CMMC & Defense Supply Chain Compliance
If your contracts touch Controlled Unclassified Information, your compliance posture is now a condition of doing business.
What this is
How we approach it
We take suppliers through CMMC readiness against NIST SP 800-171 and the DFARS 252.204-7012 clause: what is actually in scope, where the CUI really flows, and which of the 110 controls you can evidence today.
The output is the artefact set an assessor expects: a scoped System Security Plan, a POA&M that is honest about gaps, and an SPRS score you can defend, not a spreadsheet of aspirations.
- CUI scoping: data flows, enclave boundary, and what can be taken out of scope
- Gap assessment against all 110 NIST SP 800-171 controls
- System Security Plan (SSP) and POA&M
- SPRS score calculation and submission support
- C3PAO assessment preparation and evidence walkthrough
Who this is for
You will recognise yourself here
How an engagement runs
Four stages
Each stage produces something you keep, whether or not you continue to the next one.
Questions we get asked
Straight answers
Do we need CMMC Level 1 or Level 2?
Level 1 applies if you only handle Federal Contract Information; Level 2 applies once Controlled Unclassified Information is in play and mirrors the 110 controls of NIST SP 800-171. The scoping step settles it, and the answer determines whether you need a self-assessment or a C3PAO assessment.
How long does CMMC readiness take?
It depends on how much you can take out of scope. A tightly scoped CUI enclave can be assessment-ready in a few months; a flat network handling CUI everywhere takes considerably longer, which is exactly why scoping comes first.
Can you write the SSP and POA&M for us?
Yes. We author the System Security Plan and POA&M with your team, so the documents describe the environment you actually run and your people can defend them under assessment.
Does a low SPRS score stop us bidding?
A current self-assessment score in SPRS is a condition of many awards, and a low score is a competitive disadvantage rather than an automatic disqualification. We prioritise the controls that move the score most per unit of effort.
Other services
Often scoped together
Cloud Architecture Security & FinOps
Secure, optimise and govern your cloud architecture.
Read more →Cyber Risk, Compliance & Resilience
Manage your cyber risks, ensure compliance, verify your resilience.
Read more →AI Risk Services
Leverage your AI practices based on benchmarks.
Read more →Vulnerability & Penetration Testing
Identify weaknesses before someone else does.
Read more →Let's talk
Plan your security
Pick the conversation that fits. We will spend the time on your actual exposure, not on a slide deck.
Security incident? Mark it urgent when you book.
Let's review your security posture.
Let's see how to govern your security programme and strategy.
A short introductory call.
