CMMC Compliance Services for Defense Suppliers

CMMC 2.0 enforcement is live: the acquisition rule took effect November 10, 2025, and CMMC clauses are in DoD contracts today. On July 13, 2026 the Department of War suspended the Phase 2 third-party assessment phase-in pending a program review — but DFARS 252.204-7012 still requires NIST SP 800-171, and a current SPRS score with an annual affirmation is still a condition of award. The certification calendar paused. The legal obligation did not.

We get Southern California machine shops, precision manufacturers, and subcontractors ready: scoping CUI, implementing the 110 NIST 800-171 controls, and building the evidence your assessor will ask for. We prepare you for your C3PAO assessment — we are not a C3PAO, and we don't certify anyone. That distinction matters, and we lead with it.

What CMMC 2.0 actually demands

Update — July 13, 2026: the Department of War suspended CMMC Phase II and paused the Phase III and IV milestones, ordering a program review. For existing contracts carrying a Level 2 (C3PAO) or Level 3 (DIBCAC) requirement, contracting officers are directed to remove that requirement by modification, before the next option period or administrative modification. Level 1 (Self) and Level 2 (Self) designations remain, and no waivers are granted during the review. What did not change: DFARS 252.204-7012 still requires NIST SP 800-171, DFARS 252.204-7019 and -7020 still require a current SPRS score and annual affirmation, Phase 1 self-assessments remain in force, and government-led DIBCAC assessments continue. A suspended phase-in is not a repealed rule. Read the suspension memorandum →

The program rule (32 CFR) took effect December 16, 2024; the acquisition rule (48 CFR) followed on November 10, 2025, putting CMMC requirements into contracts. Three levels, keyed to the data you handle:

LevelDataRequirementsHow it's assessed
Level 1 — FoundationalFederal contract information (FCI)15 basic safeguarding requirementsAnnual self-assessment + executive affirmation
Level 2 — AdvancedControlled unclassified information (CUI)The 110 requirements of NIST SP 800-171C3PAO assessment every three years for most contracts; self-assessment for a smaller set — plus affirmations
Level 3 — ExpertCUI on the most sensitive programs110 from NIST SP 800-171 + 24 from NIST SP 800-172Government-led assessment
CMMC 2.0 ladder: Level 1 Foundational, 15 practices with annual self-assessment; Level 2 Advanced, 110 NIST SP 800-171 controls with C3PAO assessment every three years for most contracts; Level 3 Expert, adding 24 NIST SP 800-172 requirements with government-led assessment

Want the full rulemaking story, timeline, and prep sequence? Read our deep dive: CMMC 2.0 — what defense suppliers need to do now.

A passive alarm versus a shield actively containing a threat, representing the gap between ordinary IT and CMMC-ready IT

IT-as-usual is not CMMC-ready IT

Most suppliers we meet have working IT and real gaps against NIST 800-171 — not because anyone was careless, but because ordinary business IT was never asked to evidence itself. The pattern repeats:

  • Nobody can say precisely where CUI lives — it is in email threads, quoting folders, and a shared drive named Engineering
  • No System Security Plan, no POA&M, and an SPRS score nobody wants to sign
  • MFA on some logins, logging nobody reviews, backups nobody has test-restored

Closing that gap is the same discipline as managed security done properly — plus documentation that proves it. That second half is where preparation lives or dies.

The honest part

We prepare you. Your C3PAO assesses you.

CMMC deliberately separates the people who get you ready from the people who judge the result — the same reason your accountant doesn't audit their own books. So here is our lane, stated plainly: CRC Cloud prepares defense suppliers for their C3PAO assessment. We are not a C3PAO, we do not conduct certification assessments, and we never promise a certificate. Anyone who promises one is selling something the rules don't allow.

The pressure is real either way: primes are asking subcontractors for SPRS scores and remediation plans ahead of contract deadlines, a current SPRS score and annual affirmation remain conditions of award, and that affirmation is a signed legal statement the Department of Justice's Civil Cyber-Fraud Initiative watches under the False Claims Act. Preparation done honestly — scoped, implemented, documented — is what turns that pressure back into ordinary work.

How CRC Cloud gets you assessment-ready

Four moves, in order. Scope first — because every control you don't need to apply everywhere is money saved.

1 · Scope the CUI

Find where FCI and CUI actually live, then shrink the footprint — often with an enclave strategy that concentrates CUI into one contained, hardened environment instead of 110 controls across the whole company.

2 · Implement 800-171 controls

Close the gap assessment findings with a prioritized, costed plan: MFA and access control, hardening, encryption, logging, media and remote-work rules — mapped requirement by requirement.

3 · Document & evidence

System Security Plan support, policies, training records, and the artifacts assessors ask for — so your SPRS score is one your senior official can affirm truthfully. We also keep your plan of action honest: the rules only let a narrow set of low-value items sit on a POA&M, and only for 180 days, so we work to close them rather than to list them. Your customer responsibility matrix — which of the 110 requirements we own, which you own, which are shared — is a deliverable of the engagement, not something we assemble the week the assessor arrives.

4 · Operate & monitor

24/7 SOC monitoring, SIEM, and managed detection and response keep the monitoring, response, and audit-log requirements operating between assessments — not just written down. Application allowlisting — only approved software can run — covers the software-execution controls (CM.L2-3.4.8) assessors check by hand, and the annual vendor risk review answers the supply-chain questions that now open every assessment.

For CUI itself, be aware of the boundary: DFARS 252.204-7012 requires a cloud service provider at FedRAMP Moderate (or equivalent) before covered defense information may be stored or processed there — SOC 2, ISO 27001 and Tier III-standard design do not satisfy that test, and CRC Cloud does not hold a FedRAMP authorization. We keep CUI workloads scoped to systems that meet the requirement and align everything around them.

Built for Southern California's defense ecosystem

Southern California's supplier base is exactly who CMMC lands on hardest: machine shops, precision and aerospace manufacturers, engineering firms, and government contractors with real DoD-adjacent work and a two-person (or zero-person) IT department. We support that supply chain from Orange County and Los Angeles out to the high desert — including Yucca Valley, Joshua Tree, and the contractors around the Twentynine Palms Marine base.

CMMC is one of ten frameworks we align IT to — if your work spans more than defense, start at the compliance overview or the foundation itself, NIST CSF 2.0.

CMMC, asked and answered

Is CRC Cloud a C3PAO? Can you certify us?

No, and no MSP can. Level 2 certification comes only from an assessment by an authorized C3PAO (CMMC Third-Party Assessment Organization), and Level 3 assessments are government-led. Our role is everything before and after that visit: scoping, gap assessment against NIST 800-171, remediation, documentation, and the managed security that keeps you assessment-ready. The separation between preparers and assessors is deliberate — be wary of anyone who blurs it.

What CMMC level do we need?

The data decides. Federal contract information (FCI) generally means Level 1 — 15 basic safeguarding requirements with an annual self-assessment and executive affirmation. Controlled unclassified information (CUI) generally means Level 2 — the 110 requirements of NIST SP 800-171, with C3PAO assessment for most contracts and self-assessment allowed for a smaller set. Level 3 adds 24 requirements from NIST SP 800-172 with government-led assessment, for the most sensitive programs. Your solicitation states the required level.

How long does CMMC Level 2 preparation take?

For most small suppliers, the honest answer is quarters, not weeks. The 110 requirements include policy, documentation, and evidence work as well as technical fixes — and while the November 2026 third-party phase-in was suspended in July 2026, the underlying NIST 800-171 obligation under DFARS 252.204-7012 never paused. Starting after a solicitation names CMMC is usually starting late.

What does CMMC readiness cost?

It depends almost entirely on scope — which is why scoping comes first. Many suppliers save real money with an enclave strategy: concentrating CUI into a contained, hardened environment so the 110 controls apply to one enclave instead of the whole company. The managed-security base is Secure IT at $250 per user per month, and CMMC/DFARS work carries a published +25% uplift on the per-user plan and per-server management — $312.50 per user — covering the system security plan, plan of action and milestones, and assessment support. The one-time 800-171 gap assessment and remediation projects are quoted in writing after the initial gap read.

What is an SSP, and why does everyone keep asking for it?

The System Security Plan is the document that explains how your environment meets each of the 110 requirements — it is the artifact your assessor works from, alongside a plan of action for open items (POA&M) and your SPRS score. That score carries a senior official's affirmation, which is a legal statement the Department of Justice's Civil Cyber-Fraud Initiative has shown it takes seriously. We help build and maintain all three so they reflect reality.

We're two tiers below the prime. Does CMMC really reach us?

If FCI or CUI flows down to you, yes. Primes are required to flow CMMC requirements to subcontractors, and many are already asking for SPRS scores and remediation plans ahead of contract deadlines because their own awards depend on the answers. A machine shop with one drawing of CUI on a shared drive is in scope.

Can our CUI systems live in your private cloud?

Short answer: no. Under DFARS 252.204-7012, a cloud that stores, processes or transmits CUI must be FedRAMP Moderate authorized, or validated as FedRAMP Moderate equivalent by a third-party assessor. CRC Cloud's private cloud is neither. Datacenter credentials like SOC 2 and ISO 27001 are facility facts. They do not satisfy that rule, and a provider who implies otherwise is setting you up to fail. CUI belongs in an environment built for it, such as Microsoft 365 GCC High — and what we do is run that environment for you.

We prepare it, close the gaps we find, and organize the evidence. The goal is that the assessment becomes a confirmation rather than a discovery exercise — but it is an independent judgement, and we will never call it a formality. If the assessor still flags something, we remediate it fast. Our private cloud is the right home for everything that never touches CUI. Splitting the two is usually the cheapest way to shrink your scope.

Can we just put the gaps on a POA&M and fix them later?

Far less than most suppliers assume, and the rule is specific. Under 32 CFR 170.21, a plan of action and milestones is not permitted at all for a Level 1 self-assessment. At Level 2 you may only carry one if your assessment score is at least 0.8 of the total — 88 of the 110 requirements — and nothing on the plan is worth more than 1 point under the CMMC scoring methodology. Since 3-point and 5-point requirements make up most of the hard ones, they must be genuinely met before the assessor scores them.

There is one narrow exception: CUI encryption (SC.L2-3.13.11) may go on the plan if you are encrypting but not yet with a FIPS-validated module. Six 1-point requirements are barred outright — external connections, control of public information, the System Security Plan itself, escorting visitors, physical access logs, and managing physical access. And a plan only earns you Conditional status: a closeout assessment must confirm the items are closed within 180 days of the conditional status date, or that status expires.

For a certification assessment the closeout must be done by an authorized C3PAO. In practice this means the plan is for the last few loose ends, not a way to defer the work.

You manage our IT. Does that put you inside our assessment?

Yes, and you should expect that of any provider worth hiring. Under 32 CFR 170, an external service provider is in scope when controlled unclassified information or security protection data is processed, stored or transmitted on its systems. Security protection data is the second trigger people miss — the logs, alerts, vulnerability findings, backup metadata and identity records that our monitoring and management tools hold. That means we are usually in scope even on engagements where no CUI ever reaches us.

The rule requires our relationship and the services we provide to be described in your System Security Plan, and it requires us to give you a customer responsibility matrix: a line-by-line statement of which of the 110 requirements we implement, which you implement, and which are shared and how. We produce that matrix as a named deliverable of the engagement, we keep it current as the environment changes, and we hand it to your assessor with the evidence behind it. If a provider cannot give you one, they are not ready to support a CMMC assessment.

Priced openly, like everything else we do. CMMC / DFARS work carries a published uplift of +25% on the per-user plan and per-server management fee — documentation, evidence and audit support are real recurring hours, so we price them instead of hiding them in a quote. Secure IT is the starting point for compliance work — Core IT is not an option for a regulated environment, because the frameworks lean on the monitored layer it adds. On Secure IT that is $312.50 per user per month — covering the system security plan, plan of action & milestones, enclave design and assessment support. Backup, private cloud resources and add-ons stay at their flat published rates. See the full compliance uplift table →

Get your CMMC gap read in one 30-minute call

A free call with the owner: where your CUI lives, how far you are from the 110 controls, and what to fix first.

Book the Free CMMC Gap Read