CMMC LEVEL 2 ROADMAP

Know exactly where you stand — down to the assessment objective.

The Roadmap is where every Greypike engagement starts. A paid, fixed-scope assessment that scores your gaps against all 110 NIST SP 800-171 controls — and the ~320 assessment objectives behind them — then hands you a corrected SPRS score and a prioritized plan you can defend. With CMMC audits suspended, this is also our SPRS Attestation Assurance engagement: the independent check your score gets before your Affirming Official signs it.

Objective-level gap analysis Corrected SPRS score & POA&M

Four phases, 4–6 weeks

1ScopingCUI boundary & asset categorization
2Policy gap analysisWhat exists, what’s missing
3Technical verificationMet / Unmet at the objective level
4Roadmap & POA&MPrioritized plan, yours to keep

WHAT YOU GET

A defensible score, not a checklist dump.

NIST SP 800-171A doesn't evaluate compliance at the control level — it breaks the 110 controls into roughly 320 individual assessment objectives, and a control only counts as implemented when every objective behind it is met. Most gap assessments stop at the 110. We go down to the objective level, because that's the standard a government-led assessment applies, since July 13, 2026 — the standard your Affirming Official personally attests to in SPRS every year. Every deliverable is yours to keep, usable with any vendor.

CUI scoping & asset categorizationYour CMMC boundary, CUI categories, and asset inventory — the foundation for defensible scope.
Objective-level gap analysisAll 110 controls reviewed at the assessment-objective level — ~320 objectives, Met / Unmet / N/A with evidence.
Corrected SPRS scoreYour score calculated per the DoD Assessment Methodology — including the partial-credit rules most self-assessments miss — ready to submit and defend, plus the projected score after remediation.
Prioritized POA&MNIST-format plan with effort estimates, SPRS impact per item, dependencies, and recommended sequence.
Attestation defensibility review Could your score survive scrutiny — from a government-led assessment, a prime's supplier review, or a DOJ inquiry? We review your evidence the way an assessor would, so your affirmation is signed on solid ground. If third-party audits return after the CMMC review, you're already prepared for those too.

HOW IT WORKS

From first call to a plan in hand.

A focused, fixed-scope engagement. No drawn-out discovery — just a clear process that ends with a deliverable you own.

01

Scoping session

A working call to understand your contracts, your environment, and where CUI lives.

02

Boundary & assessment

We define your CMMC boundary and assess every control against NIST SP 800-171.

03

Roadmap build

We prioritize the gaps and sequence remediation into a realistic, costed plan.

04

Deliverable & walkthrough

You get the written roadmap, SSP/POA&M framework, and a live walkthrough of next steps.

YOUR DELIVERABLE PACKAGE

Five documents. One complete Roadmap.

Everything you receive is yours to keep and written to be assessor-defensible — usable with Greypike, your existing IT vendor, or any other firm.

Word

Scoping Report

Your CMMC boundary, CUI categories, asset inventory with categorization, and architecture pattern — the foundation for defensible scope.

Word

Policy Gap Analysis

A side-by-side review of your policies against CMMC requirements, with verified gaps, severity ratings, and remediation guidance per gap.

Excel

Assessment Objective Status

Met / Unmet / Not Applicable for every assessment objective, with reasoning and linked evidence.

Excel

Prioritized POA&M

NIST-format Plan of Action & Milestones with effort estimates, SPRS impact per item, dependencies, and recommended sequence.

PDF

Roadmap Executive Summary

A branded PDF with your current and projected SPRS score, timeline visualization, and resource requirements.

Live

Walkthrough Call

A 60-minute session to review the package, answer questions, and map out exactly what comes next.

COMMON QUESTIONS

Questions about the Roadmap.

CMMC audits are suspended. Is the Roadmap still worth it?
More than before, honestly. The suspension paused the C3PAO audit — it didn't touch DFARS 252.204-7012, your NIST 800-171 obligations, or the SPRS score a senior official at your company personally affirms to the federal government every year. What changed is who catches mistakes: previously, an auditor would find the gap between your paperwork and your reality before the government relied on it. Now nothing stands between an inflated score and False Claims Act exposure except the rigor of your own assessment. The Roadmap is that rigor — an independent, objective-level check performed before your Affirming Official signs, at a fixed fee that's a fraction of what the audit journey cost..
Why does every engagement start with a Roadmap?
Because compliance work done without a defined scope and gap analysis wastes time and money. The Roadmap establishes exactly what's in scope and where your gaps are — reviewed down to the ~320 assessment objectives in NIST SP 800-171A, the same standard government assessors apply — so any later work is targeted and priced accurately rather than guessed at.
Is the Roadmap a paid engagement?
Yes. The Roadmap is a paid, fixed-scope engagement — the entry point to working with Greypike. You get a concrete written deliverable you own, whether or not you continue with us afterward. See pricing for current scope and tiers.
How long does it take?
The Roadmap runs 4–6 weeks from engagement start, with weekly status updates throughout. You’ll have Phase 1 outputs by the end of week 1 and policy gaps identified by the end of week 3.
Do I have to use Greypike for the remediation work?
No. The Roadmap is a standalone deliverable you own outright. You can execute it with your own team, another provider, or continue with Greypike through a Managed Compliant Enclave or Managed Compliance — your choice.
Does the Roadmap make us compliant?
The Roadmap tells you — precisely — how compliant you are and what it takes to close the distance. It doesn't implement the fixes; it scopes, scores, and sequences them. What it does deliver on day one: a submission-ready SPRS score you can actually stand behind, and a POA&M in the format the government expects. (And to the old version of this question: C3PAO certification assessments are suspended as of July 13, 2026, and cannot currently be required in contracts. When and if a reformed assessment model returns, a Roadmap-assessed environment walks into it prepared.)

START HERE

Every defensible score starts with a Roadmap.

Book a scoping session and we'll define your boundary, size the work, and hand you a plan — and a number — you can sign for.

No obligation · Veteran-owned · Cyber AB RPA-led