Nationwide CMMC & NIST 800-171 implementation for the Defense Industrial Base

Nationwide · Defense Industrial Base

CMMC Compliance Services for Defense Contractors

We get contractors from an honest gap assessment to an assessment-ready environment — SSP, POA&M, SPRS score, and the technical controls behind them. Remote delivery nationwide.

  • Level 1 and Level 2 implementation, start to assessment-ready
  • Real SPRS baseline scoring, not a questionnaire
  • SSP and POA&M written against your actual environment
  • Remote delivery to contractors nationwide

Get Your Free CMMC Gap Assessment

Tell us where you are. We'll come back with your likely level, the highest-weighted gaps, and a scoped range — not a brochure.

Not sure? That's the most common answer — and it's the first thing we work out with you.

No cost. No obligation. NDA available on request.

We respond within 1 business hour · We are not a C3PAO and do not perform certification assessments

Level 1
achieved for an industrial robotics manufacturer
Defense
software built for defense contractors
Federal
law-enforcement task force under active support
Regulated
HIPAA, IRS WISP & FTC Safeguards work

What is CMMC compliance?

CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense program that verifies contractors protect Federal Contract Information and Controlled Unclassified Information. Level 1 covers FCI and is an annual self-assessment against 15 requirements. Level 2 covers CUI, requires all 110 NIST SP 800-171 controls, and for most contracts requires a third-party assessment by an authorized C3PAO every three years. Requirements are phasing into DoD solicitations now, so the practical deadline is your next contract award, not a single government date.

Level 1 or Level 2?

One question decides it: do you handle CUI, or only FCI?

Level 1

Federal Contract Information

  • 15 requirements from FAR 52.204-21
  • Annual self-assessment
  • Senior official affirmation in SPRS
  • No third-party assessment
  • No POA&Ms permitted
CMMC Level 1 requirements →

Level 2

Controlled Unclassified Information

  • All 110 NIST SP 800-171 controls
  • 14 control families
  • C3PAO assessment every 3 years for most contracts
  • Annual affirmations in between
  • Limited POA&Ms, closed within 180 days
CMMC Level 2 requirements →

What we actually do

Scoping & enclave design

The highest-leverage decision in any Level 2 program. We design a CUI boundary you can actually operate inside.

Gap assessment & SPRS scoring

A real baseline against all 110 controls, scored with the DoD Assessment Methodology.

Remediation engineering

Identity, endpoint, logging, segmentation, and encryption work — done, not just recommended.

SSP & POA&M authorship

Written against your environment. Template SSPs with the company name swapped in do not survive a C3PAO.

Ongoing managed IT

Controls decay. We keep your environment in the state your SSP describes.

Software & engineering support

We build custom software for defense contractors, so we understand how CUI moves through repos and pipelines.

We do the work. We don't grade it.

Smith Network Solutions is not a C3PAO and not a registered RPO. We are the engineering and managed-services partner that closes your gaps, writes your System Security Plan, and gets your SPRS score where it needs to be. Your assessment is performed by an independent, authorized C3PAO — and that separation is deliberate. Under CMMC independence rules your assessor cannot remediate what they assess, so you need an implementation partner either way. We are that partner, and we will introduce you to C3PAOs when you are ready.

Where our experience comes from

We would rather tell you exactly what we have done than imply more than we have.

We took a Georgia-based industrial robotics manufacturer through CMMC Level 1 — scoping Federal Contract Information, closing the 15 FAR 52.204-21 requirements, and standing up the annual self-assessment and SPRS affirmation process.

We have designed and built custom software for defense contractors, so we understand how CUI actually moves through an engineering organization — not just how it looks on a network diagram.

We provide managed IT and security for a federally funded multi-state law enforcement task force, including VPN, firewall, and endpoint lifecycle work under government scrutiny.

We already work inside regulated environments every day — HIPAA for medical practices, Written Information Security Plans for CPA firms, FTC Safeguards for financial services, and ITAR-adjacent manufacturing. The control families rhyme; the documentation discipline is the same.

How an engagement runs

01

Scope

We determine which level applies and where CUI is allowed to live. This decision drives your entire budget, so we do it first and we do it carefully.

02

Assess

We assess your live environment against the applicable control set and produce a real SPRS baseline — not a questionnaire result.

03

Remediate

We close gaps in weighted priority order, so the controls that move your score most get attacked first.

04

Document

System Security Plan and POA&M written against your actual environment, with the evidence package an assessor will ask for.

05

Sustain

Managed services keep controls in place between assessments, so annual affirmations are a review rather than a rebuild.

Find out which level you're in — for free

Most contractors we talk to are not certain whether they handle CUI. That single answer changes your budget by an order of magnitude. We'll scope it with you at no cost.

Nationwide remote delivery · Response within 1 business hour

CMMC Compliance FAQs

What is CMMC and who does it apply to?

CMMC is the Department of Defense program that verifies contractors adequately protect Federal Contract Information and Controlled Unclassified Information. It applies to companies across the Defense Industrial Base — primes, subcontractors, and suppliers — whose contracts include the relevant DFARS clauses. If you receive non-public information from the government or a prime under a federal contract, you are almost certainly in scope at some level.

What level do we need?

It comes down to what data you handle. Federal Contract Information only means Level 1, an annual self-assessment against 15 requirements. Any Controlled Unclassified Information means Level 2, which requires all 110 NIST SP 800-171 controls and, for most contracts, a third-party assessment by an authorized C3PAO. Level 3 applies to a small number of highest-priority programs and is assessed by the government directly.

When is the deadline?

There is no single date that applies to everyone. CMMC requirements phase into DoD solicitations over time, so your practical deadline is the next contract or option year that carries the requirement. Contractors who wait for a universal deadline tend to discover their real one with only a few weeks of notice — which is not enough time for a Level 2 program.

Are you a C3PAO? Can you certify us?

No. Smith Network Solutions is not a C3PAO and is not a registered RPO, and we do not perform certification assessments. We are the implementation partner that closes your gaps, writes your SSP and POA&M, and gets your environment assessment-ready. Your certification comes from an independent authorized C3PAO — a separation that CMMC independence rules require regardless of who you hire.

Do you work with contractors outside Georgia?

Yes. We support defense contractors nationwide. Compliance engineering is delivered remotely — scoping, remediation, documentation, and ongoing managed services do not require us to be in your building. Our headquarters is in the Atlanta metro, which matters only if you want onsite work in the Southeast.

What does the free gap assessment actually include?

We scope which level applies to you, assess your environment against the applicable control set, produce a real SPRS baseline score where Level 2 applies, and identify the highest-weighted gaps in priority order. You get a scoped remediation range afterward. There is no cost and no obligation, and we will sign an NDA first if you prefer.