CMMC Level 2 documentation for machine shops in Ventura and north LA County

The audit paused. The obligation didn’t.

We write the paperwork behind your Cybersecurity Maturity Model Certification (CMMC) Level 2 self-assessment: your System Security Plan and the documents that go with it.

We work with machine shops and precision manufacturers in Ventura County and north Los Angeles County, and we come to your shop.

Third-party CMMC certification is paused. The self-assessment you sign still applies. See what’s still required below.

Is this for your shop?

It’s for you if:

  • You make parts for defense primes, or for companies that supply them.
  • A prime has sent you a supplier questionnaire, a contract clause to follow, or a question about your Supplier Performance Risk System (SPRS) score.
  • Nobody at your shop does compliance full time.
  • You want the paperwork written for you, not a course on the rules.

It’s probably not for you if:

  • You need computers or networks set up. That’s your IT provider’s work.
  • You need an audit or a certification. We don’t do either.
  • You need a legal opinion on a contract.
  • You only handle Federal Contract Information (FCI), not CUI. Our work is built around Level 2.

Not sure? Finding out is what the first call is for.

What’s still required right now

What paused

  • Level 2 certification by third-party assessors (C3PAOs)
  • Level 3 certification by the government’s own assessors (DIBCAC)

Paused July 13, 2026, while the program is reviewed.

What still applies

  • Level 1 and Level 2 self-assessments, with a yearly affirmation (since November 10, 2025)
  • Safeguarding and 72-hour incident reporting (DFARS 252.204-7012)
  • NIST SP 800-171 Revision 2 as the standard
  • Requirements your prime flows down to you
  • Federal enforcement

What could change this

When the rules change, we update this section and the date above.

Why the paperwork matters

Here is what stands behind the score you post.

What counts and what doesn’t

Without a System Security Plan, the DoD Assessment Methodology says an assessment can’t be completed. And a plan of action earns no points: a requirement that isn’t in place is scored as not in place, whether or not there’s a plan to fix it.

What the government has enforced

Recent federal settlements with defense contractors and a university turned on inaccurate cybersecurity statements, not on breaches. Getting hacked wasn’t the trigger. Saying something inaccurate was.

What we do

We offer two engagements. Both are paperwork. We write the documents; your IT provider does the technical work.

You

Decide and sign

  • Decide whether to go further after the scope map
  • Sign your self-assessment
  • Post your own score in SPRS, on your own computer
Documents, and a walkthrough of the binder

Nexxus

Write the documents

  • Scope map
  • System Security Plan
  • Plan of action
  • Policies and the evidence binder

A second person checks each one before you get it.

The plan of action: their list of what’s left to do

Your IT provider

Do the technical work

  • Install, set up, and run your systems
  • Work through the plan of action’s list

We don’t install, set up, or run your systems, and we don’t log in to SPRS or PIEE for you.

Start here

Scope map

We visit your shop and map where controlled information comes in, where it goes, and where it’s kept.

What you get

A written scoping document you keep. It names the people, computers, and places inside your boundary, and the places where scope quietly grows:

  • a programmer’s personal laptop
  • email that forwards automatically
  • the estimator quoting off the same drawings
  • first article inspection reports (FAIRs) and coordinate measuring machine (CMM) reports going back to the prime
  • a second building
  • outside processors, like plating or heat treat, that receive your drawings
Price
$2,000 to $3,500. A fixed fee, agreed before we start. No hourly billing.
Time
The site visit takes two to four hours. We give you a date for the written document when we schedule.

Then, if it makes sense

Full write-up

The documents your self-assessment rests on, written from what we found at your shop.

What you get

  • Your System Security Plan (SSP), written by us
  • A score worksheet
  • A plan of action and milestones (POA&M) for the gaps that remain
  • Supporting policies
  • An evidence binder, organized so you can find things when asked
Price
$7,500 to $15,000. A fixed quote after the scope map, based on what we found. No hourly billing.
Time
We agree on a schedule with you before we start.

What moves the price

The scope map sets the boundary. After it, you get a fixed quote for the full write-up based on what we found.

It goes up with

  • how many computers and systems touch controlled information: CAM stations, file servers, cloud accounts
  • how many people handle drawings
  • how many buildings or locations are involved
  • how many ways drawings come in and go out, including outside processors
  • older equipment that has to be documented as an exception
  • how many outside services hold your files: your IT provider, cloud email, your ERP

It comes down with

  • documentation you already have to build on
  • defense work kept on separate computers

It doesn’t depend on

  • your revenue
  • your score
  • people who never handle drawings

We’re paid for the documents. Our fee never depends on your score or any result.

What we don’t do

These limits are on purpose.

  • We don’t audit you.
  • We don’t certify you. We’re not a C3PAO.
  • We don’t install, set up, or run your systems.
  • We don’t give legal opinions.
  • We don’t log in to SPRS or the Procurement Integrated Enterprise Environment (PIEE) for you. You post your own score, on your own computer.
  • We don’t predict or promise a score, a result, or a certification.

How your information is handled

  • We never take custody of controlled unclassified information (CUI). Not by email, not on a drive, not even to look at.
  • If your work falls under ITAR, tell us on the first call.
  • We look at where information goes, not at the information itself. We walk your office and floor with a checklist and ask who receives drawings, where files are saved, and what gets emailed. We don’t open, copy, or take drawings or files.
  • Your IT provider keeps the technical work: installing, setting up, and running your systems.
Where controlled information goes in an example shop Drawings come in from the prime by email to the office, are saved on the file server, go to the CAM programming PC, then to the machines on the floor and the quality room. First article and CMM reports go back to the prime. Six places where scope quietly grows are marked: email that forwards automatically, the estimator quoting off the same drawings, a programmer's personal laptop, the reports going back to the prime, a second building, and outside processors such as plating or heat treat that receive your drawings. Nexxus sits outside the shop: we look at where information goes, not at the information itself. YOUR SHOP the boundary the scope map draws Your prime sends the drawings Office email, quotes File server where files are saved CAM PC programs the machines Shop floor the machines Quality room CMM, first articles drawings come in by email saved programs parts 4 FAIR and CMM reports go back to the prime Forwarded email forwards automatically 2 Estimator quotes off the drawings 3 Personal laptop the programmer's own 1 Second building if you have one 5 Outside processors plating, heat treat 6 Nexxus We look at where information goes, not at the information itself. Where controlled information goes in an example shop Same diagram, arranged top to bottom for small screens. Your prime sends the drawings YOUR SHOP the boundary the scope map draws Office email, quotes File server where files are saved CAM PC programs the machines Shop floor the machines Quality room CMM, first articles Your prime gets reports back drawings come in by email 4 FAIR and CMM reports Estimator quotes off drawings 3 Forwarded email forwards automatically 2 Personal laptop the programmer's own 1 Second building if you have one 5 Processors plating, heat treat 6 Nexxus We look at where information goes, not at the information itself.
An example shop. Every shop is different; the site visit maps yours. Orange marks the places where scope quietly grows:
  1. a programmer’s personal laptop
  2. email that forwards automatically
  3. the estimator quoting off the same drawings
  4. first article inspection reports (FAIRs) and coordinate measuring machine (CMM) reports going back to the prime
  5. a second building
  6. outside processors, like plating or heat treat, that receive your drawings

Please don’t send us drawings, contracts, or controlled information, by email or through this site. We don’t need them.

How it works

Six steps, in order. You can stop after step 3.

  1. Step 1

    You call or email Josh. He asks a few quick questions, then books a free 15-minute call with Juan to see if we’re a fit. If we’re not, we’ll say so.

  2. Step 2

    Scope map: we visit your shop. We start at the desk, then walk the floor with a checklist.

  3. Step 3

    You get the written scoping document. You decide whether to go further.

  4. Step 4

    Full write-up: we write your documents. A second person checks each one before you get it.

  5. Step 5

    We walk you through the binder.

  6. Step 6

    You post your own score in SPRS, on your own computer.

Who we are

Nexxus Advisory is run by two people in Ventura County, California.

Juan Morales

Founder and Technical Director

Leads the technical work. Every technical question comes to him, including whether a rule applies to your shop. This isn’t the first business Juan has started.

Joshua Recta

Head of Client Development

Runs outreach and follow-up. If we called you, it was probably Josh. Josh studied engineering.

Common questions

Is CMMC cancelled?
Can you promise us a score or a certification?

No. We don’t predict results, and we don’t certify anyone. Our fee never depends on your score.

I already posted a score. Is that a problem?

Not necessarily. If you’re not sure your posted score matches your documents, it’s worth checking. We’ll show you the posted score next to what your documents support. If they don’t match, we’ll suggest you talk with your attorney.

My machines are old. Does that sink me?

No. Equipment that can’t meet a requirement, like an older machine controller, can be documented as an enduring exception: isolated, and described in your System Security Plan with its mitigations. Age alone isn’t a barrier.

We only handle FCI, not CUI. Do we need you?

Probably not. Our work is built around Level 2. One thing worth knowing either way: at Level 1, a plan of action isn’t allowed at any time. All 15 requirements need to be met before the yearly affirmation is signed.

Will you see our drawings?

No. We look at where information goes, not at the information itself. We don’t open, copy, or take drawings or files.

What does our IT provider still do?

All the technical work: installing, setting up, and running your systems. The plan of action we write gives them a list of what’s left to do.

What does it cost, and how long does it take?

The 15-minute call with Juan is free. The scope map is $2,000 to $3,500, and the full write-up is $7,500 to $15,000. Both are fixed fees; here’s what moves the price. The site visit takes two to four hours, and we agree on a schedule for the rest before we start.

Terms on this page

The terms you’ll see in CMMC paperwork, in plain words.

CMMC Cybersecurity Maturity Model Certification
The Defense Department program that checks whether contractors and subcontractors have put required cybersecurity requirements in place. 32 CFR 170.1
CUI Controlled Unclassified Information
Information the government creates or has, or that someone creates or has for the government, that must be handled with safeguarding or sharing controls. It isn’t classified. 32 CFR 2002.4(h)
FCI Federal Contract Information
Information made for or given by the government under a contract, not meant for the public. It doesn’t include public information or simple payment details. 48 CFR 4.1901
SPRS Supplier Performance Risk System
The Defense Department’s system for supplier performance information, where your summary self-assessment score is posted. SPRS
SSP System Security Plan
The formal document that gives an overview of the security requirements for your information system. 32 CFR 170.4
POA&M Plan of Action and Milestones
A document listing the tasks still to do, what they need, the milestones, and planned completion dates. 32 CFR 170.4
DFARS Defense Federal Acquisition Regulation Supplement
The Defense Department’s additions to the federal buying rules. Its clauses, like 252.204-7012, go into defense contracts. acquisition.gov
NIST National Institute of Standards and Technology
The federal agency that publishes SP 800-171, the standard your score is measured against. nist.gov
C3PAO CMMC Third-Party Assessment Organization
A firm authorized or accredited to conduct Level 2 certification assessments. 32 CFR 170.4
DIBCAC Defense Industrial Base Cybersecurity Assessment Center
The government’s own assessment team, part of the Defense Contract Management Agency. 32 CFR 170.4
PIEE Procurement Integrated Enterprise Environment
The Defense Department portal you log in through to reach SPRS. SPRS

Talk to us

Call or email Josh. He’ll book a free 15-minute call with Juan, who answers the technical questions.

We don’t record calls.

Please don’t send drawings, contracts, or controlled information by email or through this site.

Call (805) 253-2061