Logo of Loggerhead Dynamics

CMMC Mission Readiness

Mathew Burch
Florida Veteran owned business logo indicating service-disabled veteran-owned certification.
Logo of the U.S. Small Business Administration (SBA) indicating service-disabled veteran-owned certification.
A circular badge with the text 'Pledge Partner' at the top and 'TruthInCyber.org' at the bottom. The badge has a shield in the center with a stylized road or river leading into a horizon, symbolizing cybersecurity or digital trust.

605-519-3772

Get assessment-ready before the deadline decides for you.

If you handle DoD contracts, CMMC is no longer optional. Level 2 requirements are showing up in solicitations now. No compliance, no bid. That is the whole story.

I get defense contractors ready for their C3PAO assessment. I am a service-disabled veteran. I spent more than twenty years inside the Department of Defense. I know what these requirements are for, because I lived on the other side of them.

What I do:

I take you through the full ramp to CMMC Level 2. Scope, assess, fix, document, train, and test. When I am done, you are ready to sit for your assessment.

Here is the line I want to be clear about. I get you ready. I do not certify you. The rules do not allow the company that does the prep work to also run the official assessment. That is a separate firm called a C3PAO. I get you to their door with everything in order, and I stay with you through it.

Start with a gap assessment.

Before anyone quotes you a number, you need to know where you stand. So does whoever quotes you. That is what this is for.

For a flat fee, I look at your whole environment.

You get:

  • A penetration test. A real one, run by my testing partner, not an automated scan with a nice cover page. Most contractors have never had one. You will see what an attacker sees.

  • Your SPRS score. The number DoD actually looks at, calculated and ready to report.

  • A gap report. Every control you meet, every one you do not, in plain language.

  • A scoped quote for the full ramp. A real price, based on your real environment, not a guess.

The assessment is yours to keep whether you hire me for the ramp or not. If you take it somewhere else, it still works. I would rather earn the next step than trap you into it.

The full ramp.

Once we know the landscape, I fix it. What that takes depends on what you have, which is why I do not put a package price on it. A ten-person shop with clean systems and a contractor running twenty old machines are not the same job, and you should not pay like they are.

The ramp covers all 110 controls in NIST 800-171. In practice that means:

  • A compliant home for your CUI. Controlled Unclassified Information has to live somewhere that meets the standard. I stand up and migrate you to a GCC High environment built for it.

  • The technical controls. Endpoint protection, multi-factor, email security, backups, monitoring. Installed, configured, and maintained.

  • The paperwork that passes. Your System Security Plan, your policies, your POA&M. Documented the way an assessor expects to see it.

  • Your people. Security awareness training and phishing tests, because the rules require it and because your people are the way most breaches start.

A word on the paperwork. The days of writing a plan to fix things later and calling it done are over. Open items have to be closed inside 180 days, and some controls cannot be deferred at all. I get you actually compliant, not compliant on paper.

On-site or remote, whichever costs you less.

I work out of Central Florida and serve the defense base here directly. Some of this I do remotely. Some of it needs me in your building. I do not drive to you and bill you for it when a remote session would have done the same job. I do what the work needs and nothing more.

Why me?

I am one person, and you work with that person. Not an account manager, not a call center, not a junior tech reading a checklist he does not understand.

I am a service-disabled veteran-owned small business. For a prime looking to meet small-business and SDVOSB goals, that is worth something on your side of the ledger too.

I spent two decades making sure nothing got missed when the cost of missing something was somebody's life. Your compliance is a smaller stake than that. I treat it the same way.

The deadline is real.

CMMC requirements are entering DoD contracts now and expanding through the phase-in. The subs who handle this early keep bidding. The ones who wait find out the hard way that the enclave stand-up and the documentation take longer than they hoped.

If you have a contract that mentions CMMC, or you expect one to, start now.

Call 605-519-3772.