A DoD contract or subcontract that requires CMMC Level 2
CMMC Level 2 security plan and gap pack
We write your system security plan and score the 110 NIST SP 800-171 requirements from your own evidence, with a plan for each gap.
| Part | Who |
|---|---|
| System security plan for the systems that handle CUI | We prepare |
| Each requirement marked MET or NOT MET with your evidence | We prepare |
| Score and a plan of action for each gap | We prepare |
| Missing: multifactor sign-in proof for remote access | You supply |
| Fix the gaps, enter the score and affirm | You supply |
$3,9003900.00 USD per system security plan and gap pack, earned when you confirm the order, refunded in full if the checked plan and gap pack are not delivered by the agreed deadline
- You send
A diagram or list of the systems that store or send controlled unclassified information, such as drawings from a prime.
- We prepare
We write the security plan, mark each requirement MET or NOT MET from your evidence, compute the score and plan each gap.
- You pay
3900.00 USD per system security plan and gap pack, earned when you confirm the order, refunded in full if the checked plan and gap pack are not delivered by the agreed deadline
You enter any score in SPRS and your official affirms; an accredited assessor certifies where a contract requires it.
yourcompany.com Found
The public pages read are listed, each with its title.
- Your pages say
- A line from your site, linked to its page
- May fit
- CMMC Level 2 security plan and gap pack, with its cited rule
- The one record
- A diagram or list of the systems that store or send controlled unclassified information, such as drawings from a prime.
- Fee
- 3900.00 USD per system security plan and gap pack, earned when you confirm the order, refunded in full if the checked plan and gap pack are not delivered by the agreed deadline
Accept termsConfirm the result
The rules that usually decide this
Level 2 (Self) requires MET on all 110 NIST SP 800-171 R2 requirements, a new self-assessment with results in SPRS every three years, and an Affirming Official's SPRS affirmation at each assessment, annually, and after POA&M closeout.
32 CFR 170.16(a)(1)-(2); 170.14(c)(3); 170.4; 170.22(b)(2)Conditional Level 2 needs a score of at least 0.8 of the 110 requirements (88), POA&M items worth only 1 point (except non-FIPS-validated encryption, SC.L2-3.13.11), and none of AC.L2-3.1.20, 3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, 3.10.4 or 3.10.5 on the POA&M.
32 CFR 170.21(a)(2)(i)-(iii)A System Security Plan (CA.L2-3.12.4) describing each in-scope system must be in place at assessment; without an up-to-date SSP the assessment cannot be completed. The SSP requirement may never be placed on a POA&M.
32 CFR 170.24(c)(2)(i)(B)(5); 170.21(a)(2)(iii)(C)CMMC Phase 2 begins one calendar year after Phase 1 (Phase 1 began Nov 10, 2025, so Phase 2 begins Nov 10, 2026). DoD then intends to require Level 2 (C3PAO) certification as an award condition for applicable contracts, or may defer it to an option period.
32 CFR 170.3(e)(1)-(2); 170.17(a)(1); 90 FR 43560 (effective Nov 10, 2025)DFARS 252.204-7012 requires adequate security, applying NIST SP 800-171 to covered contractor information systems, and rapid reporting of cyber incidents to DoD at https://dibnet.dod.mil, meaning within 72 hours of discovery.
DFARS 252.204-7012(a), (b)(2)(i), (c)(1)(ii) (MAY 2024)When NIST SP 800-171 applies, an offeror needs a current NIST SP 800-171 DoD Assessment (not more than 3 years old unless the solicitation sets less) with its summary-level score, e.g. 105 out of 110, posted in SPRS for each covered system.
DFARS 252.204-7019(b), (c)(1); 252.204-7020(d) (NOV 2023)
General rules for this kind of work, from their sources: not yet checked against your company.
The clock on this work
A missed deadline turns a good claim into a lost one. Each bar starts at its own event and is drawn to scale.
Report a cyber incident to DoDDiscovery of a cyber incident
Preserve images of affected systemsSubmission of the cyber incident report
Close out the Level 2 POA&MConditional CMMC Status Date
CMMC Phase 2: Level 2 (C3PAO) award requirement begins (Nov 10, 2026)Phase 1 start: DFARS CMMC rule effective date, Nov 10, 2025
Fees
Know the fee before any work
The first look is free. Before any paid work, we agree the exact documents, deadline and fee. Each service has one published price, paid when you confirm the order; we start once your payment arrives, and if the agreed, checked documents are not delivered by the deadline, you get the fee back in full. A score, grade or contract award never changes the fee.
You accept exact termsScope, fee and the event that earns it are written out before any paid work. Nothing is agreed until you press Accept or submit the complete acceptance statement shown in your private case.
You confirm the result firstAn invoice follows only your "Confirm the result" press, for exactly the agreed amount.
One private page for the whole caseMessages, terms, files and invoices stay on one page you keep.
We use public sources for the first look. If you continue, we work from records you choose to share. We prepare CMMC self-assessments, security plans and written safety programs for you to review, sign, affirm and upload. We do not contact the DoD, your customer, an assessor or a prequalification platform for you, and we never affirm or certify on your behalf.
Questions
Do you certify us?
No. Where a contract requires certification, an accredited assessor (C3PAO) does it. We prepare the plan and the scored gap list from your evidence so you know where you stand first.
What if our evidence shows gaps?
Each gap stays NOT MET with a plan of action, and the score reflects it. Nothing is written as in place without evidence.
CMMC Level 2 security plan and gap pack
3900.00 USD per system security plan and gap pack, earned when you confirm the order, refunded in full if the checked plan and gap pack are not delivered by the agreed deadline
Show me what applies