Our Services / CMMC Compliance Services
CMMC Compliance Services for Defense Contractors
The Cybersecurity Maturity Model Certification program sets the cybersecurity requirements a contractor must meet to be eligible for a Department of Defense award. IT Solutions Technology Partners helps organizations in the defense industrial base find out which level applies to them, measure where they stand against it, and close the gaps in a defensible order.
ITS advises, facilitates, and validates alignment. The contractor owns and implements the technical and policy controls, and submits its own status. That division matters, because CMMC holds the contractor accountable regardless of who helped.
What Contractors Ask Us First
Most organizations arrive here after a prime asks a question they cannot answer, or after a solicitation lands with a clause they have not seen before. These five come up first.
Which CMMC level do we actually need?
The level is set by the information a contract involves, not by company size. Federal Contract Information points to Level 1. Controlled Unclassified Information points to Level 2, either self-assessed or certified by a third party. The solicitation itself states the required status, and IT Solutions Technology Partners starts by reading it with you.
How do we know whether we handle CUI at all?
Scoping comes before assessment. ITS works through where regulated data actually enters, moves through, and rests in an environment: email, file shares, engineering systems, backups, and the systems administrators use to manage all of it. That produces a defined assessment boundary, which is what everything else is measured against.
A contract came up and we are not ready. What happens?
Contracting officers check the Supplier Performance Risk System before award. Without a current CMMC status at the required level, and a current affirmation of continuous compliance, an offeror is not eligible. ITS builds readiness plans around that reality rather than around a general improvement timeline.
We have gaps we cannot close yet. Is a POA&M enough?
Sometimes, within limits. At Levels 2 and 3, a conditional CMMC status is available with a plan of action and milestones, and it runs for a period not exceeding 180 days from the conditional status date. ITS tracks remediation against that clock and aligns closure activity to it.
A POA&M is a commitment with a deadline attached, not a way of deferring the work. Level 1 does not offer one at all.
Our prime is asking for proof. What do we owe them?
Flow-down is real and it is not satisfied by assurances. Subcontractors submit their own affirmations and self-assessment results into SPRS. Primes cannot view a subcontractor’s CMMC information directly, so they verify independently, which is why the questionnaires arrive. ITS helps organizations produce evidence that survives that scrutiny.
A gap assessment measures an organization against the requirements that apply to its level and produces the evidence trail an assessor or a prime will ask for. ITS evaluates technical and administrative controls against NIST SP 800-171 for Level 2 or FAR 52.204-21 for Level 1, identifies missing documentation and unimplemented controls, and prioritizes remediation.
What’s Included:
- Evaluation of technical and administrative controls against the applicable requirement set
- Identification of missing documentation, unimplemented controls, and evidence gaps
- Prioritized remediation recommendations
- Readiness report with compliance score, assessment results, and next steps
- Support in preparing a self-assessment submission to SPRS
Which CMMC level applies to your contracts?
The level follows the information a contract involves. A solicitation states the required status explicitly, so this table is an orientation rather than a substitute for reading the clause.
| Feature | Level 1 | Level 2 (Self-Assessment) | Level 2 (C3PAO) | Level 3 |
|---|---|---|---|---|
| Information handled | Federal Contract Information (FCI) | Controlled Unclassified Information (CUI) | Controlled Unclassified Information (CUI) | CUI on the highest-priority programs |
| Requirements | 15 requirements from FAR 52.204-21 | 110 requirements from NIST SP 800-171 | 110 requirements from NIST SP 800-171 | NIST SP 800-171 plus selected requirements from NIST SP 800-172 |
| Who assesses | The contractor | The contractor | An accredited third-party assessment organization (C3PAO) | An accredited third-party assessment organization (C3PAO) |
| Prerequisite | None | None | None | Level 2 certification first |
| Affirmation in SPRS | Required | Required | Required | Required |
| Conditional status with a POA&M | Not available | Available, up to 180 days | Available, up to 180 days | Available, up to 180 days |
| Where ITS helps | Gap assessment, control implementation, self-assessment preparation | Gap assessment, vCISO governance, control implementation, documentation | The same, plus preparation for third-party assessment | The same, plus preparation for DIBCAC review |
Credentials and Expertise
What ITS is, and what ITS is not.
Not a C3PAO
Certification assessments are performed by accredited third-party assessment organizations. ITS does not certify its own clients, and no advisory firm can. What ITS provides is the readiness work that happens before an assessment and the governance that sustains compliance after one.
Framework-Based Assessment Practice
ITS assessments measure against published requirement sets rather than internal checklists: NIST SP 800-171, FAR 52.204-21, and the CIS Critical Security Controls.
SOC 2 Type II
ITS maintains SOC 2 Type II compliance, an audited assessment of how its own security, availability, and confidentiality controls operate over time. Contractors evaluating an external service provider generally ask for this.
SSAE 18 Type II
ITS is SSAE 18 Type II compliant, the attestation standard a contractor’s auditors use when reviewing a service provider’s controls.
Ready to Streamline CMMC Compliance?
Contact us via the form below or call at 866.742.5487. Whether you need compliance support, secure cloud hosting, or managed security services, our team is here to help.
Are you an ITS Client looking for support? Please use our Client Support Center.