CAPITALCYBER

CMMC Level 2 · defense suppliers of 1 to 5 people

Jenna runs a one-person shop. She is going through CMMC Level 2 right now.

Watch her say what it actually took. We did not write her script and we did not edit out the hard parts. Then decide whether you want the same thing.

Iron Lift · CMMC Level 2 readiness

What you get

An environment, the paperwork that proves it, and someone who owns it with you.

The container

A FedRAMP Moderate Authorized cloud environment holding all of your CUI. Email, file sharing, an isolated browser for prime portals, logging and training records. CUI never lands on your laptop, which is what keeps your assessment small.

Authorized, not Equivalent. Most platforms sold into this market are Equivalent, which means you hold a body of evidence and defend it. Authorized means the answer is a package ID and the argument does not happen.

The paperwork

System Security Plan. Plan of Action and Milestones. Asset inventory. Authorized User List. CUI flow, network boundary and physical site diagrams. The full policy set.

These are the artifacts an assessor asks for first, and a missing one is the most common finding there is.

The program

Your SPRS score, calculated honestly and posted. Quarterly review. Evidence collected on a schedule so it exists with real dates rather than being manufactured the week before an assessment. Annual affirmation preparation.

We are your Managed Compliance Provider and your MSSP, and we stay after go-live.

How it runs

Six weeks to documented, then it keeps running.

  1. Week 1

    Stand it up

    Scoping call, intake, environment built, your data migrated.

  2. Weeks 2–4

    Write it

    Documentation drafted against your actual environment, not a template.

  3. Week 5

    Deliver and score

    SSP, POA&M and diagrams delivered. SPRS score calculated with you.

  4. Week 6 →

    Keep it alive

    Training, then quarterly review, evidence, POA&M closure, affirmation prep.

Documentation delivered inside 45 days of your completed intake, or the build fee is refunded in full. The clock pauses on any day we are waiting on you, and pauses are logged and shared weekly so there is never a dispute about the count.

Pricing

Published, because you should not need a sales call to learn a number.

Solo · 1 user

$750 /mo

plus a $6,000 one-time build

First year total
$15,000
Years two and three, each
$9,000
Total over 36 months
$33,000
Five · up to 5 users

$3,000 /mo

plus a $15,000 one-time build

First year total
$51,000
Years two and three, each
$36,000
Total over 36 months
$123,000

The industry average for a small-business Level 2 is about $138,000 in year one. Platform licensing is included at cost inside the monthly fee, with no separate line and no markup. The platform carries no long-term commitment of its own, so your term is a commitment to us and never to a vendor we picked. If a better environment appears we move you inside your term at no charge. Prices hold for 30 days.

Questions

The ones worth asking first.

Does this certify me?+

No, and be careful with anyone who says otherwise. This is readiness. Only an accredited C3PAO can certify you and only the Department of Defense can accept a score.

Who signs the annual affirmation?+

Your Affirming Official does, in SPRS. We prepare it and tell you plainly what is and is not implemented. Signing an inflated score is a False Claims Act matter and it stays with you, which is exactly why we will not put a number in front of you that we cannot defend.

Why a 36 month term?+

Compliance is not a project with an end date. Evidence has to keep accumulating with real dates on it and the affirmation is annual, so the term matches the obligation rather than the build. After 36 months it is month to month with 60 days notice, and on exit you keep every document we produced in editable form.

Do you take custody of our CUI?+

No. Our administrative access is limited and logged. Any privileged access is requested, approved by you in writing, time limited and recorded.

Where is this the wrong answer?+

Once more than a handful of people touch CUI, or a large existing network has to come into scope, the container stops being the cheap answer. Tell us on the call and we will say so rather than sell it to you.

What is excluded?+

C3PAO assessment fees, hardware, third-party licensing outside the container, legal advice, and remediation of your existing endpoints, servers or networks. That last one is quoted separately once we have seen it.

Let us draw the boundary with you.

A scoping call is a conversation, not a pitch. Thirty minutes usually settles whether the container is right for your shop. If it is not, we will say so.

If you are a defense supplier under 25 people, start with the grant. Cyber Grants Alliance, a nonprofit, awards a fully funded gap assessment. It costs you nothing and you are under no obligation to buy anything afterwards, from us or from anyone.