Program Management

Virtual Compliance Management
Blog About Contact
Schedule Consultation →

CMMC

The Department of Defense's certification program for protecting federal contract information and controlled unclassified information across the defense supply chain.

Assessment & ReadinessVirtual Compliance Management
Schedule Consultation →

The Cybersecurity Maturity Model Certification (CMMC) is how the DoD verifies that contractors and subcontractors are protecting sensitive government information. We help defense contractors scope their environment, implement the required controls, and get fully prepared for the assessment that confirms their level - whether that is a Level 1 self-assessment or a Level 2 assessment conducted by a C3PAO.

CMMC is the Department of Defense's framework for ensuring that companies in the Defense Industrial Base (DIB) adequately protect the sensitive information they handle. It applies to any organization that does business with the DoD, from prime contractors down through the subcontractors in their supply chain. If your contracts include the DFARS clause 252.204-7021, CMMC certification is becoming a condition of award, not a nice-to-have.

CMMC 2.0 defines three levels of increasing rigor. Level 1 (Foundational) covers the 15 basic safeguarding requirements from FAR 52.204-21 and applies to companies handling Federal Contract Information (FCI); it is met through an annual self-assessment. Level 2 (Advanced) aligns to the 110 security requirements in NIST SP 800-171 and applies to companies handling Controlled Unclassified Information (CUI); depending on the contract, it requires either a self-assessment or a third-party assessment conducted by a Certified Third-Party Assessment Organization (C3PAO) every three years. Level 3 (Expert) builds on Level 2 with a subset of NIST SP 800-172 controls and is assessed by the government.

The CMMC Program rule (32 CFR Part 170) took effect on December 16, 2024, and the DFARS acquisition rule that puts CMMC requirements into contracts is phasing in across DoD solicitations. That means the requirement is real and arriving now. Contractors who wait until a CMMC level appears in a solicitation often find they need 12 to 18 months of remediation to close the gap, which is far too long once a bid is on the table.

The work behind a CMMC outcome is substantial. Level 2 requires a documented System Security Plan (SSP) and evidence that the 110 requirements are implemented. A limited set of lower-weighted requirements can be deferred on a Plan of Action and Milestones (POA&M), but only if you score at least 80 percent, and every POA&M item must be closed within 180 days. Self-assessment scores must be posted in the Supplier Performance Risk System (SPRS), and a senior official must affirm compliance annually. We guide defense contractors through every step: scoping the assessment boundary, identifying where CUI actually lives, implementing controls in a way that fits how your business operates, and preparing the documentation and evidence a C3PAO will expect to see.

Key areas of CMMC.

01

Scoping & CUI Identification

Defining the assessment boundary, mapping where Federal Contract Information and Controlled Unclassified Information are stored, processed, and transmitted, and minimizing scope so you only protect what you must.

02

NIST SP 800-171 Controls

Implementing the 110 security requirements across the 14 control families - access control, audit and accountability, configuration management, incident response, and the rest - that form the backbone of CMMC Level 2.

03

System Security Plan (SSP)

Producing and maintaining the SSP that documents how each requirement is satisfied, the boundaries of your environment, and the roles responsible for each control - the central document an assessor works from.

04

POA&M & SPRS Reporting

Tracking open items in a Plan of Action and Milestones with realistic remediation dates, calculating your self-assessment score, and posting and maintaining it in the Supplier Performance Risk System.

05

Assessment Readiness

Preparing for a self-assessment or a C3PAO certification assessment - validating evidence, running mock assessments, and closing gaps before they become findings.

How we help with CMMC.

Hands-on expertise from practitioners who've guided dozens of organizations through CMMC compliance.

Gap Assessment & Scoping

We assess your current posture against NIST SP 800-171, define a defensible assessment boundary, and pinpoint exactly where CUI flows so you protect the right systems and avoid scoping your whole company into the requirement.

Control Implementation

We implement the required controls in a way that works with your tooling and team, including the enclave or GCC High decisions that often make Level 2 achievable, and map them to any other frameworks you maintain so you are not duplicating effort.

Documentation & Evidence

We build your System Security Plan, POA&M, and the supporting policies and evidence that a C3PAO will request, and we help you post and maintain an accurate score in SPRS.

Certification Preparation

We run mock assessments, validate that controls are operating and evidenced, coordinate with your C3PAO, and prepare your team for the assessment so there are no surprises on the day.

Ideal For

Defense contractors and subcontractors who handle Federal Contract Information or Controlled Unclassified Information
Companies bidding on DoD contracts that now include or will soon include the DFARS 252.204-7021 CMMC requirement
Organizations that need to reach CMMC Level 2 through a C3PAO assessment and have limited time before a solicitation closes
Prime contractors who need their supply chain to meet CMMC requirements and want a partner to guide their subcontractors
Companies already aligned to NIST SP 800-171 that want an independent readiness check before a formal assessment
Talk to an expert

Every engagement starts with a free call. No pitch, just an honest assessment of where you stand with CMMC.

Book a Free Call →

How we can help

Assessment & Readiness

Know exactly where you stand before committing to an audit.

Virtual Compliance Management

Your dedicated compliance team, without the full-time headcount.

Interactive Guide

Compare CMMC with other frameworks

See how control areas overlap, what's unique to each standard, and which frameworks complement each other.

Framework Navigator

Ready to move forward?

Book a free consultation with Glenn Chamberlain, Managing Principal. We'll scope out your CMMC engagement: timeline, deliverables, and what audit-ready looks like for your team.

Book Your Free Consultation →
Glenn Chamberlain, Managing Principal

I've never met a team who could make compliance as easy, and dare I say FUN!

Cailey Ryckman, VP of Finance

Rainforest Pay