NIST 800-171 · CMMC Level 2
Audit-ready compliance documentation for small defense contractors. Fixed price. Human-reviewed. Delivered in Word, ready for your assessor.
At a glance
The problem
Primes are already writing CMMC requirements into subcontracts. Assessments take months to schedule, and an incomplete SSP is a first-week finding.
Traditional cyber consultancies quote $15,000 to $50,000 or more for a single SSP and POA&M engagement. Big 4 firms don't quote small contractors at all.
Free DoD templates exist. They don't explain how to implement 110 controls against your actual stack. A draft that misses an assessor's objectives costs time you don't have.
The product
Pricing
Why us
Brassrook exists because its founder is taking his own organization through a CMMC Level 2 assessment. Every control, every implementation statement, every POA&M entry we produce is one we'd defend in front of our own C3PAO.
That's the honest moat: we are not a consultancy selling compliance theater. We are a shop that ships the documentation we ourselves rely on, at a price small defense contractors can actually pay.
Brassrook does not perform C3PAO assessments or represent clients to the assessor. We draft and revise the SSP and POA&M documentation that your assessment will rely on.
Request an intake link
Enter your email. We'll send you a secure, resume-any-time intake form. No account to create, no password to manage.
By requesting an intake link, you agree we'll email you the link and follow up about your engagement. No other marketing, no list sharing.