Nationwide · Defense Industrial Base
CMMC Compliance Services for Defense Contractors
We get contractors from an honest gap assessment to an assessment-ready environment — SSP, POA&M, SPRS score, and the technical controls behind them. Remote delivery nationwide.
- Level 1 and Level 2 implementation, start to assessment-ready
- Real SPRS baseline scoring, not a questionnaire
- SSP and POA&M written against your actual environment
- Remote delivery to contractors nationwide
Get Your Free CMMC Gap Assessment
Tell us where you are. We'll come back with your likely level, the highest-weighted gaps, and a scoped range — not a brochure.
- Level 1
- achieved for an industrial robotics manufacturer
- Defense
- software built for defense contractors
- Federal
- law-enforcement task force under active support
- Regulated
- HIPAA, IRS WISP & FTC Safeguards work
What is CMMC compliance?
CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense program that verifies contractors protect Federal Contract Information and Controlled Unclassified Information. Level 1 covers FCI and is an annual self-assessment against 15 requirements. Level 2 covers CUI, requires all 110 NIST SP 800-171 controls, and for most contracts requires a third-party assessment by an authorized C3PAO every three years. Requirements are phasing into DoD solicitations now, so the practical deadline is your next contract award, not a single government date.
Level 1 or Level 2?
One question decides it: do you handle CUI, or only FCI?
Level 1
Federal Contract Information
- 15 requirements from FAR 52.204-21
- Annual self-assessment
- Senior official affirmation in SPRS
- No third-party assessment
- No POA&Ms permitted
Level 2
Controlled Unclassified Information
- All 110 NIST SP 800-171 controls
- 14 control families
- C3PAO assessment every 3 years for most contracts
- Annual affirmations in between
- Limited POA&Ms, closed within 180 days
What we actually do
Scoping & enclave design
The highest-leverage decision in any Level 2 program. We design a CUI boundary you can actually operate inside.
Gap assessment & SPRS scoring
A real baseline against all 110 controls, scored with the DoD Assessment Methodology.
Remediation engineering
Identity, endpoint, logging, segmentation, and encryption work — done, not just recommended.
SSP & POA&M authorship
Written against your environment. Template SSPs with the company name swapped in do not survive a C3PAO.
Ongoing managed IT
Controls decay. We keep your environment in the state your SSP describes.
Software & engineering support
We build custom software for defense contractors, so we understand how CUI moves through repos and pipelines.
We do the work. We don't grade it.
Smith Network Solutions is not a C3PAO and not a registered RPO. We are the engineering and managed-services partner that closes your gaps, writes your System Security Plan, and gets your SPRS score where it needs to be. Your assessment is performed by an independent, authorized C3PAO — and that separation is deliberate. Under CMMC independence rules your assessor cannot remediate what they assess, so you need an implementation partner either way. We are that partner, and we will introduce you to C3PAOs when you are ready.
Where our experience comes from
We would rather tell you exactly what we have done than imply more than we have.
We took a Georgia-based industrial robotics manufacturer through CMMC Level 1 — scoping Federal Contract Information, closing the 15 FAR 52.204-21 requirements, and standing up the annual self-assessment and SPRS affirmation process.
We have designed and built custom software for defense contractors, so we understand how CUI actually moves through an engineering organization — not just how it looks on a network diagram.
We provide managed IT and security for a federally funded multi-state law enforcement task force, including VPN, firewall, and endpoint lifecycle work under government scrutiny.
We already work inside regulated environments every day — HIPAA for medical practices, Written Information Security Plans for CPA firms, FTC Safeguards for financial services, and ITAR-adjacent manufacturing. The control families rhyme; the documentation discipline is the same.
How an engagement runs
Scope
We determine which level applies and where CUI is allowed to live. This decision drives your entire budget, so we do it first and we do it carefully.
Assess
We assess your live environment against the applicable control set and produce a real SPRS baseline — not a questionnaire result.
Remediate
We close gaps in weighted priority order, so the controls that move your score most get attacked first.
Document
System Security Plan and POA&M written against your actual environment, with the evidence package an assessor will ask for.
Sustain
Managed services keep controls in place between assessments, so annual affirmations are a review rather than a rebuild.
Find out which level you're in — for free
Most contractors we talk to are not certain whether they handle CUI. That single answer changes your budget by an order of magnitude. We'll scope it with you at no cost.
Nationwide remote delivery · Response within 1 business hour
CMMC compliance guides
CMMC Level 1 Compliance
If you handle Federal Contract Information but never touch CUI, Level 1 is your bar. It is the most achievable tier in CMMC — and the one contractors most often get wrong by assuming it is optional.
Read the guide →CMMC Level 2 Compliance
Level 2 is where CMMC gets expensive and where most contractors stall. 110 controls, a real assessment, and a scoping decision at the start that determines everything downstream.
Read the guide →NIST SP 800-171 Compliance
800-171 is the control set underneath CMMC Level 2 — and it has been contractually required under DFARS since long before CMMC existed. If you hold a DFARS 7012 clause, this already applies to you.
Read the guide →How Much Does CMMC Compliance Cost?
Anyone who quotes you a CMMC price before scoping your environment is guessing. Here is what actually drives the number, so you can build a defensible budget.
Read the guide →Managed IT for Defense Contractors
Getting compliant is a project. Staying compliant is an operating discipline. Most contractors fail the second one because their MSP was never built for it.
Read the guide →CMMC Compliance FAQs
What is CMMC and who does it apply to?
CMMC is the Department of Defense program that verifies contractors adequately protect Federal Contract Information and Controlled Unclassified Information. It applies to companies across the Defense Industrial Base — primes, subcontractors, and suppliers — whose contracts include the relevant DFARS clauses. If you receive non-public information from the government or a prime under a federal contract, you are almost certainly in scope at some level.
What level do we need?
It comes down to what data you handle. Federal Contract Information only means Level 1, an annual self-assessment against 15 requirements. Any Controlled Unclassified Information means Level 2, which requires all 110 NIST SP 800-171 controls and, for most contracts, a third-party assessment by an authorized C3PAO. Level 3 applies to a small number of highest-priority programs and is assessed by the government directly.
When is the deadline?
There is no single date that applies to everyone. CMMC requirements phase into DoD solicitations over time, so your practical deadline is the next contract or option year that carries the requirement. Contractors who wait for a universal deadline tend to discover their real one with only a few weeks of notice — which is not enough time for a Level 2 program.
Are you a C3PAO? Can you certify us?
No. Smith Network Solutions is not a C3PAO and is not a registered RPO, and we do not perform certification assessments. We are the implementation partner that closes your gaps, writes your SSP and POA&M, and gets your environment assessment-ready. Your certification comes from an independent authorized C3PAO — a separation that CMMC independence rules require regardless of who you hire.
Do you work with contractors outside Georgia?
Yes. We support defense contractors nationwide. Compliance engineering is delivered remotely — scoping, remediation, documentation, and ongoing managed services do not require us to be in your building. Our headquarters is in the Atlanta metro, which matters only if you want onsite work in the Southeast.
What does the free gap assessment actually include?
We scope which level applies to you, assess your environment against the applicable control set, produce a real SPRS baseline score where Level 2 applies, and identify the highest-weighted gaps in priority order. You get a scoped remediation range afterward. There is no cost and no obligation, and we will sign an NDA first if you prefer.

