CMMC compliance

Get CMMC ready without building a security team first.

If you handle Federal Contract Information or Controlled Unclassified Information for the Department of Defense, CMMC decides whether you can win the contract. A dedicated SecureSlate compliance lead scopes your CUI environment, writes your System Security Plan, and prepares you for self-assessment or a C3PAO assessment, while our compliance automation platform keeps the evidence current. One fixed price covers the work.

NIST SP 800-171 Rev. 2110 requirements

NIST SP 800-171 Rev. 2: 110 requirements, 22 Access Control, 3 Awareness and Training, 9 Audit and Accountability, 9 Configuration Management, 11 Identification and Authentication, 3 Incident Response, 6 Maintenance, 9 Media Protection, 2 Personnel Security, 6 Physical Protection, 3 Risk Assessment, 4 Security Assessment, 16 System and Communications Protection, 7 System and Information Integrity. 7 highlighted: Evidenced by included security scanning.

Evidenced by included security scanningScoped with your compliance lead
Levels
1, 2, and 3
Level 2 requirements
110 from NIST SP 800-171
Level 2 and 3 status
3 years, affirmed every year
The standard

CMMC compliance decides whether you can win defense contracts, and your data sets the level.

The Cybersecurity Maturity Model Certification verifies that defense contractors protect Federal Contract Information and Controlled Unclassified Information. Requirements can appear in DoD solicitations under a phased rollout that began on 10 November 2025.

Three levels tied to your data

Level 1 covers 15 basic safeguarding requirements for Federal Contract Information. Level 2 covers the 110 requirements of NIST SP 800-171 for Controlled Unclassified Information. Level 3 adds selected NIST SP 800-172 requirements for the most sensitive programs.

Self-assessment or third-party assessment

Level 1 is an annual self-assessment. Level 2 is a self-assessment or a C3PAO assessment depending on the contract, and Level 3 is assessed by the government. Results are recorded in SPRS and affirmed by a senior official.

Your SSP and scope carry the assessment

Assessors work from your System Security Plan and the boundary of systems that process, store, or transmit CUI. A tight enclave keeps scope and cost down, and a limited set of gaps can be carried in a POA&M if you still meet the minimum score.
How it works

We build your CMMC program so the assessment, not the paperwork, is the last step.

Four stages from the scoping call to an assessment, with a named compliance lead accountable at every one.

Scope FCI, CUI, and your level

We identify where Federal Contract Information and CUI enter and live in your environment, confirm the level your contracts require, and look for an enclave that keeps the assessment boundary small.

Gap assessment and SPRS score

Your compliance lead assesses every applicable NIST SP 800-171 requirement, calculates your current score using the DoD assessment methodology, and turns the gaps into a dated plan with owners.

Implement controls and write the SSP

Access, configuration, logging, incident response, and media controls put in place, with the System Security Plan and POA&M written against how your environment actually works and evidence collected continuously.

Assessment and annual affirmation

We prepare you for self-assessment or coordinate with your C3PAO through the assessment, then keep controls and evidence current for annual affirmations and the next assessment cycle.
What is included

Everything your CMMC assessor examines, prepared before they ask.

CMMC compliance software and the expert who runs it arrive together under one fixed price, so the program does not land on your engineers.

A dedicated compliance lead

One experienced practitioner owns your CMMC program end to end. They scope CUI, write the System Security Plan, maintain the POA&M, and work with your C3PAO directly, so your team reviews and approves instead of decoding NIST SP 800-171.

System Security Plan and POA&M

An SSP that describes how each requirement is implemented in your environment, and a POA&M that tracks any open items against their deadlines, both kept current as your systems change.

Evidence from the stack you already run

Connect your cloud provider, identity provider, code host, and devices once. Controls are tested continuously against live configuration, and when one fails, SecureSlate AI finds the gap and prepares a fix for your team to approve.

Access control and authentication

Access reviews, least privilege, multifactor authentication coverage, and joiner and leaver tasks tracked on a schedule, covering the two families that make up nearly a third of Level 2.

Subcontractors and cloud services

Subcontractors and cloud services that handle CUI tracked with their security status and contract flow-down, so your supply chain does not become the gap in your assessment.

Security awareness and incident response

Security awareness and insider threat training tracked for everyone with access to CUI, alongside an incident response capability you have actually tested.
NIST SP 800-171 evidence

Several CMMC requirements need evidence from your code and cloud, not a policy.

Vulnerability scanning, flaw remediation, configuration, and boundary protection are assessed against what actually runs. Security scanning is part of the engagement, so the evidence comes from your real repositories, domains, and cloud accounts.
NIST SP 800-171 3.11.2, 3.14.1

Code security scanning

Repositories scanned for vulnerable code, with findings ranked by severity and traced to the line, which evidences vulnerability scanning and timely correction of system flaws.
NIST SP 800-171 3.5.10

Secrets detection

Credentials committed to source code found and pinpointed to the file and line, because passwords sitting in plain text break the requirement to store only cryptographically protected passwords.
NIST SP 800-171 3.11.2, 3.11.3

Dependency and license risk

An SBOM for every repository, with vulnerable open source components flagged and prioritized, so remediation follows your risk assessment.
NIST SP 800-171 3.11.2, 3.13.1

Public surface monitoring

Your domains and forgotten subdomains scanned on a schedule and when you ship, covering vulnerability scanning and exposure at your external system boundary.
NIST SP 800-171 3.14.3

Dark web monitoring

Company email addresses checked against known breach data, giving you security alerts to act on when workforce credentials are exposed.
NIST SP 800-171 3.4.2

Cloud misconfiguration checks

AWS, Azure, and GCP configurations checked through read-only access against secure configuration settings for encryption, access, logging, and networking.
Beyond CMMC

One program, several frameworks.

CMMC is built on NIST, so the work carries into the frameworks federal and commercial buyers ask for.

NIST SP 800-171

The requirements behind CMMC Level 2, and the basis of the DFARS obligations many defense contractors already carry.

DFARS 252.204-7012

The contract clause that already requires NIST SP 800-171, cyber incident reporting to the DoD within 72 hours, and adequately secured cloud services.

FedRAMP

The certification cloud service providers need to sell to federal agencies, now assessed through FedRAMP 20x Key Security Indicators as well as NIST SP 800-53.

SOC 2

Commercial buyers ask for SOC 2, and many of its access, change, and logging controls reuse your CMMC evidence.

ISO 27001

The international certificate, with a management system around the same risk and access controls CMMC assesses.

Enterprise

How SecureSlate runs CMMC alongside SOC 2, ISO 27001, and other frameworks for larger compliance programs.
CMMC guides

What your CMMC assessment actually tests

Three guides your team can read before the scoping call, from the levels to the rule that put CMMC into contracts.

Levels 1 to 3
Which CMMC level applies to your contracts and the information you handle
110
CMMC Level 2 requirements, controls, and the certification process
Nov 2025
The final CMMC rule and what the phased rollout means for your contracts
Resources

Read up before your scoping call.

Practical guides to CMMC, from assessment types to what certification costs.

FAQs

What teams ask before starting CMMC compliance.

Find out what your CMMC assessment will take

Bring the contracts you are bidding on and the information you handle. You will leave the call with a scope summary, a timeline, and a fixed price, whether or not you work with us.

Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?