Home/Resources/CMMC 2.0 in Ohio

CMMC Compliance for Ohio Defense Contractors

CMMC 2.0 is flowing into DoD contracts across the supply chain. If your Ohio company touches CUI as a prime or a sub, the network controls have to match.

The flow-down nobody plans for

The Cybersecurity Maturity Model Certification framework is being phased into DoD contracts. If your company handles Controlled Unclassified Information or Federal Contract Information - or subcontracts to someone who does - you have obligations before your next contract is at risk.

Ohio's defense industrial base is concentrated around Wright-Patterson in the Dayton area, Columbus, and Northeast Ohio, but CMMC applies anywhere in the DoD supply chain regardless of location or contract size. The common mistake: assuming a prime's certification covers you. It does not. Each company that handles CUI is independently responsible.

Our scope is the network and communications infrastructure - access control, audit logging, system and communications protection, configuration management. We are an advisor, not a C3PAO and not an assessor. We cannot certify you, and any vendor who says they can is selling something.

CMMC 2.0 levels

Which level applies depends on what data you handle and how the contract is written.

LevelPracticesAssessment
Foundational (Level 1)15 practices - basic cyber hygiene covering access control, identification, media and physical protectionAnnual self-assessment
Advanced (Level 2)110 practices based on NIST SP 800-171, required for handling CUIThird-party C3PAO assessment for prioritized acquisitions; self-assessment otherwise
Expert (Level 3)110+ practices based on NIST SP 800-172Government-led assessment, highest-priority programs only

The technical controls we coordinate

Level 2 covers 110 practices across 14 domains. These are the network and communications domains we work in.

How readiness runs

1

Gap assessment against NIST 800-171

We review network architecture, access controls, audit logging, and communications security against the 110 practices. You get a written report scored practice by practice, in the format an assessor uses.

2

CUI boundary design

We define and document the systems, networks, and users in scope. This is the foundation of your System Security Plan and the starting point for every other control.

3

Technical control implementation

Segmentation, access controls, MFA, audit logging, and communications encryption get implemented alongside your existing IT team, with documentation written for the SSP.

4

POA&M and ongoing monitoring

The partner we place maintains the Plan of Action and Milestones and monitors the CUI environment. We source that partner, hold them to it, and keep the documentation current so you are assessment-ready on any given day.

CMMC compliance FAQ

Do I need CMMC as a subcontractor?
Yes, if you handle CUI or FCI. Requirements flow down through the supply chain, and your prime's certification does not cover your systems. This is the most common misunderstanding among Ohio subcontractors.
What changes between Level 1 and Level 2?
Level 1 is 17 basic practices - fundamental access control, identification, and media protection. Level 2 adds 93 more from NIST 800-171, including full audit and accountability, configuration management, incident response, and much stricter communications protection. Most Ohio contractors handling CUI need Level 2.
Can a small contractor self-assess?
For Level 1 and some Level 2 scenarios, yes - but the documentation burden is real. You need an SSP, a POA&M, and evidence for each practice. We source the technical implementation and documentation that makes self-assessment achievable, or prepares you for a C3PAO, and we stay accountable for the result.
How does CMMC affect our phone system?
VoIP that carries CUI has to meet the communications protection requirements - encrypted transport, access logging, and segmentation from non-CUI systems. If your phone system is flat and unencrypted, expect it to show up as a gap.
Do you write the System Security Plan?
We write the network infrastructure and communications sections - architecture diagrams, control implementation descriptions, and evidence for the practices in our scope. Your CMMC consultant or GRC team typically compiles the full SSP.
Keep reading

Related

Know where you score before an assessor does.

Free gap assessment against NIST SP 800-171, written practice by practice.

Comparing live pricing and terms from 400+ carriers and platforms
AT&TSpectrumVerizonLumenComcastCoxT-MobileFrontierZayoCogentRingCentralZoomMicrosoft TeamsWebexNextiva8x8