CMMC Level 2 · Defense Industrial Base · Leesburg, VA+1 571 410-3066
Capital Cyber Compliance

CMMC Level 2 gap assessment

A CMMC Level 2 gap assessment that scores all 110 controls.

We score your environment against every NIST SP 800-171 control, calculate your SPRS score, and tell you what is missing and what closing each gap takes. A gap assessment, published price, nothing bundled in.

Book a 30-minute callCMMC LEVEL 2 GAP ASSESSMENT, $5,000

A gap assessment is how you find out where you actually stand, before the clock matters.

The real problem

The date is not the hard part. Starting late is.

Self-assessment and evidence collection take real calendar time. Expect to be asked how long a control has been running, not only whether it exists.

Treating compliance as scheduled work with named owners, rather than a document to write the week before, is what makes the date survivable. If your assessment is inside the next two months and evidence collection has not started, that is the thing to fix first, ahead of the policies.

What it costs

$5,000 / CMMC Level 2 gap assessment, one time

For most small and mid-sized contractors. Larger firms are scoped and quoted individually. The $5,000 is the gap assessment and nothing else.

Book a 30-minute call

What you actually receive

4 DELIVERABLES

A gap assessment tells you where you stand and what closing each gap takes. It does not review or write your policies, it does not collect evidence, and it does not choose tools or design the fix.

Writing your System Security Plan and policies, collecting evidence, and closing the gaps is separate work: our System Security Plan, policy and POA&M service, or CMMC In A Container™, which runs the whole program with you. Everything else we do is listed on Services.

Control findingsSPRS scoreEvidence and scoping reviewBroad POA&M$5,000gap assessment4 deliverables

$5,000 gap assessment, 4 deliverables

  • Control findings
  • SPRS score
  • Evidence and scoping review
  • Broad POA&M

Control-by-control findings

All 110 NIST SP 800-171 controls scored against what you actually have today, with the gap named for every control that is not met.

SPRS score

Calculated against all 110 controls using the DoD Assessment Methodology, so you know your number. Posting a score to SPRS requires a System Security Plan in place. If you do not have one, that is our SSP service.

Evidence and scoping review

The evidence you already hold, and your CUI flow diagram, network boundary diagram, physical site diagram and authorized user list, or a note that one is missing.

Broad POA&M

Every open control and what closing it requires, at a high level. It does not choose tools or design the fix; that is remediation work, scoped separately.

Gap assessment, documents, or the whole program

WHAT EACH ONE BUYS
CMMC Level 2 gap assessmentSSP, policy and POA&MCMMC In A Container™
Price$5,000, one timeScoped per clientFrom $750 a month plus a $6,000 one-time build
Scores all 110 controlsYesNoYes
Calculates your SPRS scoreYesNoYes, and posts it
Writes your System Security PlanNoYesYes
Writes your policiesNo, and does not review themYesYes, the full set
POA&MA broad one, no tool or design choicesYes, writtenYes, and closed with you
Collects evidenceNo, reviews what you holdNoYes, reviewed quarterly
Runs your environment and securityNoNoYes, as your MSSP

How it works

4 STEPS

Four steps, in this order. The assessment reviews what exists. It does not build what is missing.

  1. STEP 1ScopeContract and CUI
  2. STEP 2ReviewEvidence and scoping
  3. STEP 3Score110 controls, SPRS
  4. STEP 4RecommendBroad POA&M
Step 1

Scope

We confirm which contract sets your requirement and where CUI enters, moves and rests in your business. If you are not sure you need Level 2, this is where you find out.

Step 2

Review

We review the evidence you already hold and your scoping artifacts against the 110 controls. Policies are not reviewed as part of this engagement.

Step 3

Score

Every control scored against what you actually have, and your SPRS score calculated. A straight answer on where you stand, not a sales pitch.

Step 4

Recommend

You get the findings, the score, and a broad POA&M: what closing each gap takes, at a high level, without tool or design choices. What happens next is your decision, with us or without us.

If your contract requires a C3PAO assessment, that assessment is separate, done by an authorized C3PAO, and not part of this engagement.

Closing the gaps is where calendar time goes, not the assessment. Vulnerability scan history, log retention and access reviews accumulate in weeks, not hours, so start them as soon as the findings are in.

Understanding CMMC Level 2

WHAT IT ASKS FOR

CMMC Level 2 applies when a contract requires you to handle Controlled Unclassified Information, CUI. It maps directly to the 110 security controls in NIST SP 800-171, the same controls DFARS 252.204-7012 has required contractors to implement since 2017. The obligation to post a score for those controls into SPRS comes from a different clause, DFARS 252.204-7019. CMMC adds verification on top of both.

Handling Federal Contract Information without CUI is Level 1, a lighter, self-assessed 15-control set. If your contract or subcontract flows down CUI, you are looking at Level 2.

Some Level 2 contracts allow a self-assessment: conducted every three years and submitted to SPRS, with an affirmation at the time of the assessment and annually after it. Others, tied to the DoD's most sensitive programs, require a certification assessment performed by an accredited third-party assessor, a C3PAO, every three years. Your contract, not your preference, decides which one applies to you. Capital Cyber is not a C3PAO. We prepare you for whichever one your contract requires; we do not perform the certification assessment itself. That is deliberate. A C3PAO is independent by design, which is why it does not write your documents, and it is why we can remediate what we assessed and then stay on to run it.

Status as of 26 September 2026. On 13 July 2026 the Department of War suspended the requirement for a C3PAO certification assessment as a condition of award, pending a review. The review's report was due on 11 September and has not been made public. Self-assessments against NIST SP 800-171 Rev 2, a current status and affirmation in SPRS, and DFARS 252.204-7012 all still apply. With no third-party assessor in between, your Affirming Official's signature is the only assurance the government has, which makes an honest score matter more, not less.

The 14 control families

Access ControlAwareness & TrainingAudit & AccountabilityConfiguration ManagementIdentification & AuthenticationIncident ResponseMaintenanceMedia ProtectionPersonnel SecurityPhysical ProtectionRisk AssessmentSecurity AssessmentSystem & Communications ProtectionSystem & Information Integrity

All 14 in scope for Level 2. Scored against your actual environment, not a sample.

Questions

BEFORE YOU CALL

The questions buyers ask most, with plain answers, are on the FAQ page.

Book a 30-minute call about the gap assessment.

BOOK A CALL

Tell us which contract you are working to and we will tell you what the assessment covers for you. Pick a time.

What happens in 30 minutes

  1. We read your contract's CMMC and DFARS clauses with you.
  2. We confirm which level applies and how it will be assessed.
  3. We tell you the first step, whether or not it involves us. No slides.

Ready to see where you actually stand?

A CMMC Level 2 gap assessment scores all 110 controls against your real environment. No portal, no subscription, documents you keep.

Book a 30-minute call

Defense supplier under 25 people? Start with the grant.

Cyber Grants Alliance, a nonprofit, awards in-kind cybersecurity grants. It provides the gap assessment itself, not cash. It costs you nothing, and you are under no obligation to buy anything afterward, from us or from anyone.

Apply for a CGA grant