For aerospace, marine, and manufacturing subcontractors on the Treasure Coast and in Palm Beach North

CMMC readiness built for the subcontractor, not the prime.

Level 1 self-assessments done right, honest SPRS scores, and Level 2 readiness with an SSP and POA&M a C3PAO will accept. Scoped to a machine shop or a parts distributor, not a defense prime.

  • CMMC 2.0 (32 CFR Part 170)
  • NIST SP 800-171 Rev. 2
  • DFARS 252.204-7012 / 7019 / 7020 / 7021
  • FAR 52.204-21
  • SPRS

Phase 1 is in force. Phase 2 is paused. Your obligations are not.

Verified September 2026

CMMC requirements began appearing in DoD solicitations on November 10, 2025. On July 13, 2026, DoD suspended the Phase 2 C3PAO-certification rollout pending a Reform Task Force review, with a report expected in the fall. What did not pause: DFARS 7012 safeguarding, the requirement for a current SPRS score, Level 1 and Level 2 self-assessments in Phase 1 contracts, and primes flowing requirements down to you regardless of what DoD does next. An inaccurate SPRS score is a False Claims Act exposure today.

Who this is for

  • Tier 2 to Tier 4 suppliers to Pratt & Whitney, Sikorsky, L3Harris, and Collins
  • Machine shops, composites, and precision manufacturers
  • Marine and aviation MRO and parts distributors
  • Engineering and test-services firms holding CUI
  • Any supplier who received a CMMC flow-down letter from a prime

What usually goes wrong

Your SPRS score was submitted by someone guessing

A self-attested 110 with no SSP behind it is worse than an honest 60 with a POA&M. DOJ has settled False Claims Act cases over exactly this.

You are scoping the whole company when you could scope an enclave

Most small suppliers can put CUI in a tightly scoped enclave and leave the rest of the shop out of assessment scope. Getting this right is the single biggest cost lever in the project.

The prime's questionnaire is due and nobody knows the acronyms

FCI, CUI, SSP, POA&M, C3PAO, SPRS. I speak it fluently and I will translate for your owner.

Your MSP quoted a "CMMC package" that is really a product bundle

Tools help, but CMMC is assessed on documented practices and evidence. A bundle without an SSP and evidence collection will not pass.

What you end up with

Deliverables, not deliverable-shaped PDFs.

A defensible scope

FCI and CUI boundaries documented, with an enclave design when it saves you money.

An honest gap assessment

All 110 NIST SP 800-171 requirements assessed with evidence, scored the way an assessor scores them.

SSP and POA&M a C3PAO will accept

Written in the format assessors expect, with remediation milestones you can actually meet.

A prime-ready posture

Flow-down questionnaires answered accurately, SPRS current, and a plan for whatever Phase 2 becomes.

How the engagement runs

  1. 01

    Scoping call (30 minutes)

    What contracts you hold, what data you receive, and which prime is asking. I tell you whether you are a Level 1 or Level 2 case and what that realistically costs.

  2. 02

    Boundary and enclave design (weeks 1-2)

    Where CUI lives, who touches it, and whether an enclave takes 80% of your shop out of scope.

  3. 03

    Gap assessment (weeks 2-5)

    Every requirement assessed with evidence, not interviews alone. You get the real score and the real list.

  4. 04

    SSP, POA&M, and SPRS (weeks 5-8)

    Documentation written, score submitted accurately, remediation roadmap with owners, dates, and cost estimates.

  5. 05

    Remediate and maintain

    I coordinate the fixes with your IT provider and, on Continuous Compliance, keep the evidence current for assessment day.

Pricing

CMMC & NIST 800-171 Readiness

Level 1 Self-Assessment Package

$4,500 one-time

For suppliers handling only Federal Contract Information (FCI). Get your Level 1 self-assessment done right and affirmed in SPRS.

  • Scoping: what is in and out of your FCI boundary
  • Assessment against the 15 FAR 52.204-21 safeguarding requirements
  • Gap fixes you can implement with your current IT
  • SPRS submission and annual affirmation walkthrough

Best for: Machine shops, marine suppliers, and parts distributors with FCI but no CUI.

Most common

Level 2 Readiness Project

from $25,000 per project

For suppliers that handle Controlled Unclassified Information (CUI). A full NIST SP 800-171 gap assessment, an honest SPRS score, and the documentation a C3PAO will ask for.

  • CUI scoping and enclave design (often the biggest cost saver)
  • Gap assessment against all 110 NIST SP 800-171 requirements
  • System Security Plan (SSP) and Plan of Action & Milestones (POA&M)
  • Accurate SPRS score submission (DFARS 252.204-7019/7020)
  • Remediation roadmap with cost estimates
  • Prime-contractor flow-down and questionnaire responses

Best for: Tier 2 to Tier 4 suppliers to Pratt & Whitney, Sikorsky, L3Harris, Collins, and similar primes.

Continuous Compliance

from $1,500 /month

Keep the SSP, POA&M, and evidence current so the assessment is a formality, not a fire drill.

  • Quarterly control reviews and evidence collection
  • POA&M tracking to closure
  • Change reviews for new systems and vendors
  • Annual affirmation support
  • Assessment-day support when the C3PAO arrives

Best for: Any supplier that has finished a readiness project and wants to stay ready.

Wirsing Security is not a C3PAO and does not certify anyone. Readiness work prepares you for the assessment; the assessment itself is performed by an accredited C3PAO.

FAQ

CMMC Readiness: questions people ask

Phase 2 is suspended. Should we wait?

No. Phase 1 self-assessment requirements, DFARS 7012, and SPRS are all still in force, and primes are flowing requirements down now. Readiness takes months. Waiting for the task force report only compresses your timeline.

Are you a C3PAO or an RPO?

Neither. I am not accredited by the Cyber AB and I do not certify anyone. I prepare you for the assessment, which a C3PAO performs. I will say that plainly on every proposal.

We only have FCI, no CUI. What do we need?

Level 1: the 15 basic safeguarding requirements from FAR 52.204-21, self-assessed annually and affirmed in SPRS. That is the Level 1 package, and it is a fixed price.

Can we do this with our current IT provider?

Usually yes. I have yet to meet a Treasure Coast shop that needed to replace its MSP for CMMC. What changes is that someone has to own the documentation, scoping, and evidence, and that is me.

Get your program started

Talk to Ed

[email protected] · (772) 403-3088