CMMC Readiness Consulting
Readiness guidance and gap analysis to help you understand and improve your CMMC posture. Readiness consulting — not an official certification assessment.
Explore CMMC Readiness ConsultingCybersecurity & Cloud Security Consulting
Lennox Cyber Group (LCG) is a founder-led cybersecurity and cloud security consulting firm helping organizations prepare for CMMC and NIST SP 800-171, and secure their Microsoft 365 and Azure environments — with a focus on government contractors and organizations that handle sensitive information.
LCG focuses on the frameworks and cloud platforms that most directly affect organizations handling Controlled Unclassified Information (CUI) and federal contract data — so the guidance you get is grounded in real requirements, not generic best practices.
What We Do
Focused consulting across compliance and cloud security.
Readiness guidance and gap analysis to help you understand and improve your CMMC posture. Readiness consulting — not an official certification assessment.
Explore CMMC Readiness ConsultingEntra ID, MFA, Conditional Access, and Defender configuration review for stronger identity security.
Explore Microsoft 365 SecurityArchitecture review, identity, networking, and Defender for Cloud posture assessments.
Explore Azure SecurityEvaluate your environment against NIST SP 800-171 and prioritize remediation.
Explore NIST 800-171CUI protection and compliance readiness built for defense and government contractors.
Explore Government Contractor SecurityArchitecture, identity, data, networking, and governance across your cloud environment.
Explore Cloud SecurityWhy LCG
LCG concentrates specifically on compliance frameworks and Microsoft cloud security.
Our work is grounded in CMMC and NIST 800-171 — not generic security advice retrofitted to a checklist.
Focused, hands-on experience with Microsoft 365 and Azure — the platforms most clients run on.
Based in the DC, Maryland, and Virginia region and familiar with the contractor landscape here.
About Lennox Cyber Group
Work directly with the people who do the engineering — not a sales layer.
Darius Smith is a federal cybersecurity professional with more than eight years of experience securing mission systems across DHS and DoD environments. He specializes in bridging technical engineering with governance and compliance — designing and enforcing Zero Trust controls, building automation in Microsoft Sentinel, and integrating Defender for Cloud and Entra ID to strengthen detection and response. His background includes leading RMF and FedRAMP compliance efforts, developing ATO packages, and driving vulnerability remediation across hybrid Azure environments. He is based in the Washington DC–Baltimore area and holds a DoD Secret clearance.
At Lennox Cyber Group, Darius leads the governance, risk, and compliance practice — CMMC readiness, NIST 800-171 gap assessments, and compliance documentation.
Adrian Bills is a cybersecurity engineer based in Glen Allen, Virginia, specializing in identity and access management, privileged access management, Azure architecture, and Microsoft security operations. At Lennox Cyber Group, Adrian leads the cloud and identity engineering practice — Microsoft 365 security, Azure security, and identity and access management. Together, the founders built LCG to bring hands-on engineering and compliance depth to small government contractors.
Common Questions
Readiness consulting helps you understand your current posture, identify gaps against the CMMC requirements, and prepare documentation and remediation priorities. An official CMMC Level 2 certification assessment is performed by an authorized third-party assessment organization (C3PAO). Lennox Cyber Group provides readiness consulting; we are not a C3PAO and do not certify organizations or guarantee certification outcomes.
CMMC Level 2 is built on the 110 security requirements of NIST SP 800-171. If your contracts involve Controlled Unclassified Information (CUI), a NIST 800-171 gap assessment is usually the practical starting point for CMMC preparation — the same evidence supports your SPRS self-assessment score, System Security Plan (SSP), and POA&M.
As of the DoD small-business CMMC guidance reviewed on this page's last update, Phase I self-assessment requirements were in place while Phase II requirements were suspended. Program status changes over time — verify against the official source: DoD CMMC information for small businesses. Page reviewed: September 5, 2026.
Typical areas include Entra ID identity and access configuration, MFA and Conditional Access, privileged role management, Microsoft Defender configuration, network exposure, logging and monitoring, and overall tenant or subscription governance — delivered as prioritized findings with a remediation roadmap.
We serve organizations across Washington DC, Maryland, and Virginia, and compliance and Microsoft cloud engagements can be delivered fully remotely.
Schedule a consultation to discuss CMMC readiness, NIST 800-171, or a Microsoft 365 / Azure security review.
Schedule a Security ConsultationGet In Touch
Tell us about your environment and compliance goals, and we'll follow up to schedule a consultation.