CAPITALCYBER

CMMC

CMMC is a scope problem before it is a security problem.

Most suppliers are quoted a number built for a company twenty times their size, because nobody has drawn a boundary around the systems that actually touch CUI. Draw the boundary first and everything downstream gets smaller, cheaper and more defensible.

Where we come in

Level 2 readiness

The full program: SSP, POA&M, policy set, diagrams and the evidence package, taken to self-assessment or to a C3PAO.

Gap assessment

All 110 NIST SP 800-171 controls scored the way an assessor scores them, with the evidence gaps named rather than glossed.

Managed compliance

Evidence collected on a schedule, quarterly review, POA&M closure and annual affirmation preparation.

CMMC In A Container™

For suppliers of one to five people: a FedRAMP Moderate Authorized enclave plus the whole program, at a published fixed price.

Managed security

Endpoint control, email defense, monitoring and response, run by the same people who write your documentation.

Managed IT

Helpdesk, patching and hardware lifecycle. The unglamorous half that most compliance failures trace back to.

What CMMC actually asks of you

CMMC Level 2 assesses your implementation of the 110 controls in NIST SP 800-171 against the objectives in NIST SP 800-171A. Contracts carrying DFARS 252.204-7012 oblige you to safeguard Controlled Unclassified Information and to report cyber incidents within 72 hours. That obligation is yours and cannot be transferred to a vendor.

Scoring is not pass or fail on the day you start. You post a score in SPRS, you carry open items on a Plan of Action and Milestones, and an Affirming Official affirms the position annually. Affirming a score you cannot defend is a False Claims Act exposure that stays with your company, which is why we will not put a number in front of you that we cannot evidence.

Why evidence is the long pole, not the writing

A policy set can be drafted in a week. Evidence cannot, because it accrues over real elapsed time and an assessor reads creation dates. Vulnerability scan history, log retention, training records and access reviews only exist if somebody started them months earlier.

This is the single most common reason a program that looked ready in a spreadsheet is not ready in the room. Starting late is the one mistake that cannot be fixed by working harder later.

Find out what an assessor would find, before one arrives.

Tell us where you are. We will tell you what is genuinely open, what is already done and only unevidenced, and roughly how long the rest takes.

If you are a defense supplier under 25 people, start with the grant. Cyber Grants Alliance, a nonprofit, awards a fully funded gap assessment. It costs you nothing and you are under no obligation to buy anything afterwards, from us or from anyone.