Certified Lead CMMC Assessor (LCCA)

CMMC Compliance You Can Trust

CMMC 2.0 readiness and NIST 800-171 compliance consulting for DoD contractors nationwide. Backed by 15+ years in cybersecurity, direct DoD experience, and hands-on CMMC assessor certification.

Active Credentials
Lead Certified CMMC Assessor (LCCA)
ISACA · May 2026
Certified CMMC Assessor (CCA)
ISACA · April 2026
Certified CMMC Professional (CCP)
ISACA · March 2026
CASP+
CompTIA · June 2024
CySA+ ce
CompTIA · November 2022
MS Cybersecurity
NYU · CyberFellow 2023

CMMC 2.0 Is Now a
Contractual Requirement

The Department of Defense has formally embedded CMMC requirements into contracts. Non-compliance means lost contracts — and potential legal liability. Understanding your level is the first step.

Level 1 — Foundational

Basic Cyber Hygiene

17 practices aligned to basic safeguarding of Federal Contract Information (FCI). Annual self-assessment.

Level 2 — Advanced

CUI Protection

110 practices aligned to NIST 800-171. Handles Controlled Unclassified Information. Triennial third-party assessments required for critical programs.

Level 3 — Expert

High-Value Asset Defense

110+ practices based on NIST 800-171 and select 800-172 requirements. Government-led assessments for the most sensitive programs.

Neal Fennimore, Lead Certified CMMC Assessor and founder of XNOR LLC
Neal Fennimore
Founder, XNOR LLC · LCCA

DoD Experience.
Real-World Expertise.

I'm Neal Fennimore, founder of XNOR LLC and a Lead Certified CMMC Assessor with over 15 years securing enterprise and government environments.

Most recently, I served as a Digital Service Expert at the Defense Digital Service, where I was the technical lead for the Pentagon's bug bounty program, helped audit ATO processes across multiple platforms, and integrated security solutions into cloud infrastructure.

As IT Security Director at a DoD contractor, I led CMMC compliance efforts firsthand — hardening on-prem and Azure infrastructure, deploying security systems, and building business continuity programs that meet federal requirements.

I hold an MS in Cybersecurity from NYU (CyberFellow program) and carry the full CompTIA security stack alongside ISACA's LCCA, CCA, and CCP designations.

15+
Years in Security
DoD
Direct Experience
CCA
CMMC Certified

Industry Publications

Recognized voice in cybersecurity and authentication.

CSS-Tricks · March 2023
CSS-Tricks · March 2018

CMMC Compliance Services

From NIST 800-171 gap analysis to mock assessments, XNOR provides end-to-end readiness support for defense contractors pursuing CMMC certification.

CMMC Mock Assessments

Pre-assessment evaluations led by a Lead Certified CMMC Assessor, measuring your practices against CMMC Level 1 and Level 2 requirements — so you walk into your C3PAO assessment with no surprises.

Learn more →

Gap Analysis & Readiness

Thorough review of your current security posture against NIST 800-171 controls, with a prioritized remediation roadmap before your formal assessment.

Learn more →

Zero Trust Architecture

Design and implementation guidance for Zero Trust architectures aligned to DoD and NIST frameworks — on-prem, Azure, or hybrid environments.

Policy & Documentation

Development of System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), and all supporting policies required for CMMC compliance.

Learn more →

Cloud Security (Azure/AWS)

Hardening of cloud infrastructure to meet CMMC and FedRAMP alignment requirements, including SIEM integration, VLAN segmentation, and MDM policy.

Training & Awareness

Custom cybersecurity training programs and tabletop exercises designed for defense contractor teams navigating CMMC requirements for the first time.

Built for Contractors.
Free to Use.

Tools I built to help defense contractors understand and track their compliance posture before a formal assessment.

NIST SP 800-171 Rev 2
Compliance Tracker

A free, browser-based tool to walk through all 110 controls across 14 NIST SP 800-171 R2 families. Track your implementation status, view your running SPRS score, and generate a compliance summary — all stored locally in your browser with no account required.

Access Control Audit & Accountability Configuration Mgmt Incident Response Risk Assessment System Integrity + 8 more families
Open the Tool View on GitHub
SPRS Score:
110 / 110
requirements met
03.01 — Access Control 22 / 22
03.02 — Awareness & Training 3 / 3
03.03 — Audit & Accountability 9 / 9
03.04 — Configuration Mgmt 9 / 9
03.05 — Identification & Auth 11 / 11
03.06 - Incident Response 3 / 3
+ 8 more families…

Certifications & Education

Every credential active and maintained — because the threat landscape doesn't stand still.

CMMC Compliance FAQ

Quick answers to the questions defense contractors ask most about CMMC 2.0, NIST 800-171, and the assessment process.

What is CMMC 2.0 and who needs it?

CMMC 2.0 (Cybersecurity Maturity Model Certification) is the Department of Defense's framework for verifying that contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Any company in the defense supply chain — primes and subcontractors alike — will need to meet the CMMC level specified in their contracts.

What is the difference between CMMC Level 1 and Level 2?

Level 1 covers 17 basic safeguarding practices for FCI and allows annual self-assessment. Level 2 requires all 110 NIST SP 800-171 controls for handling CUI, and most contracts involving CUI require a triennial third-party assessment by a C3PAO.

How long does it take to prepare for a CMMC assessment?

Most small and mid-sized contractors need 6 to 18 months to reach Level 2 readiness, depending on their starting posture. A gap analysis early in the process gives you a realistic timeline and a prioritized remediation roadmap.

What is an SPRS score?

Your SPRS (Supplier Performance Risk System) score reflects your self-assessed implementation of NIST SP 800-171, ranging from -203 to a perfect 110. DoD contracting officers can view it, and an accurate score is required under DFARS 252.204-7019/7020.

Does XNOR perform official CMMC certification assessments?

No — official Level 2 certification assessments are conducted by authorized C3PAOs. XNOR provides consulting, gap analysis, remediation support, and mock assessments led by a Lead Certified CMMC Assessor so you walk into your C3PAO assessment fully prepared.

Start Your Compliance Journey

Whether you're starting from scratch or preparing for a formal assessment, let's talk through where you stand and what it takes to get compliant.

Message sent!

Thanks for reaching out. Neal will be in touch within 1–2 business days.