CMMC readiness, built for small defense subcontractors

CMMC Readiness for Defense Subcontractors

A fixed-fee gap assessment against all 110 NIST SP 800-171 controls, so you know exactly what stands between you and certification. Delivered by a CISSP practitioner, not a sales team.

Prefer to talk now? Call (832) 800-3988.

  • CISSP, CCSP
  • Fixed fee, quoted up front
  • Vendor-neutral, no tools sold
  • Houston-based, on-site available
Current Guidance

CMMC isn't dead. Your obligations aren't paused.

Phase II certification timing was suspended on July 13, 2026, but DFARS 252.204-7012, your SPRS score, annual affirmations, and prime contract flow-downs still apply. Readiness against NIST SP 800-171 is the one investment that holds its value no matter what the reform task force recommends.

How it works

From first call to clear roadmap, in weeks

No open-ended consulting bills, no black box. Three steps, a fixed fee, and documentation you can hand to an assessor.

  1. Free 30-minute scoping call

    We talk through your contracts, your CUI, and your current posture. You get honest feedback on whether the assessment is right for you, even if the answer is "not yet."

  2. Fixed-fee assessment, two to three weeks

    Document review, interviews with your team, and control-by-control analysis against all 110 NIST SP 800-171 controls. Minimal disruption to your operations.

  3. Readout and prioritized roadmap

    The full deliverable package and a walkthrough of exactly what to fix first. Optional monthly advisory after that, if you want a guide through remediation.

Prefer to talk now? Call (832) 800-3988.

The flagship offer

The CMMC Gap Assessment

A fixed-fee, practitioner-led assessment that tells you exactly what stands between you and certification. Two to three weeks, one clear deliverable package, no open-ended consulting bills.

What you get

  1. 110-control gap matrix

    Every NIST SP 800-171 control, assessed as implemented, partially implemented, or not implemented, with evidence notes.

  2. CUI scoping and boundary review

    We scope your assessment boundary as small as defensibly possible first (the "enclave" approach). Tight scoping is the single biggest lever on your eventual certification cost.

  3. POA&M with owners and timelines

    Every gap gets a remediation task, an owner, and a realistic timeline. Your Plan of Action and Milestones, ready to execute.

  4. SSP review

    Your System Security Plan reviewed against what assessors actually look for. Clean documentation is how you cut hours off your eventual C3PAO bill.

  5. Executive readout

    A plain-English briefing for leadership: where you stand, what it will take, and what it will cost.

Pricing

Straightforward pricing, published up front

No "call for a quote" to find out whether you can afford us. Every engagement starts with the assessment; advisory comes after, only if you want it.

After the assessment

vCISO Advisory

Starting at $2,000 /month

A guide through remediation and beyond: steady senior counsel without a full-time hire.

  • Risk register and policy management
  • Quarterly remediation roadmap
  • Audit and assessor support
Free 30-min scoping call
Quick questions

Ad hoc advisory

$250 /hour, 4-hour minimum

For past assessment clients with quick questions. Small asks, answered fast, without turning into free consulting.

  • SPR score and affirmations help
  • Prime flow-down reviews
  • Remediation second opinions
Free 30-min scoping call

Questions about fit or scope? Book a free 30-min scoping call, or call (832) 800-3988.

About

Founder-led, on purpose

Oak City Cyber is Kurt Bain, CISSP, CCSP. There is no junior team and no sales pipeline between you and the person doing the assessment. You work directly with the founder, one client at a time.

"Some advisors sell you software at the end. Some are selling the next engagement from minute one. I do neither."

Kurt is a compliance practitioner who works with NIST SP 800-171 and CMMC every day. That means the assessment you get is shaped by the controls as assessors actually interpret them, not by a checklist run through a template mill.

Oak City Cyber is vendor-neutral and independent: no tools sold, no referral fees, no sponsored recommendations. When a gap needs fixing, the advice is about what fits your shop, not what earns a commission. Houston-based, with on-site work available across the metro.

or call (832) 800-3988 directly.

FAQ

Questions, answered straight

Are you a C3PAO?

No, and that is the point. We do readiness, not certification. Our job is getting you ready before you spend $30k+ on the real assessment, so you pass it the first time instead of paying to fail it.

How long does the assessment take?

Two to three weeks from kickoff to readout. Remediation timelines depend on the gaps we find; the POA&M gives you realistic dates and owners for each one.

We're a small shop. Is this for us?

Yes. Small subcontractors are exactly who this is built for. The fixed fee, the tight CUI scoping, and the plain-English readout are all designed for teams without a compliance department.

What if CMMC changes again?

Readiness against NIST SP 800-171 holds regardless of rulemaking. The controls are the controls; a new rule changes the timeline and the assessment mechanics, not the security work itself.

Do you sell tools or take referral fees?

No. We are vendor-neutral and independent. We do not sell software, we do not take referral fees, and we will never recommend a product because someone paid us to.

Prefer to talk now? Call (832) 800-3988.

Know where you stand.

One free 30-minute scoping call. We will talk through your contracts, your CUI, and whether a gap assessment makes sense for you right now. No pitch, no pressure.

Prefer to talk now? Call (832) 800-3988.

SECURE. ROOTED. RESILIENT.

Oak City Cyber

CMMC readiness and vCISO advisory for small defense subcontractors. Houston, TX.

(832) 800-3988

Contact

© 2026 Oak City Cyber LLC. All rights reserved. Readiness and advisory services. Oak City Cyber is not a CMMC Third Party Assessment Organization (C3PAO).