A DoD contract or subcontract that requires CMMC Level 2

CMMC Level 2 security plan and gap pack

We write your system security plan and score the 110 NIST SP 800-171 requirements from your own evidence, with a plan for each gap.

Only your company website is needed.

Free first look from your website aloneNo documents to startExact fee agreed before any work

Illustrative example
CMMC Level 2 plan and gap pack110 requirements of NIST SP 800-171 Rev. 2
PartWho
System security plan for the systems that handle CUIWe prepare
Each requirement marked MET or NOT MET with your evidenceWe prepare
Score and a plan of action for each gapWe prepare
Missing: multifactor sign-in proof for remote accessYou supply
Fix the gaps, enter the score and affirmYou supply

$3,9003900.00 USD per system security plan and gap pack, earned when you confirm the order, refunded in full if the checked plan and gap pack are not delivered by the agreed deadline

  1. You send

    A diagram or list of the systems that store or send controlled unclassified information, such as drawings from a prime.

  2. We prepare

    We write the security plan, mark each requirement MET or NOT MET from your evidence, compute the score and plan each gap.

  3. You pay

    3900.00 USD per system security plan and gap pack, earned when you confirm the order, refunded in full if the checked plan and gap pack are not delivered by the agreed deadline

You enter any score in SPRS and your official affirms; an accredited assessor certifies where a contract requires it.

Example of the format
Your website, recognised

yourcompany.com Found

The public pages read are listed, each with its title.

Your public first look
Your pages say
A line from your site, linked to its page
May fit
CMMC Level 2 security plan and gap pack, with its cited rule
The one record
A diagram or list of the systems that store or send controlled unclassified information, such as drawings from a prime.
Terms you accept, then confirm
Fee
3900.00 USD per system security plan and gap pack, earned when you confirm the order, refunded in full if the checked plan and gap pack are not delivered by the agreed deadline

Accept termsConfirm the result

The rules that usually decide this

  • Level 2 (Self) requires MET on all 110 NIST SP 800-171 R2 requirements, a new self-assessment with results in SPRS every three years, and an Affirming Official's SPRS affirmation at each assessment, annually, and after POA&M closeout.

    32 CFR 170.16(a)(1)-(2); 170.14(c)(3); 170.4; 170.22(b)(2)
  • Conditional Level 2 needs a score of at least 0.8 of the 110 requirements (88), POA&M items worth only 1 point (except non-FIPS-validated encryption, SC.L2-3.13.11), and none of AC.L2-3.1.20, 3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, 3.10.4 or 3.10.5 on the POA&M.

    32 CFR 170.21(a)(2)(i)-(iii)
  • A System Security Plan (CA.L2-3.12.4) describing each in-scope system must be in place at assessment; without an up-to-date SSP the assessment cannot be completed. The SSP requirement may never be placed on a POA&M.

    32 CFR 170.24(c)(2)(i)(B)(5); 170.21(a)(2)(iii)(C)
  • CMMC Phase 2 begins one calendar year after Phase 1 (Phase 1 began Nov 10, 2025, so Phase 2 begins Nov 10, 2026). DoD then intends to require Level 2 (C3PAO) certification as an award condition for applicable contracts, or may defer it to an option period.

    32 CFR 170.3(e)(1)-(2); 170.17(a)(1); 90 FR 43560 (effective Nov 10, 2025)
  • DFARS 252.204-7012 requires adequate security, applying NIST SP 800-171 to covered contractor information systems, and rapid reporting of cyber incidents to DoD at https://dibnet.dod.mil, meaning within 72 hours of discovery.

    DFARS 252.204-7012(a), (b)(2)(i), (c)(1)(ii) (MAY 2024)
  • When NIST SP 800-171 applies, an offeror needs a current NIST SP 800-171 DoD Assessment (not more than 3 years old unless the solicitation sets less) with its summary-level score, e.g. 105 out of 110, posted in SPRS for each covered system.

    DFARS 252.204-7019(b), (c)(1); 252.204-7020(d) (NOV 2023)

General rules for this kind of work, from their sources: not yet checked against your company.

The clock on this work

A missed deadline turns a good claim into a lost one. Each bar starts at its own event and is drawn to scale.

Report a cyber incident to DoDDiscovery of a cyber incident

Rapidly report at https://dibnet.dod.mil: within 72 hours of discovery.DFARS 252.204-7012(a), (c)(1)(ii)

Preserve images of affected systemsSubmission of the cyber incident report

Preserve and protect images of affected systems and relevant monitoring/packet capture data for at least 90 days.DFARS 252.204-7012(e)

Close out the Level 2 POA&MConditional CMMC Status Date

Remediate NOT MET items and complete a POA&M closeout assessment within 180 days, or the Conditional status expires.32 CFR 170.21(b); 170.16(a)(1)(ii)(B)

CMMC Phase 2: Level 2 (C3PAO) award requirement begins (Nov 10, 2026)Phase 1 start: DFARS CMMC rule effective date, Nov 10, 2025

Phase 2 begins one calendar year after Phase 1; DoD intends to require Level 2 (C3PAO) for applicable awards.32 CFR 170.3(e)(1)-(2); 90 FR 43560

Fees

Know the fee before any work

The first look is free. Before any paid work, we agree the exact documents, deadline and fee. Each service has one published price, paid when you confirm the order; we start once your payment arrives, and if the agreed, checked documents are not delivered by the deadline, you get the fee back in full. A score, grade or contract award never changes the fee.

Fixed pricesinvoiced only after you confirm the agreed result

  • CMMC Level 2 security plan and gap pack$3,900
  • You accept exact termsScope, fee and the event that earns it are written out before any paid work. Nothing is agreed until you press Accept or submit the complete acceptance statement shown in your private case.

  • You confirm the result firstAn invoice follows only your "Confirm the result" press, for exactly the agreed amount.

  • One private page for the whole caseMessages, terms, files and invoices stay on one page you keep.

We use public sources for the first look. If you continue, we work from records you choose to share. We prepare CMMC self-assessments, security plans and written safety programs for you to review, sign, affirm and upload. We do not contact the DoD, your customer, an assessor or a prequalification platform for you, and we never affirm or certify on your behalf.

Questions

Do you certify us?

No. Where a contract requires certification, an accredited assessor (C3PAO) does it. We prepare the plan and the scored gap list from your evidence so you know where you stand first.

What if our evidence shows gaps?

Each gap stays NOT MET with a plan of action, and the score reflects it. Nothing is written as in place without evidence.

CMMC Level 2 security plan and gap pack

3900.00 USD per system security plan and gap pack, earned when you confirm the order, refunded in full if the checked plan and gap pack are not delivered by the agreed deadline

Show me what applies

See every service