CMMC 2.0 readiness for the Defense Industrial Base

Get to assessment-ready before the contract clock runs out.

If you're a DoD subcontractor staring down a CMMC Level 1 or Level 2 assessment, we get you ready: documentation your auditor will actually accept, and an SPRS score that keeps you on contract.

  • CMMC 2.0
  • NIST SP 800-171
  • DFARS 252.204-7012
  • FAR 52.204-21
  • 110practices NIST SP 800-171 controls in CMMC Level 2
  • 17practices CMMC Level 1 baseline for Federal Contract Information
  • 72hrs DFARS 252.204-7012 cyber-incident reporting window
  • 1business day Our reply time to every inquiry

Our point of view


Living Compliance over checkbox security.

Compliance you write once and file away fails the first time it's tested.

We build programs that hold up in the real world. Your team follows the policies because they make sense. The evidence is already there when someone asks for it. And when a customer, an auditor, or an actual incident puts your controls to the test, they stand.

We call that the Living Compliance Framework, and it's how we run every engagement.

Scope honesty


LED Defense is a CMMC consulting practice. We get contractors ready for assessment.

We're not a C3PAO. The official certification assessment is run by a Cyber AB-authorized assessor. Our job is to have your environment, documentation, and evidence in order before they walk in the door.

Frameworks we work to


The regulations we live in.

  • CMMC 2.0

    Level 1 (Federal Contract Information, 17 practices) and Level 2 (Controlled Unclassified Information, 110 practices).

  • NIST SP 800-171 Rev 2

    The current 110-control baseline. We're already tracking Rev 3 as it rolls out.

  • DFARS 252.204-7012

    Safeguarding covered defense information and cyber incident reporting.

  • DFARS 252.204-7019, -7020, -7021

    NIST 800-171 assessment requirements and the CMMC assessment clause.

  • FAR 52.204-21

    Basic safeguarding of covered contractor information systems.

  • NIST SP 800-53 Rev 5

    Where the engagement touches federal information systems.

How an engagement runs


From flow-down clause to assessment-ready.

  1. Scope & boundary

    First we figure out what's in scope, what's out, and exactly where your assessment boundary sits.

  2. Gap assessment

    We check your environment against all 110 NIST SP 800-171 controls and hand you a fix list, worst gaps first.

  3. Remediate & document

    We close the gaps, write your SSP, and pull together the evidence and policies your assessor asks for first.

  4. Pre-assessment readiness

    We run a full mock assessment before the C3PAO shows up, so nothing catches you off guard.

  5. Living Compliance

    We keep the program running between assessments, so the next one is routine.

What we deliver


What you'll actually walk away with.

  • CMMC scoping and boundary definition

    What's in scope, what's out, and how to defend where you drew the line.

  • Gap assessments

    Every NIST SP 800-171 control checked, with a clear list of what to fix first.

  • System Security Plan (SSP) authorship

    The first document your assessor opens. We write it so it holds up.

  • POA&M development

    A Plan of Action and Milestones for your open gaps, written so you can actually close them.

  • SPRS score calculation and roadmap

    Where your score is now, where it needs to be, and how to get there.

  • Evidence collection and policy library

    The proof your controls aren't just words on paper.

  • Pre-assessment readiness reviews

    A practice run before the real thing.

  • Ongoing compliance maintenance

    Living Compliance that stays current between assessments.

Behind on a CMMC flow-down?

The clock starts the day that clause lands, not the day the assessor calls. Let's find you the fastest way through.

Who we work with


Tier 2 and Tier 3 DIB subcontractors.

Usually it's a company without a full-time compliance team that just found a CMMC clause buried in a flow-down. Some hire us for a single gap assessment. Others keep us on for a readiness program that runs a few quarters.

Founder


Seth Ledbetter

Founder and Principal

I've spent my career around the defense industrial base and the technology behind the mission. I started LED Secure Infrastructure after watching the same thing happen too many times: contractors handed checkbox compliance that fell apart the moment it mattered. So I built the practice around a simpler idea. Compliance should hold up under pressure, not just pass an audit.

Credentials: CompTIA Security+

Contact


Schedule a 30-minute consultation.

We'll talk through your contract requirements, where you stand today, and the best place to start.

We'll only use this to reply to you. See our privacy policy.
Prefer email? info@leddefense.com