PJCINC

  • About PJC
    • Why PJC
    • Our “A to Z” Approach
    • PJC Testimonials
    • PJC Clients
    • News & Events
    • Supplier Audits
    • Risk Management
    • Compliance Audit
  • Standards
    • ISO 9001
      • ISO 9000 Implementation
      • ISO 9000 Maintenance
    • AS9100
      • AS9100 Implementation
      • AS9100 Maintenance
    • TNI 2016
    • IATF 16949
      • IATF 16949 Implementation
      • IATF 16949 Maintenance
    • ISO 13485
      • Medical Device Single Audit Program
    • ISO/IEC 17025
      • Cannabis
    • ISO 14001
      • ISO 14000 Implementation
      • ISO 14000 Maintenance
    • ISO 27001
    • ISO 20000-1
    • CMMC
      • CMMC Executive Summary
    • R2 – Responsible Recycling
    • RIOS
    • ISO 45001
    • HACCP
    • FSSC 22000
    • Risk Assessment
  • ISO Consulting
  • Training
    • Virtual Public Seminars
      • ISO 27001 Lead Auditor Course
      • ISO 27001 Internal Auditor
    • ISO 9001:2015 Overview Course (Online)
    • ISO 9001:2015
      Internal Auditor
    • ISO 14000
      Internal Auditor
    • IATF 16949
      Internal Auditor
    • AS9100
      Internal Auditor
    • Measurement Uncertainty
    • ISO/IEC 17025 Internal Auditor
    • ISO/IEC 17025 Overview
    • Root Cause
    • SPC
    • Core Tools
      • ISO/TS 16949:2002 Linkage to the
        Core Tools
  • Resources
    • PJC Blog
    • PJC Podcast
    • PJC Videos
    • Green Paper Library
    • Executive Overviews
    • ISO Consultation
    • Quality Manual Review
  • Blog
  • Contact PJC
    • Request A FREE Quote
    • Request A FREE Quick Quote
      • A to Z Implementation
      • Training
      • Internal Audits
      • Assistance/Consulting
    • Here To Answer Your Questions

CMMC Executive Summary

What is CMMC?

Man working on laptop showing a map of the world and a security shieldCMMC was created to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) across the Defense Industrial Base (DIB) which includes contractors and subcontractors supporting DoD operations.

Cyber theft of intellectual property and sensitive defense information is considered a national security risk, and CMMC enforces verified cybersecurity implementation rather than self-attestation.

CMMC certification is a contract eligibility requirement, not just a compliance framework like ISO 27001:2022.

CMMC Model Overview

CMMC is a 3-tiered model based on the NIST Cybersecurity Standards.

Level Foundation Protects What It Is Who Needs It
Level 1 FAR 52.204-21 FCI Basic cyber hygiene Government contractors
Level 2 NIST SP 800-171 CUI Protection of CUI Contractors in the defense industry
Level 3 NIST SP 800-172 Critical/high-value CUI Advanced threat protection High-risk programs

CMMC Levels 1 and 2 validate compliance with existing regulations, while Level 3 adds protection against advanced persistent threats (APTs).

What Certification Actually Requires

  1. Define CMMC Assessment Scope
  2. Implement required security controls
  3. Document implementation in a System Security Plan (SSP)
  4. Track gaps in a Plan of Action and Milestones (POA&M)
  5. Pass assessment, (self, C3PAO, or government)
  6. Maintain continuous compliance
  7. Submit results to SPRS annually

Determining Your Required Level

  • Only FCI -> Level 1
  • Any CUI -> Level 2 (what most organizations are going to require)
  • Critical/high value CUI -> Level 3
  • Level 3 certification requires full Level 2 certification first.

Scoping (for Level 2)

You must determine the CMMC Assessment Boundary before an assessment. How to determine your scope:

  • Do you have CUI Assets?
    – Assets that process/store/transmit CUI
  • Do you have Security Protection Assets?
    – Assets that provide security functions or capabilities to the OSA’s CMMC Assessment Scope
  • Do you have Contractor Risk Managed Assets?
    – Assets that can, but are not intended to, process/store/transmit CUI because of security policy/procedures/practices in place
  • Do you have Specialized Assets?
    – Assets that can process/store/transmit CUI but are unable to be fully secured (IoT, IIoT, OT, GFE, etc.)

Cloud providers/MSPs/MSSPs must be included in the CMMC scope if they handle CUI.

What’s considered out of scope?

  • Anything that cannot process, store, or transmit CUI or provide protection for CUI assets.

Controls to Implement (for Level 2)

There are 110 controls across 17 families.

Family Code Family Name Number of Controls
AC Access Control 14
AT Awareness & Training 2
AU Audit & Accountability 5
CA Security Assessment & Monitoring 4
CM Configuration Management 6
IA Identification & Authentication 7
IR Incident Response 3
MA Maintenance 3
MP Media Protection 4
PS Personnel Security 2
PE Physical Protection 3
PL Planning 2
RA Risk Assessment 4
SA System & Services Acquisition 5
SC System & Communications Protections 9
SI System & Information Integrity 7
SR Supply Chain Risk Management 7

Level 3 adds controls to counter APTs and protect critical programs.

How to get Certified

Level Assessment Type Frequency
Level 1 Self-assessment Annual
Level 2 Self OR C3PAO (depending on the contract) Every 3 years
Level 3 Government (DIBCAC) Every 3 years

All levels require annual compliance affirmation.

What Assessors Actually Evaluate

  • Controls are implemented correctly
  • Controls operate as intended
  • Evidence supports implementation
  • Risk-based decisions are documented

Practical Certification Roadmap

  1. Determine required CMMC level
  2. Define assessment scope and boundary
  3. Inventory systems handling CUI
  4. Build Systems Security Plan (SSP)
  5. Perform gap assessment vs NIST 800-171
  6. Implement required controls based on gap assessment
  7. Build and track POA&M
  8. Conduct readiness assessment
  9. Undergo C3PAO assessment
  10. Maintain continuous compliance

For more information on CMMC or other Information Security Standards, contact PJC.

Request A FREE Quote - PJC

Request A FREE Quote - PJC

Receive News & Updates From PJC



PJC Implementation Process

Training



MORE INFO / REGISTER NOW!


PJC Blog

  • Data Theft and Ransomware Continue to be a Threat to Businesses
  • The System Must Work When No One’s Watching
  • Food Safety Trends for 2025 and Beyond

News & Updates

  • First Step in Preparing for ISO Certification: GAP Assessment

Testimonials

Our consultant, Jim Johnson, was extremely helpful not only during the implementation process but afterwards. Kudos to Jim and the staff of PJC!
Ken SeloverQuality ManagerStructural Diagnostics, Inc.
Mahindra Automotive North America (MANA) Manufacturing challenged Perry Johnson Consulting (PJC) to help implement ISO 9001:2015 while ramping up production for our ROXOR off-road vehicle. MANAM was focused on a streamlined, high-level approach to build quality into our manufacturing processes and develop the Quality Management System. PJC was a true partner! Our consultant, Nancy, embraced our approach and kept us focused on key ISO deliverables. She guided us to a successful ISO implementation… Read more
Denise VallisProject ManagerMahindra Automotive North America
From quoting to certification, everyone at Perry Johnson Consulting has been professional and a valued partner. Their auditors demonstrate a vast knowledge of quality standards and are able to translate them to real world application.
Matt NorbergQuality Control ManagerNational Products Inc.
Steve was a wonderful auditor. He was very professional and thorough. He took time to answer my questions about different parts of the standard. I would recommend him to other companies needing an internal audit.
Kelli BradburyPrecision Die Technologies
Hiring Perry Johnson to help us get certified to ISO 9001:2015 was the right move on our part. They did an excellent job on our documentation. Perry Johnson also answered a lot of questions for me going up to the audits which helped greatly. WE passed the audit in June. Thank you for your help, it was money well spent. I will refer you to anyone I talk to about this.
Tony BriaQuality ManagerHydra-Matic/Fabrics For Industry
PJC did consulting for us for our ISO 9002:2015 system and we found them to be professional and listened to our needs. They created a system that was easy to implement and use on a daily basis.
Kraig ReichwaldVP of ManufacturingCustom Metal Products
Wayne’s expertise in ISO 9001:2015 was essential in Vonco Products attaining our ISO certification. His knowledge was a great help improving our system by eliminating waste while assisting in developing our QMS.
Mike DeleoQuality ManagerVonco Products
Michael was instrumental in helping us make this transition much less stressful than I thought it would be. His attention to detail and expertise prepared us for our recertification audit. His professional demeanor made him a pleasure to work with.
Tyler HawkOperations ManagerCross Technologies Group, Inc.
We have been using Perry Johnson Consulting for 5 years and have never had a bad experience. With their expertise and knowledge of the ISO programs they have guided and helped us achieve an outstanding QMS. Thank you to all the friendly and professional people at PJC and we hope to have a long lasting relationship.
Larry ReimersQuality ManagerCTG, Inc.
Thought I’d drop a line to you and the staff to say thank you all very much for your dedicated hard work. You helped save our company, and I’m sending you all a heartfelt thanks!
Kevin J. CoffeyPresidentAlert Tubing Fabricators Inc.

RECEIVE NEWS & UPDATES FROM PJC

Subscribe to our mailing list:


Government "We are proud to provide services to the U.S. Government!"

PJC Celebrates 30 Years!

PJC's 30th Anniversary
Teresa O'Donnell – President & CEO
Teresa O'Donnell
President & CEO

Perry Johnson Consulting, Inc.

200 East Big Beaver Rd.
Troy, Michigan 48083
Phone: 1-888-248-0256 or (248) 519-2602
Email: [email protected]

PJC Contact Us

  • Facebook
  • Instagram
  • LinkedIn
  • YouTube

Copyright © 2026 PERRY JOHNSON CONSULTING, INC. (PJC) • All rights reserved.