Common Cyber

CMMC Readiness and Scope Assessment

The assessment establishes what is in scope, where you stand against the requirements, and the written statement of work to close the gaps.

Who is this assessment for?

Defense contractors and aviation or aerospace organizations that need to know whether CUI applies, where the CMMC boundary sits, and how close they are to NIST SP 800-171 readiness.

Which assessment path will apply to you?

Which path applies is set by your contract and the information you handle, not by preference. An organization may choose to meet a higher requirement than its contract sets. It cannot choose a lower one.

Level 1 is a self-assessment against the 15 basic safeguarding requirements in FAR 52.204-21, performed annually and affirmed in SPRS, with all 15 assessed as met or not applicable. No third-party assessor is involved.

Level 2 by self-assessment covers all 110 requirements in NIST SP 800-171 Revision 2, affirmed in SPRS by your organization's Affirming Official. No third-party assessor is involved.

Level 2 by certification requires an assessment by an authorized C3PAO.

Level 3 applies to a limited set of programs, requires a Level 2 certification first, and is assessed by the Government. Common Cyber does not perform Level 3 assessments.

On the two self-assessment paths, Common Cyber provides experienced execution capacity across the full path. Your organization performs the self-assessment and your Affirming Official submits the affirmation. On the certification path, we prepare you for the C3PAO and the assessment decision remains theirs.

Which assessment path will apply to you

Why do organizations start?

A prime asks a hard question. A contract introduces a flow-down. An SPRS score needs an honest answer. The current boundary cannot survive scrutiny.

What does the assessment produce?

Technical and business deliverables you can act on, not a slide deck.

  • Gap and risk register
  • Scope analysis and boundary recommendations
  • NIST SP 800-171 readiness baseline
  • Prioritized statement of work
  • Budgetary planning assumptions
  • Executive findings briefing

A fixed-fee path to a clear boundary.

The assessment clarifies applicability, maps scope, establishes a readiness baseline, and builds a prioritized statement of work.

CMMC Readiness and Scope Assessment

A defined first step that establishes scope, readiness, and a practical remediation path.

What are your options after the assessment?

You have three choices once the assessment is done. Do the work yourself. Take our statement of work to another provider. Or hire us. All three are fine, and the statement of work is yours either way.

That candor is deliberate. A statement of work is only useful if the organization can act on it, with us or without us.

Start an Assessment

Why does federal experience matter on a CMMC engagement?

Federal authorization experience shapes how we treat boundaries, evidence, and control claims.

CMMC Level 2 assesses 110 controls drawn from NIST SP 800-171, which derives from NIST SP 800-53. Our founders worked under that framework in Special Access Program and Intelligence Community environments at prior employers, where the baseline is higher, the overlays are additional, and the tolerance for a control that cannot be evidenced is lower.

They have also worked through real authorization processes with government assessors. That is closer to the experience of a C3PAO assessment than most compliance consulting provides, and it shapes how we prepare an organization: define the boundary early, build the evidence as you implement, and never mark a control satisfied if it could not survive a question.

Frequently asked questions

What does the assessment cost?

Fixed fee: $25,000. Remediation and implementation are separate and are scoped only after the assessment findings are known.

Does Common Cyber certify us for CMMC?

No. Common Cyber is not a C3PAO and does not perform certification assessments. Certification decisions belong to an authorized C3PAO. Where your contract calls for Level 1 or Level 2 self-assessment, no third-party assessor is involved. The CMMC Assessment Guide for Level 1 states that an organization may perform the annual self-assessment internally or engage a third party to assist, and that using a third party is still considered a self-assessment. We support that work through to your self-assessment and affirmation.

What information do you need to begin?

Discovery begins with contract language, information flows, systems, facilities, service providers, current documentation, and available evidence.

Can we use the statement of work with another provider?

Yes. The deliverables are designed to support internal execution, another provider, or a separately scoped Common Cyber engagement.

Do we need a C3PAO, or can we self-assess?

That is set by your contract and the information you handle, not by preference. Level 1 and the Level 2 self-assessment path involve no third-party assessor. Level 2 certification requires an authorized C3PAO. You may meet more than your contract requires; you cannot meet less.

Common Cyber does not certify organizations for CMMC. Certification decisions belong to an authorized C3PAO. This assessment supports readiness evaluation and gap identification. Recommendations are subject to discovery, validation, and the specifics of your contracts, systems, and information environment.