Meridian Compass
CMMC procurement intelligence for the defense industrial base

Know what CMMC help you need before the quotes arrive.

Buyer-side decision tools for defense contractors about to spend $10k–$100k on MSPs, RPOs, C3PAOs, vCISOs, GCC High migration, compliance software, or templates. Estimate your CMMC path and cost. Decode a quote or RFP clause before you sign. Find out which provider type fits your situation. Source-backed, no referral fees.

No CUI uploads, contracts, or system diagrams required. Meridian Compass is not a C3PAO, RPO, or MSP and does not certify, audit, or guarantee compliance. Buyer-side pre-purchase decision support only.

Posture
Independent buyer-side
Method
Transparent rules, no model
Listings
No paid placement
Free tools

Pick the tool that matches where you are.

Most paid CMMC mistakes trace back to a buyer answering the wrong question first. Each free tool is built around one specific decision pressure. Start with the one that matches yours.

Estimate
Cost & Path Calculator
The moment

Estimate your CMMC path, cost, timeline, and provider type before hiring a consultant.

Ten short questions. Likely CMMC level, rough first-year cost band, provider categories to scope first, the quote-risk flags your inputs raise, and the next questions to ask.

Start the free calculator
Decode quote
Quote Decoder
The moment

Got a CMMC quote? Check it before you sign.

Paste sanitized line items. The decoder returns inferred provider role, missing deliverables, conflict-of-interest watchouts, over/underbuild read, seven quote-risk flags, and the vendor questions to put back.

Decode a quote · free preview
Decode RFP
RFP / Contract Clause Decoder
The moment

Paste the CMMC language from your RFP or prime. Understand what it likely means.

Plain-English read of CMMC / DFARS / NIST 800-171 / CUI / SPRS clauses. Likely implications, ambiguities to clarify, questions for the prime or contracting officer, and the provider type you probably need.

Decode an RFP clause · free
Match
Provider Type Matcher
The moment

Find out whether you need a C3PAO, RPO, MSP, software, templates, GCC High, or scoping help.

Eight short questions. Which categories you need now, which to defer, where the conflict-of-interest lines run between roles, and the source-backed directory entry points.

Match my provider type · free
What the packet answers

Six questions every CMMC procurement runs into.

CMMC buyers don’t need another explainer. They need a defensible next decision before signing a five- or six-figure engagement letter.

  • Quote fear

    Is this $35k / $75k / $150k engagement quote sane, or is the vendor padding scope?

  • Wrong-path fear

    Are we Level 1 self-attest, Level 2 self, or Level 2 C3PAO? And who decides?

  • Scope fear

    Is our CUI footprint really that big, or are we accidentally pulling the whole company into scope?

  • Vendor fear

    Is this MSP, RPO, or platform selling us what we need, or what they want to sell?

  • Document fear

    Do we have a defensible SSP, POA&M, and SPRS score before someone asks?

  • Prime / contract fear

    Can we answer a prime's flowdown questionnaire without looking unserious?

What’s in the packet

The seven decisions the packet resolves.

Plain-English readout you can share with a CFO, owner, or contracts lead. No model output. Every claim explained by the inputs you gave and the public rule set we cite.

01
Likely CMMC level, with reasoning

Level 1 self-attestation, Level 2 self-assessment, or Level 2 C3PAO assessment, with the contract and CUI evidence that pushes you toward each.

02
CUI scope and where to shrink it

Where CUI probably lives in your environment today, what would happen if you enclaved it, and the boundary questions that decide cost.

03
Provider category fit

Which of C3PAO, RPO, MSP/MSSP, vCISO, compliance software, documentation templates, or independent scoping help you need now, and which to defer.

04
GCC High vs enclave vs shared-tenant

The single most expensive line item in a typical Level 2 engagement. Also the most over-prescribed. The pack walks you through the decision.

05
SPRS · SSP · POA&M readiness map

What you should have on file before a prime or assessor asks, plus which artifacts are missing, stale, or written in a way that will not hold up.

06
First-year cost band and 30-day plan

A realistic range driven by your inputs and public benchmarks, with a 30-day action sequence that names what to do this week and what not to buy yet.

07
Quote-risk read on the pitches you already have

Seven patterns we check in every CMMC quote: scope creep, vague deliverables, retainer lock-in, software bundles, junior staffing, and two more.

Plus
Optional quote sanity check

Paste sanitized line items from a vendor quote (never CUI or contracts), and the pack flags scope risk, missing deliverables, and benchmark drift.

See the full packet
Pricing

Less than the cheapest line item on a CMMC engagement.

A typical CMMC Level 2 engagement runs $20k to $150k. The Decision Pack is $249. The decoder exports are $99 each. The math works even if you only run one before signing.

Independence policy

Meridian Compass charges buyers, not providers. No referral fees, no affiliate links, no sponsored placements in the directory. The same listing rules apply to every firm.

Per-decoder export
$99
Quote Decoder export · RFP Decoder export
The moment

You ran the free Quote Decoder or RFP Decoder and want the readout as a PDF you can attach to your response, with the full vendor-question script.

PDF artifact, vendor-question or prime-question script, negotiation worksheet. Credits toward the $249 Decision Pack within 90 days.

See decoder exports
Full Decision Pack
$249
CMMC Decision Pack
The moment

You want the full picture: path, cost band, provider category fit, source-backed shortlist, quote-risk flags, and a 30-day plan in one packet.

Generated from any of the four entry points. Likely CMMC path, cost band, CUI scope reduction, provider type recommendation, matched shortlist categories, quote/RFP red flags, 30/60/90-day buying roadmap, source URLs.

Get the Decision Pack
Start free

The free Cost & Fit Check takes about four minutes.

You stay anonymous until you choose to share an email at the end. The readout is computed from your inputs and a transparent rule set. No black-box model, no CUI uploads.

What we do not ask for
  • CUI or contract documents
  • System diagrams or scoping memos
  • Authentication or company logins
  1. Step 01
    Answer ten short questions

    Self-reported only: company size, suspected level, current MSP situation, timeline, whether a quote has arrived. No CUI or contracts.

  2. Step 02
    Read your free Cost & Fit triage

    A plain-English first cut: likely level, rough cost band, the provider categories to scope first, and the quote-risk flags raised by your inputs.

  3. Step 03
    Upgrade to the full Decision Pack

    When the free triage shows you have a real spending decision in the next 90 days, the $249 pack gives you the full packet, scope worksheet, and provider-call script.

By the numbers
~80k
DIB contractors in scope of the CMMC rule
DoD CMMC rule estimate, 2024–2032
$20k–$150k
Typical first-year CMMC Level 2 engagement range
Public benchmarks: Paramify, vendor pricing pages.
Spread between cheapest and most expensive Level 2 quote
Observed across our sourced provider records
0
Listing fees, kickbacks, or paid rankings
Meridian Compass charges buyers, not providers.
Editorial stance

How we work, and what we won’t do.

Sourced

Every provider fact carries a public source URL and a retrieval date. Guides cite the rule text or vendor page they rely on.

Transparent

The readout comes from a published rule set, not a model. Every claim ties back to one of your inputs.

Independent

No paid placement, no referral fees, no listing slots. The directory is ordered alphabetically and unweighted.

Honest about scope

A lot of CMMC questions don't have one right answer. Where the answer is genuinely uncertain, we say so instead of guessing.

See how we source provider facts for the rules we follow, and disclosures for what we do and don’t accept money for.