Skip to content
CyberAutopsyCYBERSECURITY · RISK · TECHNOLOGY
CMMC SUPPORT · ALL LEVELS

Full-lifecycle CMMC support. Every level.

The Cybersecurity Maturity Model Certification program applies to every DoD contractor and subcontractor that handles Federal Contract Information or Controlled Unclassified Information. We support the readiness, remediation, documentation, and assessment work required at every level — as one specialty within our broader cybersecurity and GRC practice.

THE THREE LEVELS

Your level is dictated by your contract data.

CMMC 2.0 defines three levels. The one you need is set by the sensitivity of the information you handle under contract — not by preference. We help organizations confirm the correct target level and build the program to reach it.

LEVEL 01

Foundational

Scope
Federal Contract Information (FCI)
Controls
17 basic safeguarding practices (FAR 52.204-21)
Assessment
Annual self-assessment
Typical audience
Organizations handling only FCI — no CUI.
LEVEL 02

Advanced

Scope
Controlled Unclassified Information (CUI)
Controls
110 controls mapped one-for-one to NIST SP 800-171 Rev. 2
Assessment
Triennial C3PAO assessment (for most contracts) or self-assessment (for a narrow subset)
Typical audience
The majority of DoD contractors handling CUI.
LEVEL 03

Expert

Scope
Highest-sensitivity CUI, APT-relevant programs
Controls
Level 2 plus a subset of NIST SP 800-172 enhanced requirements
Assessment
Government-led assessment
Typical audience
Contractors on programs designated for the highest safeguarding requirements.
WHAT WE DELIVER

Every stage of the CMMC lifecycle.

We meet organizations wherever they are on the program — from the first scoping conversation to the annual senior-official affirmation years after certification.

01

Readiness assessments

Baseline your current posture against the CMMC level required by your contract or business need. Identify the highest-impact gaps first.

02

Gap assessments

Control-by-control comparison of current state to the required practices. Prioritised remediation roadmap with time and effort estimates.

03

Documentation development

System Security Plans, Plans of Action and Milestones, boundary diagrams, policies, and procedures written to withstand C3PAO and DoD scrutiny.

04

Control implementation

Hands-on remediation with your IT and security teams. We close controls against evidence, not against a checkbox.

05

Remediation planning

POA&Ms scoped to the CMMC 2.0 rules — surgical use for permitted controls, hard-deadline closure inside the 180-day window.

06

Evidence preparation

Assessment packets indexed the way an assessor reads them: by control family, by determination statement, with owners named.

07

Assessment preparation

Pre-assessment walk-throughs, mock interviews, and live escort during the formal C3PAO engagement.

08

Continuous monitoring

Post-certification drift detection, quarterly re-tests, and annual §170.22 senior-official affirmation support.

LEVEL 2 DEEP DIVE · REQUIRED ARTIFACTS

Five artifacts every Level 2 assessor asks for on day one.

Level 2 is where most defense contractors need to land. It maps one-for-one to NIST SP 800-171 Rev. 2 and is assessed by an accredited C3PAO. Nothing about it is improvisational — the assessor opens with these five artifacts.

  1. 01
    System Security Plan (SSP)

    A written description of every system in the CUI boundary and how each of the 110 controls is implemented, by whom, with what tooling, and against what evidence.

  2. 02
    Plan of Action & Milestones (POA&M)

    A dated, owned closure plan for any control not fully implemented at the time of score submission. CMMC 2.0 permits a POA&M for a defined subset; high-value controls cannot appear on it.

  3. 03
    SPRS Score

    A submitted score in the Supplier Performance Risk System, computed against the 110 controls. The current threshold is 88 of 110, with a 180-day POA&M closure obligation.

  4. 04
    Authorization Boundary Diagram

    A signed diagram of the CUI boundary: the systems, data flows, identities, and connections in scope. Out-of-scope exclusions are justified against NIST 800-171A determination statements.

  5. 05
    Evidence Library

    Per-control artifacts (configurations, screenshots, signed policies, training records) indexed by family and control number. The packet the assessor actually reads.

SPRS SCORING, EXPLAINED

Each unmet control subtracts.

SPRS begins every contractor at 110 and subtracts a weight for each control not fully implemented. Weights run 1, 3, or 5 based on assessed risk impact. The minimum required for award eligibility is currently 88, with a closure plan for the remainder.

A contractor who claims a score of 110 without a defensible evidence packet is volunteering for a False Claims Act exposure. The DOJ’s Civil Cyber-Fraud Initiative has already produced multi-million-dollar settlements over inflated scores. The score must be earned, in writing, against artifacts.

  • 110 starting score, deductions for each unmet control
  • Weights of 1, 3, 5 based on assessment objective impact
  • Minimum 88 with POA&M permitted on lower-weight controls
  • 180-day POA&M closure obligation
  • Annual affirmation by a senior company official (32 CFR §170.22)
SPRS · DoD SUPPLIER PERFORMANCE RISK SYSTEM
PASS
Self-Assessed Score
97
of 110 possible
Threshold
88
CMMC 2.0 minimum
-2030+110
Controls met
103 / 110
POA&M (allowed)
7 of 7
Confidence
Audit-ready
Submitted
To DoD SPRS
Sample posture from a $200M defense manufacturer engagement. Anonymized.
110 CONTROLS · 14 FAMILIES

You have 14 families to defend.
Three are usually failing.

This is the heatmap we produce in week two. Every cell is a defensible posture, not an opinion. Hover or tap a family to read the typical failure pattern.

Implemented
53
48% of 110
Partial
36
33% of 110
Missing
21
19% of 110

Hover a family to read its typical failure pattern across DoD contractors we’ve assessed.

POA&M RULES UNDER CMMC 2.0

A POA&M is a scalpel, not a parachute.

CMMC 2.0 permits a Plan of Action and Milestones at certification — but only against a constrained list of controls and only inside a fixed 180-day closure window. Used surgically, a POA&M can close the last-mile gap. Used broadly, it is a way to have your certification revoked.

POA&M ALLOWED

Lower-weight controls (weight 1) where absence of implementation does not undermine the core protection objective. Examples include certain training documentation gaps.

POA&M NOT ALLOWED

High-impact controls (weight 5). Examples include FIPS-validated cryptography, multifactor authentication for privileged users, and incident reporting to DoD.

POA&M CLOSURE

180 days from certification. Failure to close results in suspension of certification. Continuous monitoring keeps the clock visible.

REGULATORY TIMELINE

The clauses are already live.

  1. 2016

    DFARS 252.204-7012 finalized — CUI safeguarding and 72-hour incident reporting required of all DoD contractors.

  2. 2020

    DFARS 7019, 7020, 7021 issued via Interim Rule — SPRS scoring, DoD assessment rights, and CMMC certification clauses.

  3. 2021

    CMMC 2.0 announced — collapsed to three levels, NIST 800-171 alignment confirmed, POA&M permitted for limited controls.

  4. 2024

    32 CFR Part 170 published (Oct 15, 2024) — formal CMMC program rule, effective December 16, 2024.

  5. 2025+

    48 CFR rule phase-in via DFARS — contracting officers begin inserting CMMC certification requirements directly into solicitations.

  6. Today

    Subcontractor flow-down is happening. Primes are requiring evidence of SPRS scores from suppliers as a condition of teaming agreements.