CMMC Level 2 Compliance
for Small Defense Contractors.
From current state to assessment-ready in 6 weeks. All 110 NIST SP 800-171 practices evaluated, documented, and mapped - so you can pass your C3PAO assessment and keep your DoD contracts.
Phase 2 Starts November 10, 2026
That's when DoD begins requiring Level 2 C3PAO certification in contract solicitations - not self-attestation, third-party assessment. Lockheed Martin is already requiring suppliers to document their CMMC status in SPRS. Boeing is strongly encouraging Level 2 certification now.
The ClearanceReady Readiness Program
A 6-week engagement that takes your company from wherever you are today to assessment-ready for CMMC Level 2. We evaluate all 110 NIST SP 800-171 Rev 2 security requirements, produce all required documentation, and give you a clear remediation roadmap for any gaps.
Baseline SPRS Score
A hands-on gap assessment of all 110 practices, not a self-assessment questionnaire. You'll know exactly where you stand.
System Security Plan (SSP)
All 14 control families with implementation statements specific to your environment. Written by someone who has been on the DoD side of these assessments.
Plan of Action & Milestones (POA&M)
Prioritized remediation entries with risk ratings, timelines, and milestone tracking for every gap identified.
Evidence Artifact Inventory
Every MET practice mapped to its supporting evidence - screenshots, policy docs, configuration exports.
C3PAO Readiness Briefing
A final working session walking your leadership through exactly what the assessment will look like, what the assessor will ask, and where your risk areas are.
90-Day Remediation Support
Post-Sprint access for questions, remediation progress review, and guidance as you work through your POA&M.
6 Weeks from Kickoff to Assessment-Ready
Client completes Compass Intake Questionnaire. NDA executed. Kickoff call scheduled.
Kickoff call. Network topology review. CUI flow mapping. Asset inventory. Key personnel interviews.
Walk all 110 practices against your environment. Collect evidence. Document gaps. Score SPRS baseline.
Draft SSP and POA&M. Write implementation statements. Map evidence artifacts.
Client review. Remediation prioritization. Quick-win implementation guidance.
Leadership briefing. Assessment simulation. Final document handoff. 90-day support begins.
- Kickoff + intake 3 hours
- Key-personnel interviews 4–6 hours
- Evidence collection (screenshots, config exports) 4–6 hours
- Working-session reviews 3–5 hours
- Gap assessment against 110 practices
- CUI boundary + data flow diagrams
- SSP drafting (AI-assisted, expert-reviewed)
- POA&M generation + risk scoring
- Evidence artifact mapping
- C3PAO simulation prep + leadership briefing
We Built the eMASS for Small Contractors
Most CMMC consultants manage your compliance in spreadsheets and Word documents. We built a purpose-built compliance platform that treats your program the way the DoD treats its own - as structured data in OSCAL, the same format eMASS uses internally. That's why we ship a defensible SSP in weeks, not months.
OSCAL 1.1.2 internal data model
We manage your compliance the same way eMASS does - as structured data, not Word docs. Control families, assessment objectives, and evidence all live in OSCAL, so your SSP, POA&M, and SPRS score are always derived from the same source of truth.
110 NIST 800-171 R2 + 15 FAR 52.204-21 controls pre-loaded
Every control ships with its discussion text and assessment objectives baked in. No waiting on a consultant to "look it up" - the framework is already in the system on day one.
FedRAMP-High AI drafting, watermarked
SSP control statements and POA&M entries are drafted by AI running on AWS Bedrock (FedRAMP High) or Azure OpenAI GovCloud, then expert-reviewed. Every AI-drafted artifact is watermarked "AI-Drafted" so assessors know exactly what was generated and what was authored.
CUI-sovereign by design
Your CUI never leaves infrastructure you control. Inputs to the AI layer are hashed (SHA-256) before logging - the raw text is never persisted in our audit log. For Level 3 or air-gapped environments, the same platform runs fully on-prem with Ollama.
Your Controlled Unclassified Information Stays Controlled
The entity helping you get CMMC-ready should be the last entity to mishandle your CUI. Here's exactly how we protect it during the engagement - built to the standards you'll be assessed against.
Row-Level Security on every data table - your evidence and documents are cryptographically partitioned from every other client.
Every Solas AI consultant and system account requires MFA. No opt-out, no bypass - enforced at the identity provider.
TLS 1.3 in transit, AES-256 at rest. Customer-controlled encryption keys available for Readiness + Remediation.
Every file read, every control edit, every AI call is logged. Full audit trail handed to you at project close.
We never store the raw text of CUI sent to our AI layer - only a one-way SHA-256 hash for audit integrity.
At project close you get a full data export and signed certificate of destruction for any residual copies in our environment.
Simple, Fixed-Price Packages
No hourly billing. No scope-creep surcharges. Payment: 50% at kickoff, 50% at documentation delivery.
Recon
Companies who want to know where they stand before committing.
- Full 110-practice gap assessment
- SPRS score calculation
- High-level remediation priorities
- Summary evidence review
Readiness Program
Companies ready to prepare for a C3PAO assessment.
- Everything in Recon
- Complete System Security Plan (SSP)
- Full POA&M with risk ratings
- Detailed evidence artifact mapping
- Remediation roadmap
- C3PAO readiness briefing
- 90 days advisory support
Readiness + Remediation
Companies who need hands-on help closing the gaps.
- Everything in Readiness Program
- 12 weeks hands-on remediation guidance
- Implementation prioritization
- Vendor and tool recommendations
- Progress reviews every 2 weeks
- Policy document package (12 policies)
- Incident Response Plan build
Built by Someone Who's Been on the DoD Side
Your ClearanceReady engagement isn't run by a generalist IT consultant who added CMMC to a service menu. I've held ISSM roles inside the Department of Defense, managing the same kind of systems C3PAOs will be assessing. I hold CISSP and CISM certifications, and I'm a Cyber AB Registered Practitioner (RP) - authorized by the CMMC Accreditation Body to deliver CMMC consulting services. I know what assessors look for because I've been in the room.
The difference shows up in the documentation. An SSP written by someone who has lived the DoD security environment reads differently than one written by someone who studied the NIST framework. Assessors can tell.
Optional Extensions
Everything we don't bake into a tier by default, sold à la carte. Any can be added mid-engagement.
Onsite or virtual representation during your C3PAO assessment - answering questions, walking evidence, keeping momentum.
Hands-on work from your site: interviews, physical security review, evidence collection.
Keep documentation current as your environment changes. One working session, full document regen.
We submit your self-assessment score to SPRS correctly the first time - no submission reworks.
NIST-aligned IR plan tailored to your environment, satisfying 3.6.1–3.6.3.
12 tailored policies covering all 14 control families - organizational, operational, and technical.
Full simulation with the same artifacts and interview flow a real C3PAO uses. Surface gaps before they cost you.
Frequently Asked Questions
The Framework
3 questionsDo I actually need CMMC?
If your contracts include DFARS 252.204-7012 or you handle Controlled Unclassified Information (CUI) for a DoD prime or the government directly, yes. Search your active contracts for that clause - if it's there, CMMC applies.
What's the difference between self-attestation and C3PAO certification?
Phase 1 (through November 2026) allows self-attestation for most Level 2 contracts. Phase 2 starts requiring third-party C3PAO assessments. Some contracts already require C3PAO certification now, and major primes like Lockheed and Boeing are pushing suppliers to certify ahead of schedule.
What if my SPRS score is really low?
That's actually valuable information. A Recon assessment that tells you your score is 37 with 43 NOT MET practices gives you a clear remediation roadmap. Most small defense subs are doing 60–70% of the practices already - they just can't prove it because nothing is documented.
Scope & Fit
2 questionsCan my MSP/IT provider do this instead?
Your MSP can handle technical controls - firewall rules, MFA, patching. Where MSPs typically fall short is the documentation: writing the SSP, building the POA&M, mapping CUI boundaries, and preparing evidence for the assessor. Those require someone who understands how C3PAO assessments work. We recommend keeping your MSP for implementation and bringing us in for documentation and assessment prep.
Is Solas AI a C3PAO?
No. We are a consulting firm that helps you prepare for your C3PAO assessment. We do not conduct official CMMC assessments and have no financial relationship with any C3PAO. This independence is important - the entity that prepares you should never be the entity that assesses you.
Working With Solas AI
1 questionsDo you work remotely?
Yes. All ClearanceReady engagements are delivered remotely via secure video conference and encrypted file sharing. On-site visits are available as an add-on for companies requiring physical security assessment or classified environment reviews.
Ready to Find Out Where You Stand?
Book a free 20-minute call. I'll tell you whether your contracts require CMMC Level 1 or Level 2, what the timeline looks like for your situation, and whether a Recon assessment or full Readiness Program makes sense. No pitch, no pressure - just a straight answer from someone who knows the framework.
No commitment required · [email protected] · (307) 357-1525