Balsam Technologies Expands NIST SP 800-171 Revision 2 and CMMC Self-Assessment Support

Gloucester managed IT provider offers readiness and technical support to applicable MA defense suppliers and separately develops a custom AI workflow.

Our role is to help clients identify gaps, carry out remediation work, and prepare for organization-led self-assessments while federal CMMC policy continues to evolve.”
— Stephen Sirois
GLOUCESTER, MA, UNITED STATES, September 9, 2026 /EINPresswire.com/ -- Balsam Technologies Inc. announced an expansion of its cybersecurity-readiness services for Massachusetts organizations in the defense supply chain. In a separate development initiative, the company is building a custom workflow using large language models; the project is not yet offered for production client use.

Balsam's services include technical implementation support aligned with NIST SP 800-171 Revision 2; preparation, gap-remediation, and documentation support for organization-led CMMC Level 1 and Level 2 self-assessments; HIPAA Security Rule risk-analysis and safeguard implementation support for covered entities and business associates; and technical alignment support for the FBI CJIS Security Policy and applicable state CJIS Systems Agency requirements. Balsam provides readiness and technical support; it does not issue CMMC certifications or guarantee a customer's compliance, assessment result, or contract eligibility.

As of August 2026, federal implementation guidance has suspended the transition to CMMC Phase II and other pending implementation milestones. During the suspension, applicable procurements may require CMMC Level 1 (Self) or Level 2 (Self), but not Level 2 (C3PAO) or Level 3 (DIBCAC). Underlying contract safeguards remain in effect, including FAR 52.204-21 for Federal Contract Information and, where applicable, DFARS 252.204-7012 and NIST SP 800-171 Revision 2 for Controlled Unclassified Information.

Separately, Balsam is developing a custom AI workflow to evaluate potential workplace use cases. The initiative is not currently offered for production client use and is separate from the company's compliance-readiness services. No client-launch date has been announced.

"Massachusetts defense suppliers still need practical help implementing the controls and documentation required by their contracts," said Stephen Sirois, president of Balsam Technologies. "Our role is to help clients identify gaps, carry out remediation work, and prepare for organization-led self-assessments while federal CMMC policy continues to evolve."

Balsam also reported two internal service milestones: the company manages and monitors more than 100 client servers, and its service-management system recently recorded the company's 200,000th resolved IT support ticket.

For more information about Balsam Technologies' managed IT, cybersecurity, and compliance-readiness services, visit https://balsamtechnologies.com/

About Balsam Technologies Inc.

Located in Gloucester, Massachusetts, Balsam Technologies provides managed IT services, cybersecurity solutions, and technology consulting to organizations across the North Shore, Greater Boston, and Massachusetts. Its services include remote monitoring and management, help desk support, cloud solutions, backup and disaster recovery, and security and compliance support.

Nathan Sirois
Balsam Technologies
+1 978-281-3339 x111
email us here
Visit us on social media:
LinkedIn
Facebook

Legal Disclaimer:

EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.