→ Defense contractors are already being asked to schedule their CMMC Level 2 assessments.
→ Long waitlists.
→ Expensive certifications.
→ Zero room for error.
→ Contracts on the line.
Whether you're months out or already under pressure from a prime contractor, the time to get ready is now.
And it starts with leadership—because it’s YOUR signature that will legally attest to compliance under the False Claims Act.
Plus CMMC REQUIRES a team approach - not just your IT department or Managed Service Provider, or getting one person trained.
You don’t need a crash course. You need a certified expert to show you exactly where you stand—and what to do next.
→ Assessments cost $20K–$100K
→ A perfect score (320 objectives) is required to pass
→ Failure means ineligibility for new contracts—and potential cancellation of existing ones
→ Even self-assessments carry False Claims Act risks
→ Current cybersecurity requirements already exist for most defense contractors, dating back to 2017 that put your contracts and past payments at risk.
The longer you wait, the harder and more expensive it becomes to catch up. The CMMC clock is ticking—but panic isn’t a strategy. Precision is.
Executive Briefing
Understand your legal responsibilities, what assessors expect, and why CMMC success starts at the top—not with IT.
CMMC Masterclass for Managers (and MSP)
Clear explanation of CMMC’s structure, requirements, and assessment process—tailored to your environment, for your entire team, and your MSP.
Scope & System Review
On-site to identify where your FCI and CUI lives, what systems are in scope, and whether your IT/MSP approach will meet certification standards.
SPRS Self-Assessment Score Review
We’ll determine whether your posted SPRS score is evidence-backed—or putting you at risk.
10-Point Readiness Snapshot
A confidential, independent assessment of your current gaps in documentation, policy, controls, and proof.
Culture & Capability Fit Check
Assess whether your team is realistically positioned to maintain CMMC’s continuous compliance demands.
Actionable Roadmap
No fluff. No generic PDFs. You’ll receive a clear, structured report with priorities, next steps, and options for moving forward.
“As a small manufacturer, CMMC Level 2 has challenged us because it is confusing and misunderstood by defense contractors and by IT service providers. Thankfully, we are working with Semel Consulting. Because Mike Semel is a CMMC Certified Assessor with 20+ years of assessment experience with regulated industries, and hands-on experience as an MSP and a CIO, we are confident that we will be able to meet our compliance requirements, control our costs, and pass our CMMC Level 2 certification
assessment the first time.”
EMILY MCCLURE, CONTROLLER AT GGB INDUSTRIES
• CMMC Certified Professional (CCP) certification
• Advanced Assessor Training focused on the official certification process
• Two 3.5-hour closed-book exams
• Proof of years of real-world assessment experience
• A current cybersecurity certification
• A Tier 3 Department of Defense background check
Want to Verify Credentials? Search the official CMMC marketplace: https://cyberab.org/marketplace
Just type in the last name — try “Semel.”
→ Led by Mike Semel, a CMMC Certified Assessor (CCA) — not just a Registered Practitioner with minimal training
→ Backed by 25+ years of compliance and cybersecurity assessment experience
→ Just the essential guidance tailored to executives and managers, not just IT teams
→ Fact-based, unbiased, and aligned with real assessment expectations
PROS:
Familiar
Inexpensive
CONS:
Slow
Lacks CMMC Knowledge
High Failure Rate
PROS:
Easy to Find
CONS:
Low Expertise
Can't provide credible readiness
High Failure Rate
PROS:
Formally trained and certified in the CMMC assessment process
Years of assessor experience
High Success Rate
CONS:
Higher upfront cost—but can save millions in risk
Mike Semel is recognized as a thought leader in the IT, compliance and business continuity industries. He is the President and Complianceologist at Semel Consulting, focused on regulatory compliance and Business Continuity planning. Mike is a CMMC Certified Assessor (CCA), CMMC Certified Professional (CCP), CMMC Registered Practitioner, Certified Security Compliance Specialist, Disaster Recovery Institute Certified Business Continuity Professional & Certified Cyber Resilience Professional, Certified HIPAA Security Professional, and Certified Health IT Specialist. He has owned or managed MSP companies for over 30 years; served as Chief Information Officer (CIO) for a hospital and a K-12 school district; and managed operations at an online backup company. Mike is the only expert who consulted with CompTIA on the original Security Trustmark (2008), the Security Trustmark Plus (2014), and the Cybersecurity Trustmark (2023)He is the best-selling author of How to Avoid HIPAA Headaches.
CMMC and NIST 800-171 Compliance, NIST CSF, HIPAA Compliance (certified) & Joint Commission compliance; IT Management; Disaster and Business Continuity Planning (certified); assessments for compliance and business continuity; IT Assessments for School Districts; Executive Level consulting; CIO for hire; network design; IT policies and procedures; project management; ROI evaluation; training; Able to create compliance documentation, , executive level reports marketing materials, effective proposals; IT cost control & budgeting; IT investment justification; able to effectively communicate technology with non-technical executives.
CMMC Certifications
• CMMC-AB Certified Assessor (CCA), 2024
• Certified Professional (CCP), 2023
• Registered Practitioner (RP), 2021
Business Continuity & Cyber Resilience
• Certified Business Continuity Professional (CBCP), Disaster Recovery Institute International (since 2006)
• Led plans for a $4B credit union, a $1B health plan, and over 200 small businesses
• Clients successfully navigated Superstorm Sandy, the Joplin Tornado, and other major disruptions
• Certified Cyber Resilience Professional (CCRP), 2022
• Member, DRI International Professional Practices Select Committee, 2021
Security & Compliance Leadership
• Only person to consult on all three CompTIA Trustmarks:
- Original Security Trustmark (2008)
- Security Trustmark Plus (2014)
- Cybersecurity Trustmark (2022)
• Certified HIPAA Administrator (since 2003)
• Certified HIPAA Professional (since 2006, HIPAA Academy)
• Certified Security Compliance Specialist, 2012
• Led HIPAA Security Rule assessments for hospitals, practices, government agencies, and school districts in multiple states
• Authored the Certified HIPAA Security Professional (CHSP) Training Course (4Medapproved; CEU-qualified)
Leadership & Operational Excellence
• Outsourced CIO, White Pine County School District (2007–2012); secured over $1M in E-rate funding
• CIO, Schuyler Hospital (2004–2006); eliminated downtime, increased IT flexibility, and cut operating costs by 32%
• Apple Education Sales Consultant (1990–1991); oversaw $10M in education sales across NY and PA
• Elected Chair, CompTIA IT Security Community, 2011
• Co-chair, CompTIA Ambassadors
Industry Recognition & Thought Leadership
• Member, FBI InfraGard (2003–present)
• Best-Selling Author: How to Avoid HIPAA Headaches (2017)
• Co-author: CompTIA Security Trustmark Quick Reference Guide (2009)
• Featured in Business Solutions Magazine, Hewlett-Packard Success Story, and D-Link Case Study
• Wrote 4,000-word cover story for Computing Channels Magazine
• Speaker at national conferences with audiences of up to 800 people
• 30+ years managing teams of 7 to 30 engineers and technicians
• Advisor to Compaq, Ingram Micro, Xerox, and other leading tech firms
• Chaired software development teams and served on executive advisory panels for multi-billion-dollar companies
• Subject Matter Expert, CompTIA Security Trustmark Development Team (2008)
Semel Consulting August 2012 – Present
President / Chief Compliance Officer
Job Responsibilities: Provide startup financing. Develop and implement business and cybersecurity strategies. Hire and manage contracted workforce. Deliver consulting services. Sales and marketing. Manage client relationships. Deliver compliance services for HIPAA, CMMC, NIST, PCI DSS, GLBA, FTC Safeguards Rule, State Laws, Contracts, and Cyber Insurance. Create Business Continuity Plans across industries. Provide content for compliance software. Create compliance training courses. Conference speaking. Write for publications and websites.
Business Continuity Technologies – June 2010 – August 2012
VP / Owner / Security Officer
Job Responsibilities: Develop and implement business and cybersecurity strategies. Hire and manage workforce. Manage technical and consulting services. Sales and marketing. Manage client relationships. Deliver compliance services for HIPAA, NIST, PCI DSS, GLBA, State Laws, Contracts, and Cyber Insurance. Create Business Continuity Plans across industries.
White Pine County School District, Ely, NV – July 2007 – August 2012
Chief Information Officer
(Outsourced through Business Continuity Technologies and Connecting Point of Las Vegas)
Job Responsibilities: Develop and implement cybersecurity strategies. Select cybersecurity tools. Create and implement processes. Manage hybrid workforce of employees and contractors. Manage technical services and budgeting. Create cybersecurity policies. Oversee user training. Advise leadership and board. Managed compliance with FERPA, CIPA, E-Rate, State Laws, and grant requirements.
XiloCore (Online Backup Provider) – January – June 2010
Chief Operating Officer
Job Responsibilities: Manage technical team. Oversee helpdesk. Manage data restoration team. Train users. Manage client relationships. Managed compliance with HIPAA, FERPA, CIPA, E-Rate, State Laws, and grant requirements. Create Business Continuity Plans across industries.
Connecting Point of Las Vegas – May 2006 – June 2010
VP / Owner
Job Responsibilities: Develop and implement business and cybersecurity strategies. Hire and manage workforce. Manage technical and consulting services. Sales and marketing. Manage client relationships. Deliver compliance services for HIPAA, NIST, PCI DSS, GLBA, State Laws, Contracts, and Cyber Insurance. Create Business Continuity Plans across industries.
Schuyler Hospital / Seneca View Skilled Nursing Facility – June 2004 – May 2006
Chief Information Officer
(Outsourced through Chemung Computer and Databranch)
Job Responsibilities: Develop and implement cybersecurity strategies. Select cybersecurity tools. Create and implement processes. Manage hybrid workforce of employees and contractors. Manage technical services and budgeting. Create cybersecurity policies. Oversee user training. Advise leadership and board. Managed compliance with HIPAA, State Laws, and accreditation requirements.
Databranch, Elmira Heights, NY – June 2004 – May 2006
Regional Manager
Job Responsibilities: Develop and implement cybersecurity strategies. Hire and manage local workforce. Manage technical and consulting services. Sales and marketing. Manage client relationships. Deliver compliance services for HIPAA, NIST, PCI DSS, GLBA, State Laws, Contracts, and Cyber Insurance. Create Business Continuity Plans across industries.
Chemung Computer, Elmira Heights, NY - January 1980 – June 2004
Owner
Job Responsibilities: Provide startup financing. Develop and implement business and cybersecurity strategies. Hire and manage workforce. Manage technical and consulting services. Sales and marketing. Manage client relationships. Deliver compliance services for HIPAA, NIST, PCI DSS, GLBA, State Laws, and Contracts.
2011 “Channelnomics Influencer” Award Winner
Phone: 888-997-3635
Fax:888-667-7849
Semel Consulting, LLC
6547 Midnight Pass Road #90
Sarasota, Florida
34242
© 2025 Semel Consulting, LLC