FAQ

Common questions

Is CMMC cancelled?
Can you promise us a score or a certification?

No. We don’t predict results, and we don’t certify anyone. Our fee never depends on your score.

I already posted a score. Is that a problem?

Not necessarily. If you’re not sure your posted score matches your documents, it’s worth checking. We’ll show you the posted score next to what your documents support. If they don’t match, we’ll suggest you talk with your attorney.

We only handle FCI, not CUI. Do we need you?

Probably not. Our work is built around Level 2. One thing worth knowing either way: at Level 1, a plan of action isn’t allowed at any time. All 15 requirements need to be met before the yearly affirmation is signed.

We’re AS9100 certified. Does that cover CMMC?

No. AS9100 is a quality management standard: it shows how you control the quality of your work. CMMC Level 2 is about protecting controlled unclassified information, measured against the 110 requirements in NIST SP 800-171. One doesn’t count toward the other.

What AS9100 does give you is the habit of written procedures, document control and records. Documentation you already have is one of the things that can bring the price down: see what moves the price.

My machines are old. Does that sink me?

No. Equipment that can’t meet a requirement, like an older machine controller, can be documented as an enduring exception: isolated, and described in your System Security Plan with its mitigations. Age alone isn’t a barrier.

Will you see our drawings?

No. We look at where information goes, not at the information itself. We don’t open, copy, or take drawings or files.

What does our IT provider still do?

All the technical work: installing, setting up, and running your systems. The plan of action we write gives them a list of what’s left to do.

Do we need GCC High or an enclave?

That’s a decision for you and your IT provider. GCC High is Microsoft’s government cloud. An enclave keeps defense work on a separate, smaller set of computers.

The right choice depends on where your controlled information actually goes, and the scope map shows exactly that. Whichever setup you choose, we document it. We don’t sell either one.

What does it cost, and how long does it take?

The 15-minute call with Juan is free. The scope map is $2,000 to $3,500, and the full write-up is $7,500 to $15,000. Both are fixed fees; here’s what moves the price. The site visit takes two to four hours, and we agree on a schedule for the rest before we start.

What should we ask our prime?

These questions settle most of what you need to know:

  • Which cybersecurity clauses are in our contracts and purchase orders?
  • Will you send us controlled unclassified information (CUI), and how will it be marked?
  • Which CMMC level will you require of us, and by when?
  • Is any of the technical data export-controlled (ITAR or EAR)?
  • How will drawings reach us: by email, through a portal, or some other way?

Bring the answers to the first call.

What should we ask anyone we hire for this, including you?
  • Will you take our drawings or files? We don’t.
  • Will you need our SPRS or PIEE logins? We don’t.
  • Do you promise a score or a certification? We don’t, and no one can honestly promise either.
  • Is the price fixed, and what’s included? Ours is fixed and published on our services and prices page.
  • Do you also sell IT services, software or licenses? We don’t.
  • Who checks the documents before we get them? A second person checks every one.
  • Could you also be the one who certifies us later? Under the CMMC rule, anyone who helped prepare you can’t take part in your Level 2 certification assessment for three years. We don’t certify anyone.

Glossary

Terms in CMMC paperwork

The terms you’ll see in CMMC paperwork, in plain words.

CMMC Cybersecurity Maturity Model Certification

The Defense Department program that checks whether contractors and subcontractors have put required cybersecurity requirements in place. 32 CFR 170.1

CUI Controlled Unclassified Information

Information the government creates or has, or that someone creates or has for the government, that must be handled with safeguarding or sharing controls. It isn’t classified. 32 CFR 2002.4(h)

FCI Federal Contract Information

Information made for or given by the government under a contract, not meant for the public. It doesn’t include public information or simple payment details. 48 CFR 4.1901

SPRS Supplier Performance Risk System

The Defense Department’s system for supplier performance information, where your summary self-assessment score is posted. SPRS

SSP System Security Plan

The formal document that gives an overview of the security requirements for your information system. 32 CFR 170.4

POA&M Plan of Action and Milestones

A document listing the tasks still to do, what they need, the milestones, and planned completion dates. 32 CFR 170.4

DFARS Defense Federal Acquisition Regulation Supplement

The Defense Department’s additions to the federal buying rules. Its clauses, like 252.204-7012, go into defense contracts. acquisition.gov

NIST National Institute of Standards and Technology

The federal agency that publishes SP 800-171, the standard your score is measured against. nist.gov

C3PAO CMMC Third-Party Assessment Organization

A firm authorized or accredited to conduct Level 2 certification assessments. 32 CFR 170.4

DIBCAC Defense Industrial Base Cybersecurity Assessment Center

The government’s own assessment team, part of the Defense Contract Management Agency. 32 CFR 170.4

PIEE Procurement Integrated Enterprise Environment

The Defense Department portal you log in through to reach SPRS. SPRS

Contact

Talk to us

Call or email Josh. He’ll book a free 15-minute call with Juan, who answers the technical questions.

We don’t record calls.

Please don’t send drawings, contracts, or controlled information by email or through this site.