CMMC Level 2 gap assessment
A CMMC Level 2 gap assessment that scores all 110 controls.
We score your environment against every NIST SP 800-171 control, calculate your SPRS score, and tell you what is missing and what closing each gap takes. A gap assessment, published price, nothing bundled in.
A gap assessment is how you find out where you actually stand, before the clock matters.
The real problem
The date is not the hard part. Starting late is.
Self-assessment and evidence collection take real calendar time. Expect to be asked how long a control has been running, not only whether it exists.
Treating compliance as scheduled work with named owners, rather than a document to write the week before, is what makes the date survivable. If your assessment is inside the next two months and evidence collection has not started, that is the thing to fix first, ahead of the policies.
What it costs
For most small and mid-sized contractors. Larger firms are scoped and quoted individually. The $5,000 is the gap assessment and nothing else.
Already know you need the full build? See CMMC In A Container™, our managed program with published pricing.
Wondering how that compares? What a CMMC Level 2 gap assessment costs in 2026, with every figure sourced.
What you actually receive
4 DELIVERABLESA gap assessment tells you where you stand and what closing each gap takes. It does not review or write your policies, it does not collect evidence, and it does not choose tools or design the fix.
Writing your System Security Plan and policies, collecting evidence, and closing the gaps is separate work: our System Security Plan, policy and POA&M service, or CMMC In A Container™, which runs the whole program with you. Everything else we do is listed on Services.
$5,000 gap assessment, 4 deliverables
- Control findings
- SPRS score
- Evidence and scoping review
- Broad POA&M
Control-by-control findings
All 110 NIST SP 800-171 controls scored against what you actually have today, with the gap named for every control that is not met.
SPRS score
Calculated against all 110 controls using the DoD Assessment Methodology, so you know your number. Posting a score to SPRS requires a System Security Plan in place. If you do not have one, that is our SSP service.
Evidence and scoping review
The evidence you already hold, and your CUI flow diagram, network boundary diagram, physical site diagram and authorized user list, or a note that one is missing.
Broad POA&M
Every open control and what closing it requires, at a high level. It does not choose tools or design the fix; that is remediation work, scoped separately.
Gap assessment, documents, or the whole program
WHAT EACH ONE BUYS| CMMC Level 2 gap assessment | SSP, policy and POA&M | CMMC In A Container™ | |
|---|---|---|---|
| Price | $5,000, one time | Scoped per client | From $750 a month plus a $6,000 one-time build |
| Scores all 110 controls | Yes | No | Yes |
| Calculates your SPRS score | Yes | No | Yes, and posts it |
| Writes your System Security Plan | No | Yes | Yes |
| Writes your policies | No, and does not review them | Yes | Yes, the full set |
| POA&M | A broad one, no tool or design choices | Yes, written | Yes, and closed with you |
| Collects evidence | No, reviews what you hold | No | Yes, reviewed quarterly |
| Runs your environment and security | No | No | Yes, as your MSSP |
How it works
4 STEPSFour steps, in this order. The assessment reviews what exists. It does not build what is missing.
- STEP 1ScopeContract and CUI
- STEP 2ReviewEvidence and scoping
- STEP 3Score110 controls, SPRS
- STEP 4RecommendBroad POA&M
Scope
We confirm which contract sets your requirement and where CUI enters, moves and rests in your business. If you are not sure you need Level 2, this is where you find out.
Review
We review the evidence you already hold and your scoping artifacts against the 110 controls. Policies are not reviewed as part of this engagement.
Score
Every control scored against what you actually have, and your SPRS score calculated. A straight answer on where you stand, not a sales pitch.
Recommend
You get the findings, the score, and a broad POA&M: what closing each gap takes, at a high level, without tool or design choices. What happens next is your decision, with us or without us.
If your contract requires a C3PAO assessment, that assessment is separate, done by an authorized C3PAO, and not part of this engagement.
Closing the gaps is where calendar time goes, not the assessment. Vulnerability scan history, log retention and access reviews accumulate in weeks, not hours, so start them as soon as the findings are in.
Understanding CMMC Level 2
WHAT IT ASKS FORCMMC Level 2 applies when a contract requires you to handle Controlled Unclassified Information, CUI. It maps directly to the 110 security controls in NIST SP 800-171, the same controls DFARS 252.204-7012 has required contractors to implement since 2017. The obligation to post a score for those controls into SPRS comes from a different clause, DFARS 252.204-7019. CMMC adds verification on top of both.
Handling Federal Contract Information without CUI is Level 1, a lighter, self-assessed 15-control set. If your contract or subcontract flows down CUI, you are looking at Level 2.
Some Level 2 contracts allow a self-assessment: conducted every three years and submitted to SPRS, with an affirmation at the time of the assessment and annually after it. Others, tied to the DoD's most sensitive programs, require a certification assessment performed by an accredited third-party assessor, a C3PAO, every three years. Your contract, not your preference, decides which one applies to you. Capital Cyber is not a C3PAO. We prepare you for whichever one your contract requires; we do not perform the certification assessment itself. That is deliberate. A C3PAO is independent by design, which is why it does not write your documents, and it is why we can remediate what we assessed and then stay on to run it.
Status as of 26 September 2026. On 13 July 2026 the Department of War suspended the requirement for a C3PAO certification assessment as a condition of award, pending a review. The review's report was due on 11 September and has not been made public. Self-assessments against NIST SP 800-171 Rev 2, a current status and affirmation in SPRS, and DFARS 252.204-7012 all still apply. With no third-party assessor in between, your Affirming Official's signature is the only assurance the government has, which makes an honest score matter more, not less.
The 14 control families
All 14 in scope for Level 2. Scored against your actual environment, not a sample.
Questions
BEFORE YOU CALLThe questions buyers ask most, with plain answers, are on the FAQ page.
Book a 30-minute call about the gap assessment.
BOOK A CALLTell us which contract you are working to and we will tell you what the assessment covers for you. Pick a time.
What happens in 30 minutes
- We read your contract's CMMC and DFARS clauses with you.
- We confirm which level applies and how it will be assessed.
- We tell you the first step, whether or not it involves us. No slides.
Ready to see where you actually stand?
A CMMC Level 2 gap assessment scores all 110 controls against your real environment. No portal, no subscription, documents you keep.
Defense supplier under 25 people? Start with the grant.
Cyber Grants Alliance, a nonprofit, awards in-kind cybersecurity grants. It provides the gap assessment itself, not cash. It costs you nothing, and you are under no obligation to buy anything afterward, from us or from anyone.