FAQ
Questions contractors ask before they call.
Plain answers about CMMC Level 2, NIST SP 800-171, and what a gap assessment covers.
How do I know if I need CMMC Level 2, not Level 1?
If any contract or subcontract you hold flows down Controlled Unclassified Information, CUI, you need Level 2. If you only handle Federal Contract Information and never CUI, Level 1 is the lighter requirement. Two clauses do two different jobs here. DFARS 252.204-7012 is what puts the CUI safeguarding obligation into your contract. DFARS 252.204-7021 is where the level itself appears: the contracting officer writes it into the clause, and the options it offers are Level 1 self, Level 2 self, Level 2 C3PAO, or Level 3. If you are not sure which applies, that question is the first thing a gap assessment answers.
How long does a gap assessment take?
It depends on how wide your CUI boundary turns out to be and how much documentation already exists, so we scope the schedule with you rather than publish a number we would have to caveat. One part is fixed no matter how the rest goes: evidence collection runs on calendar time, because scan history and log retention accumulate whether you hurry or not. Start that before you think you need to.
Do I need a C3PAO, or can I self-assess?
Your contract decides this, not you. Where a contract allows the self-assessment route, 32 CFR 170.16 sets the cycle: the self-assessment is conducted every three years and submitted to SPRS, with an affirmation at the time of each assessment and annually thereafter. Other contracts, tied to DoD's highest-priority programs, require a certification assessment by an accredited C3PAO. We help you find out which one your contract actually requires, and prepare you for it either way.
We already have Microsoft GCC High. Are we covered?
GCC High addresses where CUI is stored and processed, which is real and worth having. It does not on its own satisfy any of the 14 control families end to end: access control, incident response, personnel security, physical protection and the rest still need to be configured, documented and evidenced against your own environment. A gap assessment tells you exactly what GCC High already covers and what is still open.
What if the assessment finds we are not ready?
That is the expected outcome for most first assessments, not a failure. You leave with a broad POA&M: every open control and what closing it requires, at a high level. Working that list to closure is the job, and Iron Lift, our named engagement, is at 110 of 110 controls met as of 2026-09-15, per their self-assessment.
Does the $5,000 cover everything?
It covers the CMMC Level 2 gap assessment and the four deliverables listed above, for most small and mid-sized contractors, and nothing else. It does not include remediation work a client chooses to have us perform afterward, such as implementing specific controls or standing up new tooling. It does not review or write your policies, it does not write your System Security Plan, it does not collect evidence, and its POA&M does not choose tools or design the fix. Each of those is scoped and priced separately once the gap assessment shows what is actually needed. Larger firms are scoped and quoted individually rather than against the published figure.
Already know you want to talk?
BOOK A CALLSkip the form. Pick a time and talk to us directly.
What happens in 30 minutes
- We read your contract's CMMC and DFARS clauses with you.
- We confirm which level applies and how it will be assessed.
- We tell you the first step, whether or not it involves us. No slides.
Defense supplier under 25 people? Start with the grant.
Cyber Grants Alliance, a nonprofit, awards in-kind cybersecurity grants. It provides the gap assessment itself, not cash. It costs you nothing, and you are under no obligation to buy anything afterward, from us or from anyone.