Skip to content

Service

CMMC and DFARS compliance

Pierce County has a dense defence supply base around Joint Base Lewis McChord, and requirements flow down the chain to businesses that never contract with the government directly. The single most consequential decision is scoping, because it determines whether you are securing one system or your entire company.

Level 2 control count

110

NIST SP 800-171 controls

Scope determines how many systems each control has to cover. Get scoping wrong and everything downstream is wrong.

The three levels

Most suppliers in this region sit at Level 1 or Level 2, and the gap between them is substantial in both control count and cost.

CMMC levels, the data each covers, control counts and assessment type
LevelData handledAssessment
Level 117 basic safeguarding practicesFederal contract information onlyAnnual self assessment
Level 2110 NIST 800-171 controlsControlled unclassified informationThird party assessment for most, self assessment for some
Level 3110 controls plus additional requirementsHighest priority programmesGovernment led assessment

General information about the framework, not legal or contractual advice. Confirm the requirements applicable to your specific contracts with your contracting officer or prime contractor.

What you have to produce

Assessment is a documentation exercise as much as a technical one. Six artefacts carry most of the weight.

Required CMMC documentation artefacts and their purpose
ArtefactWhat it is
System security planRequired. An assessor reads this firstDescribes how each control is implemented in your environment
Plan of action and milestonesRequired where controls are not yet metLists gaps, owners and target dates
SPRS scoreRequired before contract award in many casesA numeric self assessment score submitted to the government
Asset inventory and scoping documentScoping errors are the most expensive mistake availableDefines exactly which systems hold controlled information
Policies and proceduresAssessors check practice against document, not just existenceWritten, current, and matching actual practice
Evidence of operationControls must be shown operating, not merely configuredLogs, review records, training completion

Five scoping errors

Scoping decides the size of the entire programme. These five account for most of the wasted money in this space.

  • Treating the entire company network as in scope when controlled information lives in one system, which multiplies the control burden enormously
  • Treating scope as narrower than it is, which fails assessment and can carry contractual consequences
  • Forgetting that backups, email and file sharing carry controlled information wherever it travels
  • Assuming a cloud provider's certification covers your configuration of their service, which it does not
  • Overlooking personal devices and home working arrangements that touch controlled data

The enclave approach

The most cost effective pattern for a small supplier is usually to stop controlled information spreading across the whole business and instead contain it in a defined enclave: a specific set of systems, accounts and storage locations, separated from general company operations.

The 110 controls then apply to that enclave rather than to every laptop in the building. The rest of the business is secured well, because it should be, but it is not carrying assessment scope.

This requires discipline about where controlled material is allowed to travel, which is a process problem more than a technical one. Email is usually the hardest part, because it is where controlled documents most often leak into general scope without anyone deciding they should.

Common questions

Answered before you ask.

How do we know which level applies to us?

It follows from the data your contract requires you to handle. Federal contract information alone puts you at Level 1 with a modest set of basic safeguards. Controlled unclassified information brings Level 2 and the full 110 control set from NIST 800-171. The reliable way to establish this is to ask your prime contractor or contracting officer which category applies to the specific contract, in writing. Guessing in either direction is expensive: over-scoping wastes substantial money, under-scoping risks the contract.

How long does Level 2 readiness take?

For a business starting from a typical commercial baseline, plan on a year to be comfortable, though the range is wide. Technical controls generally move within three to six months. What extends the timeline is documentation, policy that matches actual practice, and the evidence requirement, because several controls have to be shown operating over a period rather than merely switched on. Businesses that already run multi factor authentication, endpoint detection, logging and managed backup start considerably further along.

What is an SPRS score and can it be negative?

It is a self assessment score against the NIST 800-171 controls, submitted to a government system, and yes it can be negative. The scoring begins at 110 and deducts weighted points for each control not implemented, with the most significant controls carrying the heaviest deductions. A low or negative score is not automatically disqualifying, but it is visible to contracting officers and it sits alongside a plan of action showing how and when the gaps close.

We supply Joint Base Lewis McChord indirectly. Does this apply?

Frequently yes. Requirements flow down through the supply chain, so a subcontractor handling controlled unclassified information carries obligations even without a direct government contract. The trigger is the data you handle rather than your position in the chain. If a prime contractor sends you technical drawings, specifications or other controlled material, ask them explicitly what flows down to you and get the answer in writing.

Start with scoping, not with controls.

The assessment establishes which systems actually hold controlled information. Businesses routinely discover the scope is far smaller, or far larger, than assumed.

CallFree assessment