Compliance readiness

CMMC Readiness

We prepare defense and space organizations to demonstrate compliance with the Cybersecurity Maturity Model Certification program: scoping the environment, closing gaps, and building the evidence an assessor will ask to see.

Why this reaches you

CMMC exists because the Department of Defense concluded that adversaries were reaching sensitive information through contractors rather than through the Department. The supply chain was the soft edge, and self-attestation under DFARS 252.204-7012 was not producing the security it described.

The question of whether it applies to you has nothing to do with your size. It depends on whether Federal Contract Information or Controlled Unclassified Information touches systems you own or operate. A twelve-person machine shop holding export-controlled drawings is in scope. A large firm handling nothing but public information is not.

Most companies that discover they are in scope discover it through a prime, not through the Department. Flow-down clauses push the obligation down the chain, and the requirement arrives as a line in a subcontract rather than as a policy announcement.

The two triggers

FCI
Information generated for or provided by the government under a contract, not intended for public release. Broad. Points to Level 1.
CUI
Specific categories defined in the National Archives CUI Registry, including export-controlled technical data. Narrower. Points to Level 2.

CUI is frequently unmarked or mislabelled when it reaches a subcontractor. Establishing what you actually hold is part of scoping.

The three levels

Which one applies is determined by the information in your contract, not by your size, revenue, or how many people work in IT.

Level 1

Foundational

You handle FCI only

Basic safeguarding for Federal Contract Information: access control, physical protection, media handling, and keeping systems patched. Most organizations already do the substance of this. The work is proving it and getting the affirmation into SPRS.

Requirements
15 requirements
Derived from
FAR 52.204-21
Assessed by
Annual self-assessment

Level 2

Advanced

You handle CUI

The level that applies to most of the defense industrial base, and the one that involves real work. Whether you self-assess or need a third party depends on the sensitivity of the CUI in your contract, not on your size or revenue.

Requirements
110 requirements
Derived from
NIST SP 800-171 Revision 2
Assessed by
Self-assessment or C3PAO, depending on the CUI

Level 3

Expert

You support the highest-priority programs

Enhanced protections against advanced persistent threats, layered on top of Level 2. You cannot go straight here: Level 2 certification is a prerequisite. Applies to a small number of contractors on specific programs.

Requirements
134 requirements
Derived from
NIST SP 800-171 plus 24 from SP 800-172
Assessed by
Government-led, by DIBCAC

How we run a readiness engagement

Five stages. Scope first, because it governs the cost of everything after it.

  1. 01

    Scope

    Identify where FCI and CUI actually live, then decide where they should live. Most cost overruns trace back to a scope drawn too wide. An enclave that covers the work is cheaper to secure, faster to assess, and easier to keep compliant than an entire enterprise. This stage has the highest return of anything on the list.

  2. 02

    Assess

    Evaluate the environment against 110 requirements and 320 assessment objectives, producing a scored gap register rather than a narrative report. Every finding ties to a specific requirement so remediation can be budgeted and sequenced.

  3. 03

    Document

    Build the System Security Plan, policies, and procedures an assessor will ask for, written against your environment rather than templated boilerplate. An SSP that describes a system you do not operate is worse than none, because it is evidence of a control failure.

  4. 04

    Remediate

    Close gaps in priority order, tracking POA&M items and collecting the evidence that proves each control operates as described. Some requirements need a period of operating history, which is why starting late costs more than it appears to.

  5. 05

    Verify

    Run a mock assessment against the same objectives an assessor uses, so the first time you are graded is not the time that counts. Findings come back as an evidence gap list you can close before anything is on the record.

What an engagement includes

Few organizations need all of these. Nearly all start with scoping, because it is the basis for every stage that follows and determines the size of each one.

Scoping and enclave design

Determine what is genuinely in scope and whether moving CUI into a defined enclave would reduce the assessment boundary. Frequently the single largest lever on total cost, and best done before anything else.

Basic gap assessment

A control-by-control review producing a scored gap register, an SPRS score estimate, and a prioritized remediation plan. Enough to budget against and to answer a prime who is asking where you stand.

Full mock assessment

A complete dry run following assessment procedure: evidence review, interviews, and demonstration of control operation, scored against the same objectives an assessor applies. Produces a findings report and an evidence gap list.

SSP and policy development

System Security Plan, supporting policies, and the procedural documentation the requirements call for, written to describe your actual environment. Includes the artifacts people forget until an assessor asks: incident response plan, configuration baselines, and the media handling procedure nobody has written down.

Remediation support

Hands-on closure of technical gaps, from access control and logging through to encryption and boundary protection. We do the work or direct your team through it, depending on what you have in house.

SPRS scoring and affirmation support

Calculating your score correctly, preparing the submission, and making sure the affirming official understands what they are attesting to. The scoring methodology is not intuitive and small errors are common.

External service provider assessment

Working out what your cloud providers, managed service provider, and other vendors are actually responsible for, and whether their claims hold up. An ESP handling CUI on your behalf is inside your boundary, and inherited controls only count if the provider can evidence them. This is one of the most common places a readiness effort falls apart late.

Ongoing compliance management

Keeping documentation current as the environment changes, maintaining evidence between assessments, and handling the customer questionnaires that arrive without warning. Compliance decays if nobody owns it.

FAQ

CMMC questions we get asked

Does CMMC apply to us?

The determining question is not your size or revenue. It is whether Federal Contract Information or Controlled Unclassified Information touches systems you own or operate under a Department of Defense contract.

If it does, some level of CMMC applies, and it reaches subcontractors through flow-down clauses. A great many small companies discover they are in scope because a prime passed the requirement down, not because they contract with the Department directly.

What is the difference between FCI and CUI?

Federal Contract Information is information provided by or generated for the government under a contract, that is not intended for public release. A delivery schedule, a statement of work, most contract correspondence. It is broad, and almost every contractor has some.

Controlled Unclassified Information is narrower and specifically defined. It falls into categories listed in the National Archives CUI Registry: technical drawings covered by export control, certain research data, some procurement information. CUI is what pushes you from Level 1 to Level 2.

The practical difficulty is that CUI is not always marked correctly when it reaches you. Part of scoping is working out what you actually hold rather than what the labels say.

Which level do we need?

Your contract should specify it, and increasingly solicitations do. If it does not, the rule of thumb is that FCI alone points to Level 1 and CUI points to Level 2. Level 3 applies to a small number of contractors supporting the highest-priority programs and requires Level 2 first.

Within Level 2 there is a further split. Whether you may self-assess or require a third-party assessment depends on the sensitivity of the CUI involved, which is determined by the contract rather than by you.

Why do some sources say Level 1 has 17 requirements and others say 15?

Both numbers are defensible and the difference is a counting convention. FAR 52.204-21 contains 15 basic safeguarding requirements. Some of those map to more than one CMMC practice, which produces a count of 17 in materials that enumerate practices rather than requirements.

Nothing about your obligations changes either way. We mention it because seeing two different numbers on two different sites is a common reason people assume one of them is wrong.

How is an SPRS score calculated?

You start at 110 and subtract for each requirement not fully implemented. Deductions are weighted: most cost one point, some cost three, and a small number cost five, based on how much risk the gap introduces. The result can be negative, and for organizations early in the process it usually is.

Two things commonly go wrong. Partial implementation earns no partial credit, so a control that is mostly in place still costs full points. And organizations often score themselves optimistically against the requirement text rather than against the assessment objectives, which are far more specific about what counts as evidence.

What can we defer with a POA&M?

Less than most people assume. Plans of Action and Milestones are permitted only for a subset of requirements, and the highest-weighted ones cannot be deferred at all. A POA&M also carries a closeout deadline rather than being an indefinite parking space.

Treating the POA&M as a way to pass with known gaps is a strategy that works until it is examined. We would rather close the gap.

How long does readiness take?

For a scoped enclave with a cooperative team and an existing IT function, six to nine months is realistic from gap assessment to being genuinely ready. For an enterprise-wide effort with legacy systems and no dedicated security staff, eighteen months is not unusual.

The variable that moves this most is scope, followed by how much of the work your team can absorb versus how much we do. Requirements that need a period of operating evidence set a floor that money cannot compress.

Would an enclave actually save us money?

Often, substantially. If CUI can be confined to a defined environment with controlled boundaries rather than flowing through your whole network, the assessment scope shrinks to that environment. Fewer systems, fewer users, fewer controls to evidence.

It is not free. Enclaves introduce workflow friction and someone has to enforce the boundary. But for organizations where CUI touches a minority of the business, the arithmetic usually favours it. We will tell you when it does not.

Should we build to NIST SP 800-171 Revision 2 or Revision 3?

Revision 2. NIST SP 800-171 Revision 3 was published in May 2024 and reorganizes the requirements across 17 families, but it is not yet in effect for CMMC. A DoD class deviation keeps the program on Revision 2. Building to Revision 3 ahead of rulemaking risks showing unmet requirements against the standard an assessor would actually use.

Mapping your environment against Revision 3 as a forward-looking exercise is reasonable. Implementing to it as though it were the requirement is not.

Is Gigit a C3PAO?

No. Gigit provides readiness services only: gap assessments, documentation, remediation, and mock assessments. We are not an authorized Certified Third-Party Assessment Organization and do not perform certification assessments.

Our engagement leads hold individual CMMC credentials (CCP and CCA) and have supported organizations through DIBCAC audits, which is a separate thing from organizational C3PAO authorization.

We work with a few trusted C3PAOs and can recommend one suited to your scope and timeline when the assessment requirement returns. You would engage them directly, and their independence from Gigit is what makes the result mean anything.

What does a readiness engagement cost?

It depends almost entirely on scope, specifically how much of your environment touches CUI. A tightly scoped enclave serving twenty people is a fundamentally different engagement from an enterprise-wide effort at a company of five hundred.

The first conversation is about narrowing scope, because that is the single largest lever on cost. We will tell you if an enclave approach would save you money even though it means a smaller engagement for us.

Reviewed July 31, 2026. Control counts and level requirements on this page come from the published instruments rather than from summaries. Primary sources: 32 CFR 170.14, CMMC Model and level requirements , FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems , NIST SP 800-171 Rev. 2 , NIST SP 800-171A, assessment procedures , NIST SP 800-171 Rev. 3 .

Start with scope, not with a proposal

A scoping conversation costs you nothing and usually shortens the engagement.

Talk to an expert