Win DoD Contracts.
Get CMMC-Ready First.
Defense contractors handling Controlled Unclassified Information must achieve CMMC certification before pursuing new DoD contracts. Lewis IT closes your compliance gaps, builds your documentation, and gets you ready for your C3PAO assessment.
⚠ Important for DoD Contractors Do You Know Your SPRS Score?Your SPRS score is your DoD-required cybersecurity self-assessment score, ranging from -203 to +110. It must be submitted to the Supplier Performance Risk System before you can receive DoD contract awards. Prime contractors are increasingly requiring it from subcontractors before awarding subcontracts. If you haven’t filed one — or if your score is significantly negative — you have a compliance problem today, not in three years. A gap assessment tells you exactly where you stand and what it will take to improve your score. | Check Your SPRS Score → |
Are You in Scope for CMMC Level 2?
Many small defense contractors aren’t sure whether CMMC applies to them. If any of the following apply, you’re likely in scope for Level 2 and subject to all 110 NIST 800-171 controls.
|
| ||||
|
| ||||
Not sure if you’re in scope? A 15-minute discovery call is all it takes to find out — no obligation, no sales pitch. | |||||
Understanding CMMC 2.0 Levels
CMMC 2.0 has three levels. Most defense contractors in the DIB supply chain need to reach Level 1 or Level 2. We prepare contractors for both.
Level 1 — Foundational Basic Cyber Hygiene17 practices · Annual self-attestation Required for contractors handling Federal Contract Information (FCI). Covers basic security practices and can be self-attested annually by a senior company official. Typical gaps: Access controls, system and communications protection, system integrity, identification and authentication. | Most Common Requirement Level 2 — Advanced Protecting CUI110 practices · C3PAO assessment required Required for contractors handling Controlled Unclassified Information (CUI). Aligns with all 110 practices in NIST SP 800-171. Requires a triennial assessment by an accredited C3PAO. Most contractors are 40–70% compliant before engaging us. The remaining gaps are usually documentation, logging, and access control. We close those. | Level 3 — Expert Critical ProgramsNIST 800-172 · Government-led assessment Reserved for contractors supporting the DoD’s most critical programs. Requires a government-led assessment by DCSA. A small subset of the DIB supply chain. Note: If your contracts require Level 3, contact us for a referral to appropriate government assessment channels. We support Level 1 and Level 2 preparation. |
A Straight Answer We will not tell you we can certify you. Only an accredited C3PAO can issue a CMMC certificate. What we do is everything that comes before that assessment — closing the gaps, building the controls, writing the documentation, and making sure the assessor finds what they need to find. Most contractors we talk to are 40–70% compliant before we engage. The remaining gaps are usually documentation, logging, and access control. We close those. Then you go to your C3PAO confident. |
What We Do for You
Six service areas that take you from your current state to C3PAO-ready.
01 · Gap Assessment NIST 800-171 Gap AssessmentWe assess your environment against all 110 NIST 800-171 controls and deliver a written gap report with findings prioritized by risk and effort required to close. This is your roadmap to certification. | 02 · Technical Controls Technical Hardening & ImplementationMFA enforcement, encrypted communications, endpoint protection, access control configuration, audit logging, and network segmentation. We implement the technical controls the assessment will verify. |
03 · Documentation SSP, POA&M & Policy LibraryWe build your System Security Plan (SSP), Plan of Action & Milestones (POA&M), incident response plan, and the supporting policy library. These are the documents your C3PAO assessor will read first. | 04 · Monitoring Continuous MonitoringPost-certification, your controls must stay in place. We provide ongoing managed security with SIEM monitoring, endpoint detection, and regular compliance reporting to keep you ready for triennial reassessment. |
05 · Assessment Prep C3PAO Readiness WalkthroughBefore your formal assessment, we conduct an internal pre-assessment simulating what the C3PAO assessor will look for. We close any remaining items before they find them and ensure your documentation is organized and accessible. | 06 · Maryland Incentive Buy MD Cybersecurity Tax CreditMaryland-based businesses may qualify for up to $50,000 in tax credits for eligible cybersecurity investments. CMMC preparation work may qualify. We help you document eligible expenditures. |
From Gap to Ready — How It Works
Six steps from your current compliance posture to C3PAO-ready.
|
|
NIST SP 800-171 — 14 Control Domains
We address all of them. No partial coverage, no carve-outs.
Access Control 22 controls | Audit & Accountability 9 controls | Configuration Mgmt 9 controls | Identification & Auth 11 controls |
Incident Response 3 controls | Maintenance 6 controls | Media Protection 9 controls | Personnel Security 2 controls |
Physical Protection 6 controls | Risk Assessment 3 controls | Security Assessment 4 controls | System & Comms 16 controls |
System & Info Integrity 7 controls | Awareness & Training 3 controls | ||
Most frequently failed domains in Level 2 assessments: Audit & Accountability, Security Assessment, Incident Response, and Awareness & Training. These are where most contractors have zero controls in place before engaging us — no logging, no documented response plan, no training records.
Progress bars represent Lewis IT’s typical coverage capacity per domain. Your specific gap count will vary and is determined by the written gap assessment.
Why Lewis IT for CMMC Prep?
We’re a Maryland MSP with federal market experience — not a big consulting firm that will hand your engagement to a junior analyst.
SAM.gov RegisteredNAICS 541519, SBA small business. We understand the federal contracting environment because we participate in it. | Maryland-BasedBased in Southern Maryland, serving the DC Metro defense contractor community. Local presence means on-site availability when the assessment requires it. | Technical + DocumentationWe do both the technical implementation and the documentation. You don’t need to hire a separate policy consultant and a separate IT firm. |
Production Security StackWe run SIEM, endpoint detection, threat intelligence, and zero-trust networking in our own operations. We deploy what we know works. | No OversellingWe tell you exactly what you need and what we can’t do. We will not promise you certification — only a C3PAO can do that. We promise to get you ready for it. | MD Tax Credit HelpWe help Maryland contractors document eligible CMMC-related expenditures for the Buy MD Cybersecurity Tax Credit — up to $50,000 in credits. |
Investment & Pricing
Fixed-fee assessment, scoped remediation, and ongoing managed compliance. No retainer until you’ve seen the gap report and approved the plan.
Step 1 Gap Assessment$8,500 Fixed fee · 1–2 week turnaround Full assessment against all 110 NIST 800-171 controls. Written gap report with findings prioritized by risk and effort. Remediation roadmap included. Applied toward remediation if you proceed. | Core Engagement Step 2 RemediationFrom $19,800 Scoped per engagement · 3–12 weeks Technical hardening, SSP and POA&M documentation, policy library, and C3PAO readiness walkthrough. Scoped to your specific gap count after assessment. Gap assessment fee credited toward this engagement. | Step 3 Ongoing Compliance$150 Per device / month · No long-term contract Continuous SIEM monitoring, endpoint protection, patch management, and quarterly compliance reporting. Keeps your controls in place between triennial assessments. Month-to-month after initial setup. Scale as your device count changes. |
Maryland Cybersecurity Tax Credit: Maryland-based contractors may qualify for up to $50,000 in tax credits for eligible cybersecurity investments — which can offset significant portions of your gap assessment and remediation costs. We help you document eligible expenditures.
Frequently Asked Questions
What is a SPRS score and do I need one?
The Supplier Performance Risk System (SPRS) score is your DoD self-assessment score based on NIST SP 800-171. It ranges from -203 to +110. Any company with active DoD contracts that involve CUI is required to submit a score to the SPRS database. Prime contractors are increasingly requiring subcontractors to provide their SPRS score as a condition of award.
Do subcontractors need CMMC certification?
Yes, if they handle CUI. CMMC requirements flow down through the supply chain — if your prime contractor’s contract includes DFARS 252.204-7012, that requirement passes to you as a subcontractor. Many small businesses in the DIB supply chain are unaware of their obligation until a prime asks for their SPRS score or CMMC status.
How long does CMMC preparation take?
The gap assessment takes 1–2 weeks. Remediation depends on your gap count — contractors who are 60–70% compliant typically take 6–10 weeks. Contractors starting from a lower baseline may take 12–16 weeks. After remediation, the C3PAO assessment itself is a separate engagement you schedule with an accredited assessor.
What happens if my SPRS score is negative?
A negative SPRS score means you have documented control deficiencies on file with DoD. It doesn’t immediately disqualify you from contracts, but it creates risk — prime contractors can see your score, and a significantly negative score may affect award decisions. You can update your SPRS submission at any time as you close gaps. Our gap assessment gives you an accurate picture of your current score and a roadmap to improve it.
Can Lewis IT certify us for CMMC?
No — and any MSP that tells you they can is misleading you. CMMC Level 2 certification requires an assessment by an accredited C3PAO (Certified Third Party Assessment Organization). What we do is everything that comes before that assessment — closing your gaps, building your controls, writing your documentation, and making sure you’re ready when the C3PAO arrives. Once you’re ready, we can refer you to accredited C3PAOs in the region.
Know Where You Stand
Before the Assessor Does
A gap assessment takes two weeks and tells you exactly what needs to change before you can pursue CMMC Level 2 certification. No obligation beyond that.
Maryland-based · SAM.gov registered · NAICS 541519
