Services
Compliance & CMMC
CMMC certification is now a condition of contract award. We build environments where evidence of every control is ready to produce, not scrambled together at audit time.
What this covers
- CMMC Level 2 gap analysis and POA&M
- Microsoft 365 GCC High migration
- Azure Government environments
- CUI boundary design
- Assessment-ready evidence
What a CMMC engagement involves
We assess your environment against all 110 CMMC Level 2 practices and 320 assessment objectives, then give you a gap analysis and POA&M showing exactly which controls are met, which are gaps, and what it takes to close them.
From there we harden your Azure Government or Microsoft 365 GCC High environment and leave you audit-ready for your next assessment.
Which environment you belong in is settled before any of that, and it is not automatic — GCC High is not the safe default for every contractor holding CUI. We carry Microsoft 365 GCC High and Commercial licensing and will tell you plainly if your obligations do not require the stricter one.
Scope is the biggest lever on what this costs
Before anything is assessed, one decision moves the price and the effort more than any other: how much of your business is inside the boundary.
The instinct is to treat the whole organization as in scope, which is thorough and frequently unnecessary. If CUI touches four people in engineering, an enclave containing those four people and the systems they use is a materially smaller undertaking than certifying everything — fewer systems to control, fewer people to train, less evidence to maintain, and a smaller surface to keep true afterwards.
The trade is that boundaries have to be real. A line that exists on a diagram but not in the configuration is worse than no line, because it produces confident answers that turn out to be wrong. Getting the scoping right is the single highest-value hour in the whole engagement, and it happens before anyone quotes you.
What an assessor actually asks for
Two documents anchor everything, and both are expected to be living rather than produced for the occasion.
Your System Security Plan describes the environment and how each requirement is met. Your POA&M — plan of action and milestones — records what is not met yet, what will be done, and by when. Having gaps is normal and expected; not knowing about them is not, and an SSP that no longer describes the environment is worse than a thin one.
Then the evidence. "We have a policy" answers a different question from "show me this working, and show me it was working three months ago". Screenshots, configuration exports, logs, ticket records, training records, signed acknowledgements. This is where an environment built for compliance separates from one hardened afterwards — evidence is a by-product of the first and an excavation project in the second.
The 110 requirements and 320 objectives are set out family by family in NIST SP 800-171, and our shared responsibility matrix shows which typically sit with a provider and which stay with you whatever anyone promises.
Which level, and who assesses it
Level 1 covers Federal Contract Information, is 17 practices, and is self-assessed. A great many businesses are quoted Level 2 work when Level 1 is genuinely all their contracts require, and that is worth settling before you spend anything.
Level 2 covers CUI and the full 110. Depending on the contract it is either self-assessed or assessed by a certified third party, and the difference matters to your timeline because third-party assessors are a finite resource.
Your self-assessment score goes into SPRS with an affirmation from a named senior official. Scores start at 110 and lose points for unmet requirements, so a negative score is ordinary rather than alarming — but it is visible to your customers, and the affirmation is a personal statement by whoever signs it.
Compliance isn't a checkbox
It is the foundation of every system we deploy. A compliant, assessment-ready environment protects the contracts you have and opens the door to the ones you want.
It is also continuous. The affirmation is annual, the environment keeps changing, and staff join and leave — so the question is not whether you were compliant on assessment day but whether you still are in month seven. That is an operational problem more than a project one, which is why it belongs inside managed IT rather than beside it.
The regulatory timetable has moved more than once and is worth checking rather than assuming: we track it in our writing on the rule. What has not changed is that the underlying obligation under DFARS 252.204-7012 has been in force for years, independently of CMMC's schedule.
One thing that does vary is which part turns out to be difficult, and it varies by what you build rather than by where you are. We have written up what that looks like across the main defense industrial base regions — export control around Redstone, unsupportable shop-floor equipment in maritime work, collaboration boundaries in research. We work nationwide and remotely, so the region changes the problem rather than the availability.
Common questions
Do you do the assessment yourselves?
No — a C3PAO performs the certification assessment, and that independence is the point. We build and evidence the environment that assessment examines.
We are not sure which level applies to us.
That is a normal starting position and it is the first thing the gap assessment settles. It depends on whether you handle CUI and what your contracts specify. It is worth settling early, because a good number of businesses are quoted Level 2 work when Level 1 is genuinely all their contracts require.
What actually drives the cost?
Scope, more than anything else. If CUI touches four people in engineering, an enclave containing those four people and the systems they use is a materially smaller undertaking than certifying the whole organization — fewer systems, fewer people to train, less evidence to maintain. The catch is that the boundary has to be real in the configuration rather than only on a diagram. Getting the scoping right is the highest-value hour in the engagement and it happens before anyone quotes you.
Can we get certified with open gaps?
Having gaps is normal and expected — that is what a POA&M is for. It records what is not met, what will be done about it, and by when. What causes trouble is not knowing about them, or carrying a System Security Plan that no longer describes the environment it is meant to describe. Both documents are expected to be living rather than produced for the occasion.
Does a compliant environment mean we need GCC High?
Not automatically, and it is worth resisting the assumption. What usually forces GCC High is export-controlled data, or a contract or prime requiring it by name. A properly configured commercial tenant can address a great deal of NIST SP 800-171 on its own. Buying the stricter environment defensively means paying more for fewer features and a smaller application ecosystem, permanently — so establish the obligation first.
How much of this stays our responsibility?
More than most providers imply. No provider can hold all 110 requirements for you — training, personnel screening, physical security and a good deal of policy sit with the business whatever the contract says. Our shared responsibility matrix sets out which rows typically fall where, and it is worth reading before any provider quotes you the work rather than after.
The other things we do
-
Managed IT Services
We take responsibility for your systems. Unlimited helpdesk, proactive maintenance, and status monitoring, so your team stops losing hours to technology that should just work.
-
Cyber Security
End-to-end protection built on a zero-trust approach: we map normal activity and act on the outliers, rather than waiting to be told something has gone wrong.
-
Cloud Solutions
Microsoft Azure, Azure Virtual Desktop, and Microsoft 365 — designed, migrated, and run by engineers who hold the certifications for all three.
-
Backup & Disaster Recovery
Backups you have actually tested and a disaster recovery plan that has actually been rehearsed. It takes ten years to build a business and one bad day to lose its data.
-
AI Services
Practical AI inside the tools your team already uses — with the same care about where your data goes that we apply to everything else.
-
Web Development
Websites built to be fast, findable, and owned by you — treated as infrastructure to be maintained rather than a project that ends at launch.
Get in touch
Talk to us about compliance (cmmc)
Tell us what you're dealing with and we'll respond as soon as possible.