Readiness held, no certification claimed
Our CMMC readiness position
We hold no CMMC certification at any level, we have no assessment booked, and we have not submitted a supplier performance score. What we do hold is the control base that most of the 110 practices depend on, a scope decision method, and a plan with owners and windows. This page states that position in full, because a prime contractor discovering it late is worse for both of us.
2 of 14
Families fully met
57 percent
Readiness by family
Level 2
Target level
What we do and do not claim
We hold no CMMC certification, we have no assessment booked, and we have not submitted a score. We state that in proposals and questionnaire responses. Where a solicitation requires a certified contractor, we either team with one or we decline the opportunity rather than imply a status we do not hold.
When CMMC actually applies to us
- The trigger
- CMMC applies to us only when a contract or a prime contractor flow down clause places federal contract information or controlled unclassified information in our hands. We do not hold such information today, so the program is held at readiness rather than run at full cost.
- The level we would target
- The target is CMMC Level 2, which assesses the 110 practices of NIST SP 800-171 Revision 2 and is confirmed by a Certified Third Party Assessment Organization. Level 1 covers federal contract information only through fifteen basic practices and is confirmed by annual self assessment.
- The scope we would assess
- Our intended assessment scope is a single controlled enclave rather than the whole company. Controlled unclassified information would be held in one approved store with its own access group, its own logging, and its own retention rule, so an assessor examines that enclave and the people who reach it rather than every system we use.
- Why the boundary stays small
- Keeping the boundary small is the single largest cost decision in a CMMC program. A boundary drawn around the whole firm multiplies the evidence burden, the tooling cost, and the assessment fee without improving protection of the information that matters.
- The assessment path
- The sequence is a scope boundary decision, a self assessment against all 110 practices, a system security plan, a plan of action and milestones for anything not yet met, a score submitted to the government reporting system, then a third party assessment. A plan of action cannot cover the practices that the rules require to be fully met at assessment.
Where we stand across the fourteen families
Each family names what an assessor asks for and what is still open. Nothing is marked met unless dated evidence exists behind it.
AC, Access control
Being strengthenedLimit access to the enclave to authorized users, processes, and devices, and limit what each may do once inside.
What an assessor asks. The assessor asks for the access list for the enclave, the approval record for each person on it, the last two access reviews with dates, and proof that leavers were removed.
Our position. Access reviews are run and recorded. What is missing is a documented implementation statement per practice inside the system security plan.
Controls: ACC-01, ACC-02, ACC-03
AT, Awareness and training
Being strengthenedMake everyone with enclave access aware of the risks of their role and train them on the practices they must follow.
What an assessor asks. The assessor asks for the training content, the completion record per person, and the date of the last refresh.
Our position. Role specific content for handling controlled unclassified information is still to be written.
Controls: AUT-01, AUT-02
AU, Audit and accountability
Being strengthenedCreate, protect, and review audit records sufficient to trace the actions of each individual user inside the enclave.
What an assessor asks. The assessor asks which log sources are collected, the retention period, who reviews them, on what cycle, and what happened the last time a review found something.
Our position. Central collection and alerting is on the readiness timeline for months two to four and is the largest open item in this family.
Controls: MON-01
CM, Configuration management
Being strengthenedEstablish and maintain baseline configurations for the systems inside the enclave and control changes to them.
What an assessor asks. The assessor asks for the baseline, the last configuration review against it, and the record of an approved change.
Our position. A written baseline specific to the enclave is required. The general configuration review procedure exists.
Controls: CHG-01, DAT-02
IA, Identification and authentication
Being strengthenedIdentify users and devices and authenticate them, including multi factor authentication for enclave access.
What an assessor asks. The assessor asks for proof that multi factor authentication is enforced for every account that can reach the enclave, with no exceptions and no shared accounts.
Our position. Enforcement is in place for our own systems. The enclave specific configuration record is written at activation.
Controls: ACC-01, ACC-02
IR, Incident response
Being strengthenedEstablish an incident handling capability, test it, and report incidents within the required window.
What an assessor asks. The assessor asks for the plan, the last exercise record, and the reporting route with the time window written into it.
Our position. The annual tabletop is scheduled for months four to six on the readiness timeline.
Controls: IRP-01, IRP-02, IRP-03, BRE-01
MA, Maintenance
Being strengthenedPerform maintenance on enclave systems in a controlled way, including any maintenance performed by a third party.
What an assessor asks. The assessor asks how patching is performed, how remote maintenance is authorized and monitored, and how media is sanitised before it leaves.
Our position. Remote maintenance authorization needs a written statement for the enclave.
Controls: VUL-01, CHG-01
MP, Media protection
Being strengthenedProtect controlled information on media, limit access to it, and sanitise or destroy media before disposal or reuse.
What an assessor asks. The assessor asks where controlled information is stored, whether removable media is permitted, and for a destruction record.
Our position. A written prohibition on removable media inside the enclave is to be added to the plan.
Controls: DAT-01, DAT-03, CLI-02
PS, Personnel security
MetScreen people before granting enclave access and protect the enclave during and after personnel changes.
What an assessor asks. The assessor asks for the screening record, the onboarding record, and proof that access was removed on the leaving date.
Our position. None open. Screening, onboarding, and offboarding records are complete and dated.
Controls: AUT-01, ACC-03
PE, Physical protection
Being strengthenedLimit physical access to systems and work areas, and protect controlled information in a remote working setting.
What an assessor asks. The assessor asks how a remote first firm protects screens, devices, and printed material, and what the home working rule actually says.
Our position. A remote working standard specific to controlled information is to be written into the plan.
Controls: DAT-01, ACC-03
RA, Risk assessment
MetAssess risk to the enclave periodically, scan for vulnerabilities, and remediate according to the risk.
What an assessor asks. The assessor asks for the risk assessment, its date, the scan results, and the remediation record with dates.
Our position. None open. The method, the register, and the remediation record are in place and reviewed.
Controls: RSK-01, RSK-02, VUL-01
CA, Security assessment
Being strengthenedAssess the controls periodically, produce a system security plan, and maintain a plan of action for weaknesses.
What an assessor asks. The assessor reads the system security plan first, then tests whether the plan of action is real, current, and owned.
Our position. The system security plan is drafted to the boundary level. Practice by practice implementation statements are on the timeline for months three to five.
Controls: GOV-01, GOV-02, CMM-01, CMM-02
SC, System and communications protection
Being strengthenedMonitor and protect communications at the enclave boundary and encrypt controlled information in transit and at rest.
What an assessor asks. The assessor asks which cryptography is used, whether it meets the required standard, and how the boundary is enforced.
Our position. A cryptography statement naming the standard applied inside the enclave is to be added.
Controls: DAT-01, DAT-02, ACC-02
SI, System and information integrity
Being strengthenedIdentify and correct flaws promptly, protect against malicious code, and monitor for attacks and indicators of compromise.
What an assessor asks. The assessor asks how quickly flaws are corrected, what protects endpoints, and what monitoring runs against the enclave.
Our position. Monitoring coverage depends on the central logging work scheduled for months two to four.
Controls: VUL-01, MON-01, IRP-01
The plan, phase by phase
The first phase is held ready and activates within two weeks of a qualifying contract. The rest run on the windows shown, measured from activation rather than from a fixed calendar date.
Trigger watch and scope decision
Held ready, activated within two weeks of a qualifying contractDecide whether a given opportunity actually brings controlled unclassified information into our hands, and if it does, draw the smallest defensible boundary around it before any work starts.
Finished when
- A written determination for the opportunity, recording whether federal contract information or controlled unclassified information is in scope and the clause that puts it there.
- An approved enclave boundary naming the store, the access group, the devices permitted, and the people inside it.
- A data flow description showing every point at which the information enters, moves, and leaves.
Self assessment against all 110 practices
Months 1 and 2 after activationScore every practice honestly, so the plan that follows is built on the real position rather than on an optimistic reading.
Finished when
- Every one of the 110 practices scored met, not met, or not applicable, with the evidence reference or the reason recorded.
- A supplier performance score calculated from the assessment using the published scoring method.
- Every practice we rely on a client or a platform to provide named, with the responsibility recorded against that party.
System security plan and remediation
Months 2 to 5 after activationProduce the system security plan an assessor will read first, and close the practices that a plan of action is not permitted to cover.
Finished when
- A system security plan describing the enclave, the practices, the implementation of each, and the people responsible.
- A plan of action and milestones for every practice not met, each with an owner, a date, and a cost.
- Every practice that must be fully met at assessment closed rather than deferred.
Evidence operating over time
Months 4 to 9 after activationProduce the dated, repeated evidence an assessor tests, rather than a snapshot assembled the week before.
Finished when
- Three consecutive months of access reviews, vulnerability cycles, and log reviews completed on schedule.
- One tabletop exercise and one recovery test completed inside the enclave scope.
- Awareness training completed by everyone permitted inside the enclave, with records.
Score submission and third party assessment
Months 9 to 12 after activationSubmit an accurate score and pass a third party assessment without surprises on the day.
Finished when
- The score submitted to the government reporting system with the assessment date and scope.
- A readiness review completed against the assessment guide, with no open item that blocks certification.
- An assessment organization engaged, with the scope, timing, and fee agreed in writing.
What a buyer or a prime contractor should ask us
- Are you CMMC certified
- No. We hold no CMMC certification at any level, we have no assessment booked, and we have not submitted a supplier performance score. Any solicitation requiring a certified contractor is one we team on or decline.
- Do you hold controlled unclassified information today
- No. No current engagement places federal contract information or controlled unclassified information in our hands. If one did, the enclave and the plan described here activate before the information is received.
- What can you evidence right now
- The control register with owners and dated evidence, the scope boundary method, the self assessment method, the risk method, and the access, vulnerability, and incident procedures that most of the 110 practices depend on.
- How quickly could you be assessment ready
- Nine to twelve months from activation on the plan set out here, assuming a single enclave boundary and no controlled information moving outside it. We will not quote a shorter window to win work.
- Can you advise us on our own CMMC position
- Yes. Readiness advisory is a service we deliver, using the same scope boundary, self assessment, system security plan, and remediation method we apply to ourselves. We disclose our own status to every client we advise.
Open items, stated plainly
12 of the fourteen families carry open work. The largest single dependency is central log collection and alerting, which several families rely on. It is scheduled for months two to four of the readiness timeline with a named owner.