Skip to content
Epic IT Support

For businesses

CMMC readiness, including the remediation

If your contracts carry DFARS clauses, CMMC has moved from a future problem to a condition of award. We scope it honestly — often smaller than you fear — assess against NIST SP 800-171 with evidence, write the System Security Plan and POA&M, and then actually close the technical gaps rather than handing you a list.

  • Scoping that tests whether a CUI enclave cuts your cost
  • Gap assessment across all 110 NIST SP 800-171 controls
  • System Security Plan and POA&M written to your environment
  • Technical remediation delivered, not just documented
  • Evidence packaged and support through your assessment
  • Readiness work only — certification is a separate, independent firm

What we deliver

Scope before anything else

Most of the cost of CMMC is decided here. An unnecessarily wide scope is the single most expensive mistake in the process.

  • Determine whether you handle Federal Contract Information, Controlled Unclassified Information, or both
  • Identify every system that processes, stores, or transmits FCI or CUI
  • Assess whether an enclave would reduce scope materially versus assessing the whole estate
  • Confirm the level your contracts actually require rather than the highest one available
  • Map flow-down obligations to your own subcontractors

Gap assessment against NIST SP 800-171

An honest current-state assessment against each control, with evidence, rather than a self-attestation nobody can defend.

  • Control-by-control assessment across all 110 NIST SP 800-171 requirements
  • Evidence collection for controls already met
  • Objective scoring under the DoD Assessment Methodology
  • Findings ranked by contract risk and remediation effort
  • Written report suitable for leadership and for a prime contractor asking

System Security Plan and POA&M

The two documents an assessor will ask for first, written to be usable rather than to sit in a folder.

  • System Security Plan describing the environment and how each control is met
  • Plan of Action and Milestones for every open gap, with owners and dates
  • Policies and procedures written to your environment, not generic templates
  • Evidence register mapping each control to its artifact
  • Documentation maintained as the environment changes

Remediation engineering

The part most compliance consultancies hand back to you. We do it, because it is ordinary infrastructure and security work.

  • Access control, multi-factor authentication, and privileged account separation
  • Audit logging, retention, and forwarding into a monitored platform
  • Boundary protection, network segmentation, and CUI enclave build-out
  • Endpoint protection, patching discipline, and configuration baselines
  • Backup, recovery, and incident response capability with tested evidence

Platforms we work in

Named platforms, not categories — so you can tell at a glance whether we already know your environment.

Frameworks
  • CMMC Level 1
  • CMMC Level 2
  • NIST SP 800-171
  • DoD Assessment Methodology
  • FAR 52.204-21
Identity & access
  • Entra ID
  • Conditional Access
  • MFA
  • Privileged access tiering
Monitoring
  • Microsoft Sentinel
  • Defender
  • Arctic Wolf
  • CrowdStrike Falcon
Data protection
  • Microsoft Purview
  • Immutable backup
  • Encryption at rest and in transit
Enclave
  • Microsoft 365 GCC
  • Azure Government
  • Network segmentation

How it runs

From first call to sign-off

Every engagement is governed by a written statement of work naming deliverables, assumptions, and who is responsible for what.

  1. Scoping workshop

    What your contracts require, what data you actually hold, and whether an enclave would cut the assessment boundary down to something affordable.

  2. Gap assessment and score

    Control-by-control assessment with evidence, an objective score, and a findings report ranked by contract risk.

  3. Documentation and remediation

    System Security Plan and POA&M written, then the technical gaps closed by the same engineers — access control, logging, segmentation, backup.

  4. Assessment support

    Evidence packaged and organized, staff prepared for interviews, and an engineer available during the assessment to answer technical questions.

Questions

What people ask

CMMC readiness, including the remediation — questions

Can you certify us?

No, and be cautious of anyone who says they can. Certification assessments are performed by an accredited third-party assessment organization, and the same firm cannot both remediate your environment and certify it. We do readiness work: scoping, gap assessment, documentation, remediation engineering, and support through your assessment. Your C3PAO is a separate engagement with a separate firm.

What level do we actually need?

It follows from your contracts. Handling only Federal Contract Information generally points to Level 1 with an annual self-assessment. Handling Controlled Unclassified Information points to Level 2, which is where NIST SP 800-171 and a third-party assessment come in. Many organizations assume they need more than they do, and scoping honestly is the cheapest hour in the whole program.

How much does scope affect cost?

Enormously — it is the dominant variable. Putting the entire corporate estate in scope can cost several times more than building a segmented enclave that holds CUI and assessing only that. We look at enclave viability during scoping precisely because the decision is worth more than every other choice combined.

We failed a prime contractor questionnaire. Where do we start?

Send us the questionnaire. It tells us which controls are being probed and how urgently, and it usually reflects a flow-down obligation from the prime rather than a direct DoD requirement. We map the items to concrete findings in your environment and give you a remediation plan you can show the prime while the work is under way.

Do you do the technical remediation, or just tell us what is wrong?

We do it. That is the difference between this and a pure compliance consultancy. Access control, MFA, audit logging, segmentation, endpoint protection, backup and recovery are ordinary infrastructure and security engineering — the same work described elsewhere on this site, mapped to a control framework.

Can you work with our existing IT provider?

Yes, and it is common. Many providers are competent generalists with no CMMC exposure. We work alongside them, through their change control, on the specific scope the framework demands, and we do not compete for their managed services contract.

Find out how small your scope could be

Scoping is the decision that drives every other cost in CMMC. Tell us what your contracts require and what data you hold.