CMMC compliance means meeting the Cybersecurity Maturity Model Certification level in your DoD contract: Level 1 self-assessment for FCI or Level 2 against NIST SP 800-171 for CUI. IRM scopes, assesses, and prepares you, led by a CMMC Registered Practitioner.
CMMC compliance means a US defense contractor or subcontractor has met the Cybersecurity Maturity Model Certification level written into its contract. CMMC 2.0 has three levels: Level 1 covers 15 basic safeguarding requirements for Federal Contract Information and is met by an annual self-assessment; Level 2 covers the 110 security requirements of NIST SP 800-171 for Controlled Unclassified Information and, for most contracts, requires a third-party assessment by a C3PAO every three years; Level 3 adds requirements from NIST SP 800-172 and is assessed by the Department of Defense. The CMMC program rule took effect in December 2024 and the requirement is being phased into contracts from November 2025.
IRM's CMMC compliance service is led by a CMMC Registered Practitioner and takes a subcontractor from "our prime just asked for our SPRS score" to assessment-ready. We scope where FCI and CUI actually flow, run the gap assessment at the level your contracts demand, write the System Security Plan and Plan of Action and Milestones, close the gaps that matter, and prepare you for the self-assessment affirmation or the C3PAO visit.
Canadian suppliers to the US defense industrial base face the same requirement, and Canada's own Canadian Program for Cyber Security Certification (CPCSC) is being phased in alongside it. Because both programs map to NIST SP 800-171, we build one control set that satisfies both, and we do it from Toronto with the same Virtual CISO who then keeps the controls operating between assessments.
If you have no DoD prime or subcontract in your pipeline, and none of your customers handle CUI, CMMC is not your framework. A general baseline such as CIS Controls or the Canadian CAN/DGSI 104 will give you better security for the money.
If you handle only FCI and no CUI, you need Level 1, which is a self-assessment against 15 requirements and does not need a C3PAO. Many small suppliers are quoted Level 2 programs they do not need. Scoping comes first; it determines the level, the cost, and the timeline.
Defense subcontractors are sized by contract revenue rather than ARR. This is how we size CMMC engagements for the suppliers we work with.
| Stage | Typical ARR | What You Need | IRM Engagement |
|---|---|---|---|
| Small supplier, FCI only | Under $2M revenue | CMMC Level 1 self-assessment and affirmation, and a defensible answer when a prime asks for your status. | Free CMMC Level 1 assessment at cmmc.irmcon.com, then a Crawling tier sprint to close the 15 requirements and file the affirmation. |
| Growing subcontractor, first CUI contract | $2M to $10M revenue | CMMC Level 2 readiness, an SSP and POA&M, and an SPRS score you can stand behind. | Walking tier, 90 days to SSP, POA&M, and SPRS submission, then a remediation runway to C3PAO. |
| Established subcontractor, multiple CUI programs | $10M to $50M revenue | Level 2 C3PAO certification, a CUI enclave, and controls that hold across sites and product lines. | Walking or Running tier, mock assessment in month 3, C3PAO engagement in months 4 to 9. |
| Canadian supplier to US primes | Any size | CMMC for US flow-downs and CPCSC for Canadian contracts, from one control set. | Same tiers, with the CAN/DGSI 104 baseline and CPCSC mapping included. |
This is the sequence we run to get a subcontractor from first contact to a submitted SPRS score and a clear runway to assessment. Level 1 suppliers finish inside the 90 days; Level 2 suppliers leave day 90 with the remediation plan a C3PAO expects to see.
CMMC work is delivered as a monthly Virtual CISO subscription led by a CMMC Registered Practitioner, so small suppliers get a scoped program rather than an enterprise-sized quote.
From $2,000 per month
15 to 20 hours per month, sprint package. Excludes C3PAO assessment fees and any enclave licensing such as Microsoft 365 GCC High.
Level 2 readiness programs, including the SSP, POA&M, and SPRS submission, run on the Walking tier from $4,250 per month (20 to 40 hours). Multi-site Level 2 programs through C3PAO certification sit on the Running tier from $6,950 per month. Pre-packaged Cyber and AI bundles start at $4,950.
See all Pricing TiersAssess your organization against the CMMC Level 1 safeguarding requirements, score each gap, and generate a readiness report you can hand to your prime, on IRM's dedicated CMMC assessment platform at cmmc.irmcon.com.
Run the CMMC Level 1 AssessmentBook a Free ConsultationRelated: the free Cybersecurity Baseline Assessment (CAN/DGSI 104) covers the Canadian baseline for CPCSC, and Fractional CISO services keep the program running between assessments.
Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.


