Skip to content

CMMC

Cybersecurity Maturity Model Certification readiness for defense contractors handling controlled information.

Overview

If you are in the defense supply chain, CMMC determines whether you can win and keep contracts. We help you reach the required level by building the controls, around identity, access, monitoring, and data protection, into your Microsoft environment.

We map your obligations to a concrete plan, implement the technical controls, and assemble the evidence so an assessment is a confirmation, not a scramble.

How We Work

1

Scoping and gap assessment

We define where CUI lives, shrink that boundary, and assess the gap to your target level.

2

Remediation

We implement the controls and write the System Security Plan, with evidence collected as we go.

3

Assessment readiness

We run you through a mock assessment and keep controls and documentation current for the real one.

What's Included

Readiness assessment

A gap analysis against your target CMMC level and a prioritized plan.

Technical controls

Identity, access, encryption, and monitoring implemented on Microsoft.

Controlled environment

A compliant home for controlled unclassified information.

Policy and documentation

The policies and SSP evidence assessors expect to see.

Monitoring and logging

Continuous monitoring that satisfies the requirements and protects you.

Assessment support

We stand with you through the assessment process.

Implementation Options

Three ways to start, depending on how much certainty you want before you commit. Estimates and rates are quoted in your proposal.

T&M Remediation

Details
  • The full remediation on time and materials, billed to actual hours as consumed
  • A written estimate up front, revisited at every phase gate
  • Design and build run in parallel: the blueprint evolves while early phases are already being delivered
  • Scope stays flexible, with changes approved through a written change order
Best fit for
  • Simpler footprints with a clear picture of their requirements
  • Teams comfortable steering scope as the work unfolds

Fixed-Fee Gap Assessment & Roadmap

Details
  • The first phase of a full remediation, run as a standalone engagement with its own deliverables (we call it Phase 0)
  • Current state documented, future state designed, and the remediation blueprint delivered
  • A fixed-fee remediation proposal, priced against confirmed scope
  • Deliverables are platform-agnostic, not tied to Microsoft or to us, and detailed enough for any qualified partner to quote a fixed fee
  • The fee is credited in full toward the remediation if you proceed with us within three months
Best fit for
  • Complex or unclear scope, where guessing is expensive
  • Boards and leadership teams that prefer the certainty of a detailed roadmap and fixed-fee scope before implementation kicks off
Learn more about Phase 0

Fixed-Fee Remediation

Details
  • Follows a completed Discovery & Design engagement
  • The remediation at a fixed price, quoted against the scope confirmed in discovery and design
  • Milestone billing tied to deliverables you can verify
  • Change orders only when the scope itself changes
Best fit for
  • Budget certainty required before kickoff
  • Regulated or board-governed purchases

Support & Training Options

Compliance is a program, and readiness fades without upkeep. Choose how much of the program we carry. The flat-fee program runs on a rolling 90-day commitment; readiness projects are standalone.

T&M readiness project

Details
  • Gap assessment against CMMC, scoped in writing and billed hourly
  • Remediation of findings, prioritized by risk
  • A roadmap you could execute with any provider
Best fit for
  • A first engagement, or a deadline-driven push
  • Teams with internal owners who need expert hands

Flat-fee compliance program

Details
  • Reduced professional services rates for your remediation
  • Continuous monitoring of the technical controls
  • Evidence collection that stays current instead of piling up before audits
  • Policy reviews and security awareness training
  • Support during assessments and customer security questionnaires
Best fit for
  • Businesses where CMMC is a standing customer or regulator requirement
  • Leadership that never wants to scramble before an audit again

Fully managed IT & compliance

Everything in the flat-fee compliance program option, plus managed IT services:

  • Our lowest professional services rates for your remediation, as part of a holistic ongoing engagement
  • The IT operation underneath the controls, run by the same team
  • Helpdesk, patching, backups, and vendor management
  • Security monitoring, threat response, and email security
  • SLA on system-blocking issues
Best fit for
  • Regulated companies without internal IT
  • Teams tired of compliance and IT vendors pointing at each other

Who This Is For, and Who It Is Not

A strong fit if

  • You hold, or expect to hold, Department of Defense contracts carrying CMMC clauses.
  • Controlled unclassified information moves through your email, file shares, or engineering systems.
  • You have a self-assessment score posted and a plan of action nobody has worked through.
  • You want a bounded environment for controlled information rather than pulling the whole company into scope.
  • An assessment is scheduled and the system security plan and evidence are not assembled.

A poor fit if

  • You want the documentation without the controls. An assessor tests whether controls operate, not whether they are written down.
  • You are not sure whether CMMC applies to your contracts. Start with a contract review, because the answer sets both the level and the scope.
  • You need a cleared facility, classified processing, or physical security work. That sits outside what we do.

Frequently Asked Questions

All questions
What is CMMC?

CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense's cybersecurity certification for its supply chain. If your contracts touch controlled unclassified information, certification is becoming a condition of keeping and winning that work. We build the controls and get you assessment-ready. One scoping strategy that saves small suppliers real money: walling off your CUI instead of moving the whole company.

How is this different from the NIST self-assessment we already did?

For years, defense contractors self-attested to NIST 800-171 and nothing was checked. CMMC ends that: a third-party assessor verifies the controls. The difference between self-attestation and certification is the difference between saying and proving.

Does CMMC apply to us?

It applies to defense contractors and subcontractors with controlled unclassified information in scope, and the clauses are already showing up in contracts and flow-downs. If you hold no controlled information and never will, basic cyber hygiene may be all your contracts require. Scoping is the first conversation, and it sometimes shrinks the problem dramatically. One strategy that saves small suppliers real money: walling off your CUI instead of moving the whole company.

Do you run the audit or certification itself?

No. Auditors and assessors have to stay independent, so the same firm cannot build your controls and certify the result. We build the controls, assemble the evidence, and sit beside you during the assessment, so the auditor finds a running system rather than a scramble.

What happens in the first 90 days?

Weeks one and two are access and visibility: admin roles audited, MFA enforced, monitoring on your most critical systems, and a shared password vault. Weeks three to eight set the baseline: licensing rationalized, device management everywhere, backups running and test-restored. By week 13 you have a steady rhythm: a weekly status call, a patch cadence, playbooks you own, and a 90-day review that sets the roadmap.

How does pricing work?

Managed services run at a flat monthly rate per person, which covers their primary device; shared and additional devices are a small add-on. Project work is hourly and quoted in writing before it starts, or converted to a fixed monthly fee when you want budget certainty. Microsoft licensing passes through at list price.

Do you require long-term contracts?

No. Our standard commitment is a rolling 90 days, so we earn your business every quarter. Everything we build lives in your own Microsoft tenant with nothing proprietary in the way, which keeps that promise real: you could hand the keys to any provider tomorrow.

Related Reading

All insights
Featured

Latest

Jul 16, 2026CMMC and your Microsoft 365 tenant: why GCC high changes what software can connectA defense-adjacent manufacturer heading into a CMMC mock audit learned that a government-cloud Microsoft tenant can quietly limit which apps integrate with it.Microsoft SecurityJun 5, 2026Getting off paper: ERP for small regulated manufacturersFor a small regulated manufacturer still running on paper and spreadsheets, moving to an ERP is as much a change-management project as a software one. Here is what the system needs to enforce, and how to bring the team with you.Business CentralApr 22, 2026CMMC level 2 for small defense suppliers: wall off your CUI instead of moving the whole companyWhen controlled data touches only a slice of your work, you can shrink CMMC Level 2 scope by walling CUI into a governed enclave instead of dragging the whole company in.Microsoft SecurityApr 16, 2026Your staff are already using AI. For a HIPAA-regulated org, governed Copilot beats banning it.When staff paste protected health information into public chatbots, you can't ban your way out; a governed Microsoft 365 Copilot keeps the data in your tenant.Microsoft 365Apr 7, 2026FDA validation just changed (CSV to CSA): keep your quality system out of your ERPThe FDA's move from computer system validation to Computer Software Assurance, plus keeping quality management out of the ERP, can shrink the biggest cost in a regulated ERP project.Business Central

Win and keep defense work

Tell us your target level and timeline and we will show you the distance.

30 minutesNo obligationGet an initial estimate within one week