The fixed fee and the business question
The assessment has a fixed fee of $30,000. It answers five questions: Is controlled information present? Where does the boundary sit? Which NIST SP 800-171 requirements are not satisfied? What should be fixed first? And what is the work likely to involve?
Gap and risk register
Each validated gap is recorded with its operational context, evidence status, risk, dependencies, and recommended disposition. Teams use it to assign owners and track findings — not to bury them in meeting notes.
Scope analysis and boundary recommendations
We map CUI flow across people, systems, facilities, and service providers. Boundary recommendations show where segmentation, enclaves, or workflow changes may reduce what has to be assessed, subject to discovery and validation.
NIST SP 800-171 readiness baseline
The baseline distinguishes a control that actually operates and can be shown from one that exists only in a policy document. That distinction matters when an assessor asks for evidence.
Prioritized statement of work
The statement of work sequences technical, documentation, and operational work by dependency and risk. It works for internal execution, another provider, or a separately scoped Common Cyber engagement.
Budgetary planning assumptions
Budgetary assumptions turn technical findings into planning numbers. They are not a fixed remediation quote — they show which architecture and implementation decisions will materially affect cost.
Executive findings briefing
The briefing gives decision-makers a concise view of boundary, readiness, major risks, open choices, and the next funded actions. No jargon walls.
Frequently asked questions
Is remediation included in the $30,000 fee?
No. The fixed fee covers the readiness and scope assessment. Remediation and implementation are scoped separately from validated findings.
Can another provider use the deliverables?
Yes. The deliverables are designed to support internal execution, another qualified provider, or Common Cyber.
Does the assessment provide CMMC certification?
No. Common Cyber does not certify organizations. Certification decisions belong to an authorized C3PAO.
