Federal & Defense / FOCUSED SERVICE

CMMC Readiness

CMMC Level 2 readiness consulting with gap assessment, system security plans, remediation planning, evidence preparation, and mock assessments.

WHAT THIS SERVICE ADDRESSES

The challenge behind the engagement.

This service is for a defense contractor heading for CMMC Level 2, whether you self-assess and post your score or bring in a third-party assessor. We sort every asset into the program’s categories, decide whether to protect an enclave or the whole enterprise, and map what each outside service provider owns. We assess all 110 requirements against the objectives beneath them, score them the program’s way, and project the score you would post. We write your system security plan and remediation plan, keep it within the limits the program allows, and index evidence to each objective. A mock assessment marks every objective met or not met. Our principal is a CMMC Certified Assessor, and because anyone who prepares you must stay off your certification assessment for three years, you choose one of the independent C3PAOs.

WHEN THIS IS THE RIGHT FIT

Defense primes and subcontractors who handle sensitive government information and must show they protect it. The trigger is a self-assessment and affirmation due in the government’s scoring system, a score below the maximum, or a certification requirement a customer expects.

THE WORK BEHIND THE SERVICE

What we do.
What you can use.

Categorize assets and set the boundary

We start with your contracts, the sensitive information you actually receive, and read-only access to your identity system, device management, and cloud tenant. We place every asset in the right category, decide enclave or enterprise, and record the boundary and the outside providers in scope in a scoping memo and a simple diagram.

Assess every objective and score it

Requirement by requirement we examine how sign-in and multi-factor are enforced, how devices are configured, how the cloud tenant keeps its audit logs, and how encryption is validated, checking each against its objective. Every gap that is not met takes its point deduction, an owner, and a fix, and only items the program permits go on the remediation plan.

Rehearse and brief the Affirming Official

You receive the system security plan, remediation plan, policy set, projected score, and an evidence index by objective, then a mock assessment in examine, interview, and test form, with control owners answering for their own evidence. After fixes we retest each closed objective and hand your Affirming Official a readiness memo for the score entry.

IS THIS THE RIGHT ENGAGEMENT?

Who it’s for.
When you need it.

BEST SUITED FOR
  • Defense primes and subcontractors handling Controlled Unclassified Information under DFARS 252.204-7012
  • Contractors self-assessing at CMMC Level 2 and posting a score in SPRS
  • Suppliers planning for a customer requirement for independent CMMC Level 2 certification
  • Organizations storing controlled government information across cloud services, endpoints, and shared workspaces
WHEN IT’S TIME TO ENGAGE
  • A prime issues a 7012 flowdown or asks for your current SPRS score
  • Your posted SPRS score sits well below 110 and remediation has stalled
  • A solicitation names Level 2 self-assessment as a condition of award
  • You have never scored the 110 requirements and hold no current SSP
AGREED AROUND YOUR ENVIRONMENT

What the scope can include.

  • Sort every asset into the program’s categories and set the enclave or enterprise boundary

  • Map what each outside service provider and cloud provider is responsible for

  • Assess all 110 requirements against the detailed objectives beneath them

  • Score each requirement the program’s way, including the multi-factor and encryption partial-credit rules

  • Write the system security plan and remediation plan and index evidence by objective

  • Run a mock assessment and shortlist independent third-party assessors for you

TRANSPARENT PRICING

What it typically costs.
One rate: $150/hour.

Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.

Small
$12,000–$21,000

Under 50 employees, one office, defense data kept in a cloud enclave such as Microsoft GCC High

About 80–140 hours
Mid-size
$21,000–$36,000

50–250 employees, mix of cloud and on-site systems, two or three locations

About 140–240 hours
Large
$36,000–$60,000

250+ employees, several sites, shop-floor or engineering systems that touch defense data

About 240–400 hours
WHAT MOVES THE PRICE
  • How many systems, people, and locations handle defense data
  • Enclave versus whole-company scope
  • How much of NIST 800-171 is already in place and documented
  • Number of outside IT and cloud providers to account for
TYPICAL TIMELINE

6–12 weeks for scoping, gap assessment, security plan and action plan, and evidence; mock assessment scheduled once fixes are in place (often 3–6 months total)

A Level 2 certification assessment is paid separately to an authorized C3PAO; DoD estimates about $105,000–$118,000 over three years including affirmations.

Get a fixed quote for your scope

Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.

TANGIBLE DELIVERABLES

What you take forward.

  • Scoping memo, asset inventory by category, and network and data-flow diagrams
  • Projected score with per-objective met and not-met results and point deductions
  • System security plan, remediation plan, and policy set aligned to the program
  • Mock assessment report and readiness memo for your Affirming Official

Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.

SERVICE-SPECIFIC QUESTIONS

Before we get started.

What CMMC requirements should we prepare for during the program review?

Begin with your contract and the latest official guidance. The July 2026 announcement suspended the transition to Phase II while retaining Phase I self-assessments and contractual safeguarding duties. We check the required level, assessment type, score submission, and affirmation requirements before setting your readiness plan. Work can include closing control gaps, documenting the system, and organizing evidence for the review you actually face. A paused rollout milestone does not remove the obligation to protect controlled government information.

Can you also be our assessor or serve on our assessment team?

No, and be wary of anyone who says yes. Anyone who consults for an organization to prepare it for a CMMC assessment must stay off that organization’s Level 2 certification assessment for three years, and the rule applies to the assessing company and every person on its team. Our principal holds the CMMC Certified Assessor credential, which is exactly why we know what assessors look for and why we stay on the readiness side. We help you shortlist independent C3PAOs and prepare your control owners for their interviews.

REFERENCE POINTS
START AT THE SOURCE

Let’s find your next move.

A focused conversation. A clear scope. A practical path to stronger security.

Let’s talk security