CMMC Level 2 · Small Defense Subcontractors
The third-party audit was suspended on July 13, 2026. The self-assessment wasn't.
If you handle Controlled Unclassified Information for the DoD, your self-assessment is what stands behind your contracts right now — the outside auditor who was supposed to double-check it has been put on hold, not the requirement itself. Most small shops don't have a compliance person, are under-budgeted, and don't know what's actually still due. That's the gap Nexxus closes — plainly, at a fixed fee, without ever taking custody of your controlled data.
What most shops get wrong
Three assumptions that cost six figures.
The failure mode isn't your firewall. It's paperwork, scoping, and timing. Getting any of these wrong is what turns a manageable problem into an expensive one.
No fixed deadline
The third-party audit requirement was suspended in July with no new date set. Your real exposure is your next solicitation, option year, or prime questionnaire — none of which wait for Washington.
20–40%
The assessor fee, when one's involved, is only a fraction of the bill. Remediation and documentation are where the real cost lives.
Undocumented = absent
A control you actually run but never documented fails the assessment. Evidence is the deliverable, not the intent.
What Nexxus does
Two fixed-fee engagements. You know the number before we start.
Both are analysis and documentation work. No hourly billing, no surprise invoices, and nothing that touches or configures your systems — that stays with your IT provider.
Start here
Deadline & Scope Map
$1,500 – $3,000 · 3–5 days
Exactly where CMMC applies to you, at what level, and your cheapest defensible path — before you spend a dollar on tools or an assessor.
- Level 1 vs. Level 2 determination
- Your real exposure, mapped to your actual contracts
- Enclave vs. whole-environment scoping call
- A written map you can hand to leadership
The documentation
Gap Assessment & Evidence Package
$3,000 – $5,000
Where you stand against all 110 controls, and the paperwork an assessor — or your own signature — actually needs behind it, built, not hand-waved.
- Gap analysis across NIST 800-171
- System Security Plan drafting support
- POA&M and evidence record
- A clear punch list for your IT provider
How your information is handled
Built so your controlled data never leaves your building.
These are the questions an ITAR shop asks before letting anyone near compliance work. Here are the answers, up front.
U.S. person
I'm a U.S. citizen and person as defined under ITAR. Controlled technical data can be discussed within your own compliance procedures.
No custody
The engagements are built so I never hold your CUI, contracts, or credentials. I work from what you tell me and show me.
NDA first
A mutual non-disclosure agreement is signed before any working session. Yours or mine.
Document, not configure
I analyze and document. I don't touch your network or configure systems — that's your IT provider's lane.
How it works
Four steps, no mystery.
01
Intro call
Fifteen minutes to confirm you're a fit and quote the exact fee.
02
NDA and working session
We sign, then walk through your contract footprint and systems — nothing sensitive changes hands.
03
The map
You get a written report: your level, your real exposure, your cheapest path.
04
Go deeper if it makes sense
If the map shows a documentation gap, the evidence package closes it.
Next step
Find out where you actually stand.
A fifteen-minute call, no obligation. If you're not in scope, I'll tell you — that answer is free.