense contract, you have to prove you protect government information in a specific way. Most teams find out about it late, and it costs them the deal or months of scrambling. Scan Ninja becomes your security team: we find and fix what is exposed in your systems, harden the protections around them, and produce the proof your contract asks for. Book a free 30 minute session at the show and get a plain English answer on where you stand.
Free · No obligation · Remote sessions available if you are not in Austin
Already know the language? We cover CMMC 2.0, NIST 800-171, SPRS scoring, SSP and PoAM, and C3PAO readiness.
Three things that catch teams off guard
Most companies at this event are building something the government wants. The security requirements are what slow the deal down, and they usually surface later than they should.
01
You may have already agreed to it
The obligation gets passed down through contracts you sign. Many teams find the clause buried in a subcontract during investor or customer diligence, long after kickoff. It is called DFARS 252.204-7012 if you want to go looking.
02
Larger contractors screen you on a score
The government makes you self-report a security score into a database called SPRS. The big contractors you want to team with increasingly check it first. A missing or bad score quietly takes you out of the running, and nobody tells you why.
03
Fixing it later costs far more
If you decide early which small part of your systems handles government information, you only have to secure that part. Leave it and you can end up having to lock down the whole company two years in.
What you walk away with
Thirty minutes, four concrete things. This is a working session, not a demo.
The score you will be judged on
A realistic estimate of the security score you would have to report today, and which gaps are dragging it down the most.
How much of your company is in scope
Where government information actually lives in your systems, and how to fence off a small piece of your setup instead of securing everything.
What to do first
The handful of moves that improve your score and your risk the fastest, in the order we would run them if we were your security team.
Whether this applies to you yet
Some companies need the full program, some need a lighter version, and some are not on the hook at all yet. We will tell you which one you are.
Where to find us
At the table
Dual-Use Startup Crawl
Monday, August 18 · 5:00–8:00 PM
We are exhibiting at STATION Austin. Table assignments go out at check-in, so look for the Scan Ninja sign and come say hello. Scan the code on our table and you can hold a time before you walk away.
Bring your team
We are staying through Friday
Friday, August 21 · by request
Thirty minutes is enough for a straight answer, not enough to work a real scoping problem. We are holding Friday the 21st in Austin for teams who want to bring an engineering or contracts lead into a longer working session. Book any slot and note it in the booking form.
30 minutes · Free
Pick your time
Slots during the show fill first, and Friday the 21st is open for longer team sessions. If nothing in Austin works, book any open time and we will run it over video.
We are a small, operator-led team that runs security and compliance for companies that do not want to hire a security department. We went through CMMC Level 2 on our own environment before we sold it to anyone else, so the advice you get is from people who have done the work rather than read the framework.
Veteran founded, eight years U.S. Air Force
Capital Factory portfolio company, Austin, Texas
CAGE 16W60 · UEI NYQPW4FUXY28
CMMC Level 2 self-assessment completed on our own environment
Houston, Texas based, working across space, defense, and critical infrastructure
Before you book
We ask what you are building, who you sell to, and what your customers or contracting officer have asked you for. You leave knowing roughly what score you would report today, how much of your company would be in scope, and the two or three things worth doing in the next 90 days. No slides, no scripted pitch.
It is the opposite of too early. The requirement lands with the contract, not after it, so the clock starts the day you sign. Companies that figure out early which small part of their systems needs protecting spend far less than the ones securing everything after the fact. Before the award is the cheapest time to get this right.
No, and be careful with anyone who says they do. Certification has to come from an accredited independent assessor. We are the team that gets you ready for one: we work through the full control list, calculate and improve the score you report to the government, write the security plan and remediation plan you are required to have, and package the evidence your assessor will ask for.
Free, and there is no obligation. We would rather tell you honestly that you are 18 months out than sell you a program you are not ready for. If we are not the right fit, we will say so and point you somewhere useful.
Yes. The same calendar works whether you scanned the code at our table in Austin or found this page later. Remote sessions run over video.
Find us in Austin, August 18–21
Scan the code at our table on the 18th or book straight from here. Either way you get the same 30 minutes and the same straight answer, and we are around through Friday if your team needs longer.