CMMC Business Assessment


Diversified Tech Solutions  ·  Defense Contractor Compliance CMMC Readiness Assessment
Know Where You Stand Before the Assessor Does
CMMC Level 2 and NIST SP 800-171 still demand documented controls—and a SPRS score you can stand behind. Start free at DefensibleScore.com, then use our gap assessment to know exactly which of the 110 controls you satisfy and what to fix before a C3PAO assessor arrives.
CMMC Level 2 NIST SP 800-171 110-Control Gap Analysis SSP & POA&M Support Defense Contractor Specialists
Free · From Diversified Tech Solutions Start with a free SPRS Defensibility Check

Before a full 110-control readiness engagement, run our free, non-CUI triage at DefensibleScore.com. It flags optimistic scoring, weak evidence, and signature risk in about three minutes—then you can decide if a formal gap assessment is the next step.

Advisory only—we are not a C3PAO and do not certify. No CUI required. Free downloads: sign-off checklist · shared-responsibility matrix · glossary.

What’s at Stake CMMC Is Not Optional. It Is Not Going Away. Defense contractors handling Controlled Unclassified Information (CUI) must achieve CMMC Level 2 certification to bid on and receive DoD contracts. The consequences of non-compliance are direct and severe.
📋 Contract Disqualification

Without CMMC certification, your company cannot bid on DoD contracts that require it. That scope is expanding to cover most defense work.

⏱️ Assessment Lead Time

C3PAO assessments require scheduling months in advance. Companies that wait until a contract requires CMMC discover they can’t get assessed in time to bid.

📂 Documentation Burden

CMMC Level 2 requires a System Security Plan documenting how each of the 110 controls is implemented. Assembling this without preparation takes months.

🔍 Undetected Gaps

Most companies believe they satisfy more controls than they actually do. Gap assessments routinely uncover 20-40 partially or fully unaddressed controls.

The 110 Controls — What They Cover NIST SP 800-171 Covers 14 Domains

Our gap assessment evaluates your current state against all 110 controls across every domain. You already have Control 3.8.3 (Media Protection — data sanitization) documented from your DTS data destruction service. Here’s what the rest covers.

Access Control (22 controls)

Who can access CUI, under what conditions, and with what authentication.

Audit & Accountability (9 controls)

Logging, audit trail retention, and accountability for system activity.

Configuration Management (9 controls)

Baseline configurations, change control, and least-functionality settings.

Identification & Authentication (11 controls)

User identity, MFA requirements, and password management.

Incident Response (3 controls)

Incident handling capability, reporting, and testing.

Maintenance (6 controls)

System maintenance controls, remote maintenance security.

Media Protection (9 controls)

CUI on physical and digital media — including 3.8.3 (sanitization) you already have documented.

Personnel Security (2 controls)

Screening individuals with CUI access, termination procedures.

Physical Protection (6 controls)

Physical access to CUI systems and facilities.

Risk Assessment (3 controls)

Periodic risk assessments, vulnerability scanning, remediation.

Security Assessment (4 controls)

Periodic evaluation of controls, plan of action management.

System & Communications Protection (16 controls)

Network segmentation, boundary protection, encryption in transit.

System & Information Integrity (7 controls)

Malware protection, security alerts, software patching.

Awareness & Training (3 controls)

Security awareness training for all personnel with CUI access.

What You Receive Documentation That Survives a C3PAO Review
110-Control Gap Report

Every control rated: Satisfied, Partially Satisfied, or Not Satisfied. Evidence citations for satisfied controls.

Priority Remediation Roadmap

Gaps ranked by risk and remediation complexity. A clear order of operations for closing findings before assessment.

SSP Draft Template (Readiness Package)

System Security Plan template pre-populated with your satisfied controls. You complete the narrative. We provide the structure.

POA&M Template

Plan of Action and Milestones document for identified gaps — required for your CMMC assessment package.

Evidence Documentation Guidance

For each satisfied control, what documentation the assessor will look for and how to organize it.

30-Day Follow-Up Support

Email access as you work through the remediation roadmap and SSP development.

Fixed SKUs · Hours capped · Clear payment terms Start free at DefensibleScore.com. Fixed prices below. Hour caps keep the engagement bounded—extra work is quoted separately. We are not a C3PAO and do not issue certifications.
SKU-DSR · Defensibility Review $1,995 Up to 8 hours · Payment: 100% up front Short review after the free DefensibleScore check. Challenges optimistic marks and scoring integrity before you sign a SPRS score or buy a full gap engagement.
  • Review of free check results (or equivalent non-CUI inputs)
  • 1 working session (90–120 minutes)
  • Written findings: top risks, scoring issues, go/no-go on signing
  • Prioritized ~2-week action list
  • $500 credit toward Gap Analysis if booked within 90 days
SKU-GAP · Gap Analysis $4,950 Up to 28 hours · Payment: 50% up front / 50% on delivery Full 110-control gap assessment for a single, well-scoped environment. Written gap report and remediation roadmap. Hours beyond the cap are quoted before work continues.
  • Intake questionnaire + 2 working sessions
  • 110-control gap report (satisfied / partial / not satisfied)
  • Priority remediation roadmap
  • 30-day email Q&A (reasonable use, within remaining hour budget)
  • Single CUI enclave / single primary site assumed
SKU-RDY · Readiness Package $7,250 Up to 40 hours · Payment: 50% up front / 50% on delivery Gap Analysis plus SSP draft structure and POA&M support. Prepares documentation for a future C3PAO path—we still do not certify.
  • Everything in Gap Analysis
  • SSP draft template pre-populated from findings
  • POA&M document for identified gaps
  • Evidence documentation guidance per control family
  • 60-day email Q&A within hour budget
SKU-MNT · Annual Maintenance $2,995/yr Up to 14 hours / year · Payment: 100% annual up front Stay-ready documentation retainer: keep SSP and POA&M current as systems change. Not unlimited consulting or a managed SOC.
  • One scheduled annual review cycle
  • SSP / POA&M update pass for documented changes
  • Control re-check only for areas that changed
  • Unused hours do not roll to a new calendar year
How payment & the $500 Gap credit work

Payment: Defensibility Review and Annual Maintenance are due in full before work starts (small, time-boxed packages). Gap Analysis and Readiness Package are 50% to schedule / start and 50% on delivery of the written package. Work pauses if the second installment is overdue.

Hour caps: Prices include the hours listed. Out-of-scope items (extra sites, deep remediation engineering, multi-MSP rebuilds) are estimated and approved in writing before extra billable hours.

$500 Gap credit: If you purchase the Defensibility Review and then book Gap Analysis within 90 days, we subtract $500 from the Gap SKU (Gap due = $4,450). You still paid $1,995 for the Review itself—that work is delivered and kept. The credit is a loyalty discount on the next package, not a full transfer of the Review fee. Example: Review + Gap within 90 days = $1,995 + $4,450 = $6,445 total. Gap alone = $4,950. Choose Review first when you need a sign-off / scoring challenge; go straight to Gap when you already know you need the full 110-control report.

Important Scope Clarification

We provide readiness assessment and documentation support only. Diversified Tech Solutions is not a C3PAO and does not issue CMMC certifications of any level. Formal CMMC Level 2 certification (when required) must be conducted by an accredited C3PAO. Our service prepares you for that path by identifying gaps, building documentation, and establishing evidence for satisfied controls—it is not a certification, not a guarantee of assessment outcome, and not legal advice.

Free tool + paid readiness from the same team

DefensibleScore.com is our free SPRS defensibility check and CMMC education site (built by DTS). Use it to triage signature risk and learn the landscape, then book a DTS readiness engagement when you need the full 110-control gap report and SSP/POA&M package.

Already Using DTS for Secure Data Destruction?

Your DTS data destruction certificate already documents Media Protection Control 3.8.3 — one of the 110 NIST SP 800-171 requirements. That’s the starting point. Our CMMC Readiness Assessment covers the other 109 and builds the documentation package around your existing evidence. DTS data destruction clients receive a 10% discount on any CMMC Readiness tier.

Find Out Where You Stand Against the 110 Controls

Start free at DefensibleScore.com, or book a 20-minute call. We’ll tell you honestly whether a readiness gap assessment makes sense. Reminder: we prepare documentation and posture—we do not issue CMMC certifications.

Diversified Tech Solutions  ·  Johnson City, TN  ·  avery@diversifiedtechsolutions.com
CMMC Readiness Assessment available remotely to defense contractors nationwide.