
When it comes to cybersecurity compliance, and especially compliance with the US Department of Defense’s cybersecurity requirements (i.e., those in NIST SP 800-171 and CMMC), many government contractors are still trying to figure out how to get started. Some are willing to hire outside experts to help with the entire process because it allows the contractors to focus on their core business. While this approach is viable for some contractors, the idea of investing thousands, and even tens of thousands, of dollars in consulting fees to do things that the contractors could do themselves is simply a non-starter. They are willing to invest the money where it is appropriate, but if they can save money, and even learn more about their company’s cybersecurity risks and obligations along the way, then that’s their preferred approach.
Unfortunately, understanding which requirements can, and even should, be done by the contractor requires that the contractor first read and understand all of the requirements. And when most open NIST SP 800-171A, the “assessment guide” for NIST SP 800-171 and the basis for the CMMC 2.0 Assessment Guide, they start by reading the requirements for 3.1.1, one of the more confusingly-worded requirements in all of 800-171. So the contractors stop reading, and put off their compliance efforts for another day.
We empathize with those contractors. That is why we have updated our free Self-Assessment Tool to include recommendations for whether a contractor can/should try to do a particular requirement or objective themselves or whether they should hire an outside expert to help.
- Reforming CMMC and Reducing Compliance Burden for the DIB
- False Claims Act in 2025 – Key take-aways
- CUI Institute Public Comments on FAR CUI Rule
- CMMC: A National Imperative
- Disseminating CUI to Someone Else (e.g., Mary)
- CUI Recipient Preparedness Questionnaire
- CUI and CMMC in a Nutshell
- Mavis’s Machine Shop Attributes (Employees, Roles, Teams)
- Mavis’ Machine Shop Written Information Security Policy
- Mavis’ Machine Shop Data Breach and Incident Response Policy and Plan
- Mavis’ Machine Shop Network Diagram
- Mavis’ Machine Shops Site 2 Data Flow Diagram
- Mavis’ Machine Shops Site 2 Map
- Mavis’ Machine Shop Site 1 Map
- Protecting the Government’s Information – Version 2023.03a
- 3.11.2 – Vulnerability Scans (Kevin Mann)
- CMMC: Budgets, Competition, and Protests…Oh My! (Eric Crusius and Josh Duvall) – Slides
- CMMC Workflow: Pre-Kickoff to Done (Thomas Graham and Robert Teague) – Slides
- 3.14.1 – Flaw Remediation (Thomas Graham) – Slides
- 3.1.11 – Terminate (Automatically) a User Session After a Defined Condition (Robert Teague) – Slides
- Evidence & Path to Compliance (Regan Edens) – Slides
- CMMC in Higher Education (Amy Starzynski Coddens, Jason Pufahl, Mike Corn) – Slides
- Techniques for Assessing a Remote Work Environment (Tara Lemieux) – Slides
- v2023.02a – FAR and Above and NIST SP 800-171 Self-Assessment DoD Score Tool
- Standardizing the Assessment Experience (Ben Tchoubineh) – Slides
- Helping Business Leaders to care about Cybersecurity (Ace Swerling) – Slides
- Gap Assessment Workflow (Leia Shilobod) – Slides
- Shared Responsibility Matrices (Carley Salmon and Robert McVay) – Slides
- Scoping your Environment (Matt Titcombe) – Slides
- Pricing Gap Assessments (Toby Musser) – Slides
- 3.11.1 Risk Assessments (Robert McVay) – Slides
- 3.5.3 Multifactor Authentication (Fernando Machado) – Slides
- Practical Approaches to Testing CMMC Compliance (Kyle Lai) – Slides
- 3.1.3 Controlling CUI Flow (Matt Hoeper) – Slides
- 3.14.1 Flaw Remediation (Thomas Graham) – Slides
- Finding Prep Expertise and a C3PAO (Joy Beland) – Workbook
- Finding Prep Expertise and a C3PAO (Joy Beland) – Slides
- OLD – v2022.11a – FAR and Above and NIST SP 800-171 Self-Assessment DoD Score Tool
- v.2021.10a – The CMMC Assessment Lifecycle
- OLD – v2022.08d – Comprehensive FAR and Above and NIST SP 800-171 Self-Assessment and DoD SPRS Scoring Tool
- OLD – FAR and Above Phased Approach to NIST SP 800-171 and CMMC Compliance
- Policy – Client Data Breach Incident Response Policy
- Plan – Client Data Breach Incident Response
- List – Processes Authorized to Act on Behalf of a User
- List – Employees and Authorized Users
- List – Authorized Visitors
- Worksheet – Client Data Breach Incident Response
- Record – Meeting Agenda
- Procedure – Employee Offboarding
- Policy – Nondiscrimination and Anti-Harassment
- Policy – Information Systems Audit
- Policy – Data Protection
- Open Letter to the President Regarding CMMC 2.0
- US DoD 2021-NOV-04 – Cybersecurity Maturity Model Certification 2.0 Updates and Way Forward
- DFARS Clause Applicability Decision Tree
- The CMMC Assessment Lifecycle – OLD
- Paper and Electronic Media (“Media”) Certificate of Destruction/Sanitization
- C3PAO ISO 17020 and 17021 Slides – Part 3
- C3PAO ISO 17020 and 17021 Slides – Part 2
- C3PAO ISO 17020 and 17021 Slides – Part 1
- DCMA C3PAO CMMC Assessment Lessons Learned
- CMMC-AB Statement of Work
- CUI Disclosure Decision Trees
In making our recommendations, we assume that if the contractor is even considering doing some of the work themselves, that they have already done some basic IT work before. For example, we assume that they are familiar with how to login to Microsoft 365 (or their local Windows Server) and can navigate the admin interface well enough to add/remove users and that they can change password requirements. At the same time, we assume that adding mobile device management and other capabilities to their environment will probably be beyond their ability (or, more correctly, that we’re approaching diminishing returns on the time they would spend trying to do it themselves vs the cost of hiring an expert).
While the recommendations may not be perfect for everyone, we hope that they are helpful in at least helping contractors get a sense for whether their understanding of a requirement, and the level of knowledge necessary to implement it, is likely to be accurate.
