The Time to Prepare for CMMC Is Now. V2 Systems Is Here to Help You Get Started.

May 26, 2020 | Cyber Security, IT News

We are already half-way through 2020. And that means you can’t put off Cybersecurity Maturity Model Certification (CMMC) preparation any longer. We here at V2 Systems are going to help with a short guide for getting the bare basics together, so that you’ll at least be prepared for Level 1 certification. Here’s a quick rundown of everything.

CMMC Level 1 Has 17 Controls.

We spoke about the different levels of CMMC in our previous blog. There are 5 levels in total, and each level is made up of numerous security actions that need to be performed in order to achieve certification for that level. The controls in Level 1 come directly from Federal Acquisition Regulation (FAR) 52.204-21, and are considered both basic and essential. Here is the general outline for CMMC Level 1, which makes up about 15% of all 5 CMMC levels:

  1. Limit information system access to authorized users, processes acting on behalf of authorized users or devices (including other information systems).
  2. Limit information system access to the types of transactions and functions that authorized users are permitted to execute.
  3. Verify and control/limit connections to and use of external information systems.
  4. Control information posted or processed on publicly accessible information systems.
  5. Identify information system users, processes acting on behalf of users or devices.
  6. Authenticate (or verify) the identities of those users, processes or devices as a prerequisite to allowing access to organizational information systems.
  7. Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.
  8. Limit physical access to organizational information systems, equipment and the respective operating environments to authorized individuals.
  9. Escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices.
  10. Maintain audit logs of physical access.
  11. Control and manage physical access devices.
  12. Monitor, control and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.
  13. Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.
  14. Identify, report, and correct information and information system flaws in a timely manner.
  15. Provide protection from malicious code at appropriate locations within organizational information systems.
  16. Update malicious code protection mechanisms when new releases are available.
  17. Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened or executed.

Everyone Should Have CMMC Level 1

The Time to Prepare for CMMC Is Now. V2 Systems Is Here to Help You Get Started.CMMC Level 1 is a pretty basic security practice by now. Just looking at the list above, you can see it covers everything from locking office doors, to escorting guests and using strong passwords. It shouldn’t take much effort to reach Level 1, and if you’re not quite there yet, it costs very little, if not almost nothing, to do so. An MSSP can absolutely help you reach the goals listed in Level 1, and that’s where V2 Systems can be a tremendous asset. Keep in mind that if you want to be NIST 800-171 compliant, you have to be at least CMMC Level 3.

Doing work for the Department of Defense is no joke. It’s a job that needs to be taken seriously, no matter the size of your organization. Let us help your image so that the DoD will take you seriously, too.

Since 1995, Manassas Park, VA-based V2 Systems has employed local systems administrators, network engineers, security consultants, help desk technicians and partnering companies to meet a wide range of clients’ IT needs, from research, to implementation, to maintenance. Concentrate on your VISION…We’ll handle the TECHNOLOGY!

More From V2 Systems

How Government Contractors Can Stay Secure During Disruptions and Staffing Gaps

Disruptions are unavoidable, but security gaps do not have to be. For government contractors, staffing shortages, PTO, turnover, shutdowns, and contract transitions can create real cybersecurity and compliance risk. This blog explains how GovCons can maintain security, protect sensitive data, and keep operations moving when key people are unavailable.

Backups Alone Are Not Enough: What True Recovery Looks Like in 2026

Backups are a critical part of business resilience, but they are not the same as recovery. In 2026, small businesses and government contractors need validated backups, tested recovery procedures, clear response plans, and secure restoration processes to keep operations moving when ransomware, outages, or system failures occur.

Downtime Is a Cybersecurity Problem, Not Just an IT Problem

Downtime can affect payroll, customer service, compliance, productivity, revenue, and reputation. For small businesses and government contractors, outages are no longer just technical issues. This blog explains why downtime should be treated as a cybersecurity and business resilience problem, and how organizations can better prepare for disruptions.

Zero Trust Without the Buzzwords: What It Actually Looks Like in Practice

Zero Trust is often discussed as a complex cybersecurity strategy, but at its core, it is about verifying access, limiting unnecessary permissions, and reducing risk. This blog explains what Zero Trust actually looks like in practice for small businesses and government contractors — without the buzzwords, hype, or confusion.

Access Creep Is a Business Risk: How Over-Permissioned Users Create Exposure

Access creep happens when users accumulate permissions over time and keep access they no longer need. For small businesses and government contractors, this creates unnecessary cybersecurity, compliance, and operational risk. This blog explains how over-permissioned users increase exposure and what organizations can do to strengthen access controls, reduce privilege misuse, and improve audit readiness.

Free
Small Business Cybersecurity Checklist

cybersecurity checklist graphic