CMMC readiness, built for small defense subcontractors
CMMC Readiness for Defense Subcontractors
A fixed-fee gap assessment against all 110 NIST SP 800-171 controls, so you know exactly what stands between you and certification. Delivered by a CISSP practitioner, not a sales team.
Prefer to talk now? Call (832) 800-3988.
- CISSP, CCSP
- Fixed fee, quoted up front
- Vendor-neutral, no tools sold
- Houston-based, on-site available
CMMC isn't dead. Your obligations aren't paused.
Phase II certification timing was suspended on July 13, 2026, but DFARS 252.204-7012, your SPRS score, annual affirmations, and prime contract flow-downs still apply. Readiness against NIST SP 800-171 is the one investment that holds its value no matter what the reform task force recommends.
From first call to clear roadmap, in weeks
No open-ended consulting bills, no black box. Three steps, a fixed fee, and documentation you can hand to an assessor.
-
Free 30-minute scoping call
We talk through your contracts, your CUI, and your current posture. You get honest feedback on whether the assessment is right for you, even if the answer is "not yet."
-
Fixed-fee assessment, two to three weeks
Document review, interviews with your team, and control-by-control analysis against all 110 NIST SP 800-171 controls. Minimal disruption to your operations.
-
Readout and prioritized roadmap
The full deliverable package and a walkthrough of exactly what to fix first. Optional monthly advisory after that, if you want a guide through remediation.
Prefer to talk now? Call (832) 800-3988.
The CMMC Gap Assessment
A fixed-fee, practitioner-led assessment that tells you exactly what stands between you and certification. Two to three weeks, one clear deliverable package, no open-ended consulting bills.
What you get
-
110-control gap matrix
Every NIST SP 800-171 control, assessed as implemented, partially implemented, or not implemented, with evidence notes.
-
CUI scoping and boundary review
We scope your assessment boundary as small as defensibly possible first (the "enclave" approach). Tight scoping is the single biggest lever on your eventual certification cost.
-
POA&M with owners and timelines
Every gap gets a remediation task, an owner, and a realistic timeline. Your Plan of Action and Milestones, ready to execute.
-
SSP review
Your System Security Plan reviewed against what assessors actually look for. Clean documentation is how you cut hours off your eventual C3PAO bill.
-
Executive readout
A plain-English briefing for leadership: where you stand, what it will take, and what it will cost.
Straightforward pricing, published up front
No "call for a quote" to find out whether you can afford us. Every engagement starts with the assessment; advisory comes after, only if you want it.
CMMC Gap Assessment
Starting at $7,500 fixed fee
The flagship. All 110 controls assessed, the full deliverable package, and a readout you can act on.
- 2 to 3 weeks, kickoff to readout
- Fee quoted up front, fixed in writing
- Final price by size and system count
vCISO Advisory
Starting at $2,000 /month
A guide through remediation and beyond: steady senior counsel without a full-time hire.
- Risk register and policy management
- Quarterly remediation roadmap
- Audit and assessor support
Ad hoc advisory
$250 /hour, 4-hour minimum
For past assessment clients with quick questions. Small asks, answered fast, without turning into free consulting.
- SPR score and affirmations help
- Prime flow-down reviews
- Remediation second opinions
Questions about fit or scope? Book a free 30-min scoping call, or call (832) 800-3988.
Founder-led, on purpose
Oak City Cyber is Kurt Bain, CISSP, CCSP. There is no junior team and no sales pipeline between you and the person doing the assessment. You work directly with the founder, one client at a time.
"Some advisors sell you software at the end. Some are selling the next engagement from minute one. I do neither."
Kurt is a compliance practitioner who works with NIST SP 800-171 and CMMC every day. That means the assessment you get is shaped by the controls as assessors actually interpret them, not by a checklist run through a template mill.
Oak City Cyber is vendor-neutral and independent: no tools sold, no referral fees, no sponsored recommendations. When a gap needs fixing, the advice is about what fits your shop, not what earns a commission. Houston-based, with on-site work available across the metro.
or call (832) 800-3988 directly.
Questions, answered straight
Are you a C3PAO?
No, and that is the point. We do readiness, not certification. Our job is getting you ready before you spend $30k+ on the real assessment, so you pass it the first time instead of paying to fail it.
How long does the assessment take?
Two to three weeks from kickoff to readout. Remediation timelines depend on the gaps we find; the POA&M gives you realistic dates and owners for each one.
We're a small shop. Is this for us?
Yes. Small subcontractors are exactly who this is built for. The fixed fee, the tight CUI scoping, and the plain-English readout are all designed for teams without a compliance department.
What if CMMC changes again?
Readiness against NIST SP 800-171 holds regardless of rulemaking. The controls are the controls; a new rule changes the timeline and the assessment mechanics, not the security work itself.
Do you sell tools or take referral fees?
No. We are vendor-neutral and independent. We do not sell software, we do not take referral fees, and we will never recommend a product because someone paid us to.
Prefer to talk now? Call (832) 800-3988.
Know where you stand.
One free 30-minute scoping call. We will talk through your contracts, your CUI, and whether a gap assessment makes sense for you right now. No pitch, no pressure.
Prefer to talk now? Call (832) 800-3988.
SECURE. ROOTED. RESILIENT.