For defense suppliers

Vermont CMMC readiness, done right.

Based in Vermont, we help defense suppliers here and across the country meet CMMC Level 1 and Level 2, from the first gap assessment to assessment day and beyond. Led by a former DoD Information System Security Manager.

NIST SP 800-171 Rev. 2

110 requirements. 14 families. We track every one.

CMMC Level 2 is built on NIST SP 800-171. Each square below is one requirement.

  • Access Control: 22 requirements
  • Awareness and Training: 3 requirements
  • Audit and Accountability: 9 requirements
  • Configuration Management: 9 requirements
  • Identification and Authentication: 11 requirements
  • Incident Response: 3 requirements
  • Maintenance: 6 requirements
  • Media Protection: 9 requirements
  • Personnel Security: 2 requirements
  • Physical Protection: 6 requirements
  • Risk Assessment: 3 requirements
  • Security Assessment: 4 requirements
  • System and Communications Protection: 16 requirements
  • System and Information Integrity: 7 requirements
Implemented In progress Not started

Illustration of a readiness project. Hover a square to see its requirement number.

Which level do you need?

Your contract decides. If you handle only Federal Contract Information, it’s Level 1. If you handle Controlled Unclassified Information, it’s Level 2.

Level 1

Foundational

Protects Federal Contract Information (FCI).

  • 15 security requirements from FAR 52.204-21
  • Annual self-assessment
  • Annual affirmation in SPRS by a senior company official
Level 2

Advanced

Protects Controlled Unclassified Information (CUI).

  • 110 security requirements from NIST SP 800-171 Rev. 2
  • Assessment by a certified third-party assessor (C3PAO), or a self-assessment where your contract allows
  • System Security Plan (SSP) and Plan of Action and Milestones (POA&M)
  • Annual affirmation in SPRS

How we get you there

The same Risk Management Framework discipline used on federal systems, sized for a small manufacturer or supplier.

We prepare you. We don’t grade you. VT CYBER is not a C3PAO and doesn’t perform certification assessments. That keeps your assessment independent.

Credentials

  • Cyber-AB Registered Practitioner
  • Former DoD ISSM
  • CISSP
  • CGRC
  • GCCC
  • GICSP
  • CEH
  1. Scope and gap assessment

    We find where your FCI and CUI live and measure every requirement against how you work today.

  2. Documentation

    Your System Security Plan, Plan of Action and Milestones, policies, and procedures, written to hold up under review.

  3. Implementation

    We put the technical controls in place on your systems: MFA, encryption, logging, patching, and more.

  4. Assessment prep

    Evidence organized requirement by requirement, and a walkthrough before the real thing.

  5. Stay compliant

    Ongoing monitoring keeps your controls running and your evidence current, month after month.

Questions about CMMC?

Call or text 802-393-4478, or email info@vtcyber.com.