CST-360: Protecting what matters

CMMC & Defense Supply Chain Compliance

If your contracts touch Controlled Unclassified Information, your compliance posture is now a condition of doing business.

What this is

How we approach it

We take suppliers through CMMC readiness against NIST SP 800-171 and the DFARS 252.204-7012 clause: what is actually in scope, where the CUI really flows, and which of the 110 controls you can evidence today.

The output is the artefact set an assessor expects: a scoped System Security Plan, a POA&M that is honest about gaps, and an SPRS score you can defend, not a spreadsheet of aspirations.

CMMC 2.0NIST SP 800-171DFARS 252.204-7012NIST SP 800-172
What you get5 deliverables
  • CUI scoping: data flows, enclave boundary, and what can be taken out of scope
  • Gap assessment against all 110 NIST SP 800-171 controls
  • System Security Plan (SSP) and POA&M
  • SPRS score calculation and submission support
  • C3PAO assessment preparation and evidence walkthrough

Who this is for

You will recognise yourself here

Defense suppliers and subcontractors whose contracts carry the DFARS 252.204-7012 clause Primes flowing CMMC requirements down to their supply chain Israeli and European vendors selling into the US Department of Defense supply chain Manufacturers, engineering firms and software vendors that receive Controlled Unclassified Information

How an engagement runs

Four stages

Each stage produces something you keep, whether or not you continue to the next one.

ScopeWe establish where Controlled Unclassified Information actually enters, lives and leaves. Most of the cost of CMMC is decided here: a tightly drawn CUI enclave can take the majority of your estate out of assessment scope entirely.
AssessA control-by-control gap assessment against all 110 practices in NIST SP 800-171 Revision 2, with the assessment objectives from NIST SP 800-171A. You get an honest current score, not an optimistic one.
RemediateWe sequence remediation by SPRS point value and effort, so the score moves as fast as the budget allows. Where a control cannot be met yet, it goes into the POA&M with a date and an owner.
EvidenceWe build the System Security Plan and the artefact set a C3PAO assessor will ask for, then walk your team through the questions they will be asked before assessment day.

Questions we get asked

Straight answers

Do we need CMMC Level 1 or Level 2?

Level 1 applies if you only handle Federal Contract Information; Level 2 applies once Controlled Unclassified Information is in play and mirrors the 110 controls of NIST SP 800-171. The scoping step settles it, and the answer determines whether you need a self-assessment or a C3PAO assessment.

How long does CMMC readiness take?

It depends on how much you can take out of scope. A tightly scoped CUI enclave can be assessment-ready in a few months; a flat network handling CUI everywhere takes considerably longer, which is exactly why scoping comes first.

Can you write the SSP and POA&M for us?

Yes. We author the System Security Plan and POA&M with your team, so the documents describe the environment you actually run and your people can defend them under assessment.

Does a low SPRS score stop us bidding?

A current self-assessment score in SPRS is a condition of many awards, and a low score is a competitive disadvantage rather than an automatic disqualification. We prioritise the controls that move the score most per unit of effort.

Other services

Often scoped together

Let's talk

Plan your security

Pick the conversation that fits. We will spend the time on your actual exposure, not on a slide deck.

Security incident? Mark it urgent when you book.