CMMC
Readiness
CMMC is what turns NIST SP 800-171 from a contractual promise into something a third party checks. If you handle Controlled Unclassified Information, your eligibility for defence contracts now depends on it. We run readiness so a C3PAO assessment finds a programme rather than a plan.
Who this is for
Readiness earns its cost when something is waiting on the other side of it. These are the situations where it pays for itself.
Defence contractors and subcontractors handling CUI
Companies with a DFARS clause in a contract and a CMMC requirement attached to the next one
Suppliers whose prime has asked for evidence of their CMMC position
Organisations with an SPRS score they know does not reflect reality
What the engagement does
Your Lorikeet team runs the assessment, collects and vets the evidence, and keeps control status current. You are not handed a spreadsheet and wished well.
- Define the CUI boundary and the assets in scope, which is where most CMMC cost is decided
- Assess all practices across the fourteen 800-171 families and record where you stand
- Build the System Security Plan properly, rather than as a document written to be filed
- Produce a POA&M for what is not yet met, with owners and dates
- Close the gap list to the level the assessment requires
- Prepare for the C3PAO assessment and support you through it
What you walk away with
A defensible CUI boundary, an SSP that describes what actually exists, a POA&M that reflects real remediation, and evidence for each practice. Where your SPRS score was optimistic, you find out from us rather than from an assessor.
How it runs
Four phases. You always know which one you are in and what is outstanding.
Scoping call
We establish what is in scope, which assessment path applies, and what you already have. It costs nothing, and it ends with a straight answer about whether readiness is the right spend right now.
Assessment
We walk the control set and record where you actually stand, control by control. The gap list lands early so your team can start on the long items while the rest of the assessment continues.
Remediate and evidence
We work the gap list down with your team and collect what each control needs, filed against the control it belongs to with an owner and an expiry date rather than dumped in a folder.
Hand off to your assessor
You go in with a package that maps requirement to control to evidence, and we stay available through the assessment itself.
What the assessment covers
The control areas we walk for CMMC. Each breaks down into individual controls carrying status, owner and evidence in Talon.
Level 2 certification assessments are performed by an authorised C3PAO. We prepare you and support the assessment; we do not perform it.
It runs in Talon, not in a spreadsheet
Every control, its status, its owner and its evidence sit in the portal your team already uses, so the readiness picture you see is the one your Lorikeet team is maintaining rather than a copy that went stale a fortnight ago.
- Control-by-control status, kept current by the people doing the work
- Evidence filed against the control it satisfies, with expiry dates tracked
- The auditor request list, so nothing is chased over email
- A readiness view that shows what an assessor would see
Tools like Vanta monitor controls continuously once they exist and work. Readiness is the part before that: deciding the boundary, designing the controls, and closing the gaps a monitoring tool would otherwise report as permanently red. We work alongside them, and we are a Vanta MSP partner.
Our partnersAsked on almost every CMMC call
It depends on the information your contracts involve. Level 1 covers federal contract information with a self-assessment. Level 2 covers CUI and generally requires a C3PAO assessment. Your contract language determines it, and reading it correctly is the first thing readiness does.
Often, substantially. An enclave that isolates CUI can reduce the assessed environment dramatically. Boundary definition is the single biggest cost lever in CMMC.
Level 2 permits a limited POA&M for certain practices, with a closeout deadline - but not for the highest-weighted ones. Which practices can sit on a POA&M and which must be met is a detail worth getting right early.
Compliance you have asserted and compliance an assessor will confirm are different things. Most self-assessments we see are optimistic, usually in evidence rather than intent.
Rarely run alone
Controls overlap heavily between frameworks, and evidence collected once counts everywhere it applies. A second framework costs a fraction of the first.
CMMC readiness, on your timeline
A scoping call costs nothing and ends with a straight answer: what the work involves, what it costs, and whether you need it yet.