Globe-America Consulting
The C3 Kit
Your interactive compliance readiness toolkit for defense contractors. Complete all three modules to receive a personalized assessment, project timeline, estimated investment, and recommended service package.
CMMC Scorecard
Self-assess your readiness across key CMMC domains and identify critical gaps.
SPRS Estimator
Estimate your NIST 800-171 score — the number DoD contracting officers actually see.
Timeline & Cost
Get a realistic project timeline and compliance investment estimate based on your gap level.
Who This Is For
Defense ContractorsDoD SubcontractorsCUI HandlersCMMC AspirantsGovCon New EntrantsFederal Contract Holders
Module 1 of 3
CMMC Readiness Scorecard
Answer each question based on your organization's current state. Be candid — this is a diagnostic, not a test.
Access Control
Does your organization limit system access to authorized users and control what those users are permitted to do?
Identification & Authentication
Are unique user IDs and multi-factor authentication (MFA) enforced for systems that process federal contract information?
Configuration Management
Does your organization maintain secure baseline configurations and have a formal process to control changes?
Incident Response
Does your organization have a documented incident response plan and capability to detect, report, and respond to cybersecurity incidents?
System & Communications Protection
Is data encrypted in transit and at rest? Are network boundaries monitored and controlled?
Risk Assessment
Does your organization periodically assess risk and document findings in a risk register or POA&M?
CUI Handling & Media Protection
Is Controlled Unclassified Information (CUI) identified, labeled, and protected from unauthorized access or disclosure?
Awareness & Training
Are employees trained on cybersecurity responsibilities, including recognizing threats and handling sensitive information?
Module 2 of 3
SPRS Score Estimator
The Supplier Performance Risk System (SPRS) score reflects your NIST SP 800-171 self-assessment posture. Scores range from −203 to +110.
User permissions, least privilege, remote access (22 practices)
Logging, monitoring, audit trail (9 practices)
Secure baselines and change control (9 practices)
User IDs, passwords, MFA (11 practices)
Detection, reporting, response (3 practices)
Risk assessments and POA&M (3 practices)
Encryption, monitoring, boundary (16 practices)
Malware, patching, alerts (7 practices)
Module 3 of 3
Timeline, Investment & Your Package
Based on your scorecard responses, here is an estimated project timeline, compliance investment range, and the Globe-America service package best suited for your organization.
📅 Readiness Assessment Project Timeline
Estimated weeks to reach assessment-ready status based on your current gap level.
Estimated Total Timeline
--
💰 Compliance Investment Estimator
Estimated investment range for pre-assessment and self-assessment readiness work. Final scope is confirmed in a written proposal.
Estimated Investment Range
--
Recommended Service Package
Based on your gap level, one package below has been highlighted as the best fit. All packages include a written proposal with confirmed scope before any engagement begins.
* Indicative ranges assume 25–200 endpoints, 1–3 sites, and a standard Microsoft 365 environment. Clients purchase security tools directly.
Ask Us About Managed Security Support
Managed EDR, SIEM, and 24x7 SOC/MDR services are available as optional add-ons through vetted third-party providers under Globe-America governance. View add-on pricing →
Your Personalized Assessment
C3 Results Report
Your complete compliance snapshot — score, SPRS posture, recommended next steps, and your direct path forward with Globe-America.
Ready to Close Your Gaps?
Globe-America Consulting provides practical, affordable CMMC readiness support tailored for defense contractors. Schedule your free discovery call and lock in your $2,500 discount before it expires.
Schedule a Free Discovery Call