Preparing for a Level 2 C3PAO assessment, validating a self-assessment score, or still working out what's in scope — each situation starts at a different point on the same pathway.
DoD suspended CMMC Phase 2 on July 13, 2026 — but Phase 1 self-assessments, SPRS scores, and annual affirmations are already in solicitations, and readiness from scratch still takes 6–12 months.
One pathway, seven stages
From "not sure where we stand" to a number that's never stale. Start where your situation puts you — every stage is a fixed fee, and Snapshot and Sprint fees credit toward later documentation stages.
Have a current SSP → start at the Snapshot. No SSP or unsure of scope → start at the Sprint. Want the full picture first → Gap Analysis. The Retainer is sold only to past clients.
Three questions route you to the right start
No quiz, no email gate. Answer honestly and start where the answers point.
Do you have a current SSP (System Security Plan)?
Yes →
48-Hour Snapshot — your SSP is the input; the verdict takes two days.
No →
5-Day Sprint — scope and baseline come first; there's nothing to snapshot yet.
Do you know where your CUI (Controlled Unclassified Information) lives?
Yes →
Full Gap Analysis — with scope settled, score all 110 practices before spending on fixes.
Unsure →
5-Day Sprint — a wrong scope makes every later dollar less effective.
The price on this page is the price on the SOW. Questions, clarifications, and the recorded debrief never run a clock.
One consolidated revision round
Every documentation engagement includes a full revision round where all stakeholder feedback is gathered and applied at once — predictable for you, focused for the work.
Your clock starts when your documents are in
The engagement timeline begins once the SOW is signed, payment has settled, and the document checklist is complete — so "48 hours" and "5 days" mean what they say, and you're never billed for waiting.
28 NIST cybersecurity assessment and readiness engagements since 2017
NIST SP 800-53 assessments for federal systems and CMMC readiness for DIB contractors — practitioner-led, every engagement.
No. Lumos is a Cyber AB Registered Practitioner (RP) providing readiness advisory and documentation services. Formal CMMC assessments are conducted only by certified C3PAOs (third-party assessment organizations). What Lumos delivers is the scope, documentation, and evidence posture that gives you the best chance of passing one.
Why is your pricing public? +
Because hidden pricing is how risk gets transferred to the buyer. Every engagement here is a fixed fee, published before the first call — you can compare, budget, and decide without a sales process. That is the differentiator, on purpose.
What is a "POA&M-eligible gap"? +
A POA&M (Plan of Action & Milestones) is the official list of gaps you are allowed to carry into assessment, provided each meets CMMC eligibility criteria and is closed within 180 days. Not every gap qualifies — some are show-stoppers. Knowing which is which is a core output of the Gap Analysis and Readiness Review.
Can these fees be allowable costs on our contracts? +
CMMC readiness consulting is generally an allowable cost under FAR 31.205-33 (professional and consultant service costs) — confirm treatment with your contracts team or DCAA point of contact.
What if we need implementation help? +
Your IT staff or MSP performs that work — Lumos does not configure, install, or remediate systems. What Lumos does is define exactly what needs to change, in language your technical team can execute, and then verify the result is documented and evidenced correctly.
Start with a free 30-minute readiness call
Tell me where you are. I'll tell you the right starting point — including when the honest answer is "you don't need Lumos yet."