CMMC Gap Assessment | Spatix Networks

NIST SP 800-171 Rev 2 · CMMC Level 2 readiness

The number your prime is asking for.

A fixed scope gap assessment against all 110 requirements. You get a score you can actually defend, a written plan for the gaps, and a list of things you can fix yourself before you spend another dollar with me.

110
Your SPRS score starts at 110, and every unimplemented requirement subtracts 1, 3, or 5 points. It can go negative. First time through, for most shops, it does.
110 · everything implemented −203 · nothing implemented
A negative number is not a failing grade. It's a starting coordinate. What matters is whether you can show your work, and what the number looks like after the first round of fixes.

Who this is for

If any of these is true, you're the shop I built this for.

01

A prime sent you a flow down clause and you're not sure what it obligates you to do.

02

Somebody asked for your SPRS score and you had to look up what that meant.

03

You handle drawings, specs, or technical data for defense work and nobody has ever mapped where those files live.

04

Your IT support keeps the network running. Nobody was ever hired to run a compliance program.

05

You've been quoted a large recurring contract and you'd rather know the size of the problem first.

06

You have shop floor equipment that can't be patched and every provider you've talked to has hand waved past it.

Scope

What this is. And what it isn't.

Most of the confusion in this market comes from providers being vague about which of these they're selling. So here it is on the front page.

What you're buying

  • A readiness and gap assessment against all 110 requirements of NIST SP 800-171 Rev 2
  • A score calculated using the DoD Assessment Methodology, with the arithmetic shown
  • Findings backed by configuration evidence and screenshots from your own environment
  • A System Security Plan skeleton, or a gap review if you already have one
  • A POA&M with owners, dates, and the score value each item recovers
  • A remediation path split into what you can do yourself and what needs engineering

What it isn't

  • Not a certification assessment. Only a C3PAO can conduct the assessment that results in CMMC status
  • I don't submit anything to SPRS for you. You calculate, you affirm, you submit. I show the work
  • No guarantee you'll pass anything. Nobody can honestly offer that
  • Not a software purchase. 110 requirements aren't a licensing problem
  • No retainer attached. If you want ongoing help afterward, that's a separate conversation you're free to skip
  • Not an enclave sales pitch. If your real environment can be made compliant, I'll tell you that

Process

What actually happens.

Roughly two weeks, remote, with two calls on your calendar. Everything else happens on my time.

00

We find out if you even need this

Thirty minutes, free. What's in your contracts, whether you handle CUI or only FCI, and which level actually applies. If the answer is Level 1, I'll tell you, and this ends here.

01

Find where the controlled data actually lives

I talk to the people who touch government work, meaning the estimator, the engineer, and the quality lead. I trace how a drawing arrives, where it lands, who opens it, and what leaves the building with it. You get a data flow map most owners have never seen.

02

Draw the boundary

Every asset gets categorized: in scope, security protection, risk managed, specialized, or out. Shop floor equipment is handled as the specialized asset category it is. Not ignored, and not over scoped into a problem you don't have.

This is where the money is saved
03

Technical discovery

Firewall rule base, segmentation, remote access, identity and MFA coverage, endpoint posture, share permissions on the directories holding your drawings, logging, and backup. Real engineering review, not a questionnaire.

04

All 110, one at a time

Met, not met, or partially met, each with evidence recorded. Requirements satisfied by policy get the same treatment as the technical ones, which is where most shops discover entire families sitting at zero.

05

The findings call

Your score, the arithmetic behind it, and the projected score after the first round of fixes. You leave with a list of things you can close yourself this week at no cost, and a fixed quote for the things you can't.

Deliverables

What you can hand to your prime.

The report outlives the engagement. That's the point. It's the thing you show when somebody asks how you know where you stand.

Executive summaryOne page, plain English, no acronyms in the first paragraph.
Data flow and boundary diagramWhere controlled information lives and what the assessed boundary contains.
Categorized asset inventoryEvery asset sorted under the CMMC scoping model, including OT.
110 requirement result matrixStatus and evidence reference for each one.
Score derivation sheetCurrent and projected, with every deduction itemized.
SSP skeleton or gap memoBoundary, system description, and the implementation statements already supportable.
POA&MOwners, target dates, and points recovered per item.
Technical findings appendixScreenshots and configuration excerpts from your environment.

Price

One number, decided before we start.

$4,500
FIXED SCOPE · NO RETAINER · NO SUBSCRIPTION
  • Intro call free
  • Assessment 2 weeks
  • Your calendar time 2 calls
  • Delivery remote
  • Self fix list included

Comparable gap assessments from registered provider organizations generally run five to eight thousand dollars for a business this size. I'm below that because I'm one engineer with no sales team and no overhead to cover, not because the work is smaller.

The price doesn't move based on endpoint count or how bad the findings turn out to be. If the scope is genuinely larger than a shop your size, meaning multiple sites, a second domain, or something I couldn't have anticipated on the intro call, you'll hear that before I start rather than after.

Remediation, if you want it, gets quoted as fixed scope after you've seen the report. You're under no obligation to buy it, and the report is just as useful if you hand it to somebody else.

Who does the work

You get the engineer, not a coordinator.

Arwin Singh, founder of Spatix Networks

I'm Arwin Singh. I run Spatix Networks, and I do the assessment myself. The same person on the intro call is the one reading your firewall config and sitting on the findings call.

My background is network security engineering, not compliance consulting. Over a decade in enterprise networking, dual CCNPs, and senior level work in OT and industrial control environments. That last part matters more than it sounds. The reason CMMC gets expensive for manufacturers is almost always bad scoping around shop floor equipment, and that's a judgment call you want made by somebody who has actually worked on those networks.

What that means in practice is that the findings are engineering findings. A compliance consultant can tell you requirement 3.13.1 is not met. I can tell you why your boundary doesn't exist, which of your controls is actually load bearing, and which finding could take the company down regardless of what it costs you in points.

CCNP Enterprise CCNP Security 10+ yrs enterprise networking OT / ICS environments Remote first

Questions

The ones that actually come up.

CMMC got paused. Do I still need this?

Part of it did. Phase 2, the stage requiring a third party assessor for certain Level 2 contracts, was suspended in July 2026 while a task force reviews the program.

What wasn't suspended: the self assessment requirement, the annual affirmation signed by a named officer at your company, and DFARS 252.204-7012, which has been in defense contracts since 2017. Primes also set their own supplier requirements for their own risk reasons, and nothing in that memo tells them to drop anything.

The government stepped back. Whether your prime did is a different question, and it's the one that decides your contract.

Are you a C3PAO? Can you certify us?

No, and no. A C3PAO conducts the official certification assessment, and by design they're barred from consulting or remediating for a company they might later assess. That separation exists so your auditor isn't grading their own work.

This is the other half of the ecosystem: readiness, gap identification, and remediation. If a firm advertises both, ask them who is actually doing your certification assessment and when.

Do we even need Level 2?

Possibly not. If you only handle Federal Contract Information and never touch CUI, you're likely looking at Level 1. That's fifteen requirements and an annual self assessment, not 110.

That's the first thing the intro call sorts out, and it's free. If the answer is Level 1, I'll say so and you won't hear a pitch. Your contracting officer can also confirm which level your contract requires, at no cost to you.

We don't have any IT staff. Is that a problem?

No. Most shops this size either have one person wearing the IT hat alongside another job, or an outside provider handling break fix. Either is normal and neither changes the assessment.

I'll need someone who can grant access and answer questions about how the business actually operates. That person doesn't need to be technical.

Do you need access to our network?

Read level access to the systems in scope, granted by you, under a signed engagement letter that spells out exactly what's authorized and what isn't. No credential harvesting, no active exploitation, nothing outside the agreed scope.

The report itself describes weaknesses in a defense supplier's environment, so it's handled as sensitive. Encrypted delivery, a defined retention period, and no identification of your company in any case study or content without written permission.

What if the findings are bad?

They usually are the first time, and a negative score is the normal starting position for a shop that has never done this. It isn't a grade and I don't deliver it like one.

What matters is the delta. You'll get a projected score showing where a defined amount of work puts you, and the first tranche of that work is usually free and takes an afternoon.

Our machines run software that can't be updated. Now what?

That's expected, and it isn't the blocker people assume. CNC controllers, CMMs, test equipment, and legacy HMIs fall under the specialized asset category. Documented and risk managed rather than fully controlled.

The failure mode I see is providers who either ignore shop floor equipment entirely or insist the whole environment has to be rebuilt around it. Neither is correct, and getting this call right is usually the difference between a four figure remediation and a five figure one.

How is this different from a network security assessment?

A security assessment asks whether you're safe. A gap assessment asks whether you can prove it. Different question, different standard, different deliverable.

If you have no compliance obligation, the network security assessment is the right one and it costs less. If a prime is asking for a score, you want this one.

Start here

Thirty minutes, no cost, no pitch.

Tell me what your prime asked for and roughly what your environment looks like. If this isn't the right thing for you, that's a two minute answer and you'll have it.