CMMC Readiness Advisory · Registered Practitioner

Get your SPRS score and CMMC readiness plan in 48 hours

CMMC readiness support for small and micro-sized DIB contractors that need help with scoping, SPRS scoring, SSP readiness, evidence organization, and C3PAO preparation.
Free 30-minute scoping call · No obligation · 48-hour Snapshot requires a completed, current SSP — No SSP yet? Start with the Sprint.
48 hours
SPRS score + readiness baseline · requires a completed, current SSP
110 practices
NIST SP 800-171 reviewed
Level 1 · Level 2 SA · Level 2 C3PAO
All assessment paths supported

CMMC can get messy fast

Most small DIB contractors are not trying to ignore CMMC. They are trying to figure out what applies, what evidence is required, and whether their current IT environment can support the assessment path.
You do not need to become a CMMC expert before you start. You need a clear scope, an honest readiness baseline, and a practical remediation path.
See the 3-step readiness process ↓
Which contracts, systems, users, and service providers are in scope?
Do we handle FCI, CUI, or both?
What is our current SPRS score?
Is our SSP current and backed by evidence?
Are we ready for Level 1, Level 2 self-assessment, or Level 2 C3PAO preparation?

A practical 3-step path to CMMC readiness

Scope the environment, identify gaps, and build the evidence needed for your assessment path.
STEP 01

Assess

Confirm scope, review FCI/CUI flow, baseline NIST SP 800-171 readiness, calculate the SPRS score, and identify initial POA&M themes.
STEP 02

Build

Create or improve the SSP, policies, procedures, diagrams, responsibility assignments, and evidence package.
STEP 03

Sustain

Support recurring reviews, evidence refresh, POA&M tracking, and readiness checks as systems and contracts change.
110
NIST SP 800-171 practices reviewed
48 hrs
To SPRS score & POA&M direction (requires a completed, current SSP)
Ongoing
Support as systems and contracts change

Why small DIB contractors work with Lumos

CMMC readiness help for small contractor environments, MSP-supported systems, and teams that need assessment evidence organized before their next affirmation — not after.
Lumos Innovations helps small and micro-sized defense contractors turn CMMC requirements into a manageable readiness plan, focusing on scoping, documentation, evidence, and remediation planning so leadership can make informed decisions before a self-assessment or C3PAO engagement.
Veteran & Native Hawaiian-owned
28 NIST cybersecurity assessment and readiness engagements since 2017
Specialized in CMMC, NIST SP 800-171, DFARS, and 32 CFR Part 170
Practical support for SSPs, SPRS scoring, POA&Ms, and evidence organization

Is Lumos the right fit for your CMMC readiness?

Lumos works best for specific types of DIB contractors. Use this to check whether our approach fits your situation.

Lumos works well for:

  • Small and micro-sized DIB contractors, typically under 50 employees
  • DoD prime contractors and subcontractors with DFARS 252.204-7012 requirements
  • Contractors pursuing Level 1, Level 2 self-assessment, or Level 2 C3PAO preparation
  • Organizations with limited internal cybersecurity staff
  • MSP-supported environments needing scope and responsibility clarification
  • Teams with an existing SSP that needs review or evidence alignment
  • Contractors who have not yet calculated an accurate SPRS score

Lumos does not serve:

  • Organizations needing a formal CMMC assessment conducted — a C3PAO must do that
  • Contractors looking for managed IT or technical tooling implementation
  • Non-DIB organizations seeking general cybersecurity consulting

Which CMMC level applies to your contracts?

Use this to identify your assessment path before booking a readiness review.
Level 1 Self-AssessmentLevel 2 Self-AssessmentLevel 2 C3PAO Assessment
HandlesFCI only (no CUI)CUI in a defined enclaveCUI in a defined enclave
Framework17 practices (FAR 52.204-21)110 practices (NIST SP 800-171 r2)110 practices (NIST SP 800-171 r2)
Who assessesContractor self-attests annuallyContractor self-assesses; affirms in SPRSC3PAO conducts formal assessment
SPRS requiredNoYes — score must be current and defensibleYes — reviewed during C3PAO assessment
SSP requiredNo formal SSP requiredYes — SSP must reflect current environmentYes — SSP is central evidence artifact
Lumos supportScope clarification, FAR reviewSPRS scoring, SSP build, gap analysis, POA&MFull readiness prep: SSP, evidence package, POA&M, pre-assessment review
Not sure which level applies?
Book a Free 30-Minute Scoping Call

Choose the right CMMC readiness starting point

48-Hour Readiness Snapshot — $4,950

For contractors with a completed, current SSP: an accurate SPRS score and readiness baseline within 2 business days of signed SOW, payment, and complete documents.
Scope review · SPRS estimate · SSP/evidence readiness check · Initial POA&M themes · Recommended next step
Start with the Snapshot →

CUI Scope & SPRS Defensibility Sprint — $6,500

No SSP, or unsure it's current? Five business days to a clear CUI scope, SPRS score, and remediation direction. Two Sprint slots per month.
Policies · Procedures · SSP updates · Responsibility mapping · Evidence organization · Remediation support
Start with the Sprint →

Full Gap Analysis — $8,500–$14,500

Optional three-week deep dive across all 110 NIST SP 800-171 practices when you want the complete picture first. Priced by headcount: $8,500 (≤25 employees), $11,500 (26–50); complex environments $14,500.
Level 1 · Level 2 SA · C3PAO preparation · Pre-assessment review
See the Full Gap Analysis →

What DIB teams say about working with Lumos

Practical feedback from contractors using Lumos for CMMC readiness, SPRS reviews, and cybersecurity compliance support.
“Lumos has become our go-to team for CMMC and SPRS reviews. When it is time for our annual checkup, we reach out to them first.”
— Operations Manager, Defense Contractor
“Their team is quick to respond and explains things in plain language. They cleared up technical concerns for us within a single email thread.”
— IT Lead, Federal Services Firm
“Working with Lumos is straightforward. Communication is clear, responses are prompt, and decisions are easier when they present the options.”
— Program Manager, Defense Industrial Base

Common questions about CMMC readiness

Answers to the questions small DIB contractors ask most often before starting their CMMC readiness work.
What is the difference between a CMMC self-assessment and a C3PAO assessment? +
A Level 2 self-assessment means your organization evaluates its own compliance against NIST SP 800-171, calculates an SPRS score, and affirms the result in SPRS. A Level 2 C3PAO assessment means a certified third-party organization independently verifies your compliance. Which path you need depends on your contract requirements. Lumos helps you determine which applies and prepares your documentation for either outcome.
What is an SPRS score and why does it matter? +
The SPRS score is a numeric value from −203 to 110 representing your implementation status against the 110 NIST SP 800-171 practices. A score of 110 means all practices are fully implemented. DoD uses SPRS scores to evaluate contractor risk, and submitting an inaccurate score can result in contract loss or False Claims Act liability. Lumos helps you calculate a defensible SPRS score backed by your SSP and supporting evidence.
What is scoping and why does it matter before starting CMMC work? +
Scoping identifies which systems, users, data flows, and service providers are in scope for your CMMC assessment. A scope that is too large increases your implementation burden; a scope that is too narrow may not accurately reflect where CUI lives, creating risk during a C3PAO assessment. Lumos reviews your contract requirements, data flows, and IT environment to establish a defensible scope before you begin implementation work.
Do I need an SSP if I am only doing a Level 2 self-assessment? +
Yes. A System Security Plan (SSP) is required for Level 2 self-assessment. It documents your scope, boundaries, personnel, service providers, and the implementation status of each NIST SP 800-171 practice. An SSP that does not reflect your actual environment creates significant risk. Lumos helps you build or improve an SSP that is accurate, current, and backed by evidence.
How long does CMMC readiness preparation take? +
Contractors starting from scratch typically need 6 to 12 months to be assessment-ready — for a self-assessment you can defend, or a C3PAO assessment if a contract requires one. Contractors with an existing SSP that needs updating may be ready in 2 to 4 months. The 48-Hour Readiness Snapshot (for contractors with a completed, current SSP) gives you an honest baseline and a realistic timeline within the first engagement.
What does Lumos actually deliver? Are you performing the assessment? +
No. Lumos is a Registered Practitioner (RP) providing CMMC readiness advisory services. We help you scope your environment, calculate your SPRS score, build or improve your SSP, organize your evidence, and prepare your POA&M. We do not conduct official CMMC assessments — that function belongs to certified C3PAOs. What we deliver is the documentation, evidence, and readiness posture that gives you the best chance of a successful self-assessment or C3PAO engagement.

Get the free CMMC Readiness Toolkit

Download five working tools — the SPRS Quick-Score Calculator, a Level 2 readiness checklist, a CUI decision tree, a document request list, and the CMMC status one-pager — to begin organizing your CMMC readiness work.
No spam. Just practical tools to help you start organizing your CMMC readiness work.

Ready to clarify your CMMC readiness path?

Tell me where you are in the process. I'll respond with recommended next steps for scoping, SPRS scoring, documentation, evidence, or assessment preparation. Prefer to talk it through? Book a free 30-minute readiness call.