Home / Services / CMMC Compliance

Service · CMMC

CMMC readiness, led by a certified professional.

CMMC is now regulation: 32 CFR Part 170 took effect December 16, 2024, and the DFARS clause began phasing into contracts November 10, 2025. We take you from "what's our level?" to assessment-ready, scoped by the official guides, not guesswork.

The two levels

Know your level. Plan your path.

0
Level 1 practices protecting FCI, per FAR 52.204-21, with annual self-assessment
0
Level 2 practices protecting CUI, covering all of NIST SP 800-171 Rev. 2
0
Level 2 domains, Access Control through System & Information Integrity
0
Level 2 assessment objectives that need evidence behind them

Level 1 spans 6 domains: AC, IA, MP, PE, SC, SI. Level 2 is typically assessed triennially by a C3PAO, with self-assessment permitted for some contracts.

What we do

From scoping to assessment day.

Scoping Workshops

Define your assessment boundary using the official Level 1 and Level 2 Scoping Guides, before you overspend protecting out-of-scope systems.

Gap Assessment

Practice-by-practice review against all 15 or 110 requirements, scored the way an assessor would score them.

SSP & POA&M Development

A System Security Plan that reflects reality, and Plans of Action & Milestones that close gaps on a defensible timeline.

SPRS Scoring & Affirmation

Accurate NIST SP 800-171 DoD Assessment Methodology scoring and support for SPRS submissions and annual affirmations.

Remediation Execution

We don't just find gaps. We fix them, often with the Microsoft 365 and Azure tooling you already license.

Assessment Readiness

Mock assessments and evidence packages aligned to the official Assessment Guides, so C3PAO day holds no surprises.

CMMC Level 2: the 14 domains of NIST SP 800-171 Rev. 2
CodeDomainCodeDomain
ACAccess ControlMPMedia Protection
ATAwareness & TrainingPSPersonnel Security
AUAudit & AccountabilityPEPhysical Protection
CMConfiguration ManagementRARisk Assessment
IAIdentification & AuthenticationCASecurity Assessment
IRIncident ResponseSCSystem & Communications Protection
MAMaintenanceSISystem & Information Integrity

Regulatory context

Level 1 covers the 15 basic safeguarding requirements of FAR 52.204-21 and protects FCI. Level 2 covers all 110 requirements of NIST SP 800-171 Rev. 2 and protects CUI. Program details are codified in 32 CFR Part 170; contractual flow-down arrives through DFARS 252.204-7021, alongside the existing 252.204-7012 safeguarding clause.

Want software that tracks all of this? Deka-Forge is our CMMC GRC platform.

See Deka-Forge

Your contracts are worth getting this right.

Start with a scoping conversation. It defines everything downstream.

Start CMMC Readiness