CMMC 2.0 Compliance Preparation

Win DoD Contracts.
Get CMMC-Ready First.

Defense contractors handling Controlled Unclassified Information must achieve CMMC certification before pursuing new DoD contracts. Lewis IT closes your compliance gaps, builds your documentation, and gets you ready for your C3PAO assessment.

110
NIST 800-171 Controls
14
Control Domains
SAM.gov
Registered · NAICS 541519
MD-based
Southern Maryland MSP

Understanding CMMC 2.0 Levels

CMMC 2.0 has three levels. Most defense contractors in the DIB supply chain need to reach Level 1 or Level 2. We prepare contractors for both.

Level 1 — Foundational

Basic Cyber Hygiene

17 practices · Annual self-attestation

Required for contractors handling Federal Contract Information (FCI). Covers basic security practices and can be self-attested annually by a senior company official.

Typical gaps: Access controls, system and communications protection, system integrity, identification and authentication.

Most Common Requirement
Level 2 — Advanced

Protecting CUI

110 practices · C3PAO assessment required

Required for contractors handling Controlled Unclassified Information (CUI). Aligns with all 110 practices in NIST SP 800-171. Requires a triennial assessment by an accredited C3PAO.

Most contractors are 40–70% compliant before engaging us. The remaining gaps are usually documentation, logging, and access control. We close those.

Level 3 — Expert

Critical Programs

NIST 800-172 · Government-led assessment

Reserved for contractors supporting the DoD’s most critical programs. Requires a government-led assessment by DCSA. A small subset of the DIB supply chain.

Note: If your contracts require Level 3, contact us for a referral to appropriate government assessment channels. We support Level 1 and Level 2 preparation.

A Straight Answer

We will not tell you we can certify you. Only an accredited C3PAO can issue a CMMC certificate. What we do is everything that comes before that assessment — closing the gaps, building the controls, writing the documentation, and making sure the assessor finds what they need to find. Most contractors we talk to are 40–70% compliant before we engage. The remaining gaps are usually documentation, logging, and access control. We close those. Then you go to your C3PAO confident.

What We Do for You

Six service areas that take you from your current state to C3PAO-ready.

01 · Gap Assessment

NIST 800-171 Gap Assessment

We assess your environment against all 110 NIST 800-171 controls and deliver a written gap report with findings prioritized by risk and effort required to close. This is your roadmap to certification.

02 · Technical Controls

Technical Hardening & Implementation

MFA enforcement, encrypted communications, endpoint protection, access control configuration, audit logging, and network segmentation. We implement the technical controls the assessment will verify.

03 · Documentation

SSP, POA&M & Policy Library

We build your System Security Plan (SSP), Plan of Action & Milestones (POA&M), incident response plan, and the supporting policy library. These are the documents your C3PAO assessor will read first.

04 · Monitoring

Continuous Monitoring

Post-certification, your controls must stay in place. We provide ongoing managed security with SIEM monitoring, endpoint detection, and regular compliance reporting to keep you ready for triennial reassessment.

05 · Assessment Prep

C3PAO Readiness Walkthrough

Before your formal assessment, we conduct an internal pre-assessment simulating what the C3PAO assessor will look for. We close any remaining items before they find them and ensure your documentation is organized and accessible.

06 · Maryland Incentive

Buy MD Cybersecurity Tax Credit

Maryland-based businesses may qualify for up to $50,000 in tax credits for eligible cybersecurity investments. CMMC preparation work may qualify. We help you document eligible expenditures.

From Gap to Ready — How It Works

Six steps from your current compliance posture to C3PAO-ready.

1
Discovery Call

15 minutes. We learn what contracts you’re pursuing, what CUI you handle, and whether you’ve had any prior assessment or self-evaluation. No forms, no sales deck.

Week 0 · 15 min

2
Gap Assessment

We assess your environment against all 110 NIST 800-171 controls. You receive a written gap report with findings prioritized by risk and effort required to close.

Weeks 1–2 · Written deliverable

3
Remediation Plan

We build a remediation roadmap scoped to your timeline and budget. Quick wins first, then structural controls, then documentation. You approve the plan before any work begins.

Week 2 · Your approval required

4
Implementation

We implement technical controls, configure your environment, and build required documentation. You receive regular progress updates against the gap report.

Weeks 3–12 · Depends on gap count

5
Pre-Assessment Walkthrough

Before you schedule your C3PAO assessment, we conduct an internal review simulating what the assessor will look for. We close any remaining items before they find them.

Week 13+ · Internal dry run

6
Ongoing Compliance

CMMC certification is triennial — you need to stay compliant between assessments. Our managed security service keeps your controls in place and generates the ongoing evidence your assessor will ask for.

Ongoing · Monthly managed service

NIST SP 800-171 — 14 Control Domains

We address all of them. No partial coverage, no carve-outs.

Access Control
22 controls
Audit & Accountability
9 controls
Configuration Mgmt
9 controls
Identification & Auth
11 controls
Incident Response
3 controls
Maintenance
6 controls
Media Protection
9 controls
Personnel Security
2 controls
Physical Protection
6 controls
Risk Assessment
3 controls
Security Assessment
4 controls
System & Comms
16 controls
System & Info Integrity
7 controls
Awareness & Training
3 controls

Progress bars represent Lewis IT’s typical coverage capacity per domain based on previous engagements. Your specific gap count will vary.

Why Lewis IT for CMMC Prep?

We’re a Maryland MSP with federal market experience — not a big consulting firm that will hand your engagement to a junior analyst.

SAM.gov Registered

NAICS 541519, SBA small business. We understand the federal contracting environment because we participate in it.

Maryland-Based

Based in Southern Maryland, serving the DC Metro defense contractor community. Local presence means on-site availability when the assessment requires it.

Technical + Documentation

We do both the technical implementation and the documentation. You don’t need to hire a separate policy consultant and a separate IT firm.

Production Security Stack

We run SIEM, endpoint detection, threat intelligence, and zero-trust networking in our own operations. We deploy what we know works.

No Overselling

We tell you exactly what you need and what we can’t do. We will not promise you certification — only a C3PAO can do that. We promise to get you ready for it.

MD Tax Credit Help

We help Maryland contractors document eligible CMMC-related expenditures for the Buy MD Cybersecurity Tax Credit — up to $50,000 in credits.

Know Where You Stand
Before the Assessor Does

A gap assessment takes two weeks and tells you exactly what needs to change before you can pursue CMMC Level 2 certification. No obligation beyond that.

Maryland-based · SAM.gov registered · NAICS 541519