CMMC / Level 2 readiness
Everything an assessor asks for, written about your business rather than a template.
A readiness engagement ends with a documented, evidenced, defensible position and a score you can affirm. It does not end with a report handed back to you to act on alone.
What gets delivered
System Security Plan
Written against your actual environment and boundary. The first document an assessor opens and the one most often generic.
Plan of Action and Milestones
Every open item with an owner, a target date and a source. A tracker that drives the work, not a parking lot.
Policy set
All fourteen control families, in language your people will actually follow, because a policy nobody reads fails at interview.
Three diagrams
CUI flow, network boundary and physical site. Missing diagrams are a routine and entirely avoidable finding.
Asset inventory and AUL
What is in scope, who has access, and the categories each asset falls into under the CMMC scoping guidance.
SPRS score
Calculated honestly with you, and posted. We will tell you when something is not implemented.
How the engagement runs
We scope first, because the boundary determines the size of everything else. Then we assess against all 110 controls, remediate what failed, and write the documentation from the environment as it actually is once the remediation has landed.
Evidence collection starts as early as possible rather than at the end, because artifacts need real dates on them. The items with a genuine clock, vulnerability scan history in particular, are identified in week one and started immediately.
What we will not do
We will not inflate a SPRS score, and we will not describe a control as implemented because implementing it is on a roadmap. Your Affirming Official signs the affirmation and the exposure is theirs, so an optimistic number is not a favour to anybody.
We are not a C3PAO and we do not certify. That is deliberate: it means we can remediate what we assess and then stay on to run it, which an assessor is constrained from doing.
Start with a scoping call.
Thirty minutes tells us the shape of your boundary, and tells you roughly what the program costs and how long it takes.
If you are a defense supplier under 25 people, start with the grant. Cyber Grants Alliance, a nonprofit, awards a fully funded gap assessment. It costs you nothing and you are under no obligation to buy anything afterwards, from us or from anyone.