Services
Fixed scope, fixed fee, no surprise invoices.
Five engagements that cover the path from "we have no idea where we stand" to a submitted SPRS score and a defensible CMMC Level 2 position. Take them in order or pick the one that matches where you are.
Stage 1 · Find out where you stand
CMMC Readiness Assessment
A full assessment of all 110 NIST SP 800-171 controls, scored the way the DoD scores them, so your SPRS number is defensible rather than guessed.
- Timeline
- 2–3 weeks
- Best for
- Contractors who need a real starting number
What you receive
- Assessment of all 110 controls with evidence review
- Scored gap report using DoD point values
- Remediation roadmap ordered by point impact
- SPRS score calculation and submission guidance
- Findings walkthrough with your team
Stage 2 · Put it in writing
SSP & POA&M Development
The two documents an assessor asks for first. Written to assessor standard, describing your actual environment rather than a template someone else's.
- Timeline
- 3–4 weeks
- Best for
- Teams with controls in place but nothing documented
What you receive
- System Security Plan covering your CUI boundary
- POA&M with owners, milestones and target dates
- Network and data flow diagrams
- Control implementation statements for all 110 controls
- One full revision round after your review
Stage 3 · Prove it holds up
Audit Readiness / Pre-Assessment
A mock assessment run the way a C3PAO runs one, so the first time your team is questioned on evidence isn't the time that counts.
- Timeline
- 4–6 weeks
- Best for
- Contractors with a certification date booked
What you receive
- Mock assessment against CMMC Level 2 practices
- Evidence and artifact gap list, control by control
- Interview preparation for technical staff
- Written readiness determination
- Remediation support through your assessment date
Ongoing
Fractional Compliance Advisory
A named compliance lead on retainer, for the years between assessments when controls quietly drift and nobody owns the POA&M.
- Term
- Month to month
- Best for
- Teams without a compliance lead in house
What you receive
- Named advisor and scheduled monthly working sessions
- POA&M tracking and quarterly SPRS updates
- Policy and procedure maintenance as the environment changes
- Flow-down review for subcontracts and vendors
- Incident reporting support when something happens
Specialist
AI in CUI Environments
Your people are already pasting work into AI tools. This engagement determines which of those tools can touch CUI, and puts rules around the rest.
- Timeline
- 2 weeks
- Best for
- Teams adopting AI tools inside a CUI boundary
What you receive
- Inventory of AI tools already in use across the business
- Data flow analysis covering prompts, logs and retention
- Vendor and FedRAMP posture review for each tool
- Acceptable use policy written for in-scope systems
- Guidance memo for leadership sign-off
Not sure which one you need?
Take the free 25-question self-check first. It takes five minutes and tells you which stage you're actually at.
How an engagement runs
Scope call
Thirty minutes, no charge. We establish your CUI boundary and contract obligations.
Fixed-fee proposal
Written scope, deliverables and dates. The price on this page is the price you sign.
Fieldwork
Interviews, evidence review and testing, scheduled around your operations.
Handover
Deliverables walked through with your team, so your staff can defend the work.
Start with a scope call
Thirty minutes to establish what your contracts require and which engagement fits. No cost, no obligation.
Fees shown are for single engagements at standard scope. Multi-service packages and organizations with multiple sites or enclaves are quoted individually.
