CMMC Compliance Services

CMMC Level 2 Compliance for Defense Contractors

Phase 2 enforcement begins November 2026. Only 1% of required contractors are certified. Strata gets small defense businesses compliant — on time, on scope, and without the Big 4 invoice.

What is CMMC?

The Cybersecurity Maturity Model Certification is the Department of Defense's framework for verifying that defense contractors actually protect Controlled Unclassified Information (CUI). It replaces the previous self-attestation model — where contractors could claim compliance on a form without anyone checking — with mandatory third-party assessments for Level 2 and above.

If your company handles CUI as part of a defense contract (or subcontract), you need CMMC Level 2 certification. That means implementing all 110 security controls from NIST SP 800-171, documenting them in a System Security Plan, collecting evidence artifacts, and passing an assessment by an accredited C3PAO. The stakes are straightforward: no certification, no contract.

Who needs it

Defense contractors and subcontractors who handle CUI. If your contract includes DFARS 252.204-7012 or 7021, you're in scope.

What's at stake

Lost contracts, ineligibility to bid, and potential False Claims Act liability for contractors who self-attested compliance they didn't have.

Three phases. No ambiguity.

Every engagement follows the same structured path from gap analysis to certification.

1

Assess

4–6 weeks

  • Gap analysis against all 110 NIST 800-171 controls
  • Current SPRS score calculation
  • CUI boundary scoping and data flow mapping
  • Technology inventory and architecture review
  • Risk assessment and prioritized remediation roadmap

Deliverable: Gap assessment report with scored findings and remediation plan

2

Remediate

3–8 months

  • System Security Plan (SSP) documentation
  • Policy and procedure creation (14 control families)
  • Technical control implementation and configuration
  • Evidence collection framework setup
  • Plan of Action & Milestones (POA&M) management
  • Employee security awareness training

Deliverable: Complete SSP package, implemented controls, evidence repository

3

Certify

4–8 weeks

  • C3PAO selection assistance
  • Mock assessment with realistic scenarios
  • Evidence review and completeness verification
  • Staff interview preparation
  • Assessment day support and coordination
  • Finding remediation if needed

Deliverable: Assessment-ready organization with verified evidence

I've implemented these controls. I didn't just read about them.

Practitioner, Not Auditor

I don't hand you a checklist and leave. I configure the firewalls, write the GPOs, set up the SIEM, and deploy the endpoint protection. The controls get implemented by the same person who documented them.

Custom Compliance Tooling

I built an AI-powered meeting assistant with a dedicated CMMC consulting mode. It transcribes assessment prep sessions, surfaces relevant NIST controls in real time, and drafts documentation. That's the level of engineering applied to every engagement.

See How We Engineer AI →

Right-Sized for Small Business

Strata is built for companies with 5–50 employees. You don't need a 20-person consulting team billing $400/hour. You need one engineer who understands your scale, your budget, and the 110 controls standing between you and your next contract.

November 2026 Is Real

Phase 2 enforcement isn't a rumor. The rule is final. Primes are already including CMMC requirements in new solicitations. Contractors who start now have time to get it right. Contractors who wait will be scrambling — and paying rush rates to firms that are already booked.

Common questions about CMMC compliance.

How long does CMMC Level 2 compliance take?

For a typical small business with 5–50 employees, expect 6 to 12 months from initial gap assessment to assessment-ready status. The timeline depends on your starting posture — companies with existing security policies and IT infrastructure move faster. Companies starting from scratch or with significant technical debt should plan for the longer end.

How much does CMMC compliance cost?

Total cost varies based on your current security posture and scope. A gap assessment typically runs $5,000–$15,000. Full remediation and documentation for a small business ranges from $30,000–$100,000 depending on technical requirements. The C3PAO assessment itself is a separate cost set by the assessor, typically $30,000–$60,000 for small organizations.

Strata's rates are structured for businesses with 5–50 employees — significantly less than Big 4 consulting firms charging $300–$500/hour per consultant.

Do I need CMMC if I'm a subcontractor?

Yes, if you handle Controlled Unclassified Information (CUI) as part of a defense contract. CMMC requirements flow down through the supply chain. If your prime contractor's contract includes DFARS 252.204-7012 or the new DFARS 252.204-7021 clause, you will need CMMC certification at the level specified.

Even if your prime hasn't asked yet, they will. The contractors who are already compliant will be first in line for work.

What's the difference between Level 1 and Level 2?

Level 1 covers 17 basic cyber hygiene practices — antivirus, password policies, physical access controls — and allows annual self-assessment. Level 2 maps to all 110 controls in NIST SP 800-171 and requires a third-party assessment by an accredited C3PAO.

Level 2 is significantly more rigorous. It requires a System Security Plan (SSP), Plan of Action & Milestones (POA&M), evidence artifacts for every control, and documented policies covering 14 control families. If you handle CUI, Level 2 is almost certainly what you need.

What happens if I fail my C3PAO assessment?

A failed assessment means you cannot bid on or fulfill contracts requiring that CMMC level until you remediate the findings and pass a reassessment. This means lost revenue and potentially losing existing contracts when they come up for renewal.

More critically, if you've been self-attesting compliance via SPRS scores while not actually meeting the controls, you face potential liability under the False Claims Act. The goal of working with a consultant is to make sure you never get to this point — a properly conducted mock assessment catches gaps before the real one.

Can I handle CMMC compliance internally?

Technically yes, but for most small businesses it's not practical. CMMC Level 2 requires deep understanding of 110 NIST 800-171 controls, proper evidence collection methodology, SSP documentation that assessors will accept, and the technical ability to implement controls across your entire CUI boundary.

The risk of getting it wrong — failed assessment, delayed contracts, FCA exposure — typically outweighs the cost of expert guidance. Most small defense businesses don't have dedicated compliance staff, and pulling engineers off production work to learn NIST 800-171 from scratch is expensive in its own way.

What is a SPRS score and why does it matter?

SPRS (Supplier Performance Risk System) is the DoD's scoring system for NIST 800-171 compliance. Scores range from -203 to 110, where 110 means full implementation of all controls. You're required to submit your SPRS score today — before CMMC assessments even begin.

Many contractors have submitted scores without actually implementing the controls. This creates real legal exposure under the False Claims Act. A gap assessment establishes your actual score so you know exactly where you stand and what needs to happen before your C3PAO assessment.

Don't wait for your prime to ask.

CMMC Phase 2 enforcement is 5 months away. A gap assessment takes 4–6 weeks. The math is straightforward — the time to start is now.