Level 2 ยท NIST SP 800-171
CMMC
CMMC is the one with a hard commercial edge: no assessment, no award. The 110 practices are knowable, but the System Security Plan, POA&M and enclave decisions are where programs lose six months.
What the engagement covers
Defense contractors and subs handling CUI. Typical timeline: 4 to 9 months, driven by your SPRS gap.
- Scoping and enclave strategy. Narrowing what is in the boundary is the cheapest control you will ever implement
- NIST SP 800-171 assessment, SPRS score and POA&M
- System Security Plan authored to withstand a C3PAO assessment
- Remediation of the practices that reliably fail: MFA, logging, FIPS-validated encryption, media protection
Phases
Where an engagement sits at any point, in the language your assessor uses.
- Scoping and self-assessment, SPRS score posted
- Enclave build and remediation
- Evidence package and pre-assessment
- C3PAO assessment passed
Related reading
- Placeholder: CMMC article
Pulled from the legacy archive until this section is migrated.
- Placeholder: CMMC article
Legacy URL preserved.
Common questions
What happens if we have no SPRS score?
Contracts carrying the DFARS clause require a current self assessment score posted in SPRS. Without one an award can be blocked regardless of technical merit. Posting a low but honest score with a credible POA and M is a better position than posting nothing.
Can we reduce CMMC scope instead of hardening everything?
Yes, and it is usually the highest leverage decision in the whole program. Moving CUI into a defined enclave shrinks the assessment boundary, which cuts both remediation cost and assessment cost. Scoping decisions made before remediation begins routinely save months.
Which CMMC practices fail most often?
Multifactor authentication coverage, audit log generation and retention, FIPS validated encryption in the right places, media protection and disposal, and the System Security Plan being out of step with how systems actually run.
START HERE
Do not guess how far away you are.
A scored assessment against the CMMC control set gives you your gap, your timeline and your cost. Fixed price from $15,000, two to four weeks, quoted before any work starts. Most clients then continue into a Virtual CISO engagement or managed compliance, which within 90 days takes 25% off the first year. Nothing obliges you to.
Start with a scope
Bring the deadline and who is asking for it. Thirty minutes.