Three SaaS products live · OpsTicket · Winrove · OnboardIQ·SAM.gov UEI PR9KWJPM4JU9 · CAGE 91CE1
IT Custom SolutionFour Practices, One Firm · Est. MMXXI
§ SAM.gov UEI · PR9KWJPM4JU9§ CAGE · 91CE1§ NYC MBE · MWCERT2022-353

CMMC Requirements for IT Service Providers: What You Need to Know

CMMC 2.0 is now appearing in DoD solicitations, and the requirements extend beyond prime contractors to IT service providers throughout the supply chain. Here's what IT firms need to understand and implement.

The Cybersecurity Maturity Model Certification (CMMC) is no longer a future requirement · it's appearing in Department of Defense solicitations now, and the compliance obligations extend throughout the defense industrial base, including IT service providers who may not directly handle classified information but who touch systems that do.

CMMC 2.0: The Streamlined Framework

CMMC 2.0 simplified the original five-level framework into three levels, aligning more directly with NIST standards that many contractors already work with:

Level 1: Foundational

Seventeen basic cybersecurity practices aligned with FAR clause 52.204-21. Annual self-assessment by the company. Covers basic safeguarding requirements for Federal Contract Information (FCI) · information provided by or generated for the government under contract that is not intended for public release.

If your IT firm processes any information under federal contract that isn't publicly available, Level 1 likely applies to you. This is the baseline that all DoD contractors must meet.

Level 2: Advanced

110 practices aligned with NIST SP 800-171. For most contracts involving Controlled Unclassified Information (CUI), Level 2 applies. Third-party assessment by a CMMC Third Party Assessment Organization (C3PAO) required for contracts designated as "prioritized acquisitions" · typically contracts that are critical to national security or involve particularly sensitive CUI.

Annual self-assessment (with a senior official affirmation) is permitted for Level 2 contracts that aren't designated as prioritized acquisitions. This is the most important nuance for small IT firms: understand whether your specific contracts will require third-party assessment or allow self-assessment.

Level 3: Expert

110+ practices from NIST SP 800-171 plus additional controls from NIST SP 800-172. Government-led assessment by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). Reserved for contracts involving highest-priority programs and most sensitive information.

Most IT service providers won't face Level 3 requirements unless they're working directly on classified programs. Focus your compliance energy on Level 2.

What CUI Actually Is (And Why It Matters)

Controlled Unclassified Information is the lynchpin of CMMC applicability. CUI is information that requires safeguarding or dissemination controls pursuant to law, regulation, or government-wide policy · but is not classified. The categories are extensive: technical data, export-controlled information, personally identifiable information, law enforcement sensitive information, and dozens of others.

For IT service providers, the critical question is: does your work for DoD contractors involve accessing, processing, or storing any information in a CUI category? If you manage networks, provide cloud services, develop software, or perform any IT function that touches information generated under DoD contracts, there's a significant probability that CUI is involved.

The CUI Registry at archives.gov/cui lists all 125+ CUI categories and sub-categories. Review it in the context of your specific work to determine your applicability.

The Flow-Down Obligation

This is where many small IT firms are caught by surprise. CMMC requirements don't apply only to prime contractors · they flow down to subcontractors and suppliers who handle CUI. If you're a subcontractor to a prime DoD IT contractor, the prime's contract likely includes DFARS clause 252.204-7021 requiring CMMC compliance, and that requirement flows to you through your subcontract.

Prime contractors are increasingly including CMMC compliance requirements in their subcontractor agreements. If you receive a subcontract and haven't looked closely at the cybersecurity clauses, now is the time.

The SPRS Score: Where You Stand Right Now

The Supplier Performance Risk System (SPRS) database now contains NIST 800-171 self-assessment scores for DoD contractors. If you're doing DoD work and haven't submitted a score, you're already out of compliance with DFARS clause 252.204-7019.

Submitting a score requires completing the NIST 800-171 self-assessment against your actual IT environment. The assessment produces a point score ranging from -203 to 110 (most organizations don't start at 110; the score is calculated by subtracting point values for each unimplemented control from a maximum of 110).

Critically: you must also have a System Security Plan (SSP) documenting your environment and control implementation, and a Plan of Action and Milestones (POA&M) documenting how you'll remediate any gaps. Submitting a self-assessment score without supporting documentation doesn't satisfy the requirement.

Preparing for a C3PAO Assessment

If your contracts will require Level 2 third-party assessment, here's what to expect from a C3PAO engagement:

Pre-Assessment Readiness

Before the assessment, you need a mature SSP documenting your system boundary, control implementation, and any inherited controls from cloud service providers. Your POA&M should reflect actual gaps with realistic remediation timelines. Evidence of control implementation · configuration records, policies, procedures, audit logs · must be readily accessible.

Assessment Process

C3PAO assessors conduct document review, interviews with system owners and administrators, and technical testing of control implementations. Expect the assessment to take 3-8 weeks depending on your environment's complexity. Plan for significant internal resource commitment during the assessment period.

Common Failure Points

The controls that most commonly cause problems in C3PAO assessments: multi-factor authentication (specifically enforcing MFA for all privileged access and remote access), audit logging and log protection, configuration management and baseline hardening, and media sanitization procedures.

Address these systematically before your assessment. Assessors are not trying to fail you · they're verifying that you've implemented what you say you've implemented.

The False Claims Act Risk

The Department of Justice has made CMMC and NIST 800-171 compliance a False Claims Act enforcement priority. Contractors who submit self-assessments overstating their compliance, or who certify CMMC level achievement without genuine implementation, face civil and criminal liability under the FCA.

The bar for FCA liability isn't perfect compliance · it's knowing misrepresentation. An honest assessment that shows gaps, accompanied by a remediation plan, is far less legally risky than an inflated score submitted under pressure to remain contract-eligible.

IT Custom Solution provides CMMC readiness assessments, gap remediation support, and SSP development for small government IT contractors. Learn more about our cybersecurity services or schedule a consultation.

#cmmc#cybersecurity#dod-contracting#nist-800-171#compliance
§ ShareX / TwitterLinkedIn
§ Need a quote?

Tell us about the work.

IT Custom Solution delivers cybersecurity, cloud, managed IT, and custom software for federal, state, and local agencies.

Analytics cookies? Details: cookies policy or privacy policy.