CMMC Compliance
Stay Eligible for DoD Contracts
CMMC is now written into DoD solicitations. We take defense contractors from “we think we’re compliant” to a defensible SPRS score: scoping under 32 CFR § 170.19, an objective-level assessment of all 110 NIST SP 800-171 Rev 2 requirements, a real System Security Plan, and a POA&M that actually satisfies the conditional-status rules.
The Self-Score in SPRS Is Usually Wrong
Most contractors posted a NIST SP 800-171 self-score years ago and have not revisited it. Under CMMC the rules are explicit: a requirement described in a POA&M is still assessed as NOT MET, drafts and unapproved policies are not acceptable evidence, and the score can go negative. We reassess against the actual assessment objectives so the number you affirm is the number an assessor would reach.
Our CMMC Readiness Services
From scoping through remediation and annual affirmation
CMMC Scoping
Sort every system into the categories 32 CFR § 170.19 defines—CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets and Out-of-Scope—so you assess what is actually in scope and nothing more.
NIST SP 800-171 Gap Assessment
All 110 Level 2 requirements assessed down to the individual assessment objectives, with each one recorded as MET, NOT MET or N/A against evidence in final, approved form.
SPRS Score Calculation
Your Supplier Performance Risk System score computed the way § 170.24(c)(2) defines it: 110 minus the point value of every NOT MET requirement, including the two partial-credit cases for MFA and CUI encryption.
System Security Plan (SSP)
A current SSP is the gate on the whole assessment—without one, an assessment cannot be completed. We build yours around your real asset inventory and network diagram.
POA&M That Passes the Rules
A Plan of Action and Milestones built to § 170.21: nothing over 1 point on it, none of the six barred requirements, and a closeout plan that fits inside the 180-day window.
Remediation and Annual Affirmation
We close the gaps, not just list them—technical controls, policy, and the annual affirmation and reassessment cadence that keeps your status alive.
Why Defense Contractors Start Now
The rule is in effect and the clock on each contract is short
Stay Eligible for DoD Awards
The 48 CFR acquisition rule took effect 10 November 2025. CMMC requirements now appear in solicitations involving CUI, and Phase 1 already requires Level 1 and Level 2 self-assessments before award.
Know Your Real SPRS Score
Most contractors self-score optimistically. Scoring at the objective level, against evidence, tells you what a C3PAO would actually find before it costs you an award.
Reach Conditional Status Faster
Conditional Level 2 needs a score of at least 88 out of 110, no POA&M item worth more than 1 point, and none of the six barred requirements open. We target that threshold deliberately.
No Surprises From Your Supply Chain
External service providers that touch CUI or security protection data land inside your scope. We document the ESP relationships and customer responsibility matrices your assessor will ask for.
Built on NIST SP 800-171 You Already Need
CMMC Level 2 assesses against NIST SP 800-171 Rev 2, the same standard DFARS 252.204-7012 has required for years. The work is not thrown away if your level changes.
Evidence That Holds Up
Working papers, drafts and unapproved policies are explicitly unacceptable as evidence. We get your documentation to final, approved state before anyone assesses it.
How the Level 2 Score Actually Works
32 CFR § 170.24(c)(2) sets the arithmetic. You start at 110 and subtract the point value of every requirement assessed NOT MET. There is no credit for partial implementation except in two specific cases, and the score can fall below zero.
Requirements worth 5 points each
The ones that sink a score fastest
Requirements worth 3 points each
Plus the two partial-credit cases
Requirements worth 1 point each
The only items a POA&M may carry
The Two Partial-Credit Exceptions
IA.L2-3.5.3 (multifactor authentication): 3 points are deducted instead of 5 if MFA covers remote and privileged users but not all users; the full 5 are deducted if MFA is not implemented for any users.
SC.L2-3.13.11 (CUI encryption): 3 points are deducted instead of 5 if encryption is in use but not FIPS-validated; the full 5 are deducted if CUI is not encrypted.
CMMC Level 1 and Level 2
Which level applies is set by your contract and by whether you handle FCI or CUI. These two cover the overwhelming majority of the defense industrial base—and they are what we do.
CMMC Level 1
Federal Contract Information (FCI)
15 basic safeguarding requirements, assessed MET or NOT MET in their entirety—no partial credit and no POA&M. An annual self-assessment with an affirmation in SPRS.
CMMC Level 2
Controlled Unclassified Information (CUI)
All 110 NIST SP 800-171 Rev 2 requirements. Either a self-assessment or a C3PAO assessment depending on the contract, scored out of 110, with a limited POA&M allowed under § 170.21.
Self-Assessment or C3PAO
Which Flavour of Level 2 Applies
The solicitation decides whether your Level 2 is a self-assessment with an affirmation in SPRS or a certification assessment by an authorized C3PAO. The 110 requirements are the same; the evidence bar and the closeout rules are not.
Scoping and ESPs
What Is Actually Assessed
Scope drives cost. Asset categorization under § 170.19, plus the treatment of cloud and non-cloud external service providers, decides how many systems face the full requirement set.
Frequently Asked Questions
Which CMMC level do I need?
It is set by your contract. If you only handle Federal Contract Information, Level 1 applies. If you process, store or transmit Controlled Unclassified Information, Level 2 applies—by self-assessment or by a C3PAO assessment depending on the solicitation. We work at Level 1 and Level 2; Level 3, which adds NIST SP 800-172 requirements assessed by DoD’s DIBCAC, is outside what we take on.
Can I bid with an open POA&M?
At Level 2, only under Conditional status, and only if all three conditions in 32 CFR § 170.21 hold: a score of at least 88 out of 110, no POA&M item worth more than 1 point (the one exception being SC.L2-3.13.11 where encryption is used but not FIPS-validated), and none of AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4 or PE.L2-3.10.5 left open. Level 1 allows no POA&M at all.
How long do I have to close a POA&M?
180 days from the Conditional status date, or the Conditional status expires. Level 2 self-assessment closeouts are performed by the contractor; C3PAO closeouts must be performed by a C3PAO.
Is CMMC the same as NIST SP 800-171?
Level 2 assesses against NIST SP 800-171 Rev 2—the same standard DFARS 252.204-7012 has required for years. What CMMC adds is verification: a defined assessment method, a scoring rule, assessment objectives, and in many cases a third-party assessor instead of a self-attestation. Our NIST compliance services are the foundation the CMMC work builds on.
Do my cloud providers and MSP fall inside my scope?
If an external service provider handles CUI and is a cloud provider, it must meet the FedRAMP requirements in DFARS 252.204-7012. If it handles security protection data only, it is assessed as a Security Protection Asset inside your scope. Either way the relationship has to be documented in your SSP and backed by the provider’s service description and customer responsibility matrix.
Can you certify us?
No—and be wary of anyone who says they can. Certification is issued only after an assessment by an authorized C3PAO. We do the readiness work: scoping, gap assessment, remediation, SSP and POA&M, and preparing your evidence so the assessment goes the way you expect.
How long does CMMC readiness take?
For a small contractor starting from a mature IT environment, scoping and a gap assessment take a few weeks; remediation to a score of 88 or better typically runs 6-12 months depending on how much of the 110 is genuinely in place. Starting from nothing, plan on a year.
Can I narrow my scope to reduce cost?
Often, yes. Enclaving CUI into a defined boundary keeps the rest of the business out of the full Level 2 requirement set. Out-of-Scope assets must be unable to handle CUI and provide no security protection to CUI assets, and you have to be ready to justify that. Scoping is the single biggest lever on the cost of the whole programme.
Related Services
The work that surrounds a CMMC programme
NIST Compliance
NIST SP 800-171 implementation and CSF 2.0—the control work underneath CMMC Level 2.
Virtual CISO
Security leadership to own the programme, the annual affirmation and the reassessment cadence.
Vendor Risk Management
External service providers land in your assessment scope. Document and govern them properly.
Find Out What Your Real SPRS Score Is
We scope your environment, assess all 110 requirements against evidence, and give you a remediation plan that gets you to a score you can affirm.