Built on NIST SP 800-171
Every Gap Documented
Remediation Proposals
Support During Certification

Find Your CMMC Level 2 Gaps
Before Your Assessor Does

A readiness assessment for Minnesota manufacturers that handle Controlled Unclassified Information or face a Level 2 requirement from a contract or prime. McNallan measures your controls against NIST SP 800-171, hands you a gap list with remediation proposals, walks leadership through it in plain terms, and can work alongside you during the C3PAO assessment. We prepare you for certification. We are not the certifier.

Readiness Is Not Certification. It Is What Makes Certification Go Smoothly.

CMMC Level 2 certification, when your contract requires it, is issued after an assessment by a Certified Third-Party Assessment Organization (C3PAO). McNallan is who you hire first. We measure your current controls against NIST SP 800-171, document every item that would fail, propose how to close each one, brief your leadership in plain terms, and sit alongside you and the assessor when questions come. This is one part of McNallan’s cybersecurity services for Minnesota businesses. You walk into the formal assessment knowing where you stand.
McNallan team meeting with a manufacturing client about CMMC Level 2 readiness

Does CMMC Level 2 Actually Apply to You?

Not every government contract carries the same CMMC requirement. The requirement lives in your solicitation, your contract, or the flow-down from your prime, and it may call for Level 1, Level 2 self-assessment, Level 2 C3PAO assessment, or Level 3.

The quick test is Controlled Unclassified Information (CUI). If your systems store, process, or transmit CUI, such as drawings, specifications, or technical data tied to a defense contract, Level 2 is likely in play, and NIST SP 800-171 is the standard you will be measured against. Federal Contract Information (FCI) alone usually points to Level 1.

Not sure what your paperwork requires? Bring the clause or the prime's letter to the first conversation. McNallan will help you identify the right starting point before anyone commits to an assessment.

This Is for You If One of These Is True

Manufacturer reviewing a CMMC Level 2 requirement from a prime contractor

A Prime or Contract Made It a Condition

We measure your current state against every Level 2 requirement before the contract is on the line.
Controlled Unclassified Information on a manufacturer's systems

You Handle CUI, or You Are Not Sure

Every item needing remediation, documented, with a remediation proposal for each one during and after the engagement.
McNallan supporting a manufacturer through the CMMC certification process

You Want Support During Certification

A C-level walkthrough, all collected data handed over, and McNallan alongside you and the certification assessor to answer questions and provide detail. CUI scope, not headcount, is the filter. If you handle it, this applies to you.

What You Walk Away With

Not a verbal summary and a longer list of questions. A control-by-control picture of where you stand against CMMC Level 2, what it takes to close each gap, and a partner who stays for the assessment itself.

Every Level 2 Requirement, Checked

Fourteen sections and over 400 questions that map to the NIST SP 800-171 control families behind CMMC Level 2. Performed in person and remote, with the people who actually run your systems.

A Gap Analysis You Can Act On

Every item that would fail, documented, before the certification process begins. Leadership sees the business risk. Your technical team sees exactly what has to change.

A Remediation Proposal for Every Gap

Findings without a fix are homework. McNallan provides remediation proposals as needed during and after the engagement, so each gap comes with a path to close it.

A Leadership Walkthrough in Plain Terms

A walkthrough with your executive team of what we found, what it will take, and what it means for your contracts, without untranslated acronyms.

The Raw Evidence, Not Just a Summary

All collected data is handed to you after the engagement, whoever you work with next.

A Partner in the Room During Certification

When the C3PAO assessor asks, McNallan can work alongside you to answer questions and provide the detail behind every control.

How the CMMC Readiness Assessment Works

Step 1: Assess

The outcome: an honest picture of where you stand today.

Step 2: Analyze and Propose

The outcome: findings and a way to close each one.

Step 3: Walk Through and Support

The outcome: leadership gets the picture. Your team can get backup during certification.

Your Primes Are Already Asking

If you machine, fabricate, or assemble parts for a defense prime, you have probably already seen it: a supplier questionnaire, a request for your SPRS score, or a new clause in a purchase order. CMMC is how the Department of Defense verifies that suppliers handling CUI actually meet NIST SP 800-171, instead of taking their word for it.

Suppliers who find their gaps early fix them on their own schedule. Suppliers who wait fix them on a prime's schedule, with a contract on the line.

Questions Manufacturers Ask Before They Call

Is this the official CMMC assessment?

No. Certification comes from a C3PAO. This is the preparation that makes that assessment go smoothly: the gaps found and documented before the assessor arrives, with McNallan available to answer questions during the formal assessment.

How long does it take, and how much of our team's time?

Scope depends on your sites, your systems, and how much documentation you already have. After the first conversation, McNallan sets who needs to participate, the split between on-site and remote work, and the schedule, before any work begins.

Will it disrupt production?

The assessment is performed in person and remote, working with the people who run your systems and processes. It is planned around your schedule, not the other way around.

What does it cost?

Scope depends on how much of your environment touches CUI. A tight enclave and a whole-plant network are different engagements. McNallan confirms the scope and the price after the first conversation, before work starts.

Another provider manages our IT. Does that matter?

The assessment stands on its own. McNallan assesses the environment as it is and works with whoever runs your systems.

What if our score is bad?

Then you learned it from us, on your schedule, with a remediation proposal for each gap. That is the point of doing readiness first.

How is this different from scoring ourselves in SPRS?

A self-score is only as good as the honesty and expertise behind it. A readiness assessment checks every requirement against what is actually in place, with the evidence to back it up, so the number you report is one you can defend.

Ready to Find Out Where You Stand on CMMC Level 2?

This is right for you if:

  • A contract or prime requires CMMC Level 2, or you expect one will
  • Your systems handle CUI, or you are not sure whether they do
  • You want the gaps found before the assessment, not during it
  • You want a partner who can work alongside you during certification

Tell Us What Is Driving Your CMMC Timeline

Share what prompted this: an upcoming bid, a contract clause, a request from a prime, or uncertainty about CUI. If you know the required level or a target date, include it. McNallan will follow up on whether a Level 2 readiness assessment is the right next step, or whether a shorter scoping conversation comes first.
Prefer a real conversation? Skip the form and call us directly during business hours.
Working hours
Mon–Fri
Emergency
8:00 AM – 5:00 PM
24/7 on-call support
Start with a conversation
No commitment to an assessment. We will tell you whether you need one, and what it would involve.