Primes and subcontractors with CUI in the contract.
If your DoD contracts carry DFARS 252.204-7012, 7019, 7020 or the 7021 CMMC clause, you need to demonstrate — not assert — that the 110 security requirements of NIST SP 800-171 Rev. 2 are implemented across every asset that stores, processes, or transmits Controlled Unclassified Information. Most organizations we meet have an SPRS score that was self-attested years ago, an SSP that no longer matches the environment, and no clear line around what is actually in scope.
We work with manufacturing, engineering, and aerospace suppliers in the 25–2,000-employee range, whether you run a Microsoft GCC High enclave, an on-premises CUI segment, or a hybrid of both.
What you getDeliverables an assessor can actually use.
- Scope and asset categorization — CUI assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets and Out-of-Scope assets documented per the CMMC Level 2 Scoping Guide, with data-flow diagrams that show where CUI lives and moves.
- Gap assessment against 320 assessment objectives — every objective in NIST SP 800-171A scored MET / NOT MET / N/A, with the evidence we found and the evidence you still need.
- SPRS score and remediation roadmap — a defensible score under the DoD Assessment Methodology, a sequenced plan that closes the 3- and 5-point weighted requirements first, and a POA&M limited to what CMMC actually allows to remain open.
- System Security Plan and policy set — an SSP written per control family with implementation narratives, plus the policies, procedures, and SOPs that back them.
- Evidence architecture and mock assessment — an organized evidence library mapped objective-by-objective, and a dry run so your team knows how to answer before the C3PAO arrives.
Assess, Map, Prioritize, Assure — applied to CMMC.
Assess the boundary
We interview your engineering, IT, and contracts teams, walk the CUI data flow end to end, and draw the boundary before touching a single control. Scope creep is the most expensive mistake in CMMC.
Map to 800-171A
Each of the 320 objectives is tested against your actual configuration — Entra ID conditional access, GCC High DLP, endpoint baselines, physical controls — not against what the policy says should be true.
Prioritize by weight
The DoD methodology weights requirements at 1, 3 or 5 points. We sequence remediation so your SPRS score improves fastest and your POA&M stays inside the rules for conditional certification.
Questions we hear on the first call.
Do we need CMMC Level 1 or Level 2?
Can we still use a POA&M?
Do we have to move to Microsoft GCC High?
What does the C3PAO look at?
Know your real SPRS score before the DoD does.
A 20-minute scoping call tells you whether you need a full gap assessment or a targeted remediation sprint.