The challenge behind the engagement.
This service is for a defense contractor heading for CMMC Level 2, whether you self-assess and post your score or bring in a third-party assessor. We sort every asset into the program’s categories, decide whether to protect an enclave or the whole enterprise, and map what each outside service provider owns. We assess all 110 requirements against the objectives beneath them, score them the program’s way, and project the score you would post. We write your system security plan and remediation plan, keep it within the limits the program allows, and index evidence to each objective. A mock assessment marks every objective met or not met. Our principal is a CMMC Certified Assessor, and because anyone who prepares you must stay off your certification assessment for three years, you choose one of the independent C3PAOs.
Defense primes and subcontractors who handle sensitive government information and must show they protect it. The trigger is a self-assessment and affirmation due in the government’s scoring system, a score below the maximum, or a certification requirement a customer expects.
What we do.
What you can use.
Categorize assets and set the boundary
We start with your contracts, the sensitive information you actually receive, and read-only access to your identity system, device management, and cloud tenant. We place every asset in the right category, decide enclave or enterprise, and record the boundary and the outside providers in scope in a scoping memo and a simple diagram.
Assess every objective and score it
Requirement by requirement we examine how sign-in and multi-factor are enforced, how devices are configured, how the cloud tenant keeps its audit logs, and how encryption is validated, checking each against its objective. Every gap that is not met takes its point deduction, an owner, and a fix, and only items the program permits go on the remediation plan.
Rehearse and brief the Affirming Official
You receive the system security plan, remediation plan, policy set, projected score, and an evidence index by objective, then a mock assessment in examine, interview, and test form, with control owners answering for their own evidence. After fixes we retest each closed objective and hand your Affirming Official a readiness memo for the score entry.
Who it’s for.
When you need it.
- Defense primes and subcontractors handling Controlled Unclassified Information under DFARS 252.204-7012
- Contractors self-assessing at CMMC Level 2 and posting a score in SPRS
- Suppliers planning for a customer requirement for independent CMMC Level 2 certification
- Organizations storing controlled government information across cloud services, endpoints, and shared workspaces
- A prime issues a 7012 flowdown or asks for your current SPRS score
- Your posted SPRS score sits well below 110 and remediation has stalled
- A solicitation names Level 2 self-assessment as a condition of award
- You have never scored the 110 requirements and hold no current SSP
What the scope can include.
- 01
Sort every asset into the program’s categories and set the enclave or enterprise boundary
- 02
Map what each outside service provider and cloud provider is responsible for
- 03
Assess all 110 requirements against the detailed objectives beneath them
- 04
Score each requirement the program’s way, including the multi-factor and encryption partial-credit rules
- 05
Write the system security plan and remediation plan and index evidence by objective
- 06
Run a mock assessment and shortlist independent third-party assessors for you
What it typically costs.
One rate: $150/hour.
Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.
Under 50 employees, one office, defense data kept in a cloud enclave such as Microsoft GCC High
About 80–140 hours50–250 employees, mix of cloud and on-site systems, two or three locations
About 140–240 hours250+ employees, several sites, shop-floor or engineering systems that touch defense data
About 240–400 hours- How many systems, people, and locations handle defense data
- Enclave versus whole-company scope
- How much of NIST 800-171 is already in place and documented
- Number of outside IT and cloud providers to account for
6–12 weeks for scoping, gap assessment, security plan and action plan, and evidence; mock assessment scheduled once fixes are in place (often 3–6 months total)
A Level 2 certification assessment is paid separately to an authorized C3PAO; DoD estimates about $105,000–$118,000 over three years including affirmations.
Get a fixed quote for your scopeRanges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- Scoping memo, asset inventory by category, and network and data-flow diagrams
- Projected score with per-objective met and not-met results and point deductions
- System security plan, remediation plan, and policy set aligned to the program
- Mock assessment report and readiness memo for your Affirming Official
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
What CMMC requirements should we prepare for during the program review?
Begin with your contract and the latest official guidance. The July 2026 announcement suspended the transition to Phase II while retaining Phase I self-assessments and contractual safeguarding duties. We check the required level, assessment type, score submission, and affirmation requirements before setting your readiness plan. Work can include closing control gaps, documenting the system, and organizing evidence for the review you actually face. A paused rollout milestone does not remove the obligation to protect controlled government information.
Can you also be our assessor or serve on our assessment team?
No, and be wary of anyone who says yes. Anyone who consults for an organization to prepare it for a CMMC assessment must stay off that organization’s Level 2 certification assessment for three years, and the rule applies to the assessing company and every person on its team. Our principal holds the CMMC Certified Assessor credential, which is exactly why we know what assessors look for and why we stay on the readiness side. We help you shortlist independent C3PAOs and prepare your control owners for their interviews.
- 32 CFR Part 170: Cybersecurity Maturity Model Certification (CMMC) Program (Federal Register final rule)
- Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements
- NIST SP 800-171 Rev. 2: Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
- NIST SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations
- FedRAMP Consolidated Rules for 2026
- FedRAMP 20x
- GovRAMP FAQs
