Overview
If you are in the defense supply chain, CMMC determines whether you can win and keep contracts. We help you reach the required level by building the controls, around identity, access, monitoring, and data protection, into your Microsoft environment.
We map your obligations to a concrete plan, implement the technical controls, and assemble the evidence so an assessment is a confirmation, not a scramble.
How We Work
Scoping and gap assessment
We define where CUI lives, shrink that boundary, and assess the gap to your target level.
Remediation
We implement the controls and write the System Security Plan, with evidence collected as we go.
Assessment readiness
We run you through a mock assessment and keep controls and documentation current for the real one.
What's Included
Readiness assessment
A gap analysis against your target CMMC level and a prioritized plan.
Technical controls
Identity, access, encryption, and monitoring implemented on Microsoft.
Controlled environment
A compliant home for controlled unclassified information.
Policy and documentation
The policies and SSP evidence assessors expect to see.
Monitoring and logging
Continuous monitoring that satisfies the requirements and protects you.
Assessment support
We stand with you through the assessment process.
Implementation Options
Three ways to start, depending on how much certainty you want before you commit. Estimates and rates are quoted in your proposal.
T&M Remediation
- The full remediation on time and materials, billed to actual hours as consumed
- A written estimate up front, revisited at every phase gate
- Design and build run in parallel: the blueprint evolves while early phases are already being delivered
- Scope stays flexible, with changes approved through a written change order
- Simpler footprints with a clear picture of their requirements
- Teams comfortable steering scope as the work unfolds
Fixed-Fee Gap Assessment & Roadmap
- The first phase of a full remediation, run as a standalone engagement with its own deliverables (we call it Phase 0)
- Current state documented, future state designed, and the remediation blueprint delivered
- A fixed-fee remediation proposal, priced against confirmed scope
- Deliverables are platform-agnostic, not tied to Microsoft or to us, and detailed enough for any qualified partner to quote a fixed fee
- The fee is credited in full toward the remediation if you proceed with us within three months
- Complex or unclear scope, where guessing is expensive
- Boards and leadership teams that prefer the certainty of a detailed roadmap and fixed-fee scope before implementation kicks off
Fixed-Fee Remediation
- Follows a completed Discovery & Design engagement
- The remediation at a fixed price, quoted against the scope confirmed in discovery and design
- Milestone billing tied to deliverables you can verify
- Change orders only when the scope itself changes
- Budget certainty required before kickoff
- Regulated or board-governed purchases
Support & Training Options
Compliance is a program, and readiness fades without upkeep. Choose how much of the program we carry. The flat-fee program runs on a rolling 90-day commitment; readiness projects are standalone.
T&M readiness project
- Gap assessment against CMMC, scoped in writing and billed hourly
- Remediation of findings, prioritized by risk
- A roadmap you could execute with any provider
- A first engagement, or a deadline-driven push
- Teams with internal owners who need expert hands
Flat-fee compliance program
- Reduced professional services rates for your remediation
- Continuous monitoring of the technical controls
- Evidence collection that stays current instead of piling up before audits
- Policy reviews and security awareness training
- Support during assessments and customer security questionnaires
- Businesses where CMMC is a standing customer or regulator requirement
- Leadership that never wants to scramble before an audit again
Fully managed IT & compliance
Everything in the flat-fee compliance program option, plus managed IT services:
- Our lowest professional services rates for your remediation, as part of a holistic ongoing engagement
- The IT operation underneath the controls, run by the same team
- Helpdesk, patching, backups, and vendor management
- Security monitoring, threat response, and email security
- SLA on system-blocking issues
- Regulated companies without internal IT
- Teams tired of compliance and IT vendors pointing at each other
Who This Is For, and Who It Is Not
A strong fit if
- You hold, or expect to hold, Department of Defense contracts carrying CMMC clauses.
- Controlled unclassified information moves through your email, file shares, or engineering systems.
- You have a self-assessment score posted and a plan of action nobody has worked through.
- You want a bounded environment for controlled information rather than pulling the whole company into scope.
- An assessment is scheduled and the system security plan and evidence are not assembled.
A poor fit if
- You want the documentation without the controls. An assessor tests whether controls operate, not whether they are written down.
- You are not sure whether CMMC applies to your contracts. Start with a contract review, because the answer sets both the level and the scope.
- You need a cleared facility, classified processing, or physical security work. That sits outside what we do.
Frequently Asked Questions
All questionsWhat is CMMC?
CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense's cybersecurity certification for its supply chain. If your contracts touch controlled unclassified information, certification is becoming a condition of keeping and winning that work. We build the controls and get you assessment-ready. One scoping strategy that saves small suppliers real money: walling off your CUI instead of moving the whole company.
How is this different from the NIST self-assessment we already did?
For years, defense contractors self-attested to NIST 800-171 and nothing was checked. CMMC ends that: a third-party assessor verifies the controls. The difference between self-attestation and certification is the difference between saying and proving.
Does CMMC apply to us?
It applies to defense contractors and subcontractors with controlled unclassified information in scope, and the clauses are already showing up in contracts and flow-downs. If you hold no controlled information and never will, basic cyber hygiene may be all your contracts require. Scoping is the first conversation, and it sometimes shrinks the problem dramatically. One strategy that saves small suppliers real money: walling off your CUI instead of moving the whole company.
Do you run the audit or certification itself?
No. Auditors and assessors have to stay independent, so the same firm cannot build your controls and certify the result. We build the controls, assemble the evidence, and sit beside you during the assessment, so the auditor finds a running system rather than a scramble.
What happens in the first 90 days?
Weeks one and two are access and visibility: admin roles audited, MFA enforced, monitoring on your most critical systems, and a shared password vault. Weeks three to eight set the baseline: licensing rationalized, device management everywhere, backups running and test-restored. By week 13 you have a steady rhythm: a weekly status call, a patch cadence, playbooks you own, and a 90-day review that sets the roadmap.
How does pricing work?
Managed services run at a flat monthly rate per person, which covers their primary device; shared and additional devices are a small add-on. Project work is hourly and quoted in writing before it starts, or converted to a fixed monthly fee when you want budget certainty. Microsoft licensing passes through at list price.
Do you require long-term contracts?
No. Our standard commitment is a rolling 90 days, so we earn your business every quarter. Everything we build lives in your own Microsoft tenant with nothing proprietary in the way, which keeps that promise real: you could hand the keys to any provider tomorrow.
Related Reading
Latest