PROTECT · Compliance · CMMC 2.0

Your DoD contracts won't wait for CMMC. Neither should you.

Media Express prepares Chicago-area defense and aerospace manufacturers for CMMC Level 1 or Level 2 readiness. Website compliance, capability statements, documentation, and C3PAO audit-partner coordination — one team, one contract, one deadline.

⚜ Plain English · Quotable
CMMC (Cybersecurity Maturity Model Certification) is the security certification the U.S. Department of Defense now requires from its contractors and suppliers. Any company that touches DoD information — including small machine shops making military parts — must reach the required level or lose federal contracts. Media Express prepares Chicago-area manufacturers for CMMC Level 2 in 6-12 months, with fixed pricing at each phase and coordinated referral to Cyber-AB-accredited audit partners.
🏆️ Who Needs It

If you sell to the Department of Defense — directly or through a prime — you need CMMC.

CMMC applies to every business in the DoD supply chain, not just primes. If Lockheed, Boeing, Raytheon, Northrop, General Dynamics, or any Tier-1 supplier sends you a drawing, a spec, or a purchase order tied to a defense program — CMMC applies to you.

Rule of thumb: if your customer's contract references DFARS 252.204-7012, you're in scope.

🏆️ The Three Levels

Level 1, Level 2, or Level 3.

CMMC 2.0 has three levels. Which one applies depends on what type of information you handle for the government. Most manufacturers handling technical drawings from DoD or primes fall under Level 2.

Level 1
Foundational
"Basic hygiene."
17
Practices
Self
Assessment

Applies if you only handle FCI (Federal Contract Information — basic contract data, not sensitive tech data). Self-attested annually. Cheapest and fastest path to compliance.

Level 2
Advanced
"The one you probably need."
110
Practices
C3PAO
Third-Party Audit

Required if you handle CUI (Controlled Unclassified Information) — technical drawings, specs, engineering data from DoD or primes. Audited every 3 years by a Cyber-AB-accredited C3PAO. Most defense manufacturers land here.

Level 3
Expert
"For high-priority programs."
110+
Practices
Gov
Assessed by DoD

Adds enhanced NIST 800-172 controls on top of Level 2. Reserved for the most sensitive DoD programs. Assessed directly by the DoD. Rare for small/mid-size manufacturers.

⚠️ If You Ignore It

The cost of doing nothing.

CMMC is being phased in. Every quarter more contracts require it. Ignoring it is a business decision to slowly exit the DoD supply chain.

⚠️ Real Consequences

Manufacturers who don't prepare face measurable losses over the next 24 months.

  • Prime contractors drop you from their approved vendor list — you stop getting purchase orders
  • New DoD contracts require CMMC compliance as a bid prerequisite — you can't even quote the work
  • False Claims Act exposure if you certified NIST 800-171 compliance without actually meeting it (self-reported SPRS score)
  • Cyber liability insurance premiums rise sharply for uncertified defense suppliers
  • Your prepared competitors take contracts you would have won
  • Recovering later costs 2-3× more than preparing now — audit slots fill up, and rushed prep produces weaker documentation
⚜ How We Help

The 5-step CMMC readiness path.

A structured, phased approach with clear deliverables and fixed pricing at each phase. You always know what's next, what it costs, and when it's done.

1
Free Readiness Assessment (15 min)

Take our 15-question quiz online. Get an instant PDF report with your readiness score, applicable CMMC level, and top-priority gaps. No commitment. This tells us whether you're a Level 1 or Level 2 target and what to focus on first.

2
Gap Analysis + Roadmap (2-3 weeks)

Fixed-price engagement. We map your current state against NIST 800-171 controls, identify every gap, and produce a phased roadmap with timelines and costs. Includes an OPSEC website audit to catch information leaks that could hurt an audit.

3
Documentation + Website Compliance (6-10 weeks)

System Security Plan (SSP) coordinated with our partner writer. POA&M (Plan of Action & Milestones). Capability Statement PDF. Government Contracting section on your website. Certifications page. Security posture page. All artifacts an auditor will look for — ready.

4
Technical Remediation (parallel)

Whatever technical gaps exist — MFA rollout, encryption, backup testing, endpoint controls, GCC High migration (via partner). We coordinate the work and verify each control is in place before your audit window.

5
C3PAO Audit Coordination (Level 2 only)

We introduce you to a Cyber-AB-accredited C3PAO partner. You engage them directly for the formal audit (Media Express does not perform the audit — that's a licensed activity). We stay involved to answer auditor questions and manage the paper trail.

💰 What It Costs

Fixed pricing at every phase. No open-ended consulting.

Level 1 is fast and cheap. Level 2 is a real engagement, but we phase it so you never write one big check. You always know the next step and what it costs before you commit.

Level 1 Readiness
Foundational Package
$8,000 – $15,000
One-time, delivered in 4-6 weeks
  • 17-control self-assessment
  • SPRS score entry support
  • Basic security policies
  • Website compliance section
  • Capability Statement PDF
  • Annual re-attestation reminder
Ongoing Retainer
Managed Compliance
$2,000 – $8,000/mo
Recurring, month-to-month
  • Monthly compliance health report
  • Framework update alerts
  • Website + SSP maintenance
  • SPRS score updates
  • Quarterly review call
  • Compliance-ready hosting included
  • Priority support

Prices depend on company size, existing security posture, and scope. Assessment results give you an accurate quote before you commit.

Above are typical Illinois market rates. Media Express pricing is more accessible — we build once and reuse across clients, so you don't pay for someone else's discovery work. Contact us for a personalized quote based on your exact situation.

⚜ Free Consultation →
❓ Common Questions

FAQ.

Which CMMC level do I need?

Level 1 if you only handle FCI (Federal Contract Information — basic contract data). Level 2 if you handle CUI (Controlled Unclassified Information — technical drawings, specs from DoD or primes). Most manufacturers making military parts need Level 2.

How long does CMMC preparation take?

Level 1 self-assessment: 1-3 months. Level 2 preparation from scratch: 6-12 months typical. Starting early matters — C3PAO audit slots are filling up and rushed prep produces weaker documentation.

How much does CMMC readiness cost?

Level 1: $8k-15k one-time. Level 2 readiness: $25k-75k phased, plus $30k-150k C3PAO audit fee paid directly to the auditor. See our pricing tiers above — assessment results give you an accurate quote.

Does Media Express perform the CMMC audit?

No. Only Cyber-AB-accredited C3PAOs can perform the formal Level 2 audit. Media Express prepares you for the audit — website compliance, documentation, capability statements, gap remediation — and coordinates the referral to our C3PAO partners when you're ready.

Do I need CMMC if I only supply commercial products to a defense contractor?

Depends on whether you touch CUI or FCI. If your customer sends you technical drawings marked CUI (or unmarked drawings from a DoD contract), yes. If you only supply COTS (commercial off-the-shelf) items with no CUI exposure, the requirement is lighter. Ask your prime contractor's procurement or supplier compliance team when in doubt.

What if I already submitted a SPRS score?

Good — that's a start. If your score was low (or negative), CMMC Level 2 preparation will pull it up. If it was self-attested optimistically without actual controls in place, we can help you close the gaps before an audit or a False Claims Act challenge exposes the discrepancy.

What happens if I ignore CMMC?

You lose access to DoD contracts as the phased rollout continues. Primes drop you from approved vendor lists. You face False Claims Act exposure if you certified compliance without meeting the standard. Competitors who prepared early win contracts you would have won.

📚 Related Terms

Also worth understanding.

CMMC references several other frameworks and terms. If you want to go deeper on any of them, our wiki covers each in plain English.

Ready to see where you stand?

Take the free 15-question Compliance Readiness Assessment. Instant PDF report with your CMMC level, readiness score, and top-priority actions. No sales pitch.

Media Express LLC · Chicago IL · Est. 1995 · Independent · 31+ years
Media Express LLC provides CMMC readiness and preparation services — including compliance-ready websites, capability statement design, OPSEC audits, security posture pages, documentation coordination, and referral to Cyber-AB-accredited audit partners. Media Express is not a C3PAO and does not perform formal CMMC certification audits. Formal audits are conducted by independent C3PAO organizations licensed by the Cyber-AB.