top of page
Frequently Asked Questions (FAQ's)
Frequently asked questions
CMMCCPCSCCybersecurityIT AuditCybersecurity TrainingPenetration TestingCybersecurity ConsultingProject Onboarding
What industries require CMMC and CPCSC compliance?
Compliance is mandatory for any organization operating within the defense industrial supply chain in the U.S. and Canada:CMMC (Cybersecurity Maturity Model Certification): Applies to prime contractors and subcontractors under the U.S. Department of Defense (DoD) that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). Key sectors include defense manufacturing, aerospace, IT/managed services, logistics, and engineering.CPCSC (Canadian Program for Cyber Security Certification): Applies to suppliers bidding on Canada’s Department of National Defence (DND) contracts that touch "Specified Information" or Controlled Goods under Public Services and Procurement Canada (PSPC).
What does CMMC Level 1 / CPCSC Level 1 mean for your team?
Level 1 establishes basic cyber hygiene focused on safeguarding basic contract data:CMMC Level 1: Covers 17 security controls derived from FAR 52.204-21 to protect Federal Contract Information (FCI). It requires an annual self-assessment verified by a company executive in the DoD's SPRST (Supplier Performance Risk System).CPCSC Level 1: Covers 13 security controls based on Canada's ITSP.10.171 standard (derived from NIST SP 800-171). Defense suppliers must conduct and submit an annual self-assessment to remain eligible for DND procurement.
How do you prepare for CMMC Level 2 & CPCSC Level 2 compliance?
Level 2 transitions your organization from basic safeguards to protecting sensitive defense data—CUI in the U.S. and Specified Information in Canada:Scope the Assessment Boundary: Map all systems, enclaves, and cloud environments where sensitive data is stored, processed, or transmitted.
Align with Technical Standards: Implement NIST SP 800-171 Rev 2 controls (110 requirements) for CMMC Level 2, or ITSP.10.171 (98 controls) for CPCSC Level 2.
Conduct Gap Analysis & POA&M: Identify security gaps and formalize a Plan of Action and Milestones (POA&M) to remediate non-compliant controls.
Prepare for Assessment:
CMMC Level 2: Undergo an external assessment by a C3PAO (Certified Third-Party Assessment Organization) or submit a self-assessment depending on contract designation.
CPCSC Level 2: Pass an external assessment conducted by an accredited third-party certification body.
How should you prepare for a compliance audit?
Audit readiness requires a documented, evidence-backed security posture:System Security Plan (SSP): Maintain an up-to-date SSP detailing how every control in NIST SP 800-171 or ITSP.10.171 is enforced within your organization.Gather Artifacts: Compile policies, system logs, screenshots, configuration baselines, and employee training records demonstrating continuous adherence.Internal Mock Audits: Perform a practice assessment led by a certified practitioner (e.g., CMMC CCP/CCA or CPCSC consultant) to validate evidence before formal third-party audits.
What should you have in place before a CMMC or CPCSC readiness review?
You should have a clear view of your current security controls, key policies, and any known gaps. If you have existing documentation, access details, or past assessments, bring those too. That helps us move faster and focus your review on the most important compliance issues.
bottom of page
