Win DoD Contracts.
Get CMMC-Ready First.
Defense contractors handling Controlled Unclassified Information must achieve CMMC certification before pursuing new DoD contracts. Lewis IT closes your compliance gaps, builds your documentation, and gets you ready for your C3PAO assessment.
Understanding CMMC 2.0 Levels
CMMC 2.0 has three levels. Most defense contractors in the DIB supply chain need to reach Level 1 or Level 2. We prepare contractors for both.
Level 1 — Foundational Basic Cyber Hygiene17 practices · Annual self-attestation Required for contractors handling Federal Contract Information (FCI). Covers basic security practices and can be self-attested annually by a senior company official. Typical gaps: Access controls, system and communications protection, system integrity, identification and authentication. | Most Common Requirement Level 2 — Advanced Protecting CUI110 practices · C3PAO assessment required Required for contractors handling Controlled Unclassified Information (CUI). Aligns with all 110 practices in NIST SP 800-171. Requires a triennial assessment by an accredited C3PAO. Most contractors are 40–70% compliant before engaging us. The remaining gaps are usually documentation, logging, and access control. We close those. | Level 3 — Expert Critical ProgramsNIST 800-172 · Government-led assessment Reserved for contractors supporting the DoD’s most critical programs. Requires a government-led assessment by DCSA. A small subset of the DIB supply chain. Note: If your contracts require Level 3, contact us for a referral to appropriate government assessment channels. We support Level 1 and Level 2 preparation. |
A Straight Answer We will not tell you we can certify you. Only an accredited C3PAO can issue a CMMC certificate. What we do is everything that comes before that assessment — closing the gaps, building the controls, writing the documentation, and making sure the assessor finds what they need to find. Most contractors we talk to are 40–70% compliant before we engage. The remaining gaps are usually documentation, logging, and access control. We close those. Then you go to your C3PAO confident. |
What We Do for You
Six service areas that take you from your current state to C3PAO-ready.
01 · Gap Assessment NIST 800-171 Gap AssessmentWe assess your environment against all 110 NIST 800-171 controls and deliver a written gap report with findings prioritized by risk and effort required to close. This is your roadmap to certification. | 02 · Technical Controls Technical Hardening & ImplementationMFA enforcement, encrypted communications, endpoint protection, access control configuration, audit logging, and network segmentation. We implement the technical controls the assessment will verify. |
03 · Documentation SSP, POA&M & Policy LibraryWe build your System Security Plan (SSP), Plan of Action & Milestones (POA&M), incident response plan, and the supporting policy library. These are the documents your C3PAO assessor will read first. | 04 · Monitoring Continuous MonitoringPost-certification, your controls must stay in place. We provide ongoing managed security with SIEM monitoring, endpoint detection, and regular compliance reporting to keep you ready for triennial reassessment. |
05 · Assessment Prep C3PAO Readiness WalkthroughBefore your formal assessment, we conduct an internal pre-assessment simulating what the C3PAO assessor will look for. We close any remaining items before they find them and ensure your documentation is organized and accessible. | 06 · Maryland Incentive Buy MD Cybersecurity Tax CreditMaryland-based businesses may qualify for up to $50,000 in tax credits for eligible cybersecurity investments. CMMC preparation work may qualify. We help you document eligible expenditures. |
From Gap to Ready — How It Works
Six steps from your current compliance posture to C3PAO-ready.
|
|
NIST SP 800-171 — 14 Control Domains
We address all of them. No partial coverage, no carve-outs.
Access Control 22 controls | Audit & Accountability 9 controls | Configuration Mgmt 9 controls | Identification & Auth 11 controls |
Incident Response 3 controls | Maintenance 6 controls | Media Protection 9 controls | Personnel Security 2 controls |
Physical Protection 6 controls | Risk Assessment 3 controls | Security Assessment 4 controls | System & Comms 16 controls |
System & Info Integrity 7 controls | Awareness & Training 3 controls | ||
Progress bars represent Lewis IT’s typical coverage capacity per domain based on previous engagements. Your specific gap count will vary.
Why Lewis IT for CMMC Prep?
We’re a Maryland MSP with federal market experience — not a big consulting firm that will hand your engagement to a junior analyst.
SAM.gov RegisteredNAICS 541519, SBA small business. We understand the federal contracting environment because we participate in it. | Maryland-BasedBased in Southern Maryland, serving the DC Metro defense contractor community. Local presence means on-site availability when the assessment requires it. | Technical + DocumentationWe do both the technical implementation and the documentation. You don’t need to hire a separate policy consultant and a separate IT firm. |
Production Security StackWe run SIEM, endpoint detection, threat intelligence, and zero-trust networking in our own operations. We deploy what we know works. | No OversellingWe tell you exactly what you need and what we can’t do. We will not promise you certification — only a C3PAO can do that. We promise to get you ready for it. | MD Tax Credit HelpWe help Maryland contractors document eligible CMMC-related expenditures for the Buy MD Cybersecurity Tax Credit — up to $50,000 in credits. |
Know Where You Stand
Before the Assessor Does
A gap assessment takes two weeks and tells you exactly what needs to change before you can pursue CMMC Level 2 certification. No obligation beyond that.
Maryland-based · SAM.gov registered · NAICS 541519
