CMMC Level 2 · Small Defense Subcontractors

The third-party audit was suspended on July 13, 2026. The self-assessment wasn't.

Third-party audit: suspended Self-assessment: in force

If you handle Controlled Unclassified Information for the DoD, your self-assessment is what stands behind your contracts right now — the outside auditor who was supposed to double-check it has been put on hold, not the requirement itself. Most small shops don't have a compliance person, are under-budgeted, and don't know what's actually still due. That's the gap Nexxus closes — plainly, at a fixed fee, without ever taking custody of your controlled data.

Jul 13 2026 · Third-party audit suspended
110 Controls · NIST 800-171
~70% Under-budgeted*

What most shops get wrong

Three assumptions that cost six figures.

The failure mode isn't your firewall. It's paperwork, scoping, and timing. Getting any of these wrong is what turns a manageable problem into an expensive one.

No fixed deadline

The third-party audit requirement was suspended in July with no new date set. Your real exposure is your next solicitation, option year, or prime questionnaire — none of which wait for Washington.

20–40%

The assessor fee, when one's involved, is only a fraction of the bill. Remediation and documentation are where the real cost lives.

Undocumented = absent

A control you actually run but never documented fails the assessment. Evidence is the deliverable, not the intent.

What Nexxus does

Two fixed-fee engagements. You know the number before we start.

Both are analysis and documentation work. No hourly billing, no surprise invoices, and nothing that touches or configures your systems — that stays with your IT provider.

Start here

Deadline & Scope Map

$1,500 – $3,000 · 3–5 days

Exactly where CMMC applies to you, at what level, and your cheapest defensible path — before you spend a dollar on tools or an assessor.

  • Level 1 vs. Level 2 determination
  • Your real exposure, mapped to your actual contracts
  • Enclave vs. whole-environment scoping call
  • A written map you can hand to leadership

The documentation

Gap Assessment & Evidence Package

$3,000 – $5,000

Where you stand against all 110 controls, and the paperwork an assessor — or your own signature — actually needs behind it, built, not hand-waved.

  • Gap analysis across NIST 800-171
  • System Security Plan drafting support
  • POA&M and evidence record
  • A clear punch list for your IT provider

How your information is handled

Built so your controlled data never leaves your building.

These are the questions an ITAR shop asks before letting anyone near compliance work. Here are the answers, up front.

U.S. person

I'm a U.S. citizen and person as defined under ITAR. Controlled technical data can be discussed within your own compliance procedures.

No custody

The engagements are built so I never hold your CUI, contracts, or credentials. I work from what you tell me and show me.

NDA first

A mutual non-disclosure agreement is signed before any working session. Yours or mine.

Document, not configure

I analyze and document. I don't touch your network or configure systems — that's your IT provider's lane.

How it works

Four steps, no mystery.

01

Intro call

Fifteen minutes to confirm you're a fit and quote the exact fee.

02

NDA and working session

We sign, then walk through your contract footprint and systems — nothing sensitive changes hands.

03

The map

You get a written report: your level, your real exposure, your cheapest path.

04

Go deeper if it makes sense

If the map shows a documentation gap, the evidence package closes it.

Next step

Find out where you actually stand.

A fifteen-minute call, no obligation. If you're not in scope, I'll tell you — that answer is free.

Book an intro call Or email Juan.morales@NexxusAdvisory.com · call (805) 630-3793