CMMC
CMMC 2.0 decides whether you can bid. We take defence suppliers from scoping to assessment-ready.
- Typical duration
- 4–12 months
- Primary audience
- CISOs & Boards
- You leave with
- Level 2 assessment readiness with the boundary — and the cost — kept small.
Three phases, start to finish.
- 01 CUI scoping and enclave design Where CUI actually lives, and how small the assessment boundary can be made without breaking how your people work. CUI flows mapped across systems, people and subcontractors Enclave design to shrink the assessment boundary Assessment cost modelled against each boundary option
- 02 800-171 implementation NIST SP 800-171 implemented with a defensible SPRS score and the documents an assessor expects to be handed. All 110 controls implemented with evidence, not intent System Security Plan authored to assessor expectations POA&M with dates your team can defend under questioning
- 03 Pre-assessment A full run against the CMMC Assessment Guide before a C3PAO sees anything. Pre-assessment against the CMMC Assessment Guide Objective-by-objective evidence review Level 2 assessment readiness with the cost kept small
Scoping decides the cost
The single largest cost driver in a CMMC engagement is how much of your environment handles Controlled Unclassified Information. An enclave design that isolates CUI to a defined set of systems can reduce the assessed boundary by an order of magnitude — and the assessment cost with it.
Deliverables
- CUI data flow mapping and enclave architecture
- NIST SP 800-171 implementation with a defensible SPRS score
- System Security Plan authored to assessor expectations
- POA&M with realistic closure dates
- Pre-assessment against the CMMC Assessment Guide, so nothing surfaces first in front of a C3PAO
CMMC: the questions we get asked.
What drives the cost of a CMMC engagement?
Scope, by an order of magnitude. Every system that stores, processes or transmits CUI is in scope for all 110 NIST SP 800-171 requirements, and so is anything providing security functions to those systems. Two companies of identical size routinely differ by a factor of five, and the variable is how far CUI has been allowed to spread.
What is an enclave, and do we need one?
A defined set of systems where CUI is permitted to exist, with everything else explicitly out of bounds. It imposes real friction on a small number of people, and in every engagement we have run it has been cheaper than applying 110 requirements to an entire estate. The trade should be made explicitly rather than by drift.
Do you perform the CMMC assessment?
No. Level 2 certification assessments are performed by an authorised C3PAO. We prepare you, run a full pre-assessment against the CMMC Assessment Guide, and make sure nothing surfaces for the first time in front of the assessor.
Can a Canadian company achieve CMMC?
Yes, and many need to. Canadian firms in US defence supply chains are subject to the same flow-down clauses as US suppliers, and CMMC requirements have been appearing in new DoD solicitations since November 2025, with C3PAO certification becoming mandatory in applicable solicitations from 10 November 2026. Data residency and export control — ITAR in particular — constrain the enclave design, which is why the boundary should be settled before anything is implemented.
Other lines of work
All servicesTell us what triggered the search. We will scope to that.
We reply to every assessment request within one business day.
