CMMC Compliance Implementation Support
Budget: $250 – $750 USD
I am ready to move our organisation to CMMC Level 1 and need a specialist who can guide the entire process from assessment through remediation and documentation. The scope spans three core areas—network security, data protection, and user access control—across all production servers, employee workstations, and our small fleet of mobile devices. Our environment is a typical Microsoft-centric stack with a mix of on-prem VMware hosts, Office 365, and a few SaaS applications that handle Federal Contract Information.
What I need first is a concise gap analysis mapped to CMMC Level 1 requirements (aligned with NIST 800-171 Rev 2). From there, we will prioritise fixes, implement the missing safeguards, and collect artefacts that demonstrate ongoing compliance. I expect clear documentation that auditors can follow without extra clarification.
Deliverables
• Gap analysis report with risk ratings
• Remediation plan, including configuration changes and policy updates
• Updated policies and procedures covering network security, data protection, and user access control
• Evidence package (screenshots, logs, tool outputs) ready for self-assessment submission
Acceptance criteria
The project is complete when the evidence package passes an internal review against every Level 1 control and our servers, workstations, and mobile devices show no open critical findings.
Familiarity with tools such as SecureScore, Nessus, or similar vulnerability scanners, along with practical experience hardening Windows Server and MDM-managed mobile devices, will be valuable throughout this engagement.
What I need first is a concise gap analysis mapped to CMMC Level 1 requirements (aligned with NIST 800-171 Rev 2). From there, we will prioritise fixes, implement the missing safeguards, and collect artefacts that demonstrate ongoing compliance. I expect clear documentation that auditors can follow without extra clarification.
Deliverables
• Gap analysis report with risk ratings
• Remediation plan, including configuration changes and policy updates
• Updated policies and procedures covering network security, data protection, and user access control
• Evidence package (screenshots, logs, tool outputs) ready for self-assessment submission
Acceptance criteria
The project is complete when the evidence package passes an internal review against every Level 1 control and our servers, workstations, and mobile devices show no open critical findings.
Familiarity with tools such as SecureScore, Nessus, or similar vulnerability scanners, along with practical experience hardening Windows Server and MDM-managed mobile devices, will be valuable throughout this engagement.