Veteran-Owned Former DoD ISSM Maryland / DC / Virginia

CMMC compliance,
led by someone who has sat on your side of the table.

CMMC Level 1 and Level 2 readiness and fractional vCISO leadership for Defense Industrial Base contractors. Gap assessment, NIST SP 800-171 alignment, SSP and POA&M development, SPRS scoring, and assessment preparation — delivered by a former DoD Information System Security Manager, not a reseller.

Federal Service20 Years — USAF & DoD
Security LeadershipFormer ISSM / Cyber Ops
FrameworkNIST SP 800-171 · CMMC
CoverageMD · DC · VA · Remote
Engagement Scope

What a readiness engagement actually covers.

CMMC is an evidence exercise. The certificate follows the documentation, and the documentation follows an honest assessment of where you actually stand. That is the order we work in.

STEP-01Assess

Gap assessment & SPRS scoring

We inventory where Federal Contract Information and Controlled Unclassified Information actually live in your environment, assess each applicable control, and produce your current NIST SP 800-171 self-assessment score for SPRS. You finish this step knowing your real number rather than an optimistic one.

ScopingCUI / FCISPRS
STEP-02Document

SSP and POA&M development

The System Security Plan documents how your environment implements each control. The Plan of Action & Milestones records what is not yet met and how it closes, with owners and dates. These are the two artifacts an assessor asks for first, and the two most contractors do not have in defensible shape.

SSPPOA&MEvidence
STEP-03Remediate

NIST SP 800-171 control alignment

Closing gaps against the 110 controls — access control, audit and accountability, configuration management, incident response, media protection. Prioritised by assessment weight and by what your contract vehicle actually requires, so effort goes where it moves the score.

NIST 800-171110 ControlsRemediation
STEP-04Sustain

Fractional vCISO leadership

Executive-level security leadership without a full-time hire: security roadmap, policy ownership, vendor and supply-chain review, continuous SSP and POA&M maintenance, and assessment preparation when the C3PAO date lands. Compliance is a posture, not a project that ends.

vCISOPolicyC3PAO Prep
Who This Is For

Defense Industrial Base contractors — including the small ones.

If your company holds or pursues DoD contracts that involve FCI or CUI, CMMC applies to you. That includes small subcontractors several tiers down from the prime, who often carry the same control obligations with none of the compliance staff. Those are the engagements this practice is built around.

Straight Answers

CMMC & vCISO — Frequently Asked

What is CMMC and who needs to comply?

CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense's framework for verifying that contractors protect Federal Contract Information and Controlled Unclassified Information. If your company holds or pursues DoD contracts that involve FCI or CUI, CMMC requirements apply to you — including small subcontractors in the Defense Industrial Base.

What is the difference between CMMC Level 1 and Level 2?

Level 1 covers 17 basic safeguarding practices for Federal Contract Information and allows annual self-assessment. Level 2 aligns with the 110 controls of NIST SP 800-171 for protecting Controlled Unclassified Information and, for most contracts, requires a third-party (C3PAO) assessment.

What does a vCISO actually do?

A virtual CISO gives you executive-level security leadership without a full-time hire: risk assessments, security roadmaps, policy development, NIST 800-171 alignment, SSP and POA&M ownership, vendor review, and audit preparation — scaled to a fraction of the cost of a salaried CISO.

What is an SSP and a POA&M?

The System Security Plan (SSP) documents how your environment implements each NIST 800-171 control. The Plan of Action & Milestones (POA&M) tracks the controls you haven't fully met and how you'll close them. Both are foundational evidence for CMMC assessment and SPRS scoring.

Where does O Williams Consulting work with clients?

We serve Maryland, Washington DC, and Virginia in person — including residential technology services for DMV homeowners — and work with defense contractors and growing businesses remotely nationwide.

Engage

Know your score before an assessor does.

Start with a gap assessment and a real SPRS number. No sales layer, straight to the operator.

Book a CMMC Consult — oliver@gratus1.io
Serving Maryland · DC · Virginia — Remote Nationwide