Skip to content

Our flagship program

CMMC Level 2 Compliance Services

If your contracts contain DFARS 252.204-7012 and you handle Controlled Unclassified Information, CMMC Level 2 is coming for you, and for most companies it means a third-party assessment by a C3PAO. We run the entire program: we find the gaps, fix them, document them, and stand beside you when the assessor shows up.
  • All 110 NIST SP 800-171 practices and 320 assessment objectives
  • Scope reduction first, so you pay to protect what actually holds CUI
  • SSP, POA&M, and SPRS submission handled for you
  • Assessment-day support with a C3PAO of your choosing
Compliance team reviewing a CMMC Level 2 readiness plan around a conference table

What CMMC Level 2 actually requires

CMMC Level 2 is built on NIST SP 800-171. That means 110 security requirements across 14 families, and when an assessor evaluates them they do not look at 110 items. They look at 320 individual assessment objectives. Every objective has to be met, documented, and evidenced. A control that is "mostly" in place is a control that is scored as not met.

The Department of Defense scores your posture on a 110-point scale. You start at 110 and subtract 5, 3, or 1 point for each requirement you have not implemented. That score goes into the Supplier Performance Risk System (SPRS), and contracting officers can see it. A low or missing score is increasingly the reason a contract award goes somewhere else.

  • Access Control, Awareness & Training, Audit & Accountability, Configuration Management
  • Identification & Authentication, Incident Response, Maintenance, Media Protection
  • Personnel Security, Physical Protection, Risk Assessment, Security Assessment
  • System & Communications Protection, System & Information Integrity

How we run a Level 2 program

We do not start with a product pitch. We start by mapping where CUI enters your business, where it lands, who touches it, and where it leaves. That map determines everything else, including how much this is going to cost you.

Once scope is settled, we run a full gap assessment against all 320 objectives, produce a weighted score, and build a remediation plan sequenced by point value and effort. High-value, low-effort items go first so your SPRS score moves early while the heavier engineering work runs in parallel.

  • Phase 1: CUI data-flow mapping and scope definition (in-scope assets, CRMA, specialized assets)
  • Phase 2: Gap assessment against all 320 assessment objectives with a weighted SPRS score
  • Phase 3: Remediation: identity, endpoints, logging, encryption, boundary, physical, policy
  • Phase 4: Documentation: System Security Plan, POA&M, policies, procedures, evidence library
  • Phase 5: Pre-assessment: mock assessment, evidence walkthrough, interview coaching
  • Phase 6: Assessment support and post-assessment continuous compliance

The POA&M rules people get wrong

There is a persistent myth that you can certify with a long list of open items and fix them later. You cannot. A Plan of Action and Milestones is only permitted if you have already scored at least 88 of 110, it can only cover lower-weighted requirements, and it must be closed out within 180 days, verified by a follow-up assessment. The heaviest requirements, including multifactor authentication and FIPS-validated cryptography, can never sit on a POA&M.

That is why we sequence remediation around the requirements that can never be deferred. If those are not genuinely in place, nothing else matters.

Self-assessment or C3PAO: which applies to you

Not every Level 2 contract requires a third-party assessment. Some are satisfied by a self-assessment plus an annual affirmation from a senior official. Most CUI-bearing contracts, however, land in the certification bucket and require a CMMC Third-Party Assessment Organization.

We read your actual contract clauses and tell you which one you are facing before you spend money. If you only need a self-assessment, we will say so, and we will help you do it correctly rather than selling you a certification program you do not need.

What you get

Concrete deliverables, not a slide deck

Every engagement produces artefacts you own, that live in your environment, and that an assessor can read.

  • 01

    CUI scope and data-flow map

    A documented picture of every system, person, and third party that stores, processes, or transmits CUI, plus the assets we deliberately leave out of scope.

  • 02

    Gap assessment and weighted score

    All 320 assessment objectives scored met / not met / partially met, with your current SPRS score and your projected score after each remediation phase.

  • 03

    System Security Plan (SSP)

    A living SSP that describes how each requirement is actually implemented in your environment, not a template with your logo dropped on it.

  • 04

    POA&M and remediation roadmap

    Every open item with an owner, a milestone date, and a resource estimate, sequenced by point value so your score climbs fastest.

  • 05

    Policy and procedure set

    The full policy library CMMC expects, written to match how your company actually operates so your staff can pass an interview.

  • 06

    Evidence library

    Screenshots, configuration exports, logs, and artifacts organized by assessment objective and kept current. It is the single thing that saves the most time on assessment day.

Straight answers

CMMC Level 2 Compliance: questions we get asked

Ask us something else

How long does CMMC Level 2 compliance take?

For a small contractor with a well-defined CUI enclave, eight to twelve months from kickoff to assessment-ready is realistic. Companies with sprawling on-premises environments, legacy engineering applications, or no existing identity platform take longer. The gap assessment gives you a real timeline in the first few weeks rather than a guess.

Do we need a C3PAO or can we self-assess?

It depends on the clauses in your contracts and the type of information you handle. Level 1 and a subset of Level 2 contracts allow self-assessment with an annual affirmation. Most CUI-bearing Level 2 contracts require a certification assessment by an accredited C3PAO. We review your contracts and tell you which applies before you commit budget.

Can you work with our existing IT provider?

Yes. We regularly act as the compliance layer alongside an incumbent MSP, taking responsibility for the CMMC program while they continue to run day-to-day IT. That said, most clients eventually consolidate with us because the handoffs between an IT provider and a separate compliance consultant are where programs stall.

What does CMMC Level 2 compliance cost?

Far less than the six-figure annual programs many contractors are quoted. Your cost is driven by how many users and endpoints are in scope, whether we can build a small CUI enclave instead of hardening your whole company, and how much of the foundation you already have. We quote fixed fees so you are not exposed to open-ended hourly billing.

Next step

Ready to talk about cmmc level 2 compliance?

Tell us your size, your contracts, and where you are today. We will tell you what it takes and roughly what it costs, usually on the first call.