RubinBrown’s team of experienced professionals can help your organization by assessing readiness, supporting and preparing you for certification, and providing on-going CMMC management.
RubinBrown’s team of experienced professionals can help your organization by assessing readiness, supporting and preparing you for certification, and providing on-going CMMC management.
The CMMC framework consists of the security requirements from NIST SP 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, and a subset of the requirements from NIST SP 800-172 Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171. There are three levels within CMMC - Level 1, Level 2, and Level 3.
The first step in the process is to go through a CMMC Readiness Assessment to determine how your organization is meeting the requirements and what needs to be done before a certifier arrives to audit the environment. Following the readiness review, the organization can focus on remediation efforts, improving the environment, and making sure they are prepared for a certification audit. Prime contractors are already working through the process and are pressuring their subcontractors to take the necessary steps to meet or exceed requirements in preparation for the certification. Smaller subcontractors will be included in the process over the next 12 to 18-months. If your organization is in the supply chain for the DoD, it is time to prepare for CMMC.