Services
Fixed scope, fixed fee, no surprise invoices.
Five engagements that cover the path from "we have no idea where we stand" to a submitted SPRS score and a defensible CMMC Level 2 position. Take them in order or pick the one that matches where you are.
Stage 1 · Find out where you stand
CMMC Readiness Assessment
A full assessment of all 110 NIST SP 800-171 controls, scored the way the DoD scores them, so your SPRS number is defensible rather than guessed.
- Timeline
- 2–3 weeks
- Best for
- Contractors who need a real starting number
What you receive
- Assessment of all 110 controls with evidence review
- Scored gap report using DoD point values
- Remediation roadmap ordered by point impact
- SPRS score calculation and submission guidance
- Findings walkthrough with your team
Stage 2 · Put it in writing
SSP & POA&M Development
The two documents an assessor asks for first. Written to assessor standard, describing your actual environment rather than someone else's template.
- Timeline
- 3–4 weeks
- Best for
- Teams with controls in place but nothing documented
What you receive
- System Security Plan covering your CUI boundary
- POA&M with owners, milestones and target dates
- Network and data flow diagrams
- Control implementation statements for all 110 controls
- One full revision round after your review
Stage 3 · Prove it holds up
Audit Readiness / Pre-Assessment
A mock assessment run the way a C3PAO runs one, so the first time your team is questioned on evidence isn't the time that counts.
- Timeline
- 4–6 weeks
- Best for
- Contractors with a certification date booked
What you receive
- Mock assessment against CMMC Level 2 practices
- Evidence and artifact gap list, control by control
- Interview preparation for technical staff
- Written readiness determination
- Remediation support through your assessment date
Ongoing
Fractional Compliance Advisory
A named compliance lead on retainer, for the years between assessments when controls quietly drift and nobody owns the POA&M.
- Term
- Month to month
- Best for
- Teams without a compliance lead in house
What you receive
- Named advisor and scheduled monthly working sessions
- POA&M tracking and quarterly SPRS updates
- Policy and procedure maintenance as the environment changes
- Flow-down review for subcontracts and vendors
- Incident reporting support when something happens
Specialist
AI in CUI Environments
Your people are already pasting work into AI tools. This engagement determines which of those tools can touch CUI, and puts rules around the rest.
- Timeline
- 2 weeks
- Best for
- Teams adopting AI tools inside a CUI boundary
What you receive
- Inventory of AI tools already in use across the business
- Data flow analysis covering prompts, logs and retention
- Vendor and FedRAMP posture review for each tool
- Acceptable use policy written for in-scope systems
- Guidance memo for leadership sign-off
Not sure which one you need?
Take the free 25-question self-check first. It takes five minutes and tells you which stage you're actually at.
Before any engagement · Scoping
Scope is decided first — and it decides everything else.
Every asset in your environment maps to one of five categories. That mapping determines what gets assessed, what gets documented, and what the work costs. It is the first thing we establish on a scope call, and the reason the fees on this page hold.
Where CUI lives
Everything below is decided by one question: does this asset process, store or transmit Controlled Unclassified Information — or protect something that does?
CUI Assets
Process, store or transmit CUI. File servers, endpoints used for CUI work, cloud storage holding contract data. The core of the assessment.
requirements
Security Protection Assets
Provide security functions for the in-scope environment, or hold Security Protection Data. Firewalls, SIEM, log servers, security-providing ESPs.
relevant to the capability
Contractor Risk Managed Assets
Can access CUI but aren't intended to process it, and are managed under your risk-based policy. The category most often misapplied.
assessor may spot-check
Specialized Assets
OT, IoT and IIoT devices, Government Furnished Equipment, restricted systems and test equipment — assets that cannot be fully secured.
shown as managed
Out-of-Scope Assets
Cannot process, store or transmit CUI, and are physically or logically separated from assets that can. Separation has to be real and demonstrable.
requirement
You propose the boundary — the assessor tests it. Scoping is not a formality performed before the real work. It sets the cost, the timeline and the risk of the entire engagement. Drawn too wide, you pay to secure systems that never needed it. Drawn too narrow, you fail on systems you left out.
Source: 32 CFR § 170.19(c)(1), Table 3 · CMMC Level 2 Scoping Guide
How an engagement runs
Scope call
Thirty minutes, no charge. We establish your CUI boundary and contract obligations.
Fixed-fee proposal
Written scope, deliverables and dates. The price on this page is the price you sign.
Fieldwork
Interviews, evidence review and testing, scheduled around your operations.
Handover
Deliverables walked through with your team, so your staff can defend the work.
Start with a scope call
Thirty minutes to establish what your contracts require and which engagement fits. No cost, no obligation.
Fees shown are for single engagements at standard scope. Multi-service packages and organizations with multiple sites or enclaves are quoted individually.
