For years, defense contractors self-attested that they safeguarded sensitive government data. Repeated breaches across the supply chain proved self-attestation was not enough. CMMC makes verified cybersecurity a condition of doing business with the Department of Defense.
The mandate protects two kinds of government information: Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). If your contracts touch either, a CMMC requirement will appear in them — and at the required level, no certification means no eligibility to win or keep the award.
Now codified in federal rule and phasing into DoD contracts, CMMC applies across every tier of the Defense Industrial Base — from primes to the smallest subcontractor.
Federal Contract Information — information provided for or generated under a contract, not intended for public release.
Controlled Unclassified Information — sensitive government information that requires safeguarding under federal law and policy.
CMMC 2.0 scales the required rigor to the sensitivity of the information you handle. Your contracts determine which level you must reach.
Basic safeguarding of Federal Contract Information — access control, identification, media handling, and physical protection. The entry tier for contractors that handle FCI but not CUI.
Full protection of Controlled Unclassified Information, implementing all 110 NIST SP 800-171 controls across 14 domains. This is the level most of the defense supply chain will need to certify to.
The 110 NIST SP 800-171 controls plus a subset of enhanced NIST SP 800-172 requirements, defending the highest-priority programs against advanced persistent threats.
Level 2 implements all 110 controls across these fourteen families — the same control set that underpins most US federal compliance. We assess and remediate every domain.
A clear, sequenced path to certification — with the remediation phase that, for most contractors, carries the weight. Durations are indicative for a mid-market environment.
Certification is won or lost in the decisions you make before remediation begins. Get scope and level right, and the path is direct and predictable. Get them wrong, and cost and timeline balloon. These are the three things to get right first.
Whether your contracts involve Federal Contract Information, Controlled Unclassified Information, or both decides your required level. Get this wrong and you either over-invest or fail to qualify.
A tightly bounded CUI enclave is the single biggest lever on cost and timeline. We help you isolate where CUI lives so the assessment covers what it must and nothing more.
A candid gap assessment against NIST SP 800-171 is worth more than an optimistic one. We score every control, prioritize by risk, and close gaps before an assessor ever sees them.
Every CMMC engagement produces the concrete artifacts an assessor expects — and a program that keeps generating them long after certification.
The authoritative document describing your environment, scope, and how each required control is implemented — the backbone of any CMMC assessment.
A tracked, dated plan for closing any control not yet fully met, with owners and target dates an assessor can review.
Your NIST SP 800-171 self-assessment score, calculated and submitted to the Supplier Performance Risk System as the rules require.
Policies, procedures, configurations, and artifacts mapped control-by-control — organized so the assessment runs on prepared evidence, not a scramble.
A full pre-assessment run by a reviewer independent of your implementation team, with an exception log and corrective actions before the real assessment.
Coordination with your authorized C3PAO (or DIBCAC for Level 3) through assessment, findings closure, and the certification itself.
Questions on scope, levels, or the C3PAO assessment? A senior practitioner will walk you through it.
Tell us what you build and which contracts you hold. We'll confirm your level, scope your environment, and lay out a fixed-price path to a certification-ready program — and through the assessment itself.