A CMMC readiness consultant prepares a defence supplier for an assessment that somebody else performs. That sentence is the whole basis on which we take this work. Certification at Level 2 is carried out by a CMMC Third-Party Assessment Organisation authorised by the Cyber AB, and Aphelion Cyber is not one. Anybody who tells you they can both prepare and certify you has misunderstood the scheme or is hoping you have.
What we do is the work either side of that assessment. Level 1 covers fifteen basic safeguarding requirements from FAR 52.204-21 and is self-assessed annually. Level 2 covers the one hundred and ten security requirements of NIST SP 800-171, and for most contracts is assessed by a C3PAO every three years with an annual affirmation in between. Level 3 adds selected requirements from SP 800-172 and is assessed by DCMA DIBCAC.
The single decision that determines cost is scope: which systems store, process or transmit Controlled Unclassified Information, and whether you can pull that boundary tight, often into an enclave, rather than dragging your whole estate into assessment. It is the same argument as PCI DSS scoping, and it is worth making properly before a single control is written.