Common Cyber

CMMC and NIST SP 800-171 for Defense Contractors

Most defense contractors start this work when a prime asks a question they cannot answer confidently, a contract shows up with a DFARS clause, or their SPRS score does not reflect what is actually in place.

What brings defense contractors here?

Usually a specific event. Something arrives and the response cannot wait.

  • A prime asks whether you handle CUI
  • A flow-down clause arrives without implementation guidance
  • Your SPRS score needs an honest baseline
  • Your policies say one thing and your systems do another

Which CMMC level applies to you?

Many defense contractors will meet CMMC through a self-assessment rather than a third-party certification assessment, depending on the information their contracts involve.

Level 1 covers the 15 basic safeguarding requirements in FAR 52.204-21, self-assessed and affirmed annually, with all 15 assessed as met or not applicable. Level 2 covers all 110 requirements in NIST SP 800-171 Revision 2, each supported by evidence, with the affirmation submitted in SPRS by your Affirming Official.

Bringing in outside help does not change what the assessment is. The CMMC Assessment Guide for Level 1 states that an organization may perform the annual self-assessment internally or engage a third party to assist, and that using a third party is still considered a self-assessment.

Common Cyber scopes the boundary, closes the gaps, builds the evidence, and prepares the self-assessment record.

Which CMMC level applies to you

How is CUI scope clarified?

We find your scope by following the information. Which contracts bring it in, who handles it, where it ends up, and which vendors can see it.

How are NIST SP 800-171 gaps remediated?

Closing a gap takes three things: build the control, write down how it actually works, and keep the proof. Skip the third and you will be doing this again next year.

What makes readiness sustainable?

Someone has to own each control, keep the evidence current, and review change. If nobody does, readiness degrades within months.

A fixed-fee path to a clear boundary.

The assessment clarifies applicability, maps scope, establishes a readiness baseline, and builds a prioritized statement of work.

CMMC Readiness and Scope Assessment

A defined first step that establishes scope, readiness, and a practical remediation path.

Frequently asked questions

Does every defense contractor need CMMC?

No. Applicability depends on the contract, information handled, required CMMC status, and rules in force at the time of award.

What is the difference between FCI and CUI?

FCI is nonpublic information provided by or generated for the government under a contract. CUI is information that requires safeguarding or dissemination controls under applicable authority. The contract and information owner determine the relevant handling obligations.

What does an SPRS score show?

An SPRS score records a contractor's assessment result against the applicable NIST SP 800-171 methodology. It is not a certification and should be supported by current evidence.

What does the assessment cost?

The CMMC Readiness and Scope Assessment has a fixed fee of $25,000.

Do I need a C3PAO?

That depends on your contract. Level 1 and the Level 2 self-assessment path involve no third-party assessor. Level 2 certification requires an authorized C3PAO. The requirement comes from the contract and the information you handle. You may meet more than it requires; you cannot meet less.

Can Common Cyber take us through a self-assessment?

On the Level 1 and Level 2 self-assessment paths, yes. The CMMC Assessment Guide for Level 1 states that an organization may perform the annual self-assessment internally or engage a third party to assist, and that using a third party is still considered a self-assessment. We support the work up to the point of self-assessment and affirmation, which your organization performs and your Affirming Official submits in SPRS. Common Cyber is not a C3PAO and does not perform certification assessments.

What if our requirement changes to certification later?

Level 2 rests on the same 110 requirements whether it is self-assessed or assessed by a C3PAO. Requirements you have met and evidence you have built carry forward. A C3PAO applies its own independent judgment to scope and to the sufficiency of evidence, so some rework should be assumed.

Can a prime contractor see our SPRS score?

Not by looking it up. SPRS does not provide vendor-to-vendor visibility, so a prime asking about your score is asking you to provide it. Authorized government users can see it, and so can users inside your own CAGE hierarchy. Presenting a score you can explain and evidence is your responsibility.

Start an Assessment