Clarity on your required CMMC level, a gap analysis against the 110 requirements of NIST SP 800-171 and support all the way to the assessment, so your US defense contracts stay secure.
A US framework with its own terminology, its own evidence formats and fixed contract deadlines. Existing ISO or BSI certifications cover part of the requirements but do not replace the assessment.
CMMC decides whether you can bid for US Department of Defense work at all. We establish which level applies to your contracts, which of the 110 requirements you already meet and what remains to be done before the assessment.
Level 1 covers Federal Contract Information and is self-assessed annually. Level 2 applies to Controlled Unclassified Information and is usually assessed by a C3PAO. We determine from your contract clauses what actually applies to you.
We review not only the 110 requirements of NIST SP 800-171, but the underlying assessment objectives from NIST SP 800-171A that an assessor will actually score you against.
The System Security Plan describes how each requirement is implemented. The Plan of Action and Milestones tracks open items with owners and due dates. Both documents largely determine the outcome of the assessment.
We walk through the evidence with you, run an internal mock assessment and prepare your teams for the interviews with the assessors.
Passing the assessment is not the end of CMMC. Certification is valid for three years, and in between you must affirm annually that the requirements are still met. We show you what that means in day-to-day operations.