Scoping
Identify where CUI lives and flows so your assessment boundary is realistic and defensible.
Service
Defense contractors that handle Controlled Unclassified Information (CUI) need to show they meet NIST SP 800-171. We help you understand your gaps and build a practical path to CMMC Level 2 readiness.
What’s included
Identify where CUI lives and flows so your assessment boundary is realistic and defensible.
Review your environment against the NIST SP 800-171 requirements that CMMC Level 2 is built on.
Help develop or improve your System Security Plan and Plan of Action and Milestones.
Prioritize fixes by risk, effort, and assessment impact.
Draft or refine the policies and procedures assessors expect to see.
Prepare evidence and walk through what to expect from a third-party assessment.
Who it’s for
What you get
FAQ
No. Hawkcrest provides readiness consulting. Formal CMMC Level 2 certification assessments are performed by authorized third-party assessment organizations (C3PAOs).
Your platform can support many requirements, but compliance depends on configuration, scope, policies, and evidence. We review all of these.
It depends on your size, scope, and starting point. The gap assessment gives you a realistic timeline.
Why Hawkcrest
Tell us what you need. We respond within one business day.
Other solutions: Risk Assessment · OT/ICS Security · Microsoft 365 Security · AI Security & Governance · Spring, The Woodlands & North Houston