Define the assessment scope
Identify CUI workflows, people, systems, providers and responsibilities. Keep the boundary specific to your contract.
CMMC & SPRS readiness
Level 2 self-assessment and SPRS support connect your actual safeguards to the evidence your customers expect. C3PAO assessment capability adds an assurance layer when required.
Identify CUI workflows, people, systems, providers and responsibilities. Keep the boundary specific to your contract.
Review NIST SP 800-171 Rev. 2 implementation, self-assessment scoring and evidence. Confirm eligible POA&M conditions and owners.
Support SPRS record preparation, remediation and continuing compliance. Plan the appropriate C3PAO assessment engagement.
Independent assurance
When your contract calls for a third-party CMMC Level 2 assessment, discuss a scoped, independent assessment engagement with SOS.
Confirm the assessment boundary, organizational contacts, timing and required evidence before the assessment begins.
Evaluate documented evidence and working safeguards through a structured assessment of applicable requirements.
Receive assessment findings and understand the next actions under the applicable assessment process. An engagement does not guarantee certification.