# Athena Consulting Group — Full Content Index (CMMC Level 2 Assessment & Evidence Platform) > Athena (auditor-athena.com) turns live evidence into CMMC Level 2 / NIST SP 800-171 deliverables — System Security Plans (SSP), POA&Ms, SPRS submissions, Security Assessment Reports (SAR), and eMASS/OSCAL-ready packages — with cryptographic provenance a C3PAO assessor can audit. Built for U.S. defense contractors and subcontractors handling Controlled Unclassified Information (CUI) under DFARS 252.204-7012. Operated by Athena Consulting Group, LLC · 1443 Willtown St, Charleston, SC 29492-8557 · 843-224-9099 · doug.majewski@athenaconsultinggroup.com. The platform maps evidence to all 110 NIST SP 800-171 Rev. 2 requirements and the 320 assessment objectives in NIST SP 800-171A. SPRS point values should be verified against the current DoD Assessment Methodology. Athena supports readiness and evidence preparation and does not guarantee certification, which is determined by an authorized C3PAO. ## Platform & deliverables - [Pricing](https://auditor-athena.com/pricing): Plans for CMMC Level 2 readiness, evidence automation, and submission support. - [Automated SSP](https://auditor-athena.com/ssp-automation): Objective-mapped System Security Plan generated and maintained from live evidence. - [POA&M management](https://auditor-athena.com/poam-management): Draft, assign, and close Plan of Action & Milestones items. - [SPRS scoring & submission](https://auditor-athena.com/sprs-scoring): Calculate and defend an SPRS score under the DoD Assessment Methodology. - [eMASS-ready packages](https://auditor-athena.com/emass-submission): eMASS submission packages with auditable provenance. - [OSCAL for CMMC](https://auditor-athena.com/oscal-for-cmmc): Machine-readable OSCAL export of SSP and assessment data. - [Deliverables overview](https://auditor-athena.com/deliverables): SSP, POA&M, SPRS, SAR, and evidence artifacts. - [Free SPRS Quick Score](https://auditor-athena.com/quick-score): Estimate a CMMC Level 2 SPRS score quickly. - [CUI scope check](https://auditor-athena.com/scope-check): Check the CUI boundary and asset scope. - [Samples](https://auditor-athena.com/samples): Example outputs and deliverables. ## Assessment & readiness - [CMMC Level 2 readiness assessment](https://auditor-athena.com/cmmc-readiness-assessment): DIBCAC-style readiness review validating evidence the way a C3PAO will. - [DIBCAC-style mock assessment](https://auditor-athena.com/dibcac-mock-assessor): Objective-by-objective evidence review and gap findings. - [C3PAO assessment prep](https://auditor-athena.com/c3pao-assessment-prep): Assessor-grade evidence organization and mock review. - [Assessment pack](https://auditor-athena.com/assessment-pack): Complete CMMC Level 2 assessment pack. ## Control evidence library (NIST SP 800-171 Rev. 2 / 800-171A) - [Control evidence library (index)](https://auditor-athena.com/cmmc-controls) - [AC 3.1.1 — Access control: limit system access to authorized users](https://auditor-athena.com/cmmc-controls/ac-l2-3-1-1-access-control-evidence) - [AC 3.1.2 — Limit access to permitted transactions and functions (least privilege)](https://auditor-athena.com/cmmc-controls/ac-l2-3-1-2-least-privilege-evidence) - [AC 3.1.20 — Control connections to external systems](https://auditor-athena.com/cmmc-controls/ac-l2-3-1-20-external-connections-evidence) - [AU 3.3.1 — Create and retain audit logs](https://auditor-athena.com/cmmc-controls/au-l2-3-3-1-audit-logging-evidence) - [CM 3.4.1 — Establish and maintain baseline configurations](https://auditor-athena.com/cmmc-controls/cm-l2-3-4-1-baseline-configuration-evidence) - [CM 3.4.2 — Enforce security configuration settings](https://auditor-athena.com/cmmc-controls/cm-l2-3-4-2-config-enforcement-evidence) - [IA 3.5.1 — Identify system users and processes](https://auditor-athena.com/cmmc-controls/ia-l2-3-5-1-identification-evidence) - [IA 3.5.2 — Authenticate users and devices](https://auditor-athena.com/cmmc-controls/ia-l2-3-5-2-authentication-evidence) - [IA 3.5.3 — Multifactor authentication (MFA)](https://auditor-athena.com/cmmc-controls/ia-l2-3-5-3-mfa-evidence) - [IA 3.5.3 — MFA (GCC High variant)](https://auditor-athena.com/cmmc-controls/ia-l2-3-5-3-mfa-evidence-gcc-high) - [IR 3.6.1 — Incident handling capability](https://auditor-athena.com/cmmc-controls/ir-l2-3-6-1-incident-handling-evidence) - [IR 3.6.2 — Track and report incidents](https://auditor-athena.com/cmmc-controls/ir-l2-3-6-2-incident-reporting-evidence) - [MP 3.8.3 — Sanitize or destroy media containing CUI](https://auditor-athena.com/cmmc-controls/mp-l2-3-8-3-media-sanitization-evidence) - [RA 3.11.2 — Vulnerability scanning](https://auditor-athena.com/cmmc-controls/ra-l2-3-11-2-vulnerability-scanning-evidence) - [CA 3.12.1 — Periodically assess security controls](https://auditor-athena.com/cmmc-controls/ca-l2-3-12-1-security-assessment-evidence) - [CA 3.12.2 — Plan of Action & Milestones (POA&M)](https://auditor-athena.com/cmmc-controls/ca-l2-3-12-2-poam-evidence) - [CA 3.12.4 — System Security Plan (SSP)](https://auditor-athena.com/cmmc-controls/ca-l2-3-12-4-ssp-evidence) - [SC 3.13.1 — Boundary protection](https://auditor-athena.com/cmmc-controls/sc-l2-3-13-1-boundary-protection-evidence) - [SC 3.13.2 — Security architecture and engineering](https://auditor-athena.com/cmmc-controls/sc-l2-3-13-2-security-architecture-evidence) - [SC 3.13.5 — Separate publicly accessible subnetworks](https://auditor-athena.com/cmmc-controls/sc-l2-3-13-5-subnetwork-separation-evidence) - [SC 3.13.8 — Protect confidentiality of CUI in transmission](https://auditor-athena.com/cmmc-controls/sc-l2-3-13-8-transmission-encryption-evidence) - [SC 3.13.11 — FIPS-validated cryptography](https://auditor-athena.com/cmmc-controls/sc-l2-3-13-11-fips-encryption-evidence) - [SI 3.14.1 — Flaw remediation](https://auditor-athena.com/cmmc-controls/si-l2-3-14-1-flaw-remediation-evidence) - [SI 3.14.2 — Malicious code protection](https://auditor-athena.com/cmmc-controls/si-l2-3-14-2-malicious-code-evidence) - [SI 3.14.6 — Monitor systems and communications](https://auditor-athena.com/cmmc-controls/si-l2-3-14-6-monitoring-evidence) ## Guides & references - [CMMC Level 2 requirements (110 practices)](https://auditor-athena.com/cmmc-level-2-requirements) - [CMMC cost & timeline](https://auditor-athena.com/cmmc-cost-and-timeline) - [CMMC compliance roadmap](https://auditor-athena.com/cmmc-roadmap) - [CUI scoping guide](https://auditor-athena.com/cui-scoping-guide) - [CUI marking guide](https://auditor-athena.com/cui-marking-guide) - [CMMC evidence collection](https://auditor-athena.com/cmmc-evidence-collection) - [Shared responsibility matrix for CMMC](https://auditor-athena.com/shared-responsibility-matrix-cmmc) - [CMMC compliance workflow automation](https://auditor-athena.com/cmmc-compliance-workflow-automation) - [NIST SP 800-171 Rev. 3 overview](https://auditor-athena.com/nist-800-171-rev-3) - [CMMC Level 1 vs Level 2](https://auditor-athena.com/cmmc-level-1-vs-level-2) - [DFARS 7012 vs 7021](https://auditor-athena.com/dfars-7012-vs-7021) - [FedRAMP vs CMMC](https://auditor-athena.com/fedramp-vs-cmmc) - [CMMC vs ISO 27001](https://auditor-athena.com/resources/cmmc-vs-iso-27001) - [ISO 27001 to CMMC mapping](https://auditor-athena.com/iso-27001-to-cmmc-mapping) - [ITAR vs CUI](https://auditor-athena.com/itar-vs-cui) - [Joint venture CMMC](https://auditor-athena.com/joint-venture-cmmc) - [CMMC for MSPs](https://auditor-athena.com/cmmc-for-msps) - [CMMC for cloud-native startups](https://auditor-athena.com/cmmc-for-cloud-native-startups) ## Tools & calculators - [Revenue-at-risk calculator](https://auditor-athena.com/revenue-at-risk): Quantify DoD contract revenue blocked by CMMC delay. - [Prime bid defender](https://auditor-athena.com/prime-bid-defender): Draft NIST 800-171-cited responses to a prime's CMMC questionnaire. - [SPRS booster](https://auditor-athena.com/sprs-booster): Points-per-hour remediation plan to reach a target SPRS score. - [Affirming Official shield](https://auditor-athena.com/affirming-official-shield): Model personal False Claims Act exposure for the affirming official. - [Conditional certification lifeline](https://auditor-athena.com/conditional-cert-lifeline) - [Subcontractor flow-down auditor (DFARS 252.204-7012)](https://auditor-athena.com/subcontractor-flowdown-auditor) - [Cyber insurance premium reducer](https://auditor-athena.com/cyber-insurance-premium-reducer) ## Solutions - [Defense contractors](https://auditor-athena.com/solutions/defense-contractors) - [Small / subcontractor businesses](https://auditor-athena.com/solutions/small-business) - [Enterprise](https://auditor-athena.com/solutions/enterprise) - [Compliance digital twin](https://auditor-athena.com/solutions/digital-twin) - [Google Workspace for CMMC](https://auditor-athena.com/solutions/google-workspace-cmmc) - [Microsoft GCC High for CMMC](https://auditor-athena.com/solutions/microsoft-gcc-high-cmmc) - [Readiness assessment service](https://auditor-athena.com/services/cmmc-level-2-readiness-assessment) ## Comparisons (Athena vs.) - [Vanta](https://auditor-athena.com/vs/vanta) - [Drata](https://auditor-athena.com/vs/drata) - [Secureframe](https://auditor-athena.com/vs/secureframe) - [Strike Graph](https://auditor-athena.com/vs/strike-graph) - [Paramify](https://auditor-athena.com/vs/paramify) - [Risk Cognizance](https://auditor-athena.com/vs/risk-cognizance) - [Kiteworks](https://auditor-athena.com/vs/kiteworks) ## Blog - [How to calculate your SPRS score](https://auditor-athena.com/blog/how-to-calculate-sprs-score) - [Configure Google Workspace for CMMC](https://auditor-athena.com/blog/configure-google-workspace-for-cmmc) - [Common CMMC audit failures and findings](https://auditor-athena.com/blog/cmmc-audit-failures-common-findings) ## Company & partners - [About Athena](https://auditor-athena.com/about) - [Partners](https://auditor-athena.com/partners) · [Service](https://auditor-athena.com/partners/service) · [Audit](https://auditor-athena.com/partners/audit) · [Reseller](https://auditor-athena.com/partners/reseller) · [Technology](https://auditor-athena.com/partners/technology) - [Trust](https://auditor-athena.com/trust) - [Sitemap](https://auditor-athena.com/sitemap.xml)