Compliance
CMMC
Get assessment-ready before the C3PAO arrives.
CMMC applies to companies in the US defense supply chain. If your contracts involve Federal Contract Information or Controlled Unclassified Information, certification is a condition of eligibility rather than a differentiator. Companies that are not on a path to it are already losing bids.
Levels, scoping, and who assesses you
Level 1 applies to companies handling Federal Contract Information and covers fifteen basic safeguarding requirements, met through annual self-assessment. Level 2 applies to companies handling Controlled Unclassified Information and requires the 110 security requirements of NIST SP 800-171 — for most contracts, verified by a third-party assessment. Scoping is where organisations lose the most time and money. The requirements apply to the environment where CUI is stored, processed, or transmitted. A company that lets CUI spread across its general corporate network has brought its entire estate into scope. A company that segments a defined enclave has a dramatically smaller and cheaper assessment. This decision is made early and is expensive to reverse. The roles matter and are frequently confused. A Registered Provider Organisation offers advisory and readiness services. A C3PAO — a CMMC Third-Party Assessment Organisation — performs the certification assessment. They are separate roles held by separate organisations, and a C3PAO cannot assess an environment it has consulted on. Before assessment you will need a System Security Plan describing how each requirement is met, and a Plan of Action and Milestones for anything not yet met. Engaging an assessor without an SSP in place is one of the more expensive mistakes available.
Who needs it
- Companies holding or bidding on DoD contracts that involve FCI or CUI
- Subcontractors whose prime has flowed CMMC requirements down to them
- Manufacturers and suppliers in the Defense Industrial Base uncertain which level applies
- Organisations that have submitted an SPRS score and need the underlying gaps genuinely closed
What you get
Level and scope determined first
Which level your contracts require, and where the CUI boundary sits. Scoping decisions drive the cost of everything downstream.
Gap analysis against the 110 requirements
An honest assessment of current state against NIST SP 800-171, with remediation ordered by what blocks certification versus what can follow.
Readiness separate from assessment
We match you with consultants and RPOs for the preparation work. The certification assessment is booked with an authorised C3PAO independently.
Frequently asked questions
What is the difference between Level 1 and Level 2?
Level 1 covers Federal Contract Information and fifteen basic safeguarding requirements, met by annual self-assessment. Level 2 covers Controlled Unclassified Information and the 110 requirements of NIST SP 800-171, generally requiring assessment by an authorised C3PAO. Which applies is determined by your contract terms and the type of information you handle, not by your preference.
What is the difference between an RPO and a C3PAO?
An RPO provides advisory and readiness services — helping you prepare. A C3PAO performs the certification assessment itself. They are distinct roles, and a C3PAO cannot assess an environment it has consulted on, for the same independence reasons that apply to ISO and SOC 2. Confirm which role a provider holds before engaging them.
How much does CMMC readiness cost?
The range is wide because scope drives it. A company that has segmented CUI into a defined enclave faces a far smaller programme than one where CUI is scattered across the corporate network. The assessment fee is separate from readiness work, and remediation — replacing systems that cannot meet requirements — is frequently the largest line item of the three.
Do we need an SSP before we start?
You need one before assessment, and building it early is the more efficient sequence. The System Security Plan documents how each requirement is met across your environment; the assessment is substantially a test of whether reality matches it. Engaging a C3PAO without an SSP in place typically means delay and repeated work.