CMMC 2.0 Readiness

CMMC Level 2 readiness for defense contractors handling CUI.

Scope your enclave, close the gaps against NIST SP 800-171, and walk into your C3PAO assessment with evidence that holds up — led by a CMMC Certified Professional (CCP) candidate with current DoD CUI training.

Who this is for

Primes and subcontractors with CUI in the contract.

If your DoD contracts carry DFARS 252.204-7012, 7019, 7020 or the 7021 CMMC clause, you need to demonstrate — not assert — that the 110 security requirements of NIST SP 800-171 Rev. 2 are implemented across every asset that stores, processes, or transmits Controlled Unclassified Information. Most organizations we meet have an SPRS score that was self-attested years ago, an SSP that no longer matches the environment, and no clear line around what is actually in scope.

We work with manufacturing, engineering, and aerospace suppliers in the 25–2,000-employee range, whether you run a Microsoft GCC High enclave, an on-premises CUI segment, or a hybrid of both.

What you get

Deliverables an assessor can actually use.

  • Scope and asset categorization — CUI assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets and Out-of-Scope assets documented per the CMMC Level 2 Scoping Guide, with data-flow diagrams that show where CUI lives and moves.
  • Gap assessment against 320 assessment objectives — every objective in NIST SP 800-171A scored MET / NOT MET / N/A, with the evidence we found and the evidence you still need.
  • SPRS score and remediation roadmap — a defensible score under the DoD Assessment Methodology, a sequenced plan that closes the 3- and 5-point weighted requirements first, and a POA&M limited to what CMMC actually allows to remain open.
  • System Security Plan and policy set — an SSP written per control family with implementation narratives, plus the policies, procedures, and SOPs that back them.
  • Evidence architecture and mock assessment — an organized evidence library mapped objective-by-objective, and a dry run so your team knows how to answer before the C3PAO arrives.
How we work

Assess, Map, Prioritize, Assure — applied to CMMC.

1

Assess the boundary

We interview your engineering, IT, and contracts teams, walk the CUI data flow end to end, and draw the boundary before touching a single control. Scope creep is the most expensive mistake in CMMC.

2

Map to 800-171A

Each of the 320 objectives is tested against your actual configuration — Entra ID conditional access, GCC High DLP, endpoint baselines, physical controls — not against what the policy says should be true.

3

Prioritize by weight

The DoD methodology weights requirements at 1, 3 or 5 points. We sequence remediation so your SPRS score improves fastest and your POA&M stays inside the rules for conditional certification.

CMMC FAQ

Questions we hear on the first call.

Do we need CMMC Level 1 or Level 2?
Level 1 applies when you handle only Federal Contract Information (FCI) and covers the 15 basic safeguarding requirements of FAR 52.204-21. Level 2 applies when CUI is in scope and covers all 110 requirements of NIST SP 800-171. Your contract clauses and the CUI markings on what you receive from the prime determine which one you need; we confirm this in the scoping call.
Can we still use a POA&M?
Only within limits. Under 32 CFR Part 170 a Level 2 conditional certification requires a minimum score, no open 5-point requirements (with narrow exceptions), and closure of every open item within 180 days. We design the roadmap so anything left on the POA&M is genuinely eligible.
Do we have to move to Microsoft GCC High?
Not necessarily. GCC High simplifies FedRAMP-equivalency and ITAR questions, but a well-scoped commercial tenant or on-premises enclave can also meet Level 2. The right answer depends on your data, your customers' flow-down requirements, and your budget — we lay out the options with costs before you commit.
What does the C3PAO look at?
Assessors test each objective through examination of artifacts, interviews with your staff, and observation of the control operating. Our mock assessment rehearses all three so the real assessment is confirmation, not discovery.

Know your real SPRS score before the DoD does.

A 20-minute scoping call tells you whether you need a full gap assessment or a targeted remediation sprint.