BRITECITY
CMMC Walkthrough
Setting expectations for Level 1, Level 2, and Level 3 engagements
Make IT Easy
The Framework
What is CMMC?
CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense framework that requires every contractor and subcontractor handling federal contract information or controlled unclassified information to prove a measured level of cybersecurity. It is codified in 32 CFR Part 170 and enforced through DFARS clauses 252.204-7012, -7019, -7020, and -7021.
Why It Matters Now
The rules already in your contracts
Three Levels
Pick the level your contracts require
Federal Contract Information (FCI)
- 17 basic safeguarding practices
- Annual self-assessment, submitted to SPRS
Controlled Unclassified Information (CUI)
- 110 practices from NIST SP 800-171 Rev 2
- C3PAO assessment every 3 years (most CUI contracts)
CUI in programs facing advanced persistent threats
- 110 Level 2 practices + 24 enhanced from NIST SP 800-172
- Government-led DIBCAC assessment
Most defense contractors handling CUI need Level 2.
Level 1, Scope
Federal Contract Information (FCI)
Applies to any contractor that processes, stores, or transmits FCI but no CUI. Covers basic hygiene: access control, identification, media handling, physical protection, system integrity.
Level 1, Delivery
BRITECITY delivers Level 1 end-to-end
- 01
Discovery, confirm FCI scope, inventory systems, identify named POC
- 02
Gap analysis, map current state to the 17 practices
- 03
Remediation, close gaps, document configurations
- 04
System Security Plan (SSP), written and maintained for you
- 05
Annual self-attestation support, score calculation, SPRS submission
Level 2, Scope
Controlled Unclassified Information (CUI)
Applies to most defense contractors handling CUI, engineering drawings, technical data, test results, ITAR-controlled material. Triggered by DFARS clause 252.204-7021.
Level 2, Delivery
BRITECITY co-delivers Level 2 with a 3rd-party CMMC partner
You don’t go through Level 2 alone, and neither do we. The 3rd-party partner brings both BRITECITY and you through the assessment.
- BRITECITY brings in an accredited CMMC RPO / C3PAO partner
- The partner walks both the client and BRITECITY through the assessment process
- BRITECITY owns the IT remediation work, MFA, FIPS encryption, SIEM, EDR, network segmentation, account lifecycle automation
- The partner owns the assessment artifacts, SSP review, POA&M coordination, C3PAO scheduling
- Multi-month engagement; typical readiness window is 12–18 months for a contractor starting from a low SPRS score
Level 3, Referral
BRITECITY does not provide Level 3 today
Applies to a small subset of high-priority programs. Government-led assessment by the Defense Industrial Base Cybersecurity Assessment Center.
- Level 3 is reserved for a small subset of high-priority DoD programs
- It is assessed by the government (DIBCAC), not a commercial C3PAO
- Requires NIST SP 800-172 enhanced controls beyond standard MSP scope
- BRITECITY refers Level 3 prospects to a specialty defense-cyber firm
What You Provide
What we need from you to get started
- 01
Contract scope, which contracts contain DFARS 252.204-7021 and what data flows under them
- 02
System inventory, every device, app, and cloud tenant that touches FCI or CUI
- 03
Named project sponsor with budget authority
- 04
Named day-to-day point of contact
- 05
Decision on enclave-vs-enterprise scoping (a CUI enclave is usually cheaper to certify than the whole company)
- 06
Access to existing security tooling, M365 / Google tenant, and HR offboarding process
The Roadmap
From discovery to certification
- 01
Discovery
Scope contracts, inventory systems, identify CUI flow, choose enclave vs. enterprise.
- 02
Gap Analysis
Map current state to required practices. Score against SPRS scale (-203 to 110).
- 03
Remediation
Close gaps. Deploy MFA, FIPS-validated encryption, SIEM, EDR, account lifecycle automation, and policy.
- 04
SSP & POA&M
Write the System Security Plan. Document any open items in a Plan of Action & Milestones.
- 05
Assessment
Level 1, submit self-assessment to SPRS. Level 2, schedule and pass C3PAO assessment.
- 06
Annual Upkeep
Reassess yearly. Maintain SPRS score. Re-certify Level 2 every 3 years.
Pricing Model
How engagements get billed
Scoped IT project
Single billable IT engagement at our standard rate. Scoped up front based on system count and current state.
Co-delivered + pass-through
Billable engagement at our standard rate, plus 3rd-party assessor fees passed through at cost. Scoped after a paid readiness assessment.
Referral
Not offered. Referral only.
Specific dollar figures and daily rates are confirmed in writing during the scoping call, not in this deck.
Common Pitfalls
What costs contractors the most time and money
Inflating your SPRS score
Self-reported scores will be audited under -7020. A score that does not match reality becomes a False Claims Act exposure once a C3PAO confirms the gap.
Treating Level 2 as a checklist
Practices like MFA and FIPS-validated encryption cannot be POA&M items. Critical gaps must be closed before the assessment.
Ignoring subcontractor flow-down
Primes must flow CMMC requirements to subs. A sub that cannot certify will be removed from the contract.
Scoping the whole company when an enclave will do
A bounded CUI enclave is typically the fastest, cheapest path to Level 2. Whole-company scoping is rarely required.
Starting too late
Readiness for a contractor starting from scratch is usually 12–18 months. Waiting until the clause hits the solicitation is too late.
Next Steps
Four steps from here
- 01
CMMC Scoping Call
Free 30-minute call. We confirm the level you need, the contracts in play, and whether BRITECITY is a fit (Level 1 or Level 2) or whether you need a referral (Level 3).
- 02
Paid Readiness Assessment
Fixed-fee engagement. We document your current SPRS score, scope the CUI environment, and produce a written remediation plan with effort and timeline.
- 03
Remediation Engagement
Billable IT engagement at our standard rate. Level 1 = scoped project. Level 2 = co-delivered with the 3rd-party assessor.
- 04
Assessment & Certification
Level 1 self-attestation submitted to SPRS, or C3PAO assessment scheduled and supported through award.
britecity.com/book-a-call , 30 minutes, free, no commitment.
Prefer a printed handout? Download the walkthrough as a Word doc.
Make IT Easy