We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Security & Compliance
  2. CMMC 2.0 Compliance
CMMC 2.0 Compliance USA

CMMC 2.0 readiness, assessed, remediated, and audit-ready.

The Cybersecurity Maturity Model Certification (CMMC) 2.0 is the US Department of Defense's mandatory cybersecurity framework for the Defense Industrial Base. Level 1 requires 17 basic controls, Level 2 requires 110 NIST 800-171 controls, Level 3 adds 35 NIST 800-172 controls. GR IT Services runs CMMC readiness assessments, closes the gaps, and prepares C3PAO-ready evidence packs.

Book a CMMC readiness reviewSee gap-assessment phases
Defense Industrial Base IT operations
  • Level 1-3All tiers
  • 110+35Controls covered
  • C3PAOAudit-ready
  • GCC HighMicrosoft alignment
What we deliver

CMMC engagements built for the Defense Industrial Base.

Nine capability areas covering everything a DoD contractor needs between contract award and CMMC certification.

Scoping & boundary definition

Identify CUI and FCI in your environment, draw the assessment boundary, document data flows, and right-size the scope so the certification covers what the contract demands, and nothing more.

Readiness gap assessment

Map your current state against all 110 NIST 800-171 Level-2 controls (or 17 Level-1 / 145 Level-3). Output: written gap report, remediation plan, and cost-to-close estimate.

System Security Plan (SSP)

Author and maintain the SSP, the central CMMC document covering control implementation, system boundaries, and responsibility assignments. Updated through every control change.

Plan of Action & Milestones (POAM)

POAM tracking with weekly stand-ups, owned remediation tasks, and evidence collection. Visible, accountable, audit-ready progress against every gap.

Technical control remediation

Endpoint hardening (CIS Benchmarks), Entra MFA enforcement, Defender deployment, encryption at rest and in transit, network segmentation, FIPS 140-validated cryptography.

CUI environment build (GCC High)

Migrate CUI workloads to Microsoft 365 GCC High when contract requirements call for it. Tenant provisioning, identity migration, eDiscovery handover, audit-log retention.

Incident-response program

Written IR plan aligned to NIST SP 800-61, tabletop exercises, on-call rotation, DoD reporting workflow under DFARS 252.204-7012 (72-hour incident notification).

Continuous-monitoring stack

Microsoft Sentinel SIEM or Splunk integration, audit-log retention beyond CMMC defaults, vulnerability scanning, and configuration-drift detection on the in-scope environment.

C3PAO pre-audit dry run

Full-scope dress rehearsal against the CMMC assessment guide before the C3PAO walks in. Closes residual findings; no surprises on assessment day.

Why GR IT for CMMC

Four reasons DoD contractors pick us for the readiness journey.

CMMC is a written-evidence regime, not a checkbox exercise. Here is what makes our delivery different.

NIST 800-171 fluency

Every consultant on our CMMC bench has run a NIST 800-171 self-assessment to completion. We know which controls auditors actually probe and which evidence formats they accept.

Microsoft GCC High partner

Verified GCC High deployment experience. We handle Microsoft eligibility validation, tenant provisioning, and the migration of CUI workloads from commercial M365.

Nationwide remote-first delivery

Remote-first delivery across the US Defense Industrial Base corridor (DC metro, Huntsville, Boulder, San Diego, Boston), with on-site presence arranged through vetted partners where an engagement requires it.

Evidence pack as a deliverable

We do not just close the gaps. We deliver the binder: SSP, POAM, control evidence index, IR runbook, training records, vulnerability scan history. Hand it to the C3PAO unedited.

Industries we work with

CMMC engagements across the Defense Industrial Base.

Five DIB segments where we have run CMMC readiness to certification-ready state.

Defense manufacturers

Tier-2 and Tier-3 prime suppliers handling CUI on engineering drawings, ITAR-controlled data, and quality records. Typical scope: 50-300 engineering endpoints.

Aerospace & component suppliers

Avionics, propulsion, and component vendors with CMMC Level 2 requirements flowing down from primes like Lockheed, Boeing, RTX, Northrop. Mixed cleared/uncleared environments.

DoD professional services

Federal consultancies, integrators, and SaaS vendors handling FCI in DoD engagements. CMMC Level 1 baselines through Level 2 readiness as contracts ramp up.

Logistics & supply chain

DoD-supplying logistics firms, freight forwarders, and supply-chain vendors handling shipment data, inventory feeds, and routing information classified as CUI.

Higher-ed research & federally funded R&D

University labs and FFRDC-affiliated researchers handling CUI in DoD-funded research projects. CMMC Level 2 with NIST SP 800-171 baselines tuned for academic environments.

Federal SaaS / cloud-services vendors

SaaS vendors selling into DoD where CMMC certification or FedRAMP authorization is a contracting prerequisite. Often paired with our FedRAMP-readiness engagements.

CMMC levels at a glance

Level 1 vs Level 2 vs Level 3 - what each requires.

The three CMMC 2.0 levels and what your contract actually obligates you to implement. We map your contract clauses to the correct level in scoping.
Controls required
CMMC Level 117 (FAR 52.204-21)
CMMC Level 2110 (NIST 800-171)
CMMC Level 3110 + 35 (800-172)
Data covered
CMMC Level 1Federal Contract Info (FCI)
CMMC Level 2Controlled Unclassified Info (CUI)
CMMC Level 3CUI with APT threat
Assessment type
CMMC Level 1Self-assessment annual
CMMC Level 2C3PAO third-party every 3 yrs
CMMC Level 3DIBCAC government assessment
Affirmation cadence
CMMC Level 1Annual
CMMC Level 2Annual
CMMC Level 3Annual
POAM allowed at assessment?
CMMC Level 1No (controls in place)
CMMC Level 2Limited (180-day close)
CMMC Level 3No (all controls in place)
GCC High typically required?
CMMC Level 1
CMMC Level 2Often
CMMC Level 3
Typical readiness cost
CMMC Level 1Five figures
CMMC Level 2Low-to-mid six figures
CMMC Level 3Mid-to-high six figures
Typical engagement length
CMMC Level 12-4 months
CMMC Level 26-12 months
CMMC Level 312-18 months
Feature
CMMC Level 1
FCI only
CMMC Level 2
CUI (most contracts)
CMMC Level 3
CUI + APT defense
Controls required
17 (FAR 52.204-21)110 (NIST 800-171)110 + 35 (800-172)
Data covered
Federal Contract Info (FCI)Controlled Unclassified Info (CUI)CUI with APT threat
Assessment type
Self-assessment annualC3PAO third-party every 3 yrsDIBCAC government assessment
Affirmation cadence
AnnualAnnualAnnual
POAM allowed at assessment?
No (controls in place)Limited (180-day close)No (all controls in place)
GCC High typically required?
Often
Typical readiness cost
Five figuresLow-to-mid six figuresMid-to-high six figures
Typical engagement length
2-4 months6-12 months12-18 months
How a CMMC engagement runs

From scoping to C3PAO-ready in five phases.

A CMMC readiness engagement is six to twelve months for Level 2, twelve to eighteen for Level 3. Every engagement runs the same five phases with written milestones.
  1. 1

    Scoping & boundary

    2-3 weeks

    Identify CUI and FCI, document data flows, define the assessment boundary, and right-size scope. Output: scoping memo, asset inventory, written boundary diagram.

  2. 2

    Gap assessment

    3-4 weeks

    Map current-state controls against the level (17 / 110 / 145). Output: written gap report, prioritized remediation backlog, cost-to-close estimate.

  3. 3

    Remediation

    3-9 months

    Close technical gaps (MFA, encryption, segmentation, Defender, SIEM), policy gaps (SSP, IR plan, training program), and organizational gaps (governance, vendor risk).

  4. 4

    Pre-audit dry run

    2-3 weeks

    Full-scope mock assessment using the CMMC Assessment Guide. Close residual findings, finalise the evidence binder, brief the leadership team on auditor expectations.

  5. 5

    C3PAO audit support

    2-4 weeks

    Remote support during the C3PAO assessment, with on-site presence arranged where the assessment requires it. We sit with your team, answer auditor questions, and handle evidence presentation. Post-audit: remediation if findings, affirmation packet preparation.

Common CMMC questions

CMMC 2.0, frequently asked.

CMMC 2.0 entered phased rollout in October 2025 with a three-year ramp. Phase 1 (Oct 2025, Oct 2026): Level 1 and Level 2 self-assessment requirements appear in new DoD contracts. Phase 2 (Oct 2026, Oct 2027): Level 2 C3PAO third-party assessments required for select contracts. Phase 3 (Oct 2027, Oct 2028): Level 3 government-led assessments. By Oct 2028, all DoD contracts handling CUI require the appropriate level on award.

FCI (Federal Contract Information) is non-public information your company holds about a federal contract. CUI (Controlled Unclassified Info) is more sensitive: technical data, ITAR-controlled engineering drawings, financial data, source selection info. Level 1 covers FCI only. Level 2 and above cover CUI, which is why most DoD subcontracts trigger Level 2 today.

Not always. The DoD allows commercial cloud (including standard Microsoft 365) for CMMC Level 2 if you can implement the relevant FedRAMP-Moderate-equivalent baselines and document them in your SSP. In practice, GCC or GCC High is often the path of least resistance because Microsoft has pre-validated baselines aligned to FedRAMP Moderate / High. We scope the decision with you in the assessment phase.

For a typical 100-employee DoD subcontractor, the readiness engagement (gap assessment, remediation, SSP/POAM, dry-run) is scoped per engagement based on gap count and environment complexity. The C3PAO third-party assessment is billed separately by the assessor, ongoing CMMC sustainment is priced monthly after certification, and GCC High migration adds scope if you need it.

Six to twelve months on average for a Level 2 engagement. Drivers: existing security maturity, scope complexity (single environment vs multi-tenant), CUI footprint size, and leadership-engagement velocity. We deliver a written timeline in scoping with monthly milestones.

Limited. CMMC 2.0 Level 2 allows POAMs on a subset of controls, with a 180-day close-out window. Critical controls (encryption, MFA, audit logging, system & comms protection) must be in place at assessment. The auditor scores controls "MET", "NOT MET", or "NOT APPLICABLE", you get one POAM bite if your score is 88% or higher.

No. C3PAOs are independent assessors accredited by the Cyber AB. We are a readiness and remediation partner, we prepare you for the assessment, attend the audit alongside your team to answer engineer-level questions, and handle post-audit remediation. We can introduce you to vetted C3PAOs in the Cyber AB Marketplace.

Prime contractors increasingly flow CMMC requirements through their supply chain via subcontracts. If your prime contract is DFARS 252.204-7021 and your prime carries Level 2, you typically need to mirror that level at the appropriate scope. We help you decode the flow-down language in your subcontract and right-size the obligation.

CMMC borrows controls from NIST 800-171 (Level 2) and 800-172 (Level 3), both subsets of 800-53. FedRAMP is for cloud-service providers, not contractor environments, but a FedRAMP-Moderate authorized cloud is one of the easiest ways to inherit Level-2 controls. ITAR is independent: handling ITAR-controlled CUI may require GCC High and additional export-control screening on personnel.
Further reading

CMMC and DoD compliance resources.

Related compliance pillars and source documents our consultants maintain.

Cybersecurity audit & compliance services

The general-purpose audit pillar covering HIPAA, SOC 2, NYDFS, NIST CSF, ISO 27001, and PCI.

Learn more

Microsoft 365 for GCC and GCC High

Our Microsoft 365 pillar including the GCC and GCC High deployment paths for federal/DoD customers.

Learn more

Microsoft Sentinel SIEM

Continuous-monitoring SIEM platform that satisfies CMMC audit-log retention and SIEM control families.

Learn more
Ready for CMMC?

Book a CMMC readiness review.

Sixty-minute discovery call with a senior consultant. Output: a written first-cut gap estimate, level recommendation, and engagement scope. No obligation.

Book the readiness reviewSee cybersecurity audit pillar

Related Services

Explore more solutions that work great with this service

Microsoft 365

Complete Microsoft 365 setup, migration & support

Learn more

Microsoft Defender

Advanced endpoint and email threat protection

Learn more

Microsoft Sentinel

Cloud-native SIEM and threat intelligence

Learn more

Microsoft Purview

Data governance and compliance solutions

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA