Home / Solutions

Service

CMMC Level 2 and NIST 800-171 Readiness

Defense contractors that handle Controlled Unclassified Information (CUI) need to show they meet NIST SP 800-171. We help you understand your gaps and build a practical path to CMMC Level 2 readiness.

What’s included

Scope

Scoping

Identify where CUI lives and flows so your assessment boundary is realistic and defensible.

Gap assessment

Review your environment against the NIST SP 800-171 requirements that CMMC Level 2 is built on.

SSP & POA&M support

Help develop or improve your System Security Plan and Plan of Action and Milestones.

Remediation roadmap

Prioritize fixes by risk, effort, and assessment impact.

Policy & procedure

Draft or refine the policies and procedures assessors expect to see.

Assessment preparation

Prepare evidence and walk through what to expect from a third-party assessment.

Who it’s for

  • Defense contractors and subcontractors handling CUI
  • Organizations responding to DFARS or CMMC requirements in contracts
  • Primes that need subcontractors to demonstrate readiness

What you get

  • Gap analysis against NIST SP 800-171
  • Prioritized remediation roadmap
  • SSP and POA&M input
  • Executive briefing

FAQ

Common questions

Are you a C3PAO?

No. Hawkcrest provides readiness consulting. Formal CMMC Level 2 certification assessments are performed by authorized third-party assessment organizations (C3PAOs).

We already use Microsoft 365. Does that make us compliant?

Your platform can support many requirements, but compliance depends on configuration, scope, policies, and evidence. We review all of these.

How long does readiness take?

It depends on your size, scope, and starting point. The gap assessment gives you a realistic timeline.

Why Hawkcrest

Ready to talk?

Tell us what you need. We respond within one business day.

Request a service