CMMC & NIST 800-171

CMMC Compliance for DFW Defense Contractors.

NIST 800-171 and CMMC Level 1 / Level 2 implementation for Dallas–Fort Worth suppliers to the DoD. Enclave scoping, control implementation, and evidence work — from someone with an active C3PAO Level 2 client on the books.

Live C3PAO clientLevel 2 under assessment
Enclave-firstOnly scope what needs it
L1 · L2 · 110 controlsBoth levels, all domains
DFARS 7012 / 7019 / 7020 / 7021Full clause coverage
The real problem

Most MSPs Don't Know What CUI Is.

CMMC isn't a checklist — it's a technical scoping problem wrapped in a compliance regime. If your MSP doesn't understand what Controlled Unclassified Information actually is, they'll either scope everything (turning your whole network into a controlled environment you can't afford) or scope nothing (and hand you documents that won't survive an assessor's first hour).

The right answer is almost always an enclave: a scoped, hardened environment where CUI lives and works, walled off from the rest of your business. Cheaper to build. Cheaper to maintain. Actually defensible under 32 CFR Part 170 assessment.

Building it correctly — GCC High or on-prem, Azure AD Government or commercial, endpoint whitelisting, hardware inventory, media handling, incident reporting to DIBNet — is a project a general-practice MSP has never done before. We have.

MSP without CMMC pedigree

  • "We'll just apply the 110 controls"
  • No enclave — whole tenant in scope
  • GCC High confusion (or wrong tier)
  • Policies that don't survive assessor Q&A

48 Technologies CMMC

  • Enclave-first scoping strategy
  • Only CUI-touching systems in scope
  • Tier selection you can defend
  • Policies + configs written to assessor standard
What's delivered

Four Workstreams to Assessment-Ready.

CMMC L2 is 110 controls across 14 domains. We collapse them into four operational workstreams — each with its own owner, evidence pack, and timeline.

Scoping & enclave design

  • CUI flow analysis (in, through, out)
  • Enclave vs. whole-tenant decision
  • GCC High vs. commercial tier
  • System Security Plan (SSP) draft

Technical controls

  • Identity, MFA, conditional access
  • Endpoint hardening & FIPS crypto
  • Media handling & sanitization
  • Audit logging & 90-day retention

Policy & documentation

  • 14 domain policies, all mapped
  • Plan of Action & Milestones (POA&M)
  • Incident response plan for DIBNet
  • Assessor-ready evidence binder

SPRS score & affirmation

  • Self-assessment score submission
  • Annual senior-official affirmation
  • Continuous monitoring cadence
  • C3PAO coordination for L2
Path to assessment

From SPRS Score to C3PAO-Ready.

A CMMC Level 2 engagement runs 4–9 months depending on where you start. Level 1 is faster. Every phase has a written deliverable so you always know where you stand.

Months 1–2 — Scope

Design the enclave. Draft the SSP.

CUI flow mapping. Enclave design decision. Tier selection (commercial or GCC High). System Security Plan drafted. You end this phase with a clear picture of what's in scope and what isn't.

  • CUI flow analysis
  • Enclave design decision
  • Commercial vs. GCC High tier
  • System Security Plan (SSP) draft
Months 3–6 — Implement

Stand up controls. Collect evidence as we go.

Technical controls stood up. Policies written and signed. Evidence collected as each control goes live. Monthly progress against the POA&M so the whole path is visible.

  • All 110 controls implemented (L2)
  • Policies signed and mapped
  • Evidence collected per control
  • Monthly POA&M progress reports
Months 6–9 — Ready

Mock assessment. Then the real one.

Mock assessment against L2 rubric. Gaps closed. Assessor binder finalized. C3PAO scheduled for L2 clients. For L1, self-affirmation submitted to SPRS with senior-official sign-off.

  • Mock assessment against L2 rubric
  • Gap remediation
  • Assessor binder finalized
  • C3PAO scheduled (L2) or SPRS affirmation (L1)
How we price

Level and Scope Set the Number.

CMMC Level 1 (17 controls, self-assessed) is a fundamentally smaller engagement than Level 2 (110 controls, C3PAO-assessed). Level 1 engagements typically run $8,000–$18,000 delivered in 60–90 days. Level 2 engagements typically run $45,000–$110,000 across 4–9 months, plus ongoing maintenance retainer. This is what our active C3PAO client is running through.

Do you actually need Level 2? Most primes flow-down without specifying, and half the businesses that think they need L2 are actually L1. We check this on the first call — for free. Getting the level wrong costs the difference between $15K and $80K.
  • 1. 1. Level (1 or 2)L1 is 17 controls, self-assessed. L2 is 110 controls, C3PAO-assessed. The math on scope, cost, and timeline is fundamentally different between the two.
  • 2. 2. Enclave vs. whole-tenantA tight enclave with 5 CUI-touching endpoints is dramatically cheaper than pushing controls across a 100-endpoint tenant. We design for minimum defensible scope.
  • 3. 3. Existing environment maturityA tenant with Microsoft 365 GCC and modern identity is halfway there. A commercial tenant with legacy hybrid AD is a much bigger lift. We credit what's in place.
The alternatives

DIY vs. 48 Technologies vs. Big Federal Contractor

Three ways to get CMMC done. Only one of them fits a 15–150 person DFW defense supplier without absorbing the business.

DIY CMMC

Templates and hope
  • Nobody in-house has run this before
  • Templates don't match live tenant
  • Enclave scoping usually wrong
  • Fails first C3PAO assessment
  • Prime freezes purchase orders
  • Restart from zero with a consultant
Cheapest — until the assessor arrives

48 Technologies CMMC

Enclave-first, active C3PAO client
  • Enclave-first, minimum defensible scope
  • L1 or L2 — we quote what you actually need
  • Active live C3PAO Level 2 client
  • $45K–$110K L2 (vs. $200K+ elsewhere)
  • Fractional CTO-level supervision
  • Ongoing maintenance retainer available
Priced for DFW suppliers — run to enterprise standard

Big Federal Contractor

Booz Allen, Leidos, prime-focused firms
  • $200K–$500K+ minimum
  • Optimized for prime-level enterprises
  • Long sales cycle before work starts
  • You are engagement #83 this year
  • Great — if you have 1,000+ endpoints
  • Prices assume prime-level budget
Right for primes — overkill for tier-3 suppliers
Tom Cloud, founder of 48 Technologies
I'm running an active Level 2 assessment for a DFW defense supplier right now. It's an enclave build with a real POA&M, not a folder of PDFs. That's what this looks like when it's done right.
Tom Cloud · Founder, 48 Technologies · More about Tom →
What's next

DFARS Clause in a Purchase Order? Let's Talk Before You Sign.

30 minutes on the phone. Tell us what your prime is asking for. We'll tell you what level you actually need and what the shortest path to it looks like.