top of page

Straight Answers About CMMC, CUI & Defense Contractor IT

The questions we hear every week — answered in plain English, no scare tactics.

1. What is CMMC 2.0, and does it apply to my company?

CMMC (Cybersecurity Maturity Model Certification) is the Department of War's program for verifying that contractors actually protect the sensitive information in their contracts. If your contracts include DFARS 252.204-7012 or 252.204-7021 clauses — and most defense subcontracts do — it applies to you. Companies that handle Controlled Unclassified Information (CUI) fall under Level 2, which is built on the 110 security controls of NIST 800-171.

2. I heard CMMC assessments were suspended. Am I off the hook?

No — and this is the most dangerous misunderstanding in the industry right now. In July 2026 the Department suspended the third-party (C3PAO) assessment requirement, but the underlying obligations never moved: NIST 800-171 compliance and DFARS 7012 remain in your contracts, your SPRS self-assessment score is still required, and primes are still checking it before they award work. The suspension is a pause on the audit, not on the rules.

3. What is CUI, and how do I know if I have it?

Controlled Unclassified Information is sensitive-but-not-classified government information: technical drawings, specifications, project data, and similar material tied to a defense contract. If your contract references DFARS 7012, assume you're handling CUI until a proper identification says otherwise. Most contractors have more of it than they think — sitting in email.

4. Do I need Microsoft GCC High, or is regular Microsoft 365 enough?

It depends on your data. If you touch ITAR or export-controlled technical data, GCC High is the defensible answer: U.S. datacenters, U.S.-person support, and contractual commitments that commercial Microsoft 365 simply doesn't make. If you handle CUI only, there are configurations that can work — but the wrong guess is expensive to unwind. This is exactly what our assessment settles before you spend a dollar on licensing.

5. What is an SPRS score, and why does my prime keep asking about it?

The Supplier Performance Risk System score is a self-assessment against NIST 800-171, on a scale from –203 to 110. Primes check it before awarding subcontracts. An honest score with a remediation plan beats an inflated one every time — a false score is a False Claims Act problem, not just an IT problem.

6. What does non-compliance actually cost?

Three ways it hurts: lost bids (primes screen out non-compliant subs), federal liability (the Department of Justice actively pursues false cybersecurity claims), and breach cleanup, which always costs more than prevention. The cheapest day to fix this is today.

7. We're a small shop. Isn't all this overkill for us?

Size doesn't exempt you — but it does let you be smart. A properly scoped CUI enclave keeps the compliance boundary small, which keeps the cost small. You don't need to secure everything to the same standard; you need to secure the right things and prove it.

8. How disruptive is a GCC High migration?

Done right: a weekend cutover, not a lost week. Mail, files, Teams, and device management move in planned stages, and your team keeps working. Most of the effort happens before anyone notices anything changed.

9. Can't my current IT provider handle this?

Maybe — and we're happy when they can. But compliance is a specialty: assessors expect specific evidence, specific documentation, and specific control language. We regularly work alongside existing IT providers — they keep the printers running, we own the compliance layer.

10. What does it cost to get started?

One hour. Our compliance assessment tells you where you stand, what's broken, and what order to fix it in — in plain English, with a written summary you keep either way. No obligation, no scare tactics, no 40-page proposal.

11. Do you offer ongoing monthly support, or just projects?

Both — but the monthly partnership is where the real value is. Compliance drifts the moment the project ends: patches lapse, staff changes, evidence goes stale. Our monthly plan keeps your environment managed and your compliance posture current, so an assessment or a prime's questionnaire never becomes a fire drill. We deliberately cap the number of monthly clients we serve — quality over quantity.

bottom of page