CMMC Level 2, NIST SP 800-171 and ISO 27001 support for the Defense Industrial BaseNorthern Virginia  |  Serving contractors nationwide

Services

Fixed-scope engagements for contractors who need to protect CUI, meet DFARS requirements and pass third-party assessment.

CMMC Level 2 readiness

For contractors handling Controlled Unclassified Information under DFARS 252.204-7012, 7019, 7020 and 7021.

8 to 16 weeksTypical time from gap assessment to mock assessment. Gap assessments alone take 2 to 3 weeks.

What you get

  • CUI scoping, data flow diagrams and asset inventory by category
  • Gap assessment against all 110 NIST SP 800-171 requirements and 320 objectives
  • System Security Plan written for your environment
  • Policies, procedures and a Plan of Action and Milestones
  • SPRS score calculation and submission support
  • Shared responsibility review for your MSP and cloud providers
  • Mock assessment with an evidence binder organized by objective

ISO 27001

For firms whose customers, primes or international partners require certification.

Implementation or auditFull ISMS builds or standalone internal audits, scoped to your organization.

What you get

  • ISMS scope, context and leadership commitments
  • Risk assessment methodology and risk treatment plan
  • Statement of Applicability against Annex A controls
  • Internal audit led by an ISO 27001 Lead Auditor
  • Management review and readiness for your certification body audit
  • Control mapping to NIST SP 800-171 so one program serves both

Penetration testing and vulnerability assessment

For proving your controls hold up against a real attacker, before an assessor or adversary finds out.

1 to 3 weeksTypical testing window, with a written report within 5 business days of completion.

What you get

  • External network and perimeter testing
  • Internal network and Active Directory testing
  • Microsoft 365 and cloud configuration review
  • Authenticated vulnerability scanning with prioritized fixes
  • Findings mapped to NIST SP 800-171 requirements
  • Executive summary, technical report and a retest after remediation

Common questions

Can GreenOak perform our CMMC certification assessment?

No. Certification assessments are performed by an authorized C3PAO. Because we advise you, we are independent of your assessment by design, and that protects the integrity of your certification.

Do we need Level 2 or Level 1?

If your contracts involve CUI, you will almost certainly need Level 2. If you only handle Federal Contract Information, Level 1 self-assessment may apply. We confirm this during the free scoping consultation.

How long does readiness take?

Most small contractors need 8 to 16 weeks from gap assessment to mock assessment, depending on how many gaps need technical remediation and how quickly your team or MSP can implement changes.

We already have an MSP. Do we still need you?

Usually yes. MSPs run your technology. We define what CMMC requires, document it, verify the MSP's work and prepare your people for assessment interviews. We work alongside your MSP, not in place of it.

Do you work outside Virginia?

Yes. We work on-site across the DC, Maryland and Virginia region and remotely with contractors nationwide.

Get a fixed quote

Tell us about your contracts and environment. We'll respond within one business day.

Request a consultation