Full-lifecycle CMMC support. Every level.
The Cybersecurity Maturity Model Certification program applies to every DoD contractor and subcontractor that handles Federal Contract Information or Controlled Unclassified Information. We support the readiness, remediation, documentation, and assessment work required at every level — as one specialty within our broader cybersecurity and GRC practice.
Your level is dictated by your contract data.
CMMC 2.0 defines three levels. The one you need is set by the sensitivity of the information you handle under contract — not by preference. We help organizations confirm the correct target level and build the program to reach it.
Foundational
- Scope
- Federal Contract Information (FCI)
- Controls
- 17 basic safeguarding practices (FAR 52.204-21)
- Assessment
- Annual self-assessment
- Typical audience
- Organizations handling only FCI — no CUI.
Advanced
- Scope
- Controlled Unclassified Information (CUI)
- Controls
- 110 controls mapped one-for-one to NIST SP 800-171 Rev. 2
- Assessment
- Triennial C3PAO assessment (for most contracts) or self-assessment (for a narrow subset)
- Typical audience
- The majority of DoD contractors handling CUI.
Expert
- Scope
- Highest-sensitivity CUI, APT-relevant programs
- Controls
- Level 2 plus a subset of NIST SP 800-172 enhanced requirements
- Assessment
- Government-led assessment
- Typical audience
- Contractors on programs designated for the highest safeguarding requirements.
Every stage of the CMMC lifecycle.
We meet organizations wherever they are on the program — from the first scoping conversation to the annual senior-official affirmation years after certification.
Readiness assessments
Baseline your current posture against the CMMC level required by your contract or business need. Identify the highest-impact gaps first.
Gap assessments
Control-by-control comparison of current state to the required practices. Prioritised remediation roadmap with time and effort estimates.
Documentation development
System Security Plans, Plans of Action and Milestones, boundary diagrams, policies, and procedures written to withstand C3PAO and DoD scrutiny.
Control implementation
Hands-on remediation with your IT and security teams. We close controls against evidence, not against a checkbox.
Remediation planning
POA&Ms scoped to the CMMC 2.0 rules — surgical use for permitted controls, hard-deadline closure inside the 180-day window.
Evidence preparation
Assessment packets indexed the way an assessor reads them: by control family, by determination statement, with owners named.
Assessment preparation
Pre-assessment walk-throughs, mock interviews, and live escort during the formal C3PAO engagement.
Continuous monitoring
Post-certification drift detection, quarterly re-tests, and annual §170.22 senior-official affirmation support.
Five artifacts every Level 2 assessor asks for on day one.
Level 2 is where most defense contractors need to land. It maps one-for-one to NIST SP 800-171 Rev. 2 and is assessed by an accredited C3PAO. Nothing about it is improvisational — the assessor opens with these five artifacts.
- 01System Security Plan (SSP)
A written description of every system in the CUI boundary and how each of the 110 controls is implemented, by whom, with what tooling, and against what evidence.
- 02Plan of Action & Milestones (POA&M)
A dated, owned closure plan for any control not fully implemented at the time of score submission. CMMC 2.0 permits a POA&M for a defined subset; high-value controls cannot appear on it.
- 03SPRS Score
A submitted score in the Supplier Performance Risk System, computed against the 110 controls. The current threshold is 88 of 110, with a 180-day POA&M closure obligation.
- 04Authorization Boundary Diagram
A signed diagram of the CUI boundary: the systems, data flows, identities, and connections in scope. Out-of-scope exclusions are justified against NIST 800-171A determination statements.
- 05Evidence Library
Per-control artifacts (configurations, screenshots, signed policies, training records) indexed by family and control number. The packet the assessor actually reads.
Each unmet control subtracts.
SPRS begins every contractor at 110 and subtracts a weight for each control not fully implemented. Weights run 1, 3, or 5 based on assessed risk impact. The minimum required for award eligibility is currently 88, with a closure plan for the remainder.
A contractor who claims a score of 110 without a defensible evidence packet is volunteering for a False Claims Act exposure. The DOJ’s Civil Cyber-Fraud Initiative has already produced multi-million-dollar settlements over inflated scores. The score must be earned, in writing, against artifacts.
- 110 starting score, deductions for each unmet control
- Weights of 1, 3, 5 based on assessment objective impact
- Minimum 88 with POA&M permitted on lower-weight controls
- 180-day POA&M closure obligation
- Annual affirmation by a senior company official (32 CFR §170.22)
- Controls met
- 103 / 110
- POA&M (allowed)
- 7 of 7
- Confidence
- Audit-ready
- Submitted
- To DoD SPRS
You have 14 families to defend.
Three are usually failing.
This is the heatmap we produce in week two. Every cell is a defensible posture, not an opinion. Hover or tap a family to read the typical failure pattern.
Hover a family to read its typical failure pattern across DoD contractors we’ve assessed.
A POA&M is a scalpel, not a parachute.
CMMC 2.0 permits a Plan of Action and Milestones at certification — but only against a constrained list of controls and only inside a fixed 180-day closure window. Used surgically, a POA&M can close the last-mile gap. Used broadly, it is a way to have your certification revoked.
Lower-weight controls (weight 1) where absence of implementation does not undermine the core protection objective. Examples include certain training documentation gaps.
High-impact controls (weight 5). Examples include FIPS-validated cryptography, multifactor authentication for privileged users, and incident reporting to DoD.
180 days from certification. Failure to close results in suspension of certification. Continuous monitoring keeps the clock visible.
The clauses are already live.
- 2016
DFARS 252.204-7012 finalized — CUI safeguarding and 72-hour incident reporting required of all DoD contractors.
- 2020
DFARS 7019, 7020, 7021 issued via Interim Rule — SPRS scoring, DoD assessment rights, and CMMC certification clauses.
- 2021
CMMC 2.0 announced — collapsed to three levels, NIST 800-171 alignment confirmed, POA&M permitted for limited controls.
- 2024
32 CFR Part 170 published (Oct 15, 2024) — formal CMMC program rule, effective December 16, 2024.
- 2025+
48 CFR rule phase-in via DFARS — contracting officers begin inserting CMMC certification requirements directly into solicitations.
- Today
Subcontractor flow-down is happening. Primes are requiring evidence of SPRS scores from suppliers as a condition of teaming agreements.