CMMC 2.0 has three levels. Level 1 covers basic FCI protection (17 practices), Level 2 covers CUI and requires all 110 NIST SP 800-171 controls (most common for subcontractors), and Level 3 adds NIST SP 800-172 controls for highly sensitive programs. Your DoD contract or prime contractor dictates which level you need, and a gap analysis shows where you stand.
Scope your CUI boundary carefully (too broad wastes serious money), document everything in a System Security Plan, build a remediation plan (POAM) for identified gaps, report progress in SPRS, and engage a C3PAO for the formal certification assessment.
Compliance is ongoing, not one-and-done. Regular employee training, internal audits, annual affirmations, and reassessment every three years keep certification intact and contracts protected.
From cybersecurity to compliance, we guide you every step of the way. Break radio silence and get clarity, support, and a concrete plan that closes gaps, protects systems, and retains your DoD contracts with confidence.
Phone:
(858) 538-4729
Address:
11405 W Bernardo Court Suite 211
San Diego, CA 92127
ITS Team is an IT partner that values your time as much as you do - we prioritize your company and provide a commitment to rapid service.
