BRITECITY
Setting expectations for Level 1, Level 2, and Level 3 engagements
Make IT Easy
The Framework
CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense framework that requires every contractor and subcontractor handling federal contract information or controlled unclassified information to prove a measured level of cybersecurity. It is codified in 32 CFR Part 170 and enforced through DFARS clauses 252.204-7012, -7019, -7020, and -7021.
Why It Matters Now
Three Levels
Most defense contractors handling CUI need Level 2.
Level 1 — Scope
Applies to any contractor that processes, stores, or transmits FCI but no CUI. Covers basic hygiene: access control, identification, media handling, physical protection, system integrity.
Level 1 — Delivery
Discovery — confirm FCI scope, inventory systems, identify named POC
Gap analysis — map current state to the 17 practices
Remediation — close gaps, document configurations
System Security Plan (SSP) — written and maintained for you
Annual self-attestation support — score calculation, SPRS submission
Level 2 — Scope
Applies to most defense contractors handling CUI — engineering drawings, technical data, test results, ITAR-controlled material. Triggered by DFARS clause 252.204-7021.
Level 2 — Delivery
You don’t go through Level 2 alone, and neither do we. The 3rd-party partner brings both BRITECITY and you through the assessment.
Level 3 — Referral
Applies to a small subset of high-priority programs. Government-led assessment by the Defense Industrial Base Cybersecurity Assessment Center.
What You Provide
Contract scope — which contracts contain DFARS 252.204-7021 and what data flows under them
System inventory — every device, app, and cloud tenant that touches FCI or CUI
Named project sponsor with budget authority
Named day-to-day point of contact
Decision on enclave-vs-enterprise scoping (a CUI enclave is usually cheaper to certify than the whole company)
Access to existing security tooling, M365 / Google tenant, and HR offboarding process
The Roadmap
Scope contracts, inventory systems, identify CUI flow, choose enclave vs. enterprise.
Map current state to required practices. Score against SPRS scale (-203 to 110).
Close gaps. Deploy MFA, FIPS-validated encryption, SIEM, EDR, account lifecycle automation, and policy.
Write the System Security Plan. Document any open items in a Plan of Action & Milestones.
Level 1 — submit self-assessment to SPRS. Level 2 — schedule and pass C3PAO assessment.
Reassess yearly. Maintain SPRS score. Re-certify Level 2 every 3 years.
Pricing Model
Single billable IT engagement at our standard rate. Scoped up front based on system count and current state.
Billable engagement at our standard rate, plus 3rd-party assessor fees passed through at cost. Scoped after a paid readiness assessment.
Not offered. Referral only.
Specific dollar figures and daily rates are confirmed in writing during the scoping call — not in this deck.
Common Pitfalls
Self-reported scores will be audited under -7020. A score that does not match reality becomes a False Claims Act exposure once a C3PAO confirms the gap.
Practices like MFA and FIPS-validated encryption cannot be POA&M items. Critical gaps must be closed before the assessment.
Primes must flow CMMC requirements to subs. A sub that cannot certify will be removed from the contract.
A bounded CUI enclave is typically the fastest, cheapest path to Level 2. Whole-company scoping is rarely required.
Readiness for a contractor starting from scratch is usually 12–18 months. Waiting until the clause hits the solicitation is too late.
Next Steps
Free 30-minute call. We confirm the level you need, the contracts in play, and whether BRITECITY is a fit (Level 1 or Level 2) or whether you need a referral (Level 3).
Fixed-fee engagement. We document your current SPRS score, scope the CUI environment, and produce a written remediation plan with effort and timeline.
Billable IT engagement at our standard rate. Level 1 = scoped project. Level 2 = co-delivered with the 3rd-party assessor.
Level 1 self-attestation submitted to SPRS, or C3PAO assessment scheduled and supported through award.
britecity.com/book-a-call — 30 minutes, free, no commitment.
Prefer a printed handout? Download the walkthrough as a Word doc.
Make IT Easy