CMMC 2.0 readiness for the Defense Industrial Base
Get to assessment-ready before the contract clock runs out.
If you're a DoD subcontractor staring down a CMMC Level 1 or Level 2 assessment, we get you ready: documentation your auditor will actually accept, and an SPRS score that keeps you on contract.
- CMMC 2.0
- NIST SP 800-171
- DFARS 252.204-7012
- FAR 52.204-21
- 110practices NIST SP 800-171 controls in CMMC Level 2
- 17practices CMMC Level 1 baseline for Federal Contract Information
- 72hrs DFARS 252.204-7012 cyber-incident reporting window
- 1business day Our reply time to every inquiry
Our point of view
Living Compliance over checkbox security.
Compliance you write once and file away fails the first time it's tested.
We build programs that hold up in the real world. Your team follows the policies because they make sense. The evidence is already there when someone asks for it. And when a customer, an auditor, or an actual incident puts your controls to the test, they stand.
We call that the Living Compliance Framework, and it's how we run every engagement.
Scope honesty
LED Defense is a CMMC consulting practice. We get contractors ready for assessment.
We're not a C3PAO. The official certification assessment is run by a Cyber AB-authorized assessor. Our job is to have your environment, documentation, and evidence in order before they walk in the door.
Frameworks we work to
The regulations we live in.
-
CMMC 2.0
Level 1 (Federal Contract Information, 17 practices) and Level 2 (Controlled Unclassified Information, 110 practices).
-
NIST SP 800-171 Rev 2
The current 110-control baseline. We're already tracking Rev 3 as it rolls out.
-
DFARS 252.204-7012
Safeguarding covered defense information and cyber incident reporting.
-
DFARS 252.204-7019, -7020, -7021
NIST 800-171 assessment requirements and the CMMC assessment clause.
-
FAR 52.204-21
Basic safeguarding of covered contractor information systems.
-
NIST SP 800-53 Rev 5
Where the engagement touches federal information systems.
How an engagement runs
From flow-down clause to assessment-ready.
-
Scope & boundary
First we figure out what's in scope, what's out, and exactly where your assessment boundary sits.
-
Gap assessment
We check your environment against all 110 NIST SP 800-171 controls and hand you a fix list, worst gaps first.
-
Remediate & document
We close the gaps, write your SSP, and pull together the evidence and policies your assessor asks for first.
-
Pre-assessment readiness
We run a full mock assessment before the C3PAO shows up, so nothing catches you off guard.
-
Living Compliance
We keep the program running between assessments, so the next one is routine.
What we deliver
What you'll actually walk away with.
-
CMMC scoping and boundary definition
What's in scope, what's out, and how to defend where you drew the line.
-
Gap assessments
Every NIST SP 800-171 control checked, with a clear list of what to fix first.
-
System Security Plan (SSP) authorship
The first document your assessor opens. We write it so it holds up.
-
POA&M development
A Plan of Action and Milestones for your open gaps, written so you can actually close them.
-
SPRS score calculation and roadmap
Where your score is now, where it needs to be, and how to get there.
-
Evidence collection and policy library
The proof your controls aren't just words on paper.
-
Pre-assessment readiness reviews
A practice run before the real thing.
-
Ongoing compliance maintenance
Living Compliance that stays current between assessments.
Behind on a CMMC flow-down?
The clock starts the day that clause lands, not the day the assessor calls. Let's find you the fastest way through.
Who we work with
Tier 2 and Tier 3 DIB subcontractors.
Usually it's a company without a full-time compliance team that just found a CMMC clause buried in a flow-down. Some hire us for a single gap assessment. Others keep us on for a readiness program that runs a few quarters.
Founder
Seth Ledbetter
Founder and Principal
I've spent my career around the defense industrial base and the technology behind the mission. I started LED Secure Infrastructure after watching the same thing happen too many times: contractors handed checkbox compliance that fell apart the moment it mattered. So I built the practice around a simpler idea. Compliance should hold up under pressure, not just pass an audit.
Credentials: CompTIA Security+
Contact
Schedule a 30-minute consultation.
We'll talk through your contract requirements, where you stand today, and the best place to start.