Media Express prepares Chicago-area defense and aerospace manufacturers for CMMC Level 1 or Level 2 readiness. Website compliance, capability statements, documentation, and C3PAO audit-partner coordination — one team, one contract, one deadline.
CMMC applies to every business in the DoD supply chain, not just primes. If Lockheed, Boeing, Raytheon, Northrop, General Dynamics, or any Tier-1 supplier sends you a drawing, a spec, or a purchase order tied to a defense program — CMMC applies to you.
Rule of thumb: if your customer's contract references DFARS 252.204-7012, you're in scope.
CMMC 2.0 has three levels. Which one applies depends on what type of information you handle for the government. Most manufacturers handling technical drawings from DoD or primes fall under Level 2.
Applies if you only handle FCI (Federal Contract Information — basic contract data, not sensitive tech data). Self-attested annually. Cheapest and fastest path to compliance.
Required if you handle CUI (Controlled Unclassified Information) — technical drawings, specs, engineering data from DoD or primes. Audited every 3 years by a Cyber-AB-accredited C3PAO. Most defense manufacturers land here.
Adds enhanced NIST 800-172 controls on top of Level 2. Reserved for the most sensitive DoD programs. Assessed directly by the DoD. Rare for small/mid-size manufacturers.
CMMC is being phased in. Every quarter more contracts require it. Ignoring it is a business decision to slowly exit the DoD supply chain.
A structured, phased approach with clear deliverables and fixed pricing at each phase. You always know what's next, what it costs, and when it's done.
Take our 15-question quiz online. Get an instant PDF report with your readiness score, applicable CMMC level, and top-priority gaps. No commitment. This tells us whether you're a Level 1 or Level 2 target and what to focus on first.
Fixed-price engagement. We map your current state against NIST 800-171 controls, identify every gap, and produce a phased roadmap with timelines and costs. Includes an OPSEC website audit to catch information leaks that could hurt an audit.
System Security Plan (SSP) coordinated with our partner writer. POA&M (Plan of Action & Milestones). Capability Statement PDF. Government Contracting section on your website. Certifications page. Security posture page. All artifacts an auditor will look for — ready.
Whatever technical gaps exist — MFA rollout, encryption, backup testing, endpoint controls, GCC High migration (via partner). We coordinate the work and verify each control is in place before your audit window.
We introduce you to a Cyber-AB-accredited C3PAO partner. You engage them directly for the formal audit (Media Express does not perform the audit — that's a licensed activity). We stay involved to answer auditor questions and manage the paper trail.
Level 1 is fast and cheap. Level 2 is a real engagement, but we phase it so you never write one big check. You always know the next step and what it costs before you commit.
Prices depend on company size, existing security posture, and scope. Assessment results give you an accurate quote before you commit.
Above are typical Illinois market rates. Media Express pricing is more accessible — we build once and reuse across clients, so you don't pay for someone else's discovery work. Contact us for a personalized quote based on your exact situation.
⚜ Free Consultation →Level 1 if you only handle FCI (Federal Contract Information — basic contract data). Level 2 if you handle CUI (Controlled Unclassified Information — technical drawings, specs from DoD or primes). Most manufacturers making military parts need Level 2.
Level 1 self-assessment: 1-3 months. Level 2 preparation from scratch: 6-12 months typical. Starting early matters — C3PAO audit slots are filling up and rushed prep produces weaker documentation.
Level 1: $8k-15k one-time. Level 2 readiness: $25k-75k phased, plus $30k-150k C3PAO audit fee paid directly to the auditor. See our pricing tiers above — assessment results give you an accurate quote.
No. Only Cyber-AB-accredited C3PAOs can perform the formal Level 2 audit. Media Express prepares you for the audit — website compliance, documentation, capability statements, gap remediation — and coordinates the referral to our C3PAO partners when you're ready.
Depends on whether you touch CUI or FCI. If your customer sends you technical drawings marked CUI (or unmarked drawings from a DoD contract), yes. If you only supply COTS (commercial off-the-shelf) items with no CUI exposure, the requirement is lighter. Ask your prime contractor's procurement or supplier compliance team when in doubt.
Good — that's a start. If your score was low (or negative), CMMC Level 2 preparation will pull it up. If it was self-attested optimistically without actual controls in place, we can help you close the gaps before an audit or a False Claims Act challenge exposes the discrepancy.
You lose access to DoD contracts as the phased rollout continues. Primes drop you from approved vendor lists. You face False Claims Act exposure if you certified compliance without meeting the standard. Competitors who prepared early win contracts you would have won.
CMMC references several other frameworks and terms. If you want to go deeper on any of them, our wiki covers each in plain English.
Take the free 15-question Compliance Readiness Assessment. Instant PDF report with your CMMC level, readiness score, and top-priority actions. No sales pitch.