CMMC LEVEL 2 ROADMAP
Know exactly where you stand — down to the assessment objective.
The Roadmap is where every Greypike engagement starts. A paid, fixed-scope assessment that scores your gaps against all 110 NIST SP 800-171 controls — and the ~320 assessment objectives behind them — then hands you a corrected SPRS score and a prioritized plan you can defend. With CMMC audits suspended, this is also our SPRS Attestation Assurance engagement: the independent check your score gets before your Affirming Official signs it.
Four phases, 4–6 weeks
WHAT YOU GET
A defensible score, not a checklist dump.
NIST SP 800-171A doesn't evaluate compliance at the control level — it breaks the 110 controls into roughly 320 individual assessment objectives, and a control only counts as implemented when every objective behind it is met. Most gap assessments stop at the 110. We go down to the objective level, because that's the standard a government-led assessment applies, since July 13, 2026 — the standard your Affirming Official personally attests to in SPRS every year. Every deliverable is yours to keep, usable with any vendor.
HOW IT WORKS
From first call to a plan in hand.
A focused, fixed-scope engagement. No drawn-out discovery — just a clear process that ends with a deliverable you own.
Scoping session
A working call to understand your contracts, your environment, and where CUI lives.
Boundary & assessment
We define your CMMC boundary and assess every control against NIST SP 800-171.
Roadmap build
We prioritize the gaps and sequence remediation into a realistic, costed plan.
Deliverable & walkthrough
You get the written roadmap, SSP/POA&M framework, and a live walkthrough of next steps.
YOUR DELIVERABLE PACKAGE
Five documents. One complete Roadmap.
Everything you receive is yours to keep and written to be assessor-defensible — usable with Greypike, your existing IT vendor, or any other firm.
Scoping Report
Your CMMC boundary, CUI categories, asset inventory with categorization, and architecture pattern — the foundation for defensible scope.
Policy Gap Analysis
A side-by-side review of your policies against CMMC requirements, with verified gaps, severity ratings, and remediation guidance per gap.
Assessment Objective Status
Met / Unmet / Not Applicable for every assessment objective, with reasoning and linked evidence.
Prioritized POA&M
NIST-format Plan of Action & Milestones with effort estimates, SPRS impact per item, dependencies, and recommended sequence.
Roadmap Executive Summary
A branded PDF with your current and projected SPRS score, timeline visualization, and resource requirements.
Walkthrough Call
A 60-minute session to review the package, answer questions, and map out exactly what comes next.
COMMON QUESTIONS
Questions about the Roadmap.
CMMC audits are suspended. Is the Roadmap still worth it?
Why does every engagement start with a Roadmap?
Is the Roadmap a paid engagement?
How long does it take?
Do I have to use Greypike for the remediation work?
Does the Roadmap make us compliant?
START HERE
Every defensible score starts with a Roadmap.
Book a scoping session and we'll define your boundary, size the work, and hand you a plan — and a number — you can sign for.
No obligation · Veteran-owned · Cyber AB RPA-led