We Need CMMC Level 2. Where Do We Start?

If your organization needs CMMC Level 2, start by understanding the contractual requirement, where Controlled Unclassified Information enters and moves through your environment, what systems and people are actually in scope, what existing cybersecurity controls can be reused, and what gaps must be remediated before assessment.

Do not start by buying a CMMC tool.

Do not start by writing 110 isolated answers.

And do not assume the entire company must automatically be included in the assessment boundary.

CMMC Level 2 is an implementation and operating challenge before it is an assessment challenge.

Hotman Group helps organizations scope, assess, design, implement, remediate, document, prepare and sustain cybersecurity programs that need to meet CMMC Level 2 requirements.

The fastest path to CMMC is not rushing to the assessment. It is accurately defining scope, understanding what already works, fixing what does not, and building evidence that demonstrates the required practices are operating.

Who Can Help Us Get Ready for CMMC Level 2?

Organizations often need more than a CMMC gap assessment.

Depending on the current state, the work may require:

  • CUI scoping;
  • architecture analysis;
  • NIST SP 800-171 assessment;
  • control design;
  • technical remediation;
  • policy and procedure development;
  • control narratives;
  • evidence development;
  • System Security Plan development;
  • POA&M management;
  • assessment readiness;
  • and ongoing program operation.

Hotman Group can help across that lifecycle rather than stopping after identifying gaps.

What Is CMMC Level 2?

CMMC Level 2 is the level generally associated with organizations that handle Controlled Unclassified Information and must demonstrate implementation of applicable cybersecurity requirements based on NIST SP 800-171.

The practical challenge is not merely understanding the requirements.

The organization must be able to demonstrate that applicable practices are implemented within the defined assessment scope.

What Should We Do First?

Start with five questions:

  • Why does CMMC apply to us?
  • What information creates the requirement?
  • Where does that information flow?
  • What people, systems and services interact with it?
  • What cybersecurity capabilities already exist?

Those answers shape almost everything that follows.

How Do We Know Whether We Actually Need CMMC Level 2?

Review the applicable contractual and information-handling requirements.

Determine whether the organization receives, creates, stores, processes or transmits information that drives the Level 2 requirement and what contractual obligations apply.

Do not rely only on a verbal statement that “you need CMMC.”

Why Is CMMC Scope So Important?

Scope determines which parts of the environment must satisfy the applicable requirements and be prepared for assessment.

An unnecessarily broad scope can increase:

  • implementation cost;
  • technical complexity;
  • evidence requirements;
  • assessment effort;
  • and ongoing operating burden.

An incorrectly narrow scope can leave required systems or information outside the program.

See what is actually in scope for CMMC.

What Is CUI?

Controlled Unclassified Information, or CUI, is information that requires safeguarding or dissemination controls under applicable federal requirements but is not classified national security information.

For CMMC planning, the organization needs to understand what information it actually receives or creates and where that information goes.

Should We Map CUI Before Performing a Gap Assessment?

Yes.

A gap assessment performed against an undefined or inaccurate environment can produce an inaccurate implementation plan.

Understand:

  • where CUI enters;
  • where it is stored;
  • where it is processed;
  • where it is transmitted;
  • who accesses it;
  • which systems protect it;
  • and which external providers may be involved.

Does the Entire Company Have to Be in Scope?

Not automatically.

The appropriate boundary depends on how CUI and supporting systems are structured.

Some organizations intentionally design more limited environments to reduce complexity.

The architecture still has to support actual business operations and satisfy the applicable requirements.

Should We Build a CMMC Enclave?

An enclave can be useful when the organization can reasonably isolate CUI-related activity into a controlled environment.

But an enclave is not automatically the right answer.

Consider:

  • how employees work;
  • where CUI originates;
  • required applications;
  • collaboration;
  • external users;
  • business processes;
  • technical dependencies;
  • and ongoing administration.

The goal is a secure and sustainable operating model, not merely the smallest theoretical boundary.

What Is the Relationship Between CMMC Level 2 and NIST SP 800-171?

NIST SP 800-171 provides the underlying security requirements relevant to protecting CUI in nonfederal systems and organizations.

CMMC adds an assessment and assurance structure around implementation of the applicable requirements.

For an organization preparing for CMMC Level 2, NIST SP 800-171 implementation is therefore central to the work.

Should We Start With a NIST SP 800-171 Gap Assessment?

Once scope is sufficiently understood, a current-state assessment is usually an important next step.

The assessment should determine:

  • what is implemented;
  • what is partially implemented;
  • what is missing;
  • what evidence exists;
  • what documentation exists;
  • and what requires remediation.

Can We Reuse Existing Cybersecurity Controls for CMMC?

Yes, where those controls genuinely satisfy the applicable requirements within the CMMC scope.

Organizations may already have relevant capabilities through:

  • existing cybersecurity programs;
  • SOC 2;
  • ISO 27001;
  • NIST frameworks;
  • other government requirements;
  • or mature internal security practices.

See how to reuse existing security controls for CMMC.

Does Framework Overlap Mean the CMMC Requirement Is Already Satisfied?

No.

Overlap creates an opportunity for reuse.

It does not prove implementation.

An existing control must be evaluated against the specific requirement, scope and assessment expectations.

What Should a CMMC Gap Assessment Produce?

A useful assessment should produce more than a list of failed practices.

The organization should understand:

  • what the gap actually is;
  • why it exists;
  • what must change;
  • who needs to own the remediation;
  • technical dependencies;
  • documentation requirements;
  • evidence requirements;
  • and the likely implementation sequence.

What Happens After the CMMC Gap Assessment?

Build a remediation plan.

Prioritize work based on:

  • dependencies;
  • implementation effort;
  • technical architecture;
  • available resources;
  • assessment timing;
  • and the sequence required to make controls operational.

See what should happen after a cybersecurity assessment.

Who Can Help Remediate CMMC Gaps?

Remediation may require a combination of:

  • Cyber GRC expertise;
  • security architecture;
  • IT;
  • engineering;
  • policy and process design;
  • technical implementation;
  • documentation;
  • and project coordination.

Hotman Group helps organizations move from assessment findings into implemented and sustainable cybersecurity controls.

See how Hotman Group approaches cybersecurity remediation.

Do We Need Policies for CMMC?

Policies and procedures are important where they define how required cybersecurity activities are governed and performed.

But documents should reflect the program the organization actually operates.

Creating a large policy library without implementing the underlying practices does not create assessment readiness.

What Is a System Security Plan?

The System Security Plan, or SSP, documents the system environment and how applicable security requirements are implemented.

It should reflect the actual architecture, scope, controls and operating practices.

An SSP should not be treated as a document created independently from the implementation work.

What Are Control Narratives?

Control narratives explain how the organization satisfies specific security requirements.

Strong narratives should accurately describe:

  • what happens;
  • who performs it;
  • which systems are involved;
  • how frequently it occurs where relevant;
  • and what evidence demonstrates implementation.

What Evidence Do We Need?

Evidence depends on the requirement and implementation.

It may include:

  • configurations;
  • system records;
  • tickets;
  • logs;
  • reports;
  • training records;
  • policies;
  • procedures;
  • screenshots;
  • technical documentation;
  • and other artifacts demonstrating that practices operate.

Should We Wait Until Assessment Preparation to Collect Evidence?

No.

Evidence should be considered during implementation.

A control that is difficult to prove may indicate that the operating process or evidence model needs improvement.

See how to centralize cybersecurity evidence without creating more work.

Can We Use POA&Ms for CMMC?

The applicable CMMC and contractual requirements determine when and how Plans of Action and Milestones may be used.

From a program perspective, a POA&M should document a real remediation commitment with:

  • a defined gap;
  • corrective action;
  • ownership;
  • dependencies;
  • and a completion plan.

It should not become a permanent substitute for required implementation.

Do We Need a GRC Platform for CMMC?

No.

A GRC platform can help manage:

  • requirements;
  • controls;
  • evidence;
  • findings;
  • remediation;
  • ownership;
  • and recurring work.

But software does not implement CMMC for the organization.

See how to determine whether you actually need a GRC platform.

Can Compliance Automation Get Us CMMC Ready?

Automation can reduce administrative work.

It cannot replace:

  • accurate scope;
  • technical implementation;
  • security architecture;
  • risk decisions;
  • control ownership;
  • or human judgment.

See how to automate compliance without automating bad processes.

How Do We Assign CMMC Control Ownership?

The GRC team should not automatically own every requirement.

Controls may be operated by:

  • IT;
  • security;
  • HR;
  • facilities;
  • engineering;
  • management;
  • or other functions.

See how to create clear ownership for cybersecurity controls.

What If Our Team Does Not Have Enough Capacity?

CMMC implementation can create substantial temporary and ongoing workload.

Organizations should distinguish between:

  • work that must remain internal;
  • specialized work that can be outsourced;
  • temporary remediation capacity;
  • and recurring sustainment work.

See what an overwhelmed cybersecurity and GRC team should consider outsourcing.

How Long Does CMMC Level 2 Readiness Take?

There is no universal timeline.

Timing depends on:

  • scope;
  • current maturity;
  • technical gaps;
  • architecture changes;
  • available resources;
  • documentation;
  • evidence;
  • and remediation dependencies.

A company with substantial existing capability may have a very different path from one starting with an immature security program.

How Much Does CMMC Level 2 Cost?

Cost depends on the current environment and what must change.

Potential costs include:

  • consulting;
  • technical remediation;
  • new technology;
  • architecture changes;
  • internal labor;
  • documentation;
  • assessment;
  • and ongoing operation.

Scope can materially affect these costs.

Should CMMC Be a Separate Cybersecurity Program?

Not if the organization can integrate the applicable requirements into its broader cybersecurity program.

CMMC may have specific assessment and documentation needs, but many underlying cybersecurity capabilities can support other frameworks and customer requirements too.

See how to build one cybersecurity program across multiple frameworks.

What If We Already Have SOC 2 or ISO 27001?

Use the existing program as a starting point.

Existing controls may provide meaningful reuse.

But do not assume certification against one framework automatically demonstrates satisfaction of CMMC requirements.

Evaluate the actual overlap.

Can CMMC Work Create Value Beyond One Contract?

Yes.

Where possible, implementation should create reusable cybersecurity capability that can support:

  • other government customers;
  • other frameworks;
  • future contracts;
  • customer assurance;
  • and stronger cybersecurity operations.

What If CMMC Is Driving Major Product or Business Costs?

Then CMMC is no longer only a compliance project.

The organization should understand:

  • the revenue opportunity;
  • implementation cost;
  • ongoing operating cost;
  • product implications;
  • architecture implications;
  • pricing implications;
  • and whether the capability can support future business.

See what to do when customer cybersecurity requirements are driving major cost and product decisions.

How Do We Prepare for the CMMC Assessment?

Before assessment, the organization should be able to:

  • explain scope;
  • explain how each applicable requirement is implemented;
  • identify responsible personnel;
  • produce relevant evidence;
  • demonstrate technical implementation;
  • and explain any permitted open remediation.

Assessment readiness should be the result of implementation, not a last-minute evidence exercise.

Should We Perform a Readiness Review Before the Assessment?

A readiness review can be valuable when it validates:

  • scope;
  • implementation;
  • documentation;
  • evidence;
  • and unresolved gaps

before the formal assessment begins.

What Happens After CMMC Certification?

The cybersecurity program still has to operate.

Controls can degrade as:

  • people change;
  • systems change;
  • vendors change;
  • architecture changes;
  • and business processes evolve.

See how to maintain cybersecurity compliance after certification.

How Hotman Group Helps With CMMC Level 2

Hotman Group helps organizations move through the full CMMC readiness lifecycle.

HG can help with:

  • CUI and assessment scoping;
  • current-state assessment;
  • NIST SP 800-171 implementation;
  • security architecture and control design;
  • remediation planning;
  • implementation support;
  • policy and procedure development;
  • control narratives;
  • SSP development;
  • evidence development;
  • POA&M management;
  • readiness review;
  • assessment preparation;
  • and ongoing sustainment.

CMMC Readiness Is Built, Not Documented Into Existence

Documentation matters.

Evidence matters.

Assessment preparation matters.

But they should describe and prove cybersecurity practices that actually operate.

That is why HG approaches CMMC as a cybersecurity implementation and operating problem rather than only a certification exercise.

CMMC readiness is strongest when the organization can clearly connect requirement, implementation, owner, evidence and ongoing operation.

Frequently Asked Questions

Where should we start with CMMC Level 2?

Start by confirming the requirement and understanding CUI scope. Then assess existing cybersecurity capabilities against the applicable NIST SP 800-171 requirements, identify true gaps, remediate them and build the documentation and evidence needed to demonstrate implementation.

Does our entire company have to be in CMMC scope?

Not automatically. Scope depends on CUI flows, systems, people, security protection assets and other relevant components of the environment. Accurate scoping is an important early step.

Can we reuse existing controls for CMMC?

Yes. Existing cybersecurity controls may satisfy CMMC requirements when they operate within the applicable scope and genuinely meet the specific requirement.

Do we need a GRC platform for CMMC?

No. A platform can help manage requirements, evidence and remediation, but it does not replace the implementation of required cybersecurity practices.

Is a gap assessment enough to get ready for CMMC?

No. A gap assessment identifies current-state weaknesses. The organization still needs to remediate gaps, implement controls, document the environment, develop evidence and prepare for assessment.

Can Hotman Group help us implement CMMC Level 2?

Yes. Hotman Group can help with scoping, assessment, NIST SP 800-171 implementation, remediation, documentation, evidence, SSP development, assessment readiness and ongoing sustainment.

About Hotman Group

Hotman Group is a cybersecurity and Cyber GRC professional services firm that helps organizations solve complex cybersecurity, risk, governance, compliance and technology problems.

HG helps organizations approach CMMC as part of a functioning cybersecurity program, from accurate scoping and implementation through evidence, assessment readiness and ongoing operation.

Learn more about what Hotman Group is and the cybersecurity and Cyber GRC problems HG solves.