Audit Services

Before an assessment decides whether you pass, it helps to know.

Who this is for

Organizations approaching a CMMC Level 2 assessment, organizations that need a defensible self-assessment and SPRS score, and organizations whose last assessment was performed by the same party that built the program.

Problems we address

  • A self-assessment score nobody can defend
  • Controls documented as implemented that would not survive examination
  • Evidence that exists but is not collected, current, or retrievable
  • No realistic view of assessment readiness before the assessment
  • Findings discovered during assessment rather than months before

Scope and approach

We assess against NIST SP 800-171A objectives using examine, interview, and test methods — the same methodology an assessor applies. Evidence is reviewed for sufficiency, not merely existence.

You receive findings stated plainly. A control that is partially implemented is reported as partially implemented, because a readiness assessment that tells you what you want to hear is worse than none at all.

Typical deliverables

  • Readiness assessment report against all applicable NIST SP 800-171A objectives
  • Evidence sufficiency review with identified gaps
  • Defensible self-assessment score and SPRS submission support
  • Prioritized remediation plan with effort estimates
  • POA&M development or validation
  • Assessment logistics preparation and evidence organization

Framework and technology context

NIST SP 800-171A, CMMC Level 2 scoping and assessment guidance, the CMMC Assessment Process (CAP), DFARS 252.204-7012, and SPRS reporting.

On independence

OSC personnel hold Cyber AB assessor credentials, and we take the resulting independence requirements seriously. Readiness assessment and certification assessment are separate roles that cannot be performed by the same party for the same client. Where OSC has provided consulting or readiness work for your organization, OSC personnel will not participate in your certification assessment, and we will tell you so before the engagement begins rather than after. Certification assessments are conducted by authorized C3PAOs; we will help you engage one and prepare for it.

If your assessment date is set and you are not certain how you would score, find out now.

A readiness assessment is not a certification assessment and confers no certification. Certification decisions rest solely with an authorized C3PAO and the CMMC ecosystem. Readiness findings reflect the environment as examined at a point in time.

Talk to a senior practitioner

Tell us about your contracts, your environment, and your timeline. We will tell you plainly what we would do first.