Skip to main content
Compliance Readiness

CMMC
Readiness

CMMC is what turns NIST SP 800-171 from a contractual promise into something a third party checks. If you handle Controlled Unclassified Information, your eligibility for defence contracts now depends on it. We run readiness so a C3PAO assessment finds a programme rather than a plan.

C3PAO Assessment Readiness Assessment
readiness log CMMC assessing
09:14:02scopeCMMC 2.0 Level 2confirmed
09:14:17assessAccess Control (AC)walked
09:15:18assessAwareness & Training (AT)walked
09:16:19assessAudit & Accountability (AU)walked
09:18:40gapmarked complete, no evidence attachedblocker
09:19:05gapcontrol has no named owneropen
09:22:31evidencefiled against control · expiry trackedaccepted
09:24:12handoffrequirement → control → evidencemapped
your team assesses evidence vetted tracked in Talon
12
control areas walked
2
assessment paths
14
frameworks on one programme
0
methodology slides
Fit

Who this is for

Readiness earns its cost when something is waiting on the other side of it. These are the situations where it pays for itself.

Defence contractors and subcontractors handling CUI

Companies with a DFARS clause in a contract and a CMMC requirement attached to the next one

Suppliers whose prime has asked for evidence of their CMMC position

Organisations with an SPRS score they know does not reflect reality

Scope of work

What the engagement does

Your Lorikeet team runs the assessment, collects and vets the evidence, and keeps control status current. You are not handed a spreadsheet and wished well.

  • Define the CUI boundary and the assets in scope, which is where most CMMC cost is decided
  • Assess all practices across the fourteen 800-171 families and record where you stand
  • Build the System Security Plan properly, rather than as a document written to be filed
  • Produce a POA&M for what is not yet met, with owners and dates
  • Close the gap list to the level the assessment requires
  • Prepare for the C3PAO assessment and support you through it

What you walk away with

A defensible CUI boundary, an SSP that describes what actually exists, a POA&M that reflects real remediation, and evidence for each practice. Where your SPRS score was optimistic, you find out from us rather than from an assessor.

Sequence

How it runs

Four phases. You always know which one you are in and what is outstanding.

01

Scoping call

We establish what is in scope, which assessment path applies, and what you already have. It costs nothing, and it ends with a straight answer about whether readiness is the right spend right now.

no charge
02

Assessment

We walk the control set and record where you actually stand, control by control. The gap list lands early so your team can start on the long items while the rest of the assessment continues.

Lorikeet assessor
03

Remediate and evidence

We work the gap list down with your team and collect what each control needs, filed against the control it belongs to with an owner and an expiry date rather than dumped in a folder.

joint
04

Hand off to your assessor

You go in with a package that maps requirement to control to evidence, and we stay available through the assessment itself.

with your assessor
Coverage

What the assessment covers

The control areas we walk for CMMC. Each breaks down into individual controls carrying status, owner and evidence in Talon.

01 Access Control (AC)
02 Awareness & Training (AT)
03 Audit & Accountability (AU)
04 Configuration Management (CM)
05 Identification & Authentication (IA)
06 Incident Response (IR)
07 Media Protection (MP)
08 Physical Protection (PE)
09 Risk Assessment (RA)
10 Security Assessment (CA)
11 System & Communications Protection (SC)
12 System & Information Integrity (SI)
Who performs the assessment

Level 2 certification assessments are performed by an authorised C3PAO. We prepare you and support the assessment; we do not perform it.

Where it lives

It runs in Talon, not in a spreadsheet

Every control, its status, its owner and its evidence sit in the portal your team already uses, so the readiness picture you see is the one your Lorikeet team is maintaining rather than a copy that went stale a fortnight ago.

  • Control-by-control status, kept current by the people doing the work
  • Evidence filed against the control it satisfies, with expiry dates tracked
  • The auditor request list, so nothing is chased over email
  • A readiness view that shows what an assessor would see
Already running a compliance platform?

Tools like Vanta monitor controls continuously once they exist and work. Readiness is the part before that: deciding the boundary, designing the controls, and closing the gaps a monitoring tool would otherwise report as permanently red. We work alongside them, and we are a Vanta MSP partner.

Our partners
Questions

Asked on almost every CMMC call

It depends on the information your contracts involve. Level 1 covers federal contract information with a self-assessment. Level 2 covers CUI and generally requires a C3PAO assessment. Your contract language determines it, and reading it correctly is the first thing readiness does.

Often, substantially. An enclave that isolates CUI can reduce the assessed environment dramatically. Boundary definition is the single biggest cost lever in CMMC.

Level 2 permits a limited POA&M for certain practices, with a closeout deadline - but not for the highest-weighted ones. Which practices can sit on a POA&M and which must be met is a detail worth getting right early.

Compliance you have asserted and compliance an assessor will confirm are different things. Most self-assessments we see are optimistic, usually in evidence rather than intent.

Alongside

Rarely run alone

Controls overlap heavily between frameworks, and evidence collected once counts everywhere it applies. A second framework costs a fraction of the first.

Next

CMMC readiness, on your timeline

A scoping call costs nothing and ends with a straight answer: what the work involves, what it costs, and whether you need it yet.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!