The challenge behind the engagement.
This service is for a contractor that must protect sensitive government information and post a security score for it. We find that information first: which contracts require it, which data counts, where it sits across mail, file storage, engineering tools, and business systems, and what flows to subcontractors. We choose the architecture, a walled-off enclave, your whole enterprise, or a hybrid, and gather evidence that any cloud service holding the information meets the required protection level. We assess all 110 requirements against their objectives and apply the DoD scoring method, then note where the newer edition differs so fixes made now hold up later. We write the system security plan and remediation plan and align your incident response to the fast reporting and evidence-preservation duties your contract sets. We never promise a score; it reflects what is in place.
Manufacturers, engineering firms, and research organizations that received a requirement from a prime or a solicitation asking for a security score, often with sensitive information already sitting in everyday cloud email and file tools and no current plan in place.
What we do.
What you can use.
Find the information and choose the architecture
We begin with your contracts and the requirements they flow down, then trace the sensitive information through email, file storage, engineering and design tools, and business systems into a clear data-flow map. With that map we decide enclave, enterprise, or hybrid, list every cloud service that touches the information, and gather the protection-level evidence your contract requires for each.
Score the 110 requirements the DoD way
Requirement by requirement we test the objectives across how people sign in, how devices are managed, how threats are detected, how logs are kept, and how encryption is validated, then apply the DoD scoring method to reach your score. We note where the newer edition’s wording differs so the fixes you make now hold up later.
Deliver the plan, remediation, and score record
You receive the data-flow map, a scoping memo, an objective-level gap report with your projected score, the system security plan, a dated remediation plan, a policy set, and a roadmap ordered by point value. We support your score submission, prepare control owners for a government-led assessment, and retest fixes with dated evidence.
Who it’s for.
When you need it.
- Manufacturers and engineering firms that received a 7012 flowdown from a prime
- Research organizations holding CUI in commercial Microsoft 365 with no current SSP
- Contractors that must post a Basic Assessment score under DFARS 252.204-7020
- Suppliers choosing between a GCC High enclave and an enterprise-wide boundary
- A solicitation asks for an SPRS score you have never calculated
- A prime demands proof that CUI is protected before awarding work
- A DIBCAC Medium or High assessment is scheduled for your systems
- Cyber incident reporting duties apply and no response plan is documented
What the scope can include.
- 01
Find the sensitive information across contracts, mail, file storage, and business systems
- 02
Choose the architecture, enclave, enterprise, or hybrid, and set provider responsibilities
- 03
Gather protection-level evidence for every cloud service that holds the information
- 04
Assess all 110 requirements against their objectives with the DoD scoring method
- 05
Review the newer edition so new controls are designed to its structure
- 06
Align incident response to the fast reporting and evidence-preservation duties
What it typically costs.
One rate: $150/hour.
Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.
Under 50 employees, one office, mostly cloud tools
About 50–100 hours50–250 employees, mix of cloud and on-site systems, up to three locations
About 100–180 hours250+ employees, several sites, engineering or manufacturing systems in scope
About 180–320 hours- Where sensitive defense information lives and how many systems touch it
- Number of employees and locations
- Existing documentation and security tooling
- Outside IT providers whose controls must be accounted for
4–6 weeks for small firms; 8–12+ weeks for larger, multi-site organizations
No third-party fee is required for a self-assessment score; if a contract later requires CMMC certification, the C3PAO is paid separately.
Get a fixed quote for your scopeRanges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- Data-flow map and scoping memo naming every system and provider that touches the information
- Gap report with objective-level results and a projected score
- System security plan, remediation plan, policy set, and a roadmap ordered by point value
- Score submission record and preparation notes for a government-led assessment
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
Which edition applies, and when will that change?
The earlier edition today. The standards body has published a newer edition, but the government contract clause still points to the earlier one until that changes, and the certification program relies on the same edition. The newer edition reorganizes the requirements and adds agency-set parameters, and the government has published its parameter choices as a signal that a move will eventually come. We assess and score you against the edition your contract requires today and note where the newer wording differs, so the controls you build now will not need rework.
How is this different from CMMC Level 2 readiness?
Same 110 requirements, different obligation. This service covers the duty written into your contract: protect the information, report incidents quickly, keep a current plan, and post a score that can fall below zero. CMMC Level 2 adds a formal program on top: sorting your assets, scoring by a fixed method, limits on what can sit unfinished, annual affirmations, and eventually a third-party certification. If you have never scored yourselves, start here; if you already post a score and expect a certification requirement, our CMMC Readiness service picks up from this baseline.
- 32 CFR Part 170: Cybersecurity Maturity Model Certification (CMMC) Program (Federal Register final rule)
- Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements
- NIST SP 800-171 Rev. 2: Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
- NIST SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations
- FedRAMP Consolidated Rules for 2026
- FedRAMP 20x
- GovRAMP FAQs
