CMMC readiness

Build the evidence before the assessment begins.

We define the FCI or CUI boundary, test the applicable requirements, help close the gaps, and assemble an assessment record that can stand up to review.

Discuss CMMC readiness
Start with the requirement

The solicitation determines the assessment.

Before recommending tools or writing policy, we confirm what the contract requires and which systems fall inside the assessment scope.

Level 1 (Self)

For systems that handle FCI

Level 1 uses the safeguarding requirements in FAR 52.204-21. When a solicitation requires this level, the contractor needs a current final self-assessment status before award.

Level 2 (Self or C3PAO)

For systems that handle CUI

Level 2 uses the 110 requirements in NIST SP 800-171. The solicitation states whether the assessment is completed by the contractor or by an authorized C3PAO.

Level 3 is assessed by DIBCAC and adds selected NIST SP 800-172 requirements. We confirm whether it applies before defining an engagement.

The readiness work

From contract language to defensible evidence.

The work follows the system and the people who operate it. Each stage leaves behind something your team can maintain after the engagement.

Define the assessment scope

Map the contracts, information flows, people, facilities, and systems that make up the FCI or CUI environment. Where practical, we reduce the boundary before measuring it.

Measure current implementation

Review each applicable requirement, interview the people responsible for it, inspect technical settings, and record the evidence that exists today.

Close implementation gaps

Turn the findings into assigned work: configuration changes, operating procedures, policies, and technical controls. We sequence the work around risk and assessment impact.

Build the assessment record

Update the System Security Plan, maintain the POA&M where permitted, and organize evidence so an assessor can trace a requirement to the people, process, and system that satisfy it.

Run a mock assessment

Test the package with interviews, artifact reviews, and demonstrations. Any remaining weakness is documented with an owner and a practical next action.

Clear responsibilities

Preparation and assessment are different jobs.

Glacier Byte prepares

The environment and the record

We help establish scope, evaluate implementation, coordinate remediation, update the SSP and POA&M, organize evidence, and run a mock assessment.

The required assessor evaluates

The official CMMC status

The solicitation determines whether the assessment is completed by the contractor, a C3PAO, or DIBCAC. For a Level 2 (C3PAO) requirement, an authorized C3PAO conducts the official assessment.

What remains with your team

A working record, not a binder for the shelf.

The package is organized for assessment, but it is also meant to be maintained as contracts, systems, and personnel change.

  • FCI or CUI boundary and data-flow record
  • Requirement-by-requirement gap assessment
  • Prioritized remediation plan with owners
  • System Security Plan and POA&M support
  • Evidence index tied to each requirement
  • Mock-assessment findings and closeout list
Working documents

Start with the free CMMC templates.

Download an SSP shell, POA&M workbook, and policy templates. Use them as a starting point, then tailor them to the way your system actually operates.

View the templates
Common questions

Before the work starts.

Does Glacier Byte issue a CMMC status?

No. We prepare the environment, documentation, and evidence. The required assessment method is set by the solicitation. For Level 2 (C3PAO), an authorized C3PAO conducts the official assessment; Glacier Byte is not a C3PAO.

Which assessment type applies to us?

Start with the solicitation and contract flow-downs. They identify the required CMMC level and assessment type: Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), or Level 3 (DIBCAC). We confirm that requirement before scoping the work.

How does NIST SP 800-171 relate to CMMC?

CMMC Level 2 assesses the 110 security requirements in NIST SP 800-171. The work includes implementing those requirements, describing the system in the SSP, and maintaining evidence that shows how each requirement operates.

Can a Level 2 assessment result be conditional?

Current CMMC rules allow a conditional Level 2 status in limited circumstances for up to 180 days. Not every requirement can remain open. We verify the current limits and the solicitation before treating any item as eligible for a POA&M.

How long does readiness take?

It depends on the size of the boundary, the condition of the environment, and how much evidence already exists. We begin with scope and a baseline so the schedule is based on actual findings rather than a generic estimate.

Can you join work that is already underway?

Yes. We can review an existing SSP, SPRS score, gap assessment, remediation plan, or evidence library and continue from the work that holds up. The first step is to verify the scope and test the supporting evidence.

Next step

Begin with scope.

Bring the solicitation, current system boundary, and any existing SSP or score. We will help identify the useful next piece of work.

Talk with us