Know Where You Stand Before the Assessor Does CMMC Level 2 and NIST SP 800-171 still demand documented controls—and a SPRS score you can stand behind. Start free at DefensibleScore.com, then use our gap assessment to know exactly which of the 110 controls you satisfy and what to fix before a C3PAO assessor arrives.
Before a full 110-control readiness engagement, run our free, non-CUI triage at DefensibleScore.com. It flags optimistic scoring, weak evidence, and signature risk in about three minutes—then you can decide if a formal gap assessment is the next step.
Advisory only—we are not a C3PAO and do not certify. No CUI required. Free downloads: sign-off checklist · shared-responsibility matrix · glossary.
Without CMMC certification, your company cannot bid on DoD contracts that require it. That scope is expanding to cover most defense work.
C3PAO assessments require scheduling months in advance. Companies that wait until a contract requires CMMC discover they can’t get assessed in time to bid.
CMMC Level 2 requires a System Security Plan documenting how each of the 110 controls is implemented. Assembling this without preparation takes months.
Most companies believe they satisfy more controls than they actually do. Gap assessments routinely uncover 20-40 partially or fully unaddressed controls.
Our gap assessment evaluates your current state against all 110 controls across every domain. You already have Control 3.8.3 (Media Protection — data sanitization) documented from your DTS data destruction service. Here’s what the rest covers.
Who can access CUI, under what conditions, and with what authentication.
Logging, audit trail retention, and accountability for system activity.
Baseline configurations, change control, and least-functionality settings.
User identity, MFA requirements, and password management.
Incident handling capability, reporting, and testing.
System maintenance controls, remote maintenance security.
CUI on physical and digital media — including 3.8.3 (sanitization) you already have documented.
Screening individuals with CUI access, termination procedures.
Physical access to CUI systems and facilities.
Periodic risk assessments, vulnerability scanning, remediation.
Periodic evaluation of controls, plan of action management.
Network segmentation, boundary protection, encryption in transit.
Malware protection, security alerts, software patching.
Security awareness training for all personnel with CUI access.
Every control rated: Satisfied, Partially Satisfied, or Not Satisfied. Evidence citations for satisfied controls.
Gaps ranked by risk and remediation complexity. A clear order of operations for closing findings before assessment.
System Security Plan template pre-populated with your satisfied controls. You complete the narrative. We provide the structure.
Plan of Action and Milestones document for identified gaps — required for your CMMC assessment package.
For each satisfied control, what documentation the assessor will look for and how to organize it.
Email access as you work through the remediation roadmap and SSP development.
- Review of free check results (or equivalent non-CUI inputs)
- 1 working session (90–120 minutes)
- Written findings: top risks, scoring issues, go/no-go on signing
- Prioritized ~2-week action list
- $500 credit toward Gap Analysis if booked within 90 days
- Intake questionnaire + 2 working sessions
- 110-control gap report (satisfied / partial / not satisfied)
- Priority remediation roadmap
- 30-day email Q&A (reasonable use, within remaining hour budget)
- Single CUI enclave / single primary site assumed
- Everything in Gap Analysis
- SSP draft template pre-populated from findings
- POA&M document for identified gaps
- Evidence documentation guidance per control family
- 60-day email Q&A within hour budget
- One scheduled annual review cycle
- SSP / POA&M update pass for documented changes
- Control re-check only for areas that changed
- Unused hours do not roll to a new calendar year
Payment: Defensibility Review and Annual Maintenance are due in full before work starts (small, time-boxed packages). Gap Analysis and Readiness Package are 50% to schedule / start and 50% on delivery of the written package. Work pauses if the second installment is overdue.
Hour caps: Prices include the hours listed. Out-of-scope items (extra sites, deep remediation engineering, multi-MSP rebuilds) are estimated and approved in writing before extra billable hours.
$500 Gap credit: If you purchase the Defensibility Review and then book Gap Analysis within 90 days, we subtract $500 from the Gap SKU (Gap due = $4,450). You still paid $1,995 for the Review itself—that work is delivered and kept. The credit is a loyalty discount on the next package, not a full transfer of the Review fee. Example: Review + Gap within 90 days = $1,995 + $4,450 = $6,445 total. Gap alone = $4,950. Choose Review first when you need a sign-off / scoring challenge; go straight to Gap when you already know you need the full 110-control report.
We provide readiness assessment and documentation support only. Diversified Tech Solutions is not a C3PAO and does not issue CMMC certifications of any level. Formal CMMC Level 2 certification (when required) must be conducted by an accredited C3PAO. Our service prepares you for that path by identifying gaps, building documentation, and establishing evidence for satisfied controls—it is not a certification, not a guarantee of assessment outcome, and not legal advice.
DefensibleScore.com is our free SPRS defensibility check and CMMC education site (built by DTS). Use it to triage signature risk and learn the landscape, then book a DTS readiness engagement when you need the full 110-control gap report and SSP/POA&M package.
Already Using DTS for Secure Data Destruction?Your DTS data destruction certificate already documents Media Protection Control 3.8.3 — one of the 110 NIST SP 800-171 requirements. That’s the starting point. Our CMMC Readiness Assessment covers the other 109 and builds the documentation package around your existing evidence. DTS data destruction clients receive a 10% discount on any CMMC Readiness tier.
Start free at DefensibleScore.com, or book a 20-minute call. We’ll tell you honestly whether a readiness gap assessment makes sense. Reminder: we prepare documentation and posture—we do not issue CMMC certifications.
Diversified Tech Solutions · Johnson City, TN · avery@diversifiedtechsolutions.com
CMMC Readiness Assessment available remotely to defense contractors nationwide.
