
CMMC Compliance Services
Achieve CMMC compliance to protect sensitive information and enhance your cyber security posture
LRQA experts are accredited by the Cyber-AB and CAICO as CMMC Certified Assessors, Professionals and Registered Practitioners
Developed by the U.S. Department of Defense (DoD), the Cybersecurity Maturity Model Certification (CMMC) is a comprehensive cyber risk management model that measures an organization’s capabilities against three cybersecurity maturity levels. CMMC compliance is required for companies that are part of the DoD supply chain and handle Controlled Unclassified Information (CUI).
Our CMMC Certified Assessors (CCAs), Professionals (CCPs) and Registered Practitioners (RPs) deliver world-class advisory services designed to support your compliance with CMMC standards.
Our approach to CMMC Services
Leverage GRC Software
LRQA's CMMC specialists will implement your customized GRC tool and provide management or training for your staff to develop supporting documentation.
Establish a Custom Solution
LRQA will develop a unique solution based on your existing GRC state, leveraging our cybersecurity expertise to ensure CMMC compliance.
Plan of Action and Milestones (POA&M)
LRQA follows the CMMC Scoping Guide, ensuring accurate Supplier Performance Risk System (SPRS) scoring and ongoing POA&M refinement through a structured approach.
Our approach to CMMC compliance
LRQA sees Governance, Risk & Compliance (GRC) as a vital business asset and is committed to making it a strategic advantage for your organization. Our CCAs and CCPs, accredited by the Cyber-AB, provide expert analysis and advisory services for Organizations Seeking Assessment (OSAs). By understanding your priorities, we guide you through each phase of the CMMC journey, delivering proactive advice and world-class support to help you achieve compliance.
Gap Analysis
Phase I -Initial Documentation Review
LRQA will review the following critical information:
- CUI Flow Diagram (if available)
- Network Diagram(s)
- System Security Plan (SSP)
- Asset Inventory: Hardware, Firmware, Software, Devices and Users
- Existing Policies and Procedures, Plans, and Standard Operating Procedures (SOP’s)
This documentation will be uploaded into a FedRAMP Equivalent GRC software tool for long-term collection of evidentiary data and ongoing cybersecurity maturity.
Phase II - Executive Leadership Meeting
CMMC Compliance is not an “IT issue.” CMMC is an enterprise issue because of where and how CUI flows through an organization. The security controls and evidence are not static, but rather a collection of living documents. As a result, it requires implementing significant governance, risk, and compliance (GRC) changes to how you run your business – it is NOT just the IT department's responsibility. 
Consequently, Senior and/or Executive Management must be involved in the kickoff meeting, since they will be ‘accountable’ in the CMMC Customer Responsibility Matrix (SRM) and ultimately accountable for the CMMC certification. Additionally, any staff that could possibly touch CUI needs to be involved since they will be considered the ‘data owner’ in the CRM. LRQA will cover the following in this meeting:
- Acronyms & Terms
- CMMC Assessment Process (CAP)
- Critical Items: CUI Flow Diagrams, Asset Classifications, SSP, POAM, etc.
- Gap Analysis Methodology
- Roles and Responsibilities
- Roadmap for future meetings
Phase III – CUI Scoping Workshops
The majority of IT systems don't specifically segregate data and tracking the flow of CUI within an organization can be a serious compliance headache. So, the first critical step in analyzing a company’s cybersecurity posture is determining how CUI flows within your organization. LRQA’s expert CCA’s and CCP’s follow the official CMMC Scoping Guide to visually map the flow of CUI within your company. These workshops will accomplish the following goals to create a diagram that will become part of your SSP for CMMC Certification:
- Identify & Document organizational workflows where CUI is processed, stored & transmitted
- Define how CUI is managed internally and externally
- Identify users, devices, facilities, automated processes and functions, etc. that interact with CUI – these will be “in-scope” for CMMC
- Designate a preliminary CMMC Assessment Boundary
Phase IV – CMMC Objective Evaluation
Our CCAs and CCPS follow the DoD’s CMMC Assessment Process (CAP 2.0) methodology to determine your compliance by evaluating your current security controls against the 14 Domains, 110 Practices, and 320 Objectives of CMMC. These security controls will be verified through the collaboration of your organization's staff throughout the process. The following artifacts will be compiled in the GRC software:
- Documentation of client responses in workshops
- Evidence to validate security controls for 320 objectives, if available
- Control evidence that is not available will be noted, the applicable objective will be marked as not implemented, and that control objective will be added to the POAM
Phase V – Reports and Findings
LRQA will develop and present a Final Report with the following deliverables:
- CUI Flow Diagram(s) 
- CUI Asset Inventory & Classifications
- System Security Plan (SSP)
- CMMC Assessment & Certification Boundaries
- Supplier Performance Risk System (SPRS) Score
- Plan of Action & Milestones (POAM)
- Recommend priorities & a schedule for POAM completion
Strategy and Remediation
We support project management of the remediation program, consult on the most effective corrective measures to meet requirements and report on the progress to senior management and executive stakeholders. As a world leading cybersecurity business, we also have the experts capable of fulfilling any roles where you may need support.
Advisory Services and Continuous Assurance
LRQA has flexible options for CMMC Advisory Services based on your organization’s needs. Some clients have knowledgeable IT and compliance personnel or work with an experienced NIST 800-171 compliant MSP, while other organizations have limited personnel resources and need more help. Either way, we provide the right amount of support you need.
- In conjunction with IT staff and any External Service Providers (ESPs), facilitate workshops to develop the Customer Responsibility Matrix (CRM) 
- Assist the organization with compiling evidence for POAM items
- Develop and implement CMMC/CUI training for staff 
- Mark & Label all CUI Assets that are in scope, as required for certification (documents, facilities, hardware, etc.)  
There are numerous CMMC compliance evidence documents that must be generated weekly, monthly, quarterly, semi-annually and annually to prove that an organization is following their policies, processes and procedures to maintain their cybersecurity posture and CMMC certification. LRQA can assist you in setting up a schedule for compiling evidence (artifacts) at regular intervals as required, proving on-going compliance and cyber maturity. 
Whatever your level of engagement, LRQA’s expert staff can provide you with the support necessary to be successful in your pursuit of full CMMC Compliance.
Why work with us?
Specialist expertise
Our cyber security experts hold multiple vendor certifications and accreditations as well as highly respected industry accreditations from CREST, the PCI SSC, ISC2, BCI, Chartered Institute of IT, and NCSC CHECK.

Industry leadership
We lead and shape industry on advisory boards and councils including the PCI SSC Global Executive Assessor Roundtable and CREST councils in the Americas, Asia, EMEA and the UK. We are certified by a range of governing bodies including the payment card industry and are approved as a Qualified Security Assessor.

Everywhere you are
Operating in over 55 countries, with more than 250 dedicated cyber security specialists and over 300 highly qualified information security auditors across the world, we can provide a local service with a globally consistent dedication to excellence.

Award winners
We have been recognized for the breadth and depth of our services – including the TEISS Award for Best Penetration Testing Service in 2024, Enterprise Threat Detection and Cloud Security awards at the Security Excellence Awards 2024 and the Stratus Award for Best Managed Cloud Security Service.

FAQs
What is CMMC?
CMMC is a comprehensive cybersecurity management model comprised of 14 domains that measure an organization’s capabilities against 3 cybersecurity maturity levels. It was developed by the U.S. Department of Defense to establish cybersecurity standards for suppliers who handle Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). CMMC builds upon NIST 800-171 and offers a higher level of assurance as it requires organizations to undergo an assessment conducted by Certified Third-Party Assessment Organizations (C3PAOs).
What level of maturity does my organization need to achieve?
The type of data that a supplier will handle in their work for the DoD will determine the maturity level that the supplier must certify against. For instance, projects involving only FCI will just require Level 1 certification, while projects involving CUI will require Level 2or 3 certification.
The CMMC Accreditation Body (Cyber AB) is implementing the CMMC program in phases with the current focus on certifying select suppliers against Levels 1 & 2. The number of organizations requiring CMMC certification will increase until 2028 when all suppliers handling FCI and CUI must have the appropriate level of certification.
Who carries out a CMMC assessment?
CMMC assessments are carried out by Certified Third-Party Assessment Organizations (C3PAOs). C3PAOs will conduct the certification assessments and recommend either certifying the organization or denying certification to the Cyber AB which is responsible for conferring certification.
CMMC Registered Provider Organizations (RPOs), while not conducting official assessments, are accredited by the Cyber AB to conduct CMMC pre-assessments that fully align with an official CMMC assessment. LRQA is an RPO, and as such we offer a range of services from gap analyses to pre-assessments and full-scope CMMC implementation support. We can also help manage your assessment with C3PAOs.
The world leader in CREST accreditations
We are proud to be the only organization in the world with a full suite of accreditations from The Council of Registered Ethical Security Testers (CREST).
Our team of consultants have achieved the highest accreditations for Penetration Testing, Red Teaming, Incident Response services and Threat Intelligence. In addition, we were also the first organization to be CREST accredited for our Security Operation Centre services.