Foundational
Protects Federal Contract Information (FCI).
- 15 security requirements from FAR 52.204-21
- Annual self-assessment
- Annual affirmation in SPRS by a senior company official
For defense suppliers
Based in Vermont, we help defense suppliers here and across the country meet CMMC Level 1 and Level 2, from the first gap assessment to assessment day and beyond. Led by a former DoD Information System Security Manager.
NIST SP 800-171 Rev. 2
CMMC Level 2 is built on NIST SP 800-171. Each square below is one requirement.
Illustration of a readiness project. Hover a square to see its requirement number.
Your contract decides. If you handle only Federal Contract Information, it’s Level 1. If you handle Controlled Unclassified Information, it’s Level 2.
Protects Federal Contract Information (FCI).
Protects Controlled Unclassified Information (CUI).
The same Risk Management Framework discipline used on federal systems, sized for a small manufacturer or supplier.
We prepare you. We don’t grade you. VT CYBER is not a C3PAO and doesn’t perform certification assessments. That keeps your assessment independent.
We find where your FCI and CUI live and measure every requirement against how you work today.
Your System Security Plan, Plan of Action and Milestones, policies, and procedures, written to hold up under review.
We put the technical controls in place on your systems: MFA, encryption, logging, patching, and more.
Evidence organized requirement by requirement, and a walkthrough before the real thing.
Ongoing monitoring keeps your controls running and your evidence current, month after month.
Call or text 802-393-4478, or email info@vtcyber.com.