Use code LIVING102 for a free 30-minute consultation
What every engagement delivers · no procurement back-channels

Deliverables built to survive audit day.

Every tier ships the Grade-1 cryptographic vault, hash-chained audit log, and continuous monitoring. The tier sets how much we drive.

Every tier is self-serve.Pricing is confirmed at signup.
Practitioner workspace where Key 102 engagements are delivered
Other engagement modes

Fractional vCISO, strategic advisory, and federal subcontracting are custom-scoped, not priced here. Start with a discovery call to confirm fit and scope.

CMMC · Cybersecurity Maturity Model Certification 2.0

Fortress

CMMC 2.0 Level 2 (Advanced) on NIST SP 800-171 Rev. 2.

Fortress details →
FortressGuided

CMMC 2.0 Level 2 starting block — NIST 800-171 Rev. 2 task library (110 controls, 14 families), SPRS calculator + submission, SSP template, POA&M tracker. Foundation tier — upgrade path delivers full practitioner-signed deliverables.

What you get
  • NIST 800-171 Rev. 2 task library (110 controls, 14 families)
  • SPRS score calculator and submission guidance
  • System Security Plan (SSP) template and drafting support
  • Plan of Action and Milestones (POA&M) tracker
  • Quarterly readiness reports
Start Fortress Guided
Most popular
FortressManaged

Full CMMC L2 SSP management with practitioner sign-off. C3PAO pre-audit readiness assessment, POA&M management, C3PAO-handoff-ready bundle. Your practitioner owns the SSP — not a template.

What you get
  • Everything in Fortress Guided
  • Full System Security Plan management (drafting, review, updates)
  • C3PAO pre-audit readiness assessment
  • Practitioner review and sign-off
  • C3PAO-handoff-ready bundle
Start Fortress Managed
FortressAudit Co-Pilot

DoD-assessor-grade CMMC deliverables. Practitioner sign-off, RFC 3161 TSA anchor on every SSP / POA&M / SPRS revision, public C3PAO verification page on every assessor-facing PDF. The assessor verifies you without asking us anything.

What you get
  • Everything in Fortress Managed
  • Recipient-verifiable SSP, POA&M, and Master Audit Report
  • SHA-256 + Report ID on every PDF; public verify endpoint
  • RFC 3161 TSA anchor on every report — DoD assessor-grade proof
  • Practitioner Sign & Seal embedded in tier
  • C3PAO-direct verification page on every assessor-facing PDF
Start Fortress Audit Co-Pilot
Where to start

Start with a discovery call

A scoping conversation with a practitioner. We map what is in scope, walk through where your current evidence stands against the framework, and tell you what the engagement would involve — before any commitment.

Book a discovery call →
Engagement levels

Four levels of practitioner involvement.

Self-Service
You drive. You review.

Portal, full task library, evidence vault, audit log. Your team runs the framework; practitioner support on call via the Global Review Queue.

Guided
You drive. We review.

2 Consultant Review hours/month, Tammie AI advisor tuned to your framework, quarterly readiness reports with practitioner sign-off. You execute; we validate.

Managed
We drive. You review.

Concierge engagement: monthly assessments, direct regulator liaison, priority queue (24-hour SLA). We operate the framework; you attest.

Audit Co-Pilot
We drive. The auditor verifies.

Managed delivery plus recipient-verifiable PDFs. Every Master Audit Report, AoC, and SSP carries a SHA-256 + Report ID resolvable at Key 102's public verify endpoint — no link, email, or trust in our database required. See it live at portal.key102consulting.com/verify/sprs/SPRS-L1-2026-512PCZ.