Get CMMC-ready with one certified operator — not a pitch deck.
We get small defense contractors through CMMC Level 1 and Level 2 readiness with fixed fees, plain English, and 21 years of real DoD-prime experience behind every recommendation.
Why contractors choose us
Most cybersecurity consulting is broken. We built the alternative.
If you've shopped for CMMC help, you've probably hit at least one of these. We fixed all four.
We publish every fee
Productized work is flat-priced right on this site. Custom work is quoted in writing. You know the number before you commit.
We've actually run it
What we recommend, we've deployed, hardened, audited, or recovered ourselves at DoD-prime scale — for 21 years.
We disclose our AI
Every engagement includes a written note on which AI tool touched which data. Sensitive data never enters consumer AI.
One certified operator
You work directly with a CMMC Certified Professional — not a rotating junior team. Every engagement gets the principal's attention.
How it works
A clear path from "where do I start?" to audit-ready.
Scope
We pinpoint exactly where your protected information lives — systems, people, vendors. This is where most projects over-spend; we don't.
Gap
We measure you against the controls that actually apply and hand you a documented baseline — not a vague feeling.
Plan
A prioritized, realistic roadmap (your POA&M) — what to fix, in what order, by when.
Evidence
We build your security plan (SSP) and the proof assessors need. We coach you right up to the C3PAO.
Level 1 or Level 2?
Which level you need depends on the information you handle.
Here's the honest, side-by-side version. Not sure where you land? The free Checkpoint settles it.
- What it protects: basic contract info not meant for public release.
- Scope: 15 fundamental safeguards.
- How it's verified: annual self-assessment + affirmation.
- The lift: manageable — not a six-figure project.
- What it protects: sensitive info a prime flagged as controlled.
- Scope: all 110 NIST 800-171 controls.
- How it's verified: self- or third-party (C3PAO) assessment.
- The lift: heavier — and the one most worth starting early.
What we do · pricing in the open
Seven offerings. Every price listed.
Fixed-fee work ships at the price shown; custom work is quoted in writing after a scoping call.
Level 1 Readiness Sprint
Gap assessment, populated SSP, SPRS-ready package, executive readout.
Level 2 Readiness Assessment
110-control gap analysis, SSP, POA&M, evidence index, C3PAO coaching.
Fractional vCISO Retainer
Executive report, risk register, vendor risk, IR on-call, board briefing.
AI Governance Advisory
NIST AI RMF readiness, AUP pack, shadow-AI inventory, ISO 42001 pathway.
Federal & Facility Systems Security
RMF/ATO packages, UFC 4-010-06, SSPs, SARs, OT/ICS/SCADA advisory.
IT Infrastructure Advisory
Cloud (Azure GCC/High, AWS, GCP), datacenter, vuln, patch, identity.
Fractional Director of IT Infrastructure & Security
Senior IT leadership and audit-grade security posture in one accountable engagement — for companies that need both but can't justify two full-time hires.
Our promises
Six non-negotiables. The deal never bends them.
Operator discipline
What we recommend, we've run, broken, hardened, audited, or recovered ourselves.
Honesty over politeness
We tell clients when they don't need us, and disagree with auditors when they're wrong.
AI used transparently
A written AI-use disclosure every engagement. CUI never enters consumer AI.
Pricing in the open
Hidden pricing is the first sign of a broken relationship. Ours is published.
Boundaries, drawn
We advise, architect, and assess. We're not your MSP. That protects the advice.
Boutique by intent
Small on purpose. Engagement count is capped. Quality is a capacity constraint.
The operator
21 years inside an active DoD prime — applied to your environment.
The Infinite Paradigm is a one-operator practice by design. Those years were spent running enterprise IT, cybersecurity programs, and compliance against NIST 800-171 and the supply-chain demands of CMMC.
What gets sold here isn't a framework recitation — it's the same operator discipline applied to your shop: certifications held, controls deployed, audits defended, recoveries run. The boutique scale is intentional, so your work gets real attention.
The Operator
CMMC Certified Professional · DoD-prime experienced. Each engagement gets the principal's direct attention.
One honest hour could save you months.
Book a free 60-minute Readiness Checkpoint. We assess where you are, leave you with a written one-page findings summary, and tell you honestly whether you need our help at all. Roughly 1 in 5 companies hear "you don't need us" — in writing.
Request a Checkpoint →The Knowledge Base
Every question subcontractors ask. Answered.
37 straight answers — grounded in 32 CFR Part 170, not sales copy. Read them below, or watch them answered on camera in The Checkpoint Session.
CMMC (Cybersecurity Maturity Model Certification) is the DoD's program for verifying — through self-assessments and third-party assessments — that contractors actually meet the cybersecurity requirements their contracts have required on paper since 2017. The rules aren't new; the verification is.
The information you touch. Level 1 protects Federal Contract Information (FCI) with 15 basic requirements from FAR 52.204-21, verified by an annual self-assessment. Level 2 protects Controlled Unclassified Information (CUI) with all 110 controls of NIST SP 800-171 — verified, for most contracts, by an independent third-party (C3PAO) assessment.
▶ Watch this answered on cameraInformation the government provides, or that you generate for the government under contract, that isn't released to the public. Submittal logs, RFI correspondence, project schedules, non-public pricing, daily reports on a federal job — nearly every federal subcontract involves FCI.
Information a law, regulation, or government-wide policy specifically requires to be safeguarded. On construction and engineering work that commonly means site plans of secure facilities, facility drawings, access schedules, MILCON specification packages, and export-controlled technical data. CUI handling always includes the FCI basics.
Your subcontract clauses decide — not drawing stamps, not what anyone told you verbally. Pull your terms and search five clause numbers:
| If your subcontract contains… | You likely handle… | Which means… |
|---|---|---|
| FAR 52.204-21 only | FCI | Level 1 — 15 requirements, annual self-assessment |
| + DFARS 252.204-7012 | CUI | NIST 800-171 applies now; you're on the Level 2 track |
| + DFARS 252.204-7019 / 7020 | CUI | A current SPRS score is required for award |
| + DFARS 252.204-7021 | Per the clause | CMMC is required at the level the clause names |
Not all drawings are CUI — but unmarked does not mean not-CUI, and marking gaps between agencies, primes, and subs are common across the industry. Trade scopes like flooring frequently touch only finish schedules and general arrangement drawings, which are often FCI rather than CUI.
Drawings cross into CUI — typically Controlled Technical Information or facility-related categories — when they show secure or controlled areas, base infrastructure details, or carry distribution statements. Military-construction packages increasingly require exactly this: controlled-area labeling on as-builts and CUI marking on project documentation. The move is to request a written CUI determination from your prime for every job. Either answer protects you — on paper.
▶ Watch this answered on cameraNo. Identifying CUI that flows into subcontracts is the prime's responsibility under DFARS 252.204-7012, but the safeguarding obligation lands on whoever holds the data. Request a written CUI determination from your prime for each job.
Yes. The rule applies consistent requirements to all subcontractors handling FCI or CUI, regardless of company size — there is no small-business exemption. There is, however, a much smaller Level 1 path if you only handle FCI, which describes many small trade contractors.
Not all. The level tracks the information, not the contract vehicle. FCI-only work carries Level 1; CUI work carries Level 2, and DFARS clause 252.204-7021 names the level right in the contract. The requirement flows down based on what actually reaches you — a sub receiving only FCI can hold Level 1 even on a Level 2 prime contract.
That said, subs positioned at Level 2 will be eligible for the widest range of federal work as the phase-in completes. That's a business decision, not just a compliance one.
It already has. Phase 1 began November 10, 2025 — Level 1 and Level 2 self-assessment requirements now appear in applicable solicitations, and DoD can already require third-party certification at its discretion. Phase 2 arrives November 10, 2026, when C3PAO Level 2 certification becomes the standard requirement. Phase 3 follows November 10, 2027.
Two consequences. Eligibility: once a solicitation carries a CMMC requirement, you cannot be awarded the contract without the required status posted. No certification, no award. And legal exposure: misrepresenting your compliance — posting a score or affirmation you can't support — carries False Claims Act risk, a far more expensive problem than compliance ever was.
▶ Watch this answered on cameraYou can, but the math works against it. Level 2 readiness typically takes 3 to 6 months of real work, and roughly 80,000 defense contractors are expected to need certification against a limited pool of certified assessors. Companies that wait for a contract deadline compete for assessor calendar slots with everyone else who waited.
▶ Watch this answered on cameraOnly on that contract, and only until it's modified or recompeted. DFARS 252.204-7012 has required full NIST 800-171 implementation since December 2017 on any contract involving CUI — CMMC adds verification, not new controls. If 7012 is in your subcontract, the 110-control obligation is already live today.
The 15 basic safeguarding requirements in FAR 52.204-21(b)(1): limit system access to authorized users, control connections and removable media, patch systems, run malware protection, sanitize media before disposal, and similar fundamentals. Most well-run IT environments already do much of this.
No. Level 1 is an annual self-assessment against the 15 requirements, plus an affirmation by a senior company official, both posted in SPRS (the Supplier Performance Risk System). No C3PAO, no certification body, no external audit.
No. Level 1 has no partial credit and no Plan of Action and Milestones. All 15 requirements must be MET at the time of the self-assessment. Lower bar — but pass/fail.
For a typical small contractor with a reasonably managed IT environment: 3 to 4 weeks of structured work — scoping, gap review, remediation of the short list, documentation, and the SPRS submission package. DoD's own rule estimates a small entity's self-assessment effort at roughly $6,000 in internal cost. Our fixed-fee Level 1 Readiness Sprint is $7,500, published above.
Annually. The self-assessment and the senior-official affirmation both renew every year.
Implementation of all 110 security controls in NIST SP 800-171 Revision 2, assessed against 320 individual assessment objectives, on every system that processes, stores, or transmits CUI. Revision 2 — not Revision 3 — is the operative standard for current assessments under the DoD's active class deviation.
The clause in your contract decides. Some Level 2 contracts allow self-assessment; most will require certification by an authorized C3PAO, and from November 10, 2026 the C3PAO route becomes the standard requirement in applicable solicitations. The safe planning assumption for any company on the Level 2 track is a C3PAO assessment.
Out of 110 points, with weighted deductions of 1, 3, or 5 points per unimplemented control. A minimum score of 88 — with every remaining gap on a compliant POA&M — is the floor for Conditional status. Certain controls carry no partial credit and must be fully met, including a complete System Security Plan; without the SSP, the assessment does not proceed.
▶ Watch this answered on cameraConditional means you met the 88-point floor with a limited set of allowable items on a POA&M, and you have 180 days to close them — miss the closeout and the status is lost. Final means every requirement is met outright. A well-run readiness effort aims at Final and uses Conditional only as a deliberate bridge when a deadline demands it.
The System Security Plan is the master document describing your environment, your CUI boundary, and how each of the 110 controls is implemented. Assessors treat it as the entry ticket: no SSP, no assessment. It's also the single document most small contractors have never written.
A Plan of Action and Milestones — the formal, dated remediation plan for any control not yet fully implemented. At Level 2, only certain lower-weight items are POA&M-eligible, the highest-weight controls are not, and the clock is 180 days.
Three years — with an annual affirmation by a senior official in each year between assessments. Certification is a posture you maintain, not a one-time event.
Self-assessment scores go into SPRS, accessed through the PIEE portal. C3PAO certification results are recorded in eMASS and flow to SPRS. Contracting officers check those systems — the official record is what lands there.
Yes — and scoping is the highest-return decision in the entire effort. A defined CUI enclave — a bounded set of systems, users, and data flows where CUI lives — can keep the 110 controls off your entire corporate network. The rule defines five asset categories (32 CFR 170.19), and getting them right early is the difference between a contained project and an enterprise-wide one.
It can be. Cloud services that store or process CUI must meet FedRAMP Moderate (or equivalent) requirements, and encryption used to protect CUI must be FIPS-validated. Commercial-tier tenants frequently fail both tests — one of the most common scope blockers we find, and one of the most expensive to discover late. We check it in the first hour, not the tenth week.
Large firms typically quote $90,000 to $150,000+ for readiness engagements. Our fixed-fee Level 2 Readiness Assessment runs $28,000 to $45,000 over 10 to 14 weeks depending on environment complexity — and the price is published before you ever call. The C3PAO assessment itself is a separate cost paid to the assessor; budget for it independently.
A documented AI-augmented delivery model compresses roughly 180 hours of traditional engagement work to about 60, and we pass the difference through. Two commitments come with it, in writing: every AI workflow is disclosed, and CUI never touches a commercial AI service — evidence processing runs on local, offline tooling only.
▶ Watch this answered on cameraSometimes, for Level 1. Rarely, for Level 2. CMMC readiness is an assessment discipline — control interpretation, evidence sufficiency, scoping decisions, assessor expectations — and it benefits from someone independent of the systems being assessed. We deliberately don't act as anyone's MSP for exactly that reason: the advice stays independent.
Productized engagements are flat-fee and listed openly on this page. Custom-scope work is quoted in writing after a short scoping call. You'll never get a mystery number.
A free 60-minute Readiness Checkpoint. You describe your contracts and environment; we run a structured diagnostic against the actual requirements; you receive a one-page written findings summary within 48 hours. No pitch deck, no drip sequence, no obligation.
And you should know this before you book: roughly 1 in 5 companies who complete a Checkpoint hear from us that they don't need our services — their situation is simple enough to handle in-house, or a different kind of firm is the right fit. We tell you which one you are, in writing, either way.
▶ Watch this answered on cameraOne structural point first, because it protects you: the firm that certifies you cannot be the firm that prepared you — CyberAB conflict-of-interest rules separate the assessor role from the consultant role. That's why we do readiness only, and never assessments. For the certifying side, the CyberAB Marketplace is the authoritative directory. And timing matters: assessor capacity is limited relative to the number of contractors that will need certification, so get in queue early rather than late.
A focused 60-minute session with a CMMC Certified Professional. You bring your situation; we bring the diagnostic. You leave with a one-page written findings summary within 48 hours and an honest recommendation — even if it's "you don't need us yet."
No — and that's deliberate. We advise, architect, and assess readiness; we don't take operational ownership or act as your MSP. That separation keeps our advice independent and honest.
No, by rule and by design. Under 32 CFR Part 170 and CyberAB conflict-of-interest requirements, a firm that consults on your readiness cannot assess the same client for three years. We are a readiness consultancy, not a C3PAO — and we never guarantee certification outcomes. What we deliver is an assessment-ready posture and a clean handoff to the assessor you choose.
No matching questions. Ask us directly — book the free Checkpoint.
Watch instead
The Checkpoint Session — the interviews.
A skeptical subcontractor owner sits down with The Operator and asks every question on this page. Watch the full sitting or the one-minute cuts. Prefer reading? The written answers are above.
Coming soonNarration is AI-generated. All presenters are AI avatars. We disclose our AI use. The Infinite Paradigm LLC is a readiness consultancy, not a C3PAO; nothing in these videos guarantees an assessment outcome.
Get started
Ready for an honest conversation?
Sixty minutes, no pitch deck. Pick whatever channel is easiest.