Skip to main content
LCG
  • Home
  • Services
  • About
  • FAQ
  • Contact
Schedule a Consultation
  • Home
  • Services
  • About
  • FAQ
  • Contact
  • Schedule a Consultation

Cybersecurity & Cloud Security Consulting

Microsoft Cloud Security and CMMC Readiness for Government Contractors

Lennox Cyber Group (LCG) is a founder-led cybersecurity and cloud security consulting firm helping organizations prepare for CMMC and NIST SP 800-171, and secure their Microsoft 365 and Azure environments — with a focus on government contractors and organizations that handle sensitive information.

Schedule a Security Consultation Explore Our Services
CMMC ReadinessNIST 800-171Microsoft 365AzureDC · MD · VA

Built Around the Frameworks Government Contractors Are Measured Against

LCG focuses on the frameworks and cloud platforms that most directly affect organizations handling Controlled Unclassified Information (CUI) and federal contract data — so the guidance you get is grounded in real requirements, not generic best practices.

0 CMMC Maturity Levels
0 NIST 800-171 Security Requirements
0 NIST 800-171 Control Families
0 States Served — DC, Maryland & Virginia

What We Do

Core Services

Focused consulting across compliance and cloud security.

CMMC Readiness Consulting

Readiness guidance and gap analysis to help you understand and improve your CMMC posture. Readiness consulting — not an official certification assessment.

Explore CMMC Readiness Consulting →

Microsoft 365 Security

Entra ID, MFA, Conditional Access, and Defender configuration review for stronger identity security.

Explore Microsoft 365 Security →

Azure Security

Architecture review, identity, networking, and Defender for Cloud posture assessments.

Explore Azure Security →

NIST 800-171 Assessments

Evaluate your environment against NIST SP 800-171 and prioritize remediation.

Explore NIST 800-171 →

Government Contractor Cybersecurity

CUI protection and compliance readiness built for defense and government contractors.

Explore Government Contractor Security →

Cloud Security Consulting

Architecture, identity, data, networking, and governance across your cloud environment.

Explore Cloud Security →

Why LCG

A Focused Practice, Not a Generalist Shop

LCG concentrates specifically on compliance frameworks and Microsoft cloud security.

Compliance-Focused

Our work is grounded in CMMC and NIST 800-171 — not generic security advice retrofitted to a checklist.

Microsoft Cloud Depth

Focused, hands-on experience with Microsoft 365 and Azure — the platforms most clients run on.

Regional Focus

Based in the DC, Maryland, and Virginia region and familiar with the contractor landscape here.

About Lennox Cyber Group

A Founder-Led Practice Built on Verified Credentials

Work directly with the people who do the engineering — not a sales layer.

Darius Smith, Co-Founder

Darius Smith is a federal cybersecurity professional with more than eight years of experience securing mission systems across DHS and DoD environments. He specializes in bridging technical engineering with governance and compliance — designing and enforcing Zero Trust controls, building automation in Microsoft Sentinel, and integrating Defender for Cloud and Entra ID to strengthen detection and response. His background includes leading RMF and FedRAMP compliance efforts, developing ATO packages, and driving vulnerability remediation across hybrid Azure environments. He is based in the Washington DC–Baltimore area and holds a DoD Secret clearance.

At Lennox Cyber Group, Darius leads the governance, risk, and compliance practice — CMMC readiness, NIST 800-171 gap assessments, and compliance documentation.

Connect with Darius Smith on LinkedIn

Credentials — Darius

  • CISSP — Certified Information Systems Security Professional
  • CGRC — Certified in Governance, Risk and Compliance
  • Microsoft Certified: Security Operations Analyst Associate (SC-200)

Adrian Bills, Co-Founder

Adrian Bills is a cybersecurity engineer based in Glen Allen, Virginia, specializing in identity and access management, privileged access management, Azure architecture, and Microsoft security operations. At Lennox Cyber Group, Adrian leads the cloud and identity engineering practice — Microsoft 365 security, Azure security, and identity and access management. Together, the founders built LCG to bring hands-on engineering and compliance depth to small government contractors.

Connect with Adrian Bills on LinkedIn

Credentials — Adrian

  • Microsoft Certified: Cybersecurity Architect Expert
  • Microsoft Certified: Azure Solutions Architect Expert
  • Microsoft Certified: Security Operations Analyst Associate
  • Microsoft Certified: Azure Administrator Associate
  • CompTIA Security+

Common Questions

CMMC, NIST 800-171 & Cloud Security FAQ

What is the difference between CMMC readiness consulting and an official CMMC assessment?

Readiness consulting helps you understand your current posture, identify gaps against the CMMC requirements, and prepare documentation and remediation priorities. An official CMMC Level 2 certification assessment is performed by an authorized third-party assessment organization (C3PAO). Lennox Cyber Group provides readiness consulting; we are not a C3PAO and do not certify organizations or guarantee certification outcomes.

How are CMMC and NIST SP 800-171 related?

CMMC Level 2 is built on the 110 security requirements of NIST SP 800-171. If your contracts involve Controlled Unclassified Information (CUI), a NIST 800-171 gap assessment is usually the practical starting point for CMMC preparation — the same evidence supports your SPRS self-assessment score, System Security Plan (SSP), and POA&M.

What is the current status of the CMMC program?

As of the DoD small-business CMMC guidance reviewed on this page's last update, Phase I self-assessment requirements were in place while Phase II requirements were suspended. Program status changes over time — verify against the official source: DoD CMMC information for small businesses. Page reviewed: September 5, 2026.

What does a Microsoft 365 or Azure security assessment cover?

Typical areas include Entra ID identity and access configuration, MFA and Conditional Access, privileged role management, Microsoft Defender configuration, network exposure, logging and monitoring, and overall tenant or subscription governance — delivered as prioritized findings with a remediation roadmap.

Where does Lennox Cyber Group work?

We serve organizations across Washington DC, Maryland, and Virginia, and compliance and Microsoft cloud engagements can be delivered fully remotely.

Ready to Strengthen Your Security Posture?

Schedule a consultation to discuss CMMC readiness, NIST 800-171, or a Microsoft 365 / Azure security review.

Schedule a Security Consultation

Get In Touch

Let's Strengthen Your Security Posture.

Tell us about your environment and compliance goals, and we'll follow up to schedule a consultation.

What to Expect

  • A short discovery call to understand your environment
  • A realistic scope and timeline for your engagement
  • No pressure, no generic sales pitch

Serving the DMV Region

Washington DC, Maryland, and Virginia — with remote delivery available for Microsoft 365, Azure, and compliance consulting.

Lennox Cyber Group

Cybersecurity. Cloud Security. Compliance.

Serving organizations throughout Washington, DC, Maryland, Virginia, and beyond.

Site

  • Home
  • Services
  • About
  • FAQ
  • Contact

Get Started

Ready to talk through your environment?

Schedule a Consultation

© Lennox Cyber Group. All rights reserved.