The U.S. Department of Defense (DoD) has released the Cybersecurity Maturity Model Certification (CMMC) in a move to strengthen an earlier standard known as the Defense Federal Acquisition Regulation Supplement (DFARS) and to address the growing information security concerns across their supporting contractor ecosystem.
Built on National Institute of Standards and Technology’s (NIST’s) Special Publications 800-171 and 800-172, DoD contractors with Federal Contract Information and Confidential Unclassified Information (including prime contractors and their subcontractors) must align with the applicable controls, demonstrate their effectiveness, and (in some cases) be assessed and certified via an independent third party. Once CMMC is fully rolled out by the DoD, certification will be a requirement in order to win DoD contracts.
With our CMMC readiness assessment and advisory services, we can help you:
CMMC establishes three certification levels, with each requiring a set of controls to be fully implemented and maintained:
Leverage our team’s operational and consultative experience to help you reach the certification level needed to conduct your business. A CMMC Assessment engagement follows a standardized and proven methodology that provides you with:
Completion of our CMMC Assessment Service will additionally help you determine how to allocate resources to protect the confidentiality, integrity, and availability of CUI.
If a formal, holistic assessment isn’t required, but you need to address a specific CMMC requirement, our consultants can become on-demand extensions of your team to provide you with the necessary insights to address a particular challenge.
Our CMMC Advisory Service provides consultation as needed to ensure your scoping strategies, control execution, technical solutions, and remediation activities meet the intent and rigor of the CMMC requirements.