CMMC 2.0 is flowing into DoD contracts across the supply chain. If your Ohio company touches CUI as a prime or a sub, the network controls have to match.
The Cybersecurity Maturity Model Certification framework is being phased into DoD contracts. If your company handles Controlled Unclassified Information or Federal Contract Information - or subcontracts to someone who does - you have obligations before your next contract is at risk.
Ohio's defense industrial base is concentrated around Wright-Patterson in the Dayton area, Columbus, and Northeast Ohio, but CMMC applies anywhere in the DoD supply chain regardless of location or contract size. The common mistake: assuming a prime's certification covers you. It does not. Each company that handles CUI is independently responsible.
Our scope is the network and communications infrastructure - access control, audit logging, system and communications protection, configuration management. We are an advisor, not a C3PAO and not an assessor. We cannot certify you, and any vendor who says they can is selling something.
Which level applies depends on what data you handle and how the contract is written.
| Level | Practices | Assessment |
|---|---|---|
| Foundational (Level 1) | 15 practices - basic cyber hygiene covering access control, identification, media and physical protection | Annual self-assessment |
| Advanced (Level 2) | 110 practices based on NIST SP 800-171, required for handling CUI | Third-party C3PAO assessment for prioritized acquisitions; self-assessment otherwise |
| Expert (Level 3) | 110+ practices based on NIST SP 800-172 | Government-led assessment, highest-priority programs only |
Level 2 covers 110 practices across 14 domains. These are the network and communications domains we work in.
We review network architecture, access controls, audit logging, and communications security against the 110 practices. You get a written report scored practice by practice, in the format an assessor uses.
We define and document the systems, networks, and users in scope. This is the foundation of your System Security Plan and the starting point for every other control.
Segmentation, access controls, MFA, audit logging, and communications encryption get implemented alongside your existing IT team, with documentation written for the SSP.
The partner we place maintains the Plan of Action and Milestones and monitors the CUI environment. We source that partner, hold them to it, and keep the documentation current so you are assessment-ready on any given day.
Free gap assessment against NIST SP 800-171, written practice by practice.