CMMC 2.0 · Compliance Services
More than software.
A framework.
It is truly a comprehensive framework that requires new processes, detailed documentation and true understanding of how the target organization processes FCI and CUI.
What CMMC is
The Cybersecurity Maturity Model Certification, now in version 2
This framework is meant to protect FCI (Federal Contract Information) and CUI (Controlled Unclassified Information). There are three levels of certification.
CMMC is more than just implementing certain technical tools or software packages. It is truly a comprehensive framework that requires new processes, detailed documentation, and a true understanding of how the target organization processes FCI and CUI.
Three levels of certification
Level
1
Likely for most small to mid-sized organizations
Level
2
Likely for most small to mid-sized organizations
Level
3
Requires Level 2 first · Assessed by DoD (DIBCAC)
Most small to mid-sized organizations, depending upon the data they handle, will likely require Level 1 or Level 2 certification.
Already have an MSP or IT provider?
If you are currently working with an MSP (Managed Service Provider) or general IT provider, but they are not aware of the requirements for CMMC compliance, we can act in an advisory role providing process and documentation expertise. If you need technical assistance, in addition to process and documentation services, SDG can help here as well.
Our CMMC services
Below are the CMMC services we offer
01Assessment & Gap Analysis
- Evaluate current cybersecurity posture against CMMC 2.0 requirements and identify gaps.
- Prioritize remediation efforts and document findings.
- Define the assessment boundary and scope of CUI.
- Identify which systems, personnel, and locations handle CUI.
- Reduce scope where possible to lower compliance burden and cost.
03System Security Plan (SSP)
- Develop and document the SSP required for CMMC Level 2.
- Map existing controls to NIST SP 800-171 practices.
04Plan of Action & Milestones (POA&M)
- Create a formal POA&M for any unmet requirements.
- Please note: not all unmet requirements can be placed in a POA&M.
05Policy & Procedure Development
- Write or update information security policies.
- Develop procedures and policies aligned to CMMC practices.
06Technical Remediation Guidance
- Recommend and assist with implementing required security controls.
- Technical items include, but are not limited to, MFA, encryption, endpoint protection, audit logging, network segmentation, and access control implementation.
07CMMC Level 2 Certification Prep
- Prepare your organization for a C3PAO (Certified Third Party Assessment Organization) assessment.
- Conduct mock assessments to identify remaining gaps.
08Evidence Collection & Documentation
- Organize and prepare evidence packages for assessors.
- Ensure documentation meets CMMC assessment guide requirements.
- Deliver security awareness training required by CMMC.
- Train staff on CUI handling, identification, and protection.
10Incident Response Planning
- Develop and test an incident response plan.
- Define roles, escalation paths, and reporting procedures.
11Ongoing Compliance Support
- Continuous monitoring and compliance maintenance.
- Annual review of SSP and security controls.
- Support for recertification every 3 years.