Service
CMMC and DFARS compliance
Pierce County has a dense defence supply base around Joint Base Lewis McChord, and requirements flow down the chain to businesses that never contract with the government directly. The single most consequential decision is scoping, because it determines whether you are securing one system or your entire company.
Level 2 control count
110
NIST SP 800-171 controls
Scope determines how many systems each control has to cover. Get scoping wrong and everything downstream is wrong.
The three levels
Most suppliers in this region sit at Level 1 or Level 2, and the gap between them is substantial in both control count and cost.
| Level | Data handled | Assessment |
|---|---|---|
| Level 117 basic safeguarding practices | Federal contract information only | Annual self assessment |
| Level 2110 NIST 800-171 controls | Controlled unclassified information | Third party assessment for most, self assessment for some |
| Level 3110 controls plus additional requirements | Highest priority programmes | Government led assessment |
General information about the framework, not legal or contractual advice. Confirm the requirements applicable to your specific contracts with your contracting officer or prime contractor.
What you have to produce
Assessment is a documentation exercise as much as a technical one. Six artefacts carry most of the weight.
| Artefact | What it is |
|---|---|
| System security planRequired. An assessor reads this first | Describes how each control is implemented in your environment |
| Plan of action and milestonesRequired where controls are not yet met | Lists gaps, owners and target dates |
| SPRS scoreRequired before contract award in many cases | A numeric self assessment score submitted to the government |
| Asset inventory and scoping documentScoping errors are the most expensive mistake available | Defines exactly which systems hold controlled information |
| Policies and proceduresAssessors check practice against document, not just existence | Written, current, and matching actual practice |
| Evidence of operationControls must be shown operating, not merely configured | Logs, review records, training completion |
Five scoping errors
Scoping decides the size of the entire programme. These five account for most of the wasted money in this space.
- Treating the entire company network as in scope when controlled information lives in one system, which multiplies the control burden enormously
- Treating scope as narrower than it is, which fails assessment and can carry contractual consequences
- Forgetting that backups, email and file sharing carry controlled information wherever it travels
- Assuming a cloud provider's certification covers your configuration of their service, which it does not
- Overlooking personal devices and home working arrangements that touch controlled data
The enclave approach
The most cost effective pattern for a small supplier is usually to stop controlled information spreading across the whole business and instead contain it in a defined enclave: a specific set of systems, accounts and storage locations, separated from general company operations.
The 110 controls then apply to that enclave rather than to every laptop in the building. The rest of the business is secured well, because it should be, but it is not carrying assessment scope.
This requires discipline about where controlled material is allowed to travel, which is a process problem more than a technical one. Email is usually the hardest part, because it is where controlled documents most often leak into general scope without anyone deciding they should.
Common questions
Answered before you ask.
How do we know which level applies to us?
It follows from the data your contract requires you to handle. Federal contract information alone puts you at Level 1 with a modest set of basic safeguards. Controlled unclassified information brings Level 2 and the full 110 control set from NIST 800-171. The reliable way to establish this is to ask your prime contractor or contracting officer which category applies to the specific contract, in writing. Guessing in either direction is expensive: over-scoping wastes substantial money, under-scoping risks the contract.
How long does Level 2 readiness take?
For a business starting from a typical commercial baseline, plan on a year to be comfortable, though the range is wide. Technical controls generally move within three to six months. What extends the timeline is documentation, policy that matches actual practice, and the evidence requirement, because several controls have to be shown operating over a period rather than merely switched on. Businesses that already run multi factor authentication, endpoint detection, logging and managed backup start considerably further along.
What is an SPRS score and can it be negative?
It is a self assessment score against the NIST 800-171 controls, submitted to a government system, and yes it can be negative. The scoring begins at 110 and deducts weighted points for each control not implemented, with the most significant controls carrying the heaviest deductions. A low or negative score is not automatically disqualifying, but it is visible to contracting officers and it sits alongside a plan of action showing how and when the gaps close.
We supply Joint Base Lewis McChord indirectly. Does this apply?
Frequently yes. Requirements flow down through the supply chain, so a subcontractor handling controlled unclassified information carries obligations even without a direct government contract. The trigger is the data you handle rather than your position in the chain. If a prime contractor sends you technical drawings, specifications or other controlled material, ask them explicitly what flows down to you and get the answer in writing.
Related
What sits alongside this.
IT compliance and risk
HIPAA, CMMC, PCI DSS and cyber insurance requirements.
Cybersecurity services
Endpoint detection, email security, monitoring and user training.
Backup and disaster recovery
Immutable backups with tested restores and a defined recovery window.
Cybersecurity risk assessment
Vulnerability scanning, penetration testing and a prioritised findings register.
What managed IT services cost in Tacoma
Per user pricing bands, what moves the number up, and how to read a quote.
Start with scoping, not with controls.
The assessment establishes which systems actually hold controlled information. Businesses routinely discover the scope is far smaller, or far larger, than assumed.