Find Your CMMC Level 2 Gaps
Before Your Assessor Does
A readiness assessment for Minnesota manufacturers that handle Controlled Unclassified Information or face a Level 2 requirement from a contract or prime. McNallan measures your controls against current CMMC Level 2 requirements, hands you a gap list with remediation proposals, walks leadership through it in plain terms, and can work alongside you during the C3PAO assessment. We prepare you for certification. We are not the certifier.
Readiness Is Not Certification. It Is What Makes Certification Go Smoothly.
Does CMMC Level 2 Actually Apply to You?
Not every government contract carries the same CMMC requirement. The requirement lives in your solicitation, your contract, or the flow-down from your prime, and it may call for Level 1, Level 2 self-assessment, Level 2 C3PAO assessment, or Level 3.
The quick test is Controlled Unclassified Information (CUI). If your systems store, process, or transmit CUI, such as drawings, specifications, or technical data tied to a defense contract, Level 2 is likely in play. Federal Contract Information (FCI) alone usually points to Level 1.
Not sure what your paperwork requires? Bring the clause or the prime's letter to the first conversation. Once you know what your contract calls for, McNallan can talk through what a readiness assessment would involve before anyone commits to one.
This Is for You If One of These Is True
A Prime or Contract Made It a Condition
- A prime or contracting officer made CMMC Level 2 a condition of keeping the work
- A supplier questionnaire or purchase-order clause showed up and nobody told you what comes next
- You are bidding DoD or aerospace work and know Level 2 is the price of admission
- You want a starting point that is not a guess
You Handle CUI, or You Are Not Sure
- Drawings, specs, or technical data from a defense contract sit on your file server or shop-floor PCs
- You have a SPRS score, or need one, and you are not confident in it
- You would rather find the problems now, on your own schedule, than during the formal assessment
- You want proposals to fix each gap, not just a list of findings
You Want Support During Certification
- Leadership needs a plain-language picture of where things stand and what it will take
- Your team will have questions when the C3PAO auditor is in the room
- You want McNallan available to answer questions during certification
- You already had your C3PAO audit and have a list of findings but no plan to close them
What You Walk Away With
Every Level 2 Requirement, Checked
A Gap Analysis You Can Act On
A Remediation Proposal for Every Gap
A Leadership Walkthrough in Plain Terms
The Raw Evidence, Not Just a Summary
A Partner in the Room During Certification
How the CMMC Readiness Assessment Works
Step 1: Assess
- Every CMMC Level 2 requirement, reviewed with the people who run your systems
- Performed in person and remote, around your production schedule
- Scoped to what actually touches CUI: your enclave versus your production environment
- Your current state, not a checklist filled in from a conference room
Step 2: Analyze and Propose
- Current-state gap analysis of every item needing remediation
- A remediation proposal for each gap, during and after the engagement
- All collected data handed over to you
Step 3: Walk Through and Support
- Plain-language walkthrough with your executive team
- McNallan alongside you and the C3PAO auditor during certification
- Questions answered, detail provided, no scrambling
Five Things the C3PAO Auditor Will Expect You to Have
The audit itself is the auditor’s job. It goes a lot better when these are ready before they arrive.
- NIST SP 800-171 controls in place. CMMC Level 2 is built on the 110 security requirements in NIST SP 800-171, grouped into 14 domains. The auditor measures every one.
- A System Security Plan. The document that states how each requirement is met in your environment. Auditors start here.
- A defined CUI boundary. Exactly which systems, people, and locations touch Controlled Unclassified Information, whether that is a fenced-off enclave or the whole plant.
- Your SPRS score. The self-assessment score you submitted to the Supplier Performance Risk System. The auditor compares it to what is actually in place.
- Evidence for every control. Configurations, policies, screenshots, and logs that prove each requirement is met, not just described.
McNallan’s readiness assessment shows you where you stand on each of these before the auditor does, with remediation recommendations for the gaps.
Your Primes Are Already Asking
If you machine, fabricate, or assemble parts for a defense prime, you have probably already seen it: a supplier questionnaire, a request for your SPRS score, or a new clause in a purchase order. CMMC is how the Department of Defense verifies that suppliers handling CUI actually meet the requirements, instead of taking their word for it.
Suppliers who find their gaps early fix them on their own schedule. Suppliers who wait fix them on a prime's schedule, with a contract on the line.
Questions Manufacturers Ask Before They Call
Is this the official CMMC assessment?
No. Certification comes from a C3PAO. This is the preparation that makes that assessment go smoothly: the gaps found and documented before the auditor arrives, with McNallan available to answer questions during the formal assessment.
How long does it take, and how much of our team's time?
Scope depends on your sites, your systems, and how much documentation you already have. After the first conversation, McNallan sets who needs to participate, the split between on-site and remote work, and the schedule, before any work begins.
Will it disrupt production?
The assessment is performed in person and remote, working with the people who run your systems and processes. It is planned around your schedule, not the other way around.
What does it cost?
Every environment is different. On a quick call, once McNallan knows your users, sites, and endpoints, you get a ballpark. Scope is confirmed before work starts.
Another provider manages our IT. Does that matter?
The assessment stands on its own. McNallan assesses the environment as it is and works with whoever runs your systems.
What if the results are bad?
Then you learned it from us, on your schedule, with remediation recommendations for the gaps. That is the point of doing readiness first.
We already had our C3PAO audit. Can McNallan help with the findings?
Yes. The auditor typically hands you the list and leaves. McNallan turns that list into a remediation plan and does the work: firewalls, switches, access controls, documentation, whatever the findings call for. You do not have to start over.
How is this different from scoring ourselves in SPRS?
A self-score is easy to gloss over. This is an unbiased third-party review of what is actually in place, control by control, with remediation recommendations for the gaps. It is not an official score, but it means the number you report is one you understand.
Ready to Find Out Where You Stand on CMMC Level 2?
This is right for you if:
- A contract or prime requires CMMC Level 2, or you expect one will
- Your systems handle CUI, or you are not sure whether they do
- You want the gaps found before the assessment, not during it
- You want a partner who can work alongside you during certification