top of page

CMMC & CPCSC Level 1 & 2: Compliance for Defence Contractors and Sub-Contractors

The Cybersecurity Maturity Model Certification (CMMC) is a U.S. Department of Defense program that requires contractors and sub-contractors to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Canada's equivalent, the Canadian Program for Cybersecurity Certification (CPCSC), follows a similar scope and timeline for Canadian contractors and sub-contractors working in the defence supply chain.

CyberCare Pro helps contractors and sub-contractors on both sides of the border get assessment-ready for CMMC 2.0 and CPCSC 2.0 — without the cost or complexity that usually comes with defence compliance work.

What CMMC 2.0 Requires

CMMC 2.0 took effect December 16, 2024, with mandatory implementation beginning October 1, 2026. The updated model simplifies certification into three levels:

  • Level 1 (Foundational) — Basic cyber hygiene to protect FCI. Requires an annual self-assessment and affirmation.

  • Level 2 (Advanced) — Required for handling CUI. Implements all 110 NIST SP 800-171 controls and requires a third-party assessment by a Certified Third-Party Assessment Organization (C3PAO) every three years. A Plan of Action and Milestones (POA&M) is permitted for partial compliance at the time of assessment.

  • Level 3 (Expert) — Reserved for organizations handling the most sensitive CUI, with government-led assessment.

Most small and mid-sized contractors working with the DoD or federal agencies fall into Level 1 or Level 2, where budget and resource constraints make a cost-effective path to compliance especially important.

The CyberCare Pro Approach

We focus on practical, business-friendly implementations that get you ready for a CMMC or CPCSC Level 2 assessment without over-building for your size.

CMMC/CPCSC Level 1 — typically 60 days:

  • Run a gap assessment against all 15 FAR controls using the technology you already have

  • Use free or built-in tools (e.g., Windows Defender, BitLocker) to keep costs down

  • Document compliance in a simple System Security Plan (SSP) and prepare for annual self-assessment

CMMC Level 2 — assessment-ready in 6–12 months:

  • Perform a gap assessment against all 110 NIST SP 800-171 controls

  • Invest only in the technology you actually need to close gaps — commonly MFA, SIEM, and EDR

  • Develop a full System Security Plan (SSP), including cloud solutions with FedRAMP Moderate compliance where applicable

  • Book your C3PAO assessment early — there are fewer than 80 C3PAOs serving over 80,000 organizations, so availability is limited

CyberCare Pro Total Care includes:

  • Expert vCISO consultants guiding the engagement

  • Managed technology implementation to close compliance gaps

  • Access to a risk management platform for ongoing visibility and accountability

  • Project-based or monthly pricing options

  • A cyber warranty of up to $50,000

  • Support identifying applicable financing and grant options

Your Path to Certification

  • Planning and Preparation — Define objectives and scope, conduct a gap assessment, build your SSP and POA&M, and secure leadership buy-in.

  • Implementation — Remediate gaps, train personnel, establish governance and documentation, and run internal testing.

  • Assessment Preparation — Select a C3PAO, complete a pre-assessment review, and gather evidence.

  • CMMC Assessment — Undergo the C3PAO assessment and receive your results.

  • Maintenance and Continuous Monitoring — Maintain compliance through ongoing monitoring and prepare for recertification every three years.

Program Roadmap

  • Define Objectives and Scope

  • Conduct Gap Assessment

  • Develop a System Security Plan (SSP)

  • Create a Plan of Action and Milestones (POA&M)

  • Secure Leadership Buy-In

Phase 1: Planning and Preparation

  • Remediate Gaps

  • Train Personnel

  • Establish Governance and Documentation

  • Conduct Internal Testing

Phase 2: Implementation

  • Maintain Compliance with Continuous monitoring

  • Prepare for Recertification every 3 years

Phase 5: Maintenance and Continuous Monitoring

  • Undergo C3PAO Assessment

  • Receive Assessment Results

Phase 4: CMMC Assessment

  • Select a C3PAO

  • Pre-Assessment Review

  • Gather Evidence

Phase 3: Assessment Preparation

Financing Your Compliance Journey

CMMC and CPCSC compliance is an investment, and CyberCare Pro can help you fund it. We offer access to monthly payment plans and can connect you with relevant grant programs. Book a call with an advisor to learn what financing options apply to your organization.

Why Work With CyberCare Pro

  • Industry-specific experience in defence contracting compliance

  • Budget-conscious engagements sized for small and mid-sized organizations

  • Increased productivity through streamlined, right-sized implementations

Contact Us To Apply

Industry-Specific Experience

Budget-Conscious

Budget-Conscious

Increased Productivity

Schedule A Discovery Call

bottom of page