Skip to content
Menu

Compliance

CMMC

CMMC is the American defence department's framework for proving that a contractor handling sensitive but unclassified government information has the security controls it claims, verified at intervals rather than asserted.

It matters because it reaches a long way down the supply chain. A machine shop with a defence contract is in scope, which means their MSP is too, and the requirement arrives as a condition of the client keeping work they already have rather than as a new opportunity.

The levels differ in what is assessed and by whom — the lowest is self-assessed against a short list of practices, the middle one is assessed by an outside party against a substantially longer list, and the top tier is assessed by the government. Most defence work sits at the middle level, and the jump from self-assessment to third-party assessment is where the real cost lands.

The common trap is scoping late. What is in scope depends on where the controlled information actually lives, and an environment that has never been segmented puts everything in scope by default. Providers who do the segmentation first assess a small estate; providers who leave it assess all of it.