The Time to Prepare for CMMC Is Now. V2 Systems Is Here to Help You Get Started.

May 26, 2020 | Cyber Security, IT News

We are already half-way through 2020. And that means you can’t put off Cybersecurity Maturity Model Certification (CMMC) preparation any longer. We here at V2 Systems are going to help with a short guide for getting the bare basics together, so that you’ll at least be prepared for Level 1 certification. Here’s a quick rundown of everything.

CMMC Level 1 Has 17 Controls.

We spoke about the different levels of CMMC in our previous blog. There are 5 levels in total, and each level is made up of numerous security actions that need to be performed in order to achieve certification for that level. The controls in Level 1 come directly from Federal Acquisition Regulation (FAR) 52.204-21, and are considered both basic and essential. Here is the general outline for CMMC Level 1, which makes up about 15% of all 5 CMMC levels:

  1. Limit information system access to authorized users, processes acting on behalf of authorized users or devices (including other information systems).
  2. Limit information system access to the types of transactions and functions that authorized users are permitted to execute.
  3. Verify and control/limit connections to and use of external information systems.
  4. Control information posted or processed on publicly accessible information systems.
  5. Identify information system users, processes acting on behalf of users or devices.
  6. Authenticate (or verify) the identities of those users, processes or devices as a prerequisite to allowing access to organizational information systems.
  7. Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.
  8. Limit physical access to organizational information systems, equipment and the respective operating environments to authorized individuals.
  9. Escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices.
  10. Maintain audit logs of physical access.
  11. Control and manage physical access devices.
  12. Monitor, control and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.
  13. Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.
  14. Identify, report, and correct information and information system flaws in a timely manner.
  15. Provide protection from malicious code at appropriate locations within organizational information systems.
  16. Update malicious code protection mechanisms when new releases are available.
  17. Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened or executed.

Everyone Should Have CMMC Level 1

The Time to Prepare for CMMC Is Now. V2 Systems Is Here to Help You Get Started.CMMC Level 1 is a pretty basic security practice by now. Just looking at the list above, you can see it covers everything from locking office doors, to escorting guests and using strong passwords. It shouldn’t take much effort to reach Level 1, and if you’re not quite there yet, it costs very little, if not almost nothing, to do so. An MSSP can absolutely help you reach the goals listed in Level 1, and that’s where V2 Systems can be a tremendous asset. Keep in mind that if you want to be NIST 800-171 compliant, you have to be at least CMMC Level 3.

Doing work for the Department of Defense is no joke. It’s a job that needs to be taken seriously, no matter the size of your organization. Let us help your image so that the DoD will take you seriously, too.

Since 1995, Manassas Park, VA-based V2 Systems has employed local systems administrators, network engineers, security consultants, help desk technicians and partnering companies to meet a wide range of clients’ IT needs, from research, to implementation, to maintenance. Concentrate on your VISION…We’ll handle the TECHNOLOGY!

More From V2 Systems

What Government Contractors Get Wrong About Secure Cloud Environments

Secure cloud environments require more than moving files into Microsoft 365, SharePoint, or another cloud platform. For government contractors, controlled access, proper configuration, CUI scoping, enclaves, and shared system responsibilities all matter. This blog explains what GovCons often get wrong about cloud security and how to stay aligned with current CMMC expectations.

Hybrid Work in 2026: The Endpoint Problem That Never Went Away

Hybrid work is now a normal part of business, but the endpoint problem never went away. Laptops, mobile devices, remote access tools, and unmanaged personal devices can create cybersecurity risk when they are not properly secured. This blog explains how small businesses and government contractors can strengthen endpoint security in 2026.

CMMC Update: What Government Contractors Need to Know as of August 2026

The Department of War announced the immediate suspension of CMMC Phase II requirements on July 13, 2026, pausing upcoming third-party assessment mandates. However, Phase I self-assessments, NIST SP 800-171 Rev. 2, DFARS 252.204-7012, and core cybersecurity obligations remain active. This blog explains what government contractors need to know as of August 2026 and how to stay prepared during the review period.

Summer Cyber Risks: Why Attacks Spike When Teams Are Short-Staffed

Summer vacations, lighter staffing, remote work, and busy schedules can create cybersecurity gaps for small businesses and government contractors. This blog explains why attackers take advantage of short-staffed teams and what organizations can do to reduce risk during the summer months.

Why Security Awareness Training Fails and How to Fix It

Security awareness training often fails because it is too generic, too infrequent, or too disconnected from how employees actually work. This blog explains why annual training alone is not enough and how small businesses and government contractors can build a more practical, ongoing approach to cybersecurity awareness.

Free
Small Business Cybersecurity Checklist

cybersecurity checklist graphic