Skip to content
CMMC Guidance
The CMMCg Method

Four stages,
in this order.

The g in CMMCg is guidance, and this is what the guidance actually is: a defined sequence with a deliverable at every stage, run the same way on every engagement.

Protect your DoD contracts. Achieve CMMC without guesswork.

We help defense contractors prepare for Cybersecurity Maturity Model Certification (CMMC) Level 2 with assessments, implementation, documentation, and ongoing managed compliance.

Every engagement is scored against the Department of Defense Assessment Methodology, so the number you see is the number an assessor will.

Talk to an engineerTake the readiness checkTen questions, about five minutes.
  • Veteran-owned
  • CMMC specialists
  • 25 years supporting federal contractors

Technology partners: Microsoft · Dell · Cisco · Acronis

Why a method

The order is the value.

Most CMMC work fails in sequence rather than in substance. A supplier buys tooling before anyone has decided what is in scope, remediates the findings that are easiest rather than the ones that carry the most points, or reaches certification with no plan for the eleven months afterward.

The problem isn’t what organizations know — it’s when they decide. Decisions made out of sequence create costs that usually aren’t visible until they’re difficult and expensive to fix. A disciplined methodology keeps every decision in the right order, making the complex simpler and the costly more affordable.

The stages

What happens, and what you get.

  1. 01

    Scope

    Decide what is in the boundary before securing anything.

    Scoping is the decision that sets the cost of everything after it. It determines how many systems get hardened, how much evidence has to be maintained, and how large the assessment is. Two companies of the same size can differ by an order of magnitude on that basis alone.

    So the first stage is mapping where CUI actually goes — systems, people, subcontractors, cloud services, backups — and then drawing the smallest boundary that honestly contains it. Work done here is the highest-return hour in the engagement, and it is the stage most often skipped.

    Read: scoping and the CMMC levels
    You get
    • CUI data-flow map
    • Defined assessment boundary
    See a sample scope statement
  2. 02

    Assess

    Test all 110 requirements against the live environment.

    Not a questionnaire and not a maturity survey. Engineers test the requirements against the environment as it actually runs — identity, endpoints, network boundary, logging, backups — and record what is implemented rather than what someone believes is implemented.

    The gap between those two numbers is the most common unpleasant surprise in this work, and it is the reason the assessment is technical rather than administrative.

    Read: the technical assessment
    You get
    • Gap analysis across all 110
    • Honest score, weighted correctly
    See a sample gap analysis
  3. 03

    Document

    Build a submission package that survives being read.

    The deliverable is the package: a System Security Plan, a Plan of Action and Milestones (POA&M) with named owners and real dates, and a scoring worksheet with the evidence behind every point. A score below 110 paired with a dated, owned plan reads very differently to a contracting officer than a bare number with nothing behind it.

    Remediation is sequenced by point weight rather than by ease, because closing a handful of five-point requirements moves the number further than closing a long list of one-point items.

    Read: how the score is built
    You get
    • SSP
    • POA&M with owners and dates
    • Scoring package, ready for the Supplier Performance Risk System (SPRS)
    See a sample system security plan
  4. 04

    Guidance

    Hold the score once it is real.

    A score is a measurement of an environment at a moment, and environments change without announcing it. An MFA exception added for a vendor integration, endpoints falling out of patch management, logging that fills a disk and quietly stops — none of these generate a notification, and all of them change the number.

    The fourth stage is the one that never closes: monitoring, evidence refresh, and a named team who can answer what your score is today rather than what it was at submission.

    Read: continuous guidance
    You get
    • Continuous monitoring
    • Evidence kept current
    • Reassessment readiness
    See a sample coverage report
Boundaries

What the method is not.

Being specific about the edges is part of being trustworthy on the inside of them.

It is not a certification

CMMCg is not a Certified Third-Party Assessment Organization (C3PAO) and does not certify anyone. The certifying assessment is performed by an accredited third party, and that separation exists for good reason. The method prepares you for it and maintains you after it.

It is not a guarantee of a number

The assessment reports the score your environment actually produces, including when that is negative. A firm that promises a score before looking at your environment is promising something it cannot see yet.

It is not a software product

There is no dashboard you are left alone with. Every stage has engineers attached, and the same US-based people who assess the environment are the ones who monitor it afterward.

Where it starts

Stage 01 is a conversation.

Scoping begins with a no-cost readiness call: what your contracts flow down, where Controlled Unclassified Information (CUI) is likely sitting, and what that means for the size of the boundary. An NDA is signed before anything technical. You speak to an engineer, not a sales rep.

Start with stage 01

Guidance you can defend in an audit.

The method is only worth something if it holds up when someone checks it. That is what the readiness call is for.

  • Your CUI boundary sketched on the call
  • The requirements costing you the most points, named
  • A written summary afterward, yours to keep
Book the readiness call

NDA signed before anything technical. No cost, no obligation.