CMMC compliance, from gap assessment to certification

CMMC helps decide which contractors can compete for Department of Defense (DoD) business. Contractors that handle Controlled Unclassified Information (CUI) must implement the NIST 800-171 controls, post a score to the Supplier Performance Risk System (SPRS), and, for most, pass a third-party assessment by a C3PAO. SideChannel is a CMMC Registered Provider Organization (RPO) that combines vCISO leadership with Enclave, our zero-trust platform, to take you from gap analysis to certification and keep you there. Building a defense or manufacturing program? See the DoD Contractors & the Defense Industrial Base page.

How SideChannel gets you to CMMC

SideChannel combines vCISO leadership with Enclave to run the compliance program and provide the controls behind it. These are the three core elements of a CMMC engagement.

01

Reduce your assessment scope with a CUI enclave

In CMMC and NIST 800-171, a segmented boundary around the systems that handle CUI is the standard way to reduce how much of your environment falls inside assessment scope, which lowers cost, complexity, and audit surface at once. Enclave's network segmentation builds that boundary, isolating CUI-handling systems from the rest of the network and protecting legacy shop-floor equipment that cannot be re-architected, with no network redesign.

CUI Assessment Scope
02

Build the SPRS score and POA&M evidence that holds up

An SPRS score and a Plan of Action and Milestones are only as credible as the asset inventory behind them, and a spreadsheet nobody trusts is what turns a self-attestation into risk. Enclave's asset intelligence keeps a live, accurate inventory of every system in scope, and automated certificate lifecycle management keeps CUI encrypted in transit without manual renewals that fall behind. So when the assessor asks for your inventory, the evidence behind your score is already current.

Score and Evidence
03

From gap assessment to defensive attestation

A vCISO drives the program end to end: gap analysis against NIST 800-171, System Security Plan development, POA&M management, SPRS scoring, through to a self-attestation you can defend. One team owns the program from assessment to attestation and keeps it current as the CMMC rules evolve, so you are ready if a third-party assessment is required.

Gap to Attestation

What CMMC compliance requires

When a vCISO identifies a gap against these requirements, Enclave closes the technical side of it.

NIST 800-171 and DFARS 252.204-7012

The clause that requires contractors handling CUI to implement the 110 NIST 800-171 controls and report cyber incidents to the DoD within 72 hours.

SPRS Score (DFARS 252.204-7019 and 7020)

A self-assessment score, from 110 down to negative values, that you post to the Supplier Performance Risk System and must have on file to be eligible for award. 7019 and 7020 require you to submit, maintain, and flow down that score.

CMMC 2.0 (Level 1 and Level 2)

Level 1 covers Federal Contract Information and requires a self-assessment against the 15 basic safeguarding requirements in FAR 52.204-21. Level 2 covers CUI and rests on the NIST 800-171 controls, plus an additional set of requirements written into the FAR and DFARS. Contractors complete a gap assessment, align to the controls, and attest to their compliance.

Frequently Asked Questions

What is CMMC and who needs to comply?

The Cybersecurity Maturity Model Certification (CMMC) is a Department of Defense program that requires contractors and subcontractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) to meet the security requirements appropriate to the information they handle and attest to that compliance. It applies across the Defense Industrial Base, from small subcontractors to large primes.

What is the difference between CMMC Level 1 and Level 2?

Level 1 applies to contractors handling only FCI and requires a self-assessment against the 15 basic safeguarding requirements in FAR 52.204-21. Level 2 applies to contractors handling CUI and holds them to the 110 controls in NIST 800-171, a significantly higher bar. Contractors gap-assess, align to the controls, and attest to their compliance.

How does network segmentation reduce CMMC assessment scope?

CMMC and NIST 800-171 allow contractors to limit assessment scope to the systems that actually handle CUI, provided those systems are properly isolated in a segmented enclave. Enclave's network segmentation builds that boundary, which means fewer systems fall under assessment, lowering both cost and audit complexity.

What is an SPRS score and how is it calculated?

The Supplier Performance Risk System (SPRS) score is a self-reported score, from 110 down to negative values, reflecting how many of the 110 NIST 800-171 controls a contractor has implemented. DFARS 252.204-7019 and 7020 require an SPRS score on file for DoD contracts that involve CUI, and a Plan of Action and Milestones (POA&M) documents the path to closing whatever isn't yet implemented.

Can SideChannel certify us for CMMC?

No, SideChannel builds and runs the program behind your CMMC compliance, but it does not grant certification. If an independent third-party assessment is required for your contract, SideChannel partners with assessors. SideChannel takes you through gap analysis, remediation, and readiness, then works alongside your chosen C3PAO through certification.

Get to CMMC with a team that owns the whole program

Whether you are starting a gap analysis or getting your SPRS score and attestation in order, SideChannel can get you there and keep it defensible. Tell us where you are on the path and we will start from there.