CMMC Is Complex, But You Need It If You Want to Do Business

Apr 8, 2020 | Cyber Security, IT News

You have probably heard about Cybersecurity Maturity Model Certification lately, especially while looking for work in the Federal system. In a previous article, we talked a little about a new set of standards to meet in addition to NIST. As we mentioned, Cybersecurity Maturity Model Certification, or CMMC, is basically an extension of NIST 800-171. Today we’re going to go into a little more detail on what’s involved in meeting CMMC compliance and how V2 Systems can help you achieve certification.

CMMC Is a DoD Requirement

As we mentioned before, if you plan on doing any business at all with the Department of Defense, you need CMMC certification. The CMMC is the DoD’s next step to ensure and enhance the scope of cybersecurity for national security data and networks following the Defense Federal Acquisition Regulation Supplement (DFARS) issued in 2016. This scope covers a total of 17 areas of importance:

  1. Access Control
  2. Asset Management
  3. Audit and Accountability
  4. Awareness and Training
  5. Configuration Management
  6. Identification and Authentication
  7. Incident Response
  8. Maintenance
  9. Media Protection
  10. Personnel Security
  11. Physical Security
  12. Recovery
  13. Risk Management
  14. Security Assessment
  15. Situational Awareness
  16. Systems and Communications Protection
  17. System and Information Integrity

These 17 points comprise five “levels” that make up your entire security rating, ranging from basic habits to advanced security operations.

If that sounds like a lot, that’s because it is. And what’s more, there is no “self-certification” when it comes to CMMC, like there is with NIST 800-171. Your organization will coordinate directly with an accredited and independent third-party commercial certification organization to request and schedule a CMMC assessment.

Here’s How You Can Prepare for a CMMC Assessment

CMMC Is Complex, But You Need It If You Want to Do Business.The best thing an organization can do to prepare for a CMMC assessment is to first create what NIST refers to as a System Security Plan, or SSP. An SSP basically outlines your entire security structure. NIST has provided an SSP template which can be found here. Once your SSP is fully outlined, it’s time to start identifying weak spots and – most importantly — lay out how you plan to correct them. These are known as Plan of Action and Milestones (POAM) and will link directly back to each area covered in CMMC.

All of this may seem like a lot, but it’s completely necessary. Anyone who does not meet the requirements for CMMC will not be able to do business with the Department of Defense in any way — and that’s a huge deal for many. Contact us today at 703-396-6120, and we’ll help you through a plan of action to meet these complex requirements. The less you have to worry about it, the more time you can spend focusing on what matters most to you and your organization.

 

Since 1995, Manassas Park, VA-based V2 Systems has employed local systems administrators, network engineers, security consultants, help desk technicians and partnering companies to meet a wide range of clients’ IT needs, from research, to implementation, to maintenance. Concentrate on your VISION…We’ll handle the TECHNOLOGY!

More From V2 Systems

CMMC Update: What Government Contractors Need to Know as of August 2026

The Department of War announced the immediate suspension of CMMC Phase II requirements on July 13, 2026, pausing upcoming third-party assessment mandates. However, Phase I self-assessments, NIST SP 800-171 Rev. 2, DFARS 252.204-7012, and core cybersecurity obligations remain active. This blog explains what government contractors need to know as of August 2026 and how to stay prepared during the review period.

Summer Cyber Risks: Why Attacks Spike When Teams Are Short-Staffed

Summer vacations, lighter staffing, remote work, and busy schedules can create cybersecurity gaps for small businesses and government contractors. This blog explains why attackers take advantage of short-staffed teams and what organizations can do to reduce risk during the summer months.

Why Security Awareness Training Fails and How to Fix It

Security awareness training often fails because it is too generic, too infrequent, or too disconnected from how employees actually work. This blog explains why annual training alone is not enough and how small businesses and government contractors can build a more practical, ongoing approach to cybersecurity awareness.

Cybersecurity Fatigue Is Real: How to Keep Employees Engaged Without Burnout

Employees play a critical role in cybersecurity, but constant warnings, training reminders, password prompts, and security alerts can lead to fatigue. This blog explains how small businesses and government contractors can keep employees engaged with cybersecurity without overwhelming them.

How Government Contractors Can Stay Secure During Disruptions and Staffing Gaps

Disruptions are unavoidable, but security gaps do not have to be. For government contractors, staffing shortages, PTO, turnover, shutdowns, and contract transitions can create real cybersecurity and compliance risk. This blog explains how GovCons can maintain security, protect sensitive data, and keep operations moving when key people are unavailable.

Free
Small Business Cybersecurity Checklist

cybersecurity checklist graphic