- CMMC for the Defense Industrial Base
made clear and audit-ready.
If a prime contractor is asking for CMMC, the clock has already started. JDC Security guides defense contractors and subcontractors through readiness, documentation, and self-attestation, built to withstand DoW scrutiny, not just check a box. We also help contractors and subcontractors through their FedRAMP Equivalent requirements for any cloud portions of their systems.
Overview
Built by a practitioner who has lived these controls
CMMC turns NIST SP 800-171 into a contractual requirement that flows down from primes to every supplier touching Federal Contract Information. We translate that requirement into plain language, real documentation, and a defensible path to compliance, whether you are self-attesting at Level 1 or 2 or preparing for a Level 2 or 3 assessment.
WHO WE SERVE
Small & mid-size suppliers
Manufacturers, IT and logistics shops, and professional-services firms handling FCI or CUI, typically without a full-time compliance team.
WHAT WE FIX
The documentation gap
Most companies have no System Security Plan, no written policies, and no evidence trail, exactly what a prime or auditor asks to see first.
HOW WE WORK
Done-with-you, not dumped-on-you
Fixed-fee engagements with a senior advisor at the table, so your team can speak to every control with confidence.
CMMC Life-Cycle Support
A clear path from "where do we start" to affirmed
Four phases that take the guesswork out of compliance. Each one leaves you with a tangible artifact you own.
⬤
PHASE 01
Scope & Readiness
Define your FCI or CUI boundary, inventory assets, and measure where you stand against every applicable control.
⬤
PHASE 02
Documentation
Build the System Security Plan, policies, and procedures that prove how each requirement is met.
⬤
PHASE 03
Remediation
Close gaps in priority order with a clear action plan, so nothing is left open at attestation.
⬤
PHASE 04
Attest & Affirm
Complete your self-assessment and prepare the SPRS affirmation your Affirming Official can stand behind.
Why JDC Security
Senior expertise, without the big-firm price tag
33+ Years in the Field
Cybersecurity and national-security leadership, U.S. Army veteran, Doctor of Computer Science.
Credentialed
CISSP, CISM, CRISC, CISA, CISA, experience in the federal government, and a university-level cybersecurity educator who teaches federal frameworks.
Defensible by design
Documentation built to hold up under DoW inquiry and False Claims Act scrutiny, not boilerplate.
Fixed fees
Know your cost up front. No hourly surprises, no scope creep, just a clear deliverable on a clear timeline.
CMMC Level 1 · Self-Assessment Package
Everything you need to self-attest at Level 1, done right.
CMMC Level 1 is self-assessed and self-affirmed in SPRS. There is no third-party assessor, which means the entire weight rests on your documentation being complete, accurate, and defensible. We build that documentation for you, mapped to all 17 safeguarding requirements and every one of the 59 assessment objectives. Additionally, we also help you with all of your technical requirements.
- Covers all 17 FAR 52.204-21 safeguarding requirements
- Scored against all 59 NIST SP 800-171A objectives
- Tailored to your real environment, not a template
- Delivered in 30 days or less, ready for SPRS affirmation
Level 1 Readiness Package
Fixed-fee. Three engagement depths.
$3,500 starting
- Essentials, full document set, you self-attest
- Guided, plus a working session with your team
- Done-with-you, hands-on through SPRS affirmation
What You Receive
Eleven deliverables. One audit-ready binder.
Every document you need to demonstrate Level 1 compliance and stand behind your affirmation, delivered as editable, branded files you own outright.
Security Control Family Policies and Procedures
Your system boundary, asset inventory, and how all 17 requirements are met, the cornerstone document.
System Security Plan (SSP)
Your system boundary, asset inventory, and how all 17 requirements are met, the cornerstone document.
Level 1 Self-Assessment Workbook
All 59 objectives scored met / not-met, each tied to an evidence reference.
Access Control Policy
Who can reach FCI or CUI, how access is granted, limited, and removed.
Identification & Authentication Policy
How users and devices are identified and verified before access.
Media Protection Policy
Handling, sanitizing, and disposing of media that holds FCI or CUI.
Physical Protection Policy
Controlling physical access to systems, equipment, and facilities.
System & Communications Protection Policy
Protecting information at your network boundaries and in transit.
System & Information Integrity Policy
Flaw remediation, malicious-code protection, and monitoring.
Self-Affirmation Memorandum
Ready for your Affirming Official to enter the affirmation into SPRS.
Evidence / Artifact Checklist
Exactly what to keep on file, mapped to each objective.
Remediation Tracker
Any gaps closed before affirmation, with a prioritized action plan.
Walkthrough & Guidance
A working session so your team can speak to every control and own the affirmation with confidence.
Are you ready for CMMC?
If not, that's exactly what we do.
Book a free 20-minute readiness call. We will tell you honestly where you stand and what it takes to get compliant.