CMMC Compliance
Service description
CMMC (Cybersecurity Maturity Model Certification) compliance refers to the mandatory adherence of Department of Defense (DoD) contractors to cybersecurity standards aimed at protecting sensitive information, specifically Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). CMMC 2.0, the current version, streamlines compliance into three levels, each with specific requirements based on the type of information handled. Depending on the level, compliance is verified through self-assessment, third-party assessments (by C3PAOs), or government-led assessments (by DIBCAC). CMMC compliance is heavily based on the NIST SP 800-171 standard. Level 1 compliance requires annual assessment. Levels 2 & 3 compliance requires assessment every 3 years.
Common industries
Applies to Department of Defense contractors and subcontractors handling federal contract or controlled unclassified information.
ROI
Certification is a prerequisite to win and keep DoD contracts — the return is continued eligibility for that revenue.
Benefit
Prepare for and achieve Cybersecurity Maturity Model Certification, required for Department of Defense contractors handling federal contract information.
Why get it
Contractors must hold the required CMMC status to win and keep covered contracts. Handling government information without the required safeguards puts that work at risk.
When you benefit
A one-time readiness effort, then periodic assessment and an annual affirmation to stay current.
What it costs
Typically a project fee.
When you pay
Readiness work is usually a fixed project fee or hourly, scaled to the number of systems and the gaps found. Ongoing monitoring and affirmation support is often a monthly fee. Any required third-party assessment is paid for separately.
Other costs
Third-party assessment fees where required, security tools and upgrades to close gaps, and staff time.
Risks to know
A contractor without the required CMMC status can lose contracts or be ineligible for new ones. An official of the company must affirm continued compliance each year, so the records behind it must be accurate. Covered contractors must also report cyber incidents to the Department of Defense within 72 hours of discovery.
When risks arise
Gaps surface at assessment, or when a solicitation sets a CMMC level the business lacks. An incident can start the 72-hour reporting clock at any time.
The process
The provider scopes the systems that handle covered information and assesses them against the required level. The business closes the gaps found, with the provider supporting remediation and documentation. Where the level requires it, a third-party assessor then evaluates the business, and the business affirms its status.
Your commitment
The business identifies which contracts and systems handle federal contract information or controlled unclassified information, and names an official to affirm compliance. It should give the provider access to its IT environment and policies, and budget time to fix gaps.
Documents to gather
- Contract or solicitation clauses that name a CMMC level
- System and network diagram
- List of where federal contract information or controlled unclassified information is stored
- Existing security policies and any prior self-assessment
Helpful reading
- Small Business Cybersecurity Corner — NIST
- Cybersecurity for Small Business — Federal Trade Commission
- Cybersecurity Framework — NIST
Further research
- 32 CFR Part 170 — Cybersecurity Maturity Model Certification (CMMC) Program (federal)
- 48 CFR § 252.204-7021 — Contractor Compliance With the CMMC Level Requirement (DFARS clause)
- 48 CFR § 252.204-7012 — Safeguarding Covered Defense Information and Cyber Incident Reporting (DFARS clause)
- 48 CFR § 52.204-21 — Basic Safeguarding of Covered Contractor Information Systems (FAR clause)
- NIST SP 800-171 Rev. 2 — Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (the requirements CMMC Level 2 is identical to, per 32 CFR § 170.14)
Not open yet
CMMC Compliance isn’t taking requests yet. Join the waitlist. It is listed in your requests tray.