CMMC · NIST SP 800-171 · ITAR · RMF · Insider threat+1 571 410 3066
Cybersecurity Consulting

FAQ

What do defense contractors ask before they call?

Mostly four things: which CMMC level applies, whether they need a C3PAO, what an SSP is, and who will actually do the work. The answers are below.

What are the common questions?

What is CMMC Level 2?

CMMC Level 2 is the Cybersecurity Maturity Model Certification level for defense contractors that handle Controlled Unclassified Information. It requires the 110 security requirements in NIST SP 800-171 Rev 2, and the program rule is published at 32 CFR Part 170.

How do I know whether my contracts require CMMC Level 2?

Look at what you handle and what the contract says. If a contract or subcontract gives you CUI, DFARS 252.204-7012 applies and Level 2 is the expected level. The solicitation provision, DFARS 252.204-7025, states the level and whether a self assessment or a certification assessment is required, and the contract clause, DFARS 252.204-7021, requires you to hold it. If you are unsure, that question is the first thing we answer on a call.

What is the difference between NIST SP 800-171 and CMMC?

NIST SP 800-171 is the set of security requirements for protecting CUI. CMMC is the DoD program that verifies a contractor actually meets them, through a self assessment or an independent assessment by a C3PAO, depending on the contract.

Do we need a C3PAO assessment, or can we self assess?

Your contract decides. Some Level 2 contracts allow a self assessment and others require a certification assessment by an authorized C3PAO. Both run on a three year cycle, with an annual affirmation of continued compliance by a senior official of the company. On July 13, 2026 the Department of War suspended the planned Phase 2 rollout of third party assessments pending a review; self assessment, SPRS posting and the annual affirmation continue, and preparing for a third party assessment is still the right planning assumption. What CMMC Level 2 requires in 2026.

What is a System Security Plan, and why does an assessor care about it?

The SSP describes your system boundary and how each NIST SP 800-171 requirement is implemented. An assessor uses it as the map for the whole assessment, so an SSP that does not match how your company actually works is one of the fastest ways to lose an assessor's confidence.

Can a consultant guarantee we pass a CMMC assessment?

No. The C3PAO decides the result. A consultant can make sure every requirement is implemented, documented and evidenced, and run a mock assessment beforehand. Be cautious of anyone who promises a result.

What does a virtual CISO do?

A virtual CISO provides senior security leadership on a part time basis: strategy, governance, risk decisions, vendor oversight and executive briefings. For a defense contractor, that usually includes owning the CMMC program and the supplier readiness that comes with it.

How does ITAR relate to CMMC?

ITAR, administered by the State Department, controls the export of defense articles and technical data and restricts access by foreign persons. CMMC verifies cybersecurity for CUI on defense contracts. Where a DoD contract carries DFARS 252.204-7012, export controlled technical data is Controlled Unclassified Information and the safeguarding requirements are NIST SP 800-171. That is where the two programs meet in your IT environment. Export licensing and classification stay with your empowered official and export counsel.

Who actually does the work?

The Capital Cyber team. Each engagement has one accountable lead who briefs your leadership, and the team carries out the hands on assessment, documentation and evidence work and coordinates with your MSP or MSSP.

How does an engagement start?

With a 30 minute call. We learn which contracts you hold or are bidding on, where your CUI lives and what deadline you face. If there is a fit, we send a written scope that names the engagement, the deliverables and who does what.

Ready to talk it through?

BOOK A CALL

Pick a time for a 30 minute call with the practice.

What happens in 30 minutes

  1. We learn about your company, the contracts you hold or are bidding on, and what is driving your timeline.
  2. We talk through where you stand and which engagement fits, if any does.
  3. If there is a fit, we follow up with a written scope. No slides.