Most contractors posted a self-score years ago and have not revisited it. We reassess against the actual assessment objectives, compute the score exactly as 32 CFR § 170.24 defines it, and produce the SSP and POA&M an assessor will accept.
We get you ready — we do not certify. Ready to self-attest, or ready to hand a third-party assessor something that holds up. For CMMC that assessor is an authorised C3PAO; only they can assess you for certification.
Four things that most readiness work skips, and an assessor does not.
§ 170.24(b) decides a requirement on its individual assessment objectives, not on a yes/no at the requirement. One unmet objective makes the requirement NOT MET. We record findings per objective, so the roll-up is the rule, not a judgement call.
42 requirements are worth 5 points, 14 are worth 3, and two — MFA and FIPS-validated encryption — carry partial credit. Those values come from the DoD Assessment Methodology, not from a vendor's interpretation of it.
Conditional status needs a score of at least 88, nothing over 1 point on the POA&M, and none of six specific requirements left open. A POA&M that breaks any of those is not a plan, it is a rejection waiting to happen.
Working papers, drafts and unapproved policies are explicitly unacceptable as evidence. Every requirement carries a reference to where the approved artefact lives in your environment — and a draft is flagged as one.
Hand us your existing policy set. We map every section to the requirements it speaks to and tell you what your documentation already covers.
We built our own rather than reselling a GRC seat, because the scoring had to be exact and the per-client cost had to be near zero. That is why the coverage map above is free.
Score, deductions by requirement, distance to 88, and “fix these five, gain 19 points” ordered by points recoverable per hour of effort.
All 110 practices by family, drilled to the NIST SP 800-171A objectives, with per-objective findings, implementation descriptions and evidence references.
Built from your implementation descriptions and scope, with a draft-to-approved gate, because drafts are not acceptable evidence.
Generated from NOT MET requirements and validated against § 170.21, with the 180-day closeout clock tracked from your Conditional status date.
Upload an existing policy set; AI maps each section to the requirements it addresses and shows the quoted sentence that justifies the mapping.
Where a gap needs a tool — EDR, MFA, FIPS-validated encryption, logging — we can quote it. We disclose what we earn a margin on and always show alternatives.
You assess against all 110, post the score to SPRS and sign the annual affirmation. This is the path almost everyone is on today, and it is a legal obligation right now — not something waiting on the reform.
When your contract calls for certification, an external assessor examines you — for CMMC, an authorised C3PAO. We make sure what they find matches what you told us: the scope, the evidence and the SSP all line up before anyone external opens them.
The Phase 2 transition was suspended on 13 July 2026, and a class deviation on 3 September made that binding. A lot of firms stopped work. That was a mistake.
The reform changes who checks your work. It does not change the obligation. Firms that downed tools in July will restart from zero; the ones that kept going will affirm on time.
Bring your contract clauses, your current SPRS score if you have one, and whatever documentation exists. A first call is scoping, not a pitch.