Strategy & Governance

Managed Security

Cyber Defense

Governance, Risk & Compliance

Operations & People

Talk to us

Governance, Risk & Compliance

CMMC readiness, and an honest word about who can certify you.

A CMMC readiness consultant prepares a defence supplier for an assessment that somebody else performs. That sentence is the whole basis on which we take this work. Certification at Level 2 is carried out by a CMMC Third-Party Assessment Organisation authorised by the Cyber AB, and Aphelion Cyber is not one. Anybody who tells you they can both prepare and certify you has misunderstood the scheme or is hoping you have.

What we do is the work either side of that assessment. Level 1 covers fifteen basic safeguarding requirements from FAR 52.204-21 and is self-assessed annually. Level 2 covers the one hundred and ten security requirements of NIST SP 800-171, and for most contracts is assessed by a C3PAO every three years with an annual affirmation in between. Level 3 adds selected requirements from SP 800-172 and is assessed by DCMA DIBCAC.

The single decision that determines cost is scope: which systems store, process or transmit Controlled Unclassified Information, and whether you can pull that boundary tight, often into an enclave, rather than dragging your whole estate into assessment. It is the same argument as PCI DSS scoping, and it is worth making properly before a single control is written.

Why you need it

01 / 06

Why readiness is the expensive part.

01

The scope decision costs more than the controls.

One hundred and ten requirements applied to an entire corporate estate is a different programme from the same requirements applied to a defined enclave holding CUI. Most of the saving available to you is made in the first month, on a whiteboard, before anybody buys anything.

02

A score you submitted is a representation you made.

Self-assessment scores are posted to the Supplier Performance Risk System and affirmed by a named senior official. In the United States those affirmations have been the basis of False Claims Act settlements. This is not paperwork; it is an assertion with consequences.

03

An SSP that does not match reality fails quickly.

The System Security Plan describes how each requirement is met in your environment. Assessors test the description against the system. A plan written from a template rather than from the estate is the most common reason an assessment goes badly.

04

The flow-down reaches your suppliers.

If you pass CUI to subcontractors, the requirement travels with it. Managing that flow-down, and knowing which of your suppliers can actually meet it, is part of readiness, not an afterthought once your own assessment is booked.

Instrument

02 / 06

Where 800-171 overlaps what you already run.

The one hundred and ten requirements against the frameworks you may already hold, so the overlap is funded once.

What we deliver

03 / 06

What we deliver.

01

CUI identification and scoping

What CUI you actually hold, where it flows, and which assets are in scope as CUI assets, security protection assets, contractor risk managed assets or specialised assets. Categorised the way an assessor will categorise them.

02

Enclave design

Where it makes sense, a bounded environment that holds CUI and keeps the rest of the estate out of assessment, with the segmentation, identity and data-flow controls that make the boundary defensible rather than asserted.

03

Gap assessment against all 110 requirements

Each requirement assessed with evidence, scored on the DoD methodology, and recorded honestly. Where something is not met, it is listed as not met rather than rounded up.

04

SSP and POA&M

A System Security Plan that describes your environment as it is, and a Plan of Action and Milestones that is a real schedule with owners and dates. These two documents carry the engagement.

05

Remediation

Hands-on closure of the gaps: access control and MFA, audit and accountability, configuration management, incident response, media protection, and the FIPS-validated cryptography requirement that catches people late.

06

Assessment preparation

Evidence organised against each requirement, a mock assessment run the way a C3PAO runs one, and the awkward questions asked while there is still time to fix the answers.

How we run it

04 / 06

The engagement, step by step.

  1. 01

    Contract and CUI review

    Read the contracts, find the clauses, and establish what CUI is actually in play and at which level you need to be.

    Weeks 1-2
  2. 02

    Scope and boundary

    Asset categorisation and, where it is the right answer, enclave design. Agreed before control work begins, because it changes the size of everything after it.

    Weeks 2-4
  3. 03

    Gap assessment

    All one hundred and ten requirements assessed against evidence, scored, and written into the SSP as it stands today.

    Weeks 4-8
  4. 04

    Remediate

    Work the POA&M with your teams. FIPS-validated cryptography, audit logging and identity usually set the critical path.

    Months 3-8
  5. 05

    Mock assessment

    Run the assessment internally the way a C3PAO would, against the evidence you have, and fix what it exposes.

    Month 9
  6. 06

    Hand over to the C3PAO

    Support you through the certification assessment performed by an authorised third party, then set the annual affirmation rhythm.

    Month 10, then annually

Key benefits

05 / 06

What changes afterwards.

You stay eligible to bid

As the rule phases into contracts, the certificate stops being a differentiator and becomes a gate, and readiness done early means an assessment slot booked on your schedule rather than against a deadline.

A smaller environment to hold to a hard standard

An enclave that contains CUI means one hundred and ten requirements apply to a defined boundary rather than to everything you own, which is cheaper to build and materially cheaper to keep.

Documents that describe the real system

An SSP written from the estate rather than from a template stays useful after the assessment, for onboarding, for incidents, and for the next assessment three years later.

Tools we use

06 / 06

Named, and used on your engagement.

No “latest tech tools”. These are the ones your report will cite, alongside the manual work that a tool cannot do for you.

Standards

  • NIST SP 800-171 Rev 2
  • NIST SP 800-171A assessment objectives
  • NIST SP 800-172
  • FAR 52.204-21

Assessment

  • DoD Assessment Methodology scoring
  • CMMC asset categorisation
  • Mock assessment against 800-171A

Technical validation

  • Nessus
  • BloodHound
  • AphelioNYX AD Pen-Test

Evidence

  • SSP and POA&M maintained as living documents
  • AphelioNYX Compliance Hub

Mapping

  • 800-171 to ISO 27001 and NIST CSF
  • AphelioNYX Frameworks Hub

Why Aphelion

Shared

Four things you can check.

01

The work is done by people with names.

Darshap Nayak, formerly of KPMG, holds a master’s degree in cybersecurity and more than seven years in security operations. Jaimin Somani brings fifteen-plus years of academic and hands-on VAPT. Hemang Desai is an ICT network specialist from Australia. You will meet them, not a logo.

Meet the team
02

Evidence, not adjectives.

Every finding arrives with the reproduction steps, the affected asset and the fix, ranked by what it actually reaches in your environment, not by a CVSS number copied from a scanner. You get the report and the raw output, not a summary of a summary.

See how we test
03

Two offices, one practice.

Ahmedabad and Sharjah, working the same methodology on the same tooling. Indian data-residency requirements and UAE delivery are both ordinary here, and the AphelioNYX AD Pen-Test module runs entirely inside your perimeter when regulation says it must.

The platform
04

What we will not do.

Invent a statistic to make a slide land. Publish your name as a client without written permission. Print an award badge nobody awarded. Founded in 2024. We say so, and we attribute experience to the people who have it.

Ask us anything

100+ organizations secured

Across the globe, and across eight industries. We name a client only with their written permission.

  • Finance & Banking
  • Healthcare
  • Retail & E-commerce
  • Technology
  • SaaS
  • Hospitality
  • Manufacturing
  • Pharmaceuticals

AphelioNYX is SOC 2, ISO and GDPR compliant; attestations are available on request under NDA. We would rather hand you the report than print a badge.

Questions

FAQ

Asked often enough to answer here.

Can Aphelion Cyber certify us for CMMC?
No, and it is worth being blunt about it. A CMMC Level 2 certification assessment can only be performed by a CMMC Third-Party Assessment Organisation authorised by the Cyber AB, and Level 3 is assessed by DCMA DIBCAC. We are neither. We prepare you for that assessment: scoping, gap assessment, SSP and POA&M, remediation and a mock assessment, and we support you through it. Preparation and certification are deliberately separated in the scheme, and a firm claiming to do both is not describing the programme accurately.
Which level do we need?
It is determined by the contract and by what information it involves. Level 1 applies where you handle Federal Contract Information only, covers fifteen requirements from FAR 52.204-21, and is self-assessed annually. Level 2 applies where Controlled Unclassified Information is involved, covers the one hundred and ten requirements of NIST SP 800-171, and is usually assessed by a C3PAO. Level 3 applies to a small number of programmes with the highest risk and adds selected SP 800-172 requirements. Read the clauses in the contract before assuming a level.
Can we rely on a POA&M to pass?
Only within narrow limits. Conditional status is available for some requirements, with a defined period to close the remaining items, but a number of requirements cannot be deferred at all and the overall score must meet a minimum threshold. Planning to pass on the strength of a POA&M is a strategy that tends to fail, and it is much more expensive than closing the gaps first, because the clock on closure runs whether or not your remediation budget arrived.
We are not a US company. Does CMMC affect us?
It can. The requirement follows the information, not the geography: if you are a subcontractor or supplier in a defence supply chain and CUI is flowed down to you, the obligation reaches you through the contract. Several of our clients meet CMMC requirements as second-tier or third-tier suppliers to primes. Data residency and personnel considerations do need care in that situation, and they are part of the scoping conversation rather than an afterthought.
How long does readiness take?
Nine to twelve months is realistic for an organisation starting without an SSP, and the range is wide because it depends almost entirely on the scope decision and on how much of NIST SP 800-171 you already meet through an existing programme. An organisation with ISO 27001 in place and a clean enclave design can move considerably faster. The parts that most often set the critical path are FIPS-validated cryptography, audit logging with the required retention, and identity and access management.

Forty-five minutes. Your environment, not a slide deck.

A personalised walkthrough and a free readiness assessment against the frameworks you are actually being asked for. Pick a time that suits you, or write to us. We reply within one business day.