5 Keys to CMMC Success: How to Build a Strategy for Compliance

This blog post will explore the five key steps to achieving CMMC success, with a focus on building a comprehensive strategy based on your organization’s unique requirements.

  • Bill Wootton

    Bill Wootton

    Chief Growth Officer

It’s official: the Cybersecurity Maturity Model Certification (CMMC) program is now in effect and will soon be a requirement for defense contractors bidding on new contracts. This increases the pressure to meet stringent compliance requirements to ensure the protection of sensitive information within the Defense Industrial Base (DIB). This blog post will explore the five key steps to achieving CMMC success, with a focus on building a comprehensive strategy based on your organization’s unique requirements.

1. Build a Strategy

The foundation of CMMC success lies in developing a robust strategy. This process begins with a thorough understanding of your business, enabling you to set the appropriate system boundary, understand the impact on your organization, and determine the expertise you need to pursue certification successfully.  

Know Your Business 

The better you know your business, the easier it will be to answer the following questions. Keep in mind that to build your strategy, you need to consider both the external and internal factors that impact CMMC compliance. 

External Considerations 

  • Customer Base: Identify the agencies you work with. Does your work involve Federal Contract Information (FCI) or Controlled Unclassified Information (CUI)? You need to know whether your organization handles FCI or CUI to determine what level of CMMC you need to pursue. 
  • Partnerships: Who are your prime contractors and subcontractors? Many large prime contractors are accelerating CMMC adoption faster than official timelines, so you need to understand their requirements for continuing to work together. 
  • Contract Clauses: Review your existing contracts for the presence of clauses, such as Clause 7012, that require you to safeguard covered defense information. These clauses are a good indication that CMMC requirements will be included in future contract renewals or option years. 
  • Future Plans: What is your long-term business strategy? If your organization is planning to expand into DoD work, your strategy will be significantly different than it will be if you foresee exiting the defense industry. Make sure your investment in CMMC aligns with these business plans. 

Internal Factors 

  • Personnel: Identify which team members interact directly or indirectly with CUI. 
  • Systems: Determine which systems store, process, or transmit CUI data. 
  • Data Inventory: Assess your current CUI and export-controlled data. Can you segment this data from the rest of the organization? Your data inventory must include both the parts that work with CUI and those that don’t in order to proceed with the next step, which is determining system boundaries. 

Decide on a System Boundary Strategy 

With an analysis of your business in hand, it’s time to decide on your system boundary strategy. There are two basic categories: building an enclave or going all-in. Let’s look at the pros and cons of each approach. 

Enclave 

An enclave approach requires a smaller initial investment, in part because there is reduced scope for deploying your system boundary and a smaller attack surface to worry about protecting. An enclave approach enables your organization to have a more controlled system boundary because it’s limited in terms of the number of systems included in that enclave. This approach also requires minimal data migration 

On the other hand, an enclave approach may create a situation where individuals have to maintain an identity in both the enclave environment and in the larger corporate environment, and they’ll need to be able to jump between both easily and securely. Enclaves may also appear to be less expensive at first glance, but it really depends on how many users are in the enclave. Plus, you’ll need to administer two separate IT organizations, which introduces additional costs and challenges, including the risk of unintended data spillage from one environment to another. 

All-In 

In the all-in approach, you put your entire organization within the scope of your CMMC boundary, creating a single, consolidated environment. Creating a new environment will likely eliminate corporate technical debt because you’ll need to deploy systems that are FedRAMP moderate for cloud systems services. An all-in approach is also an opportunity to build a unified security posture across your entire organization.  

The fresh start of creating an all-in environment doesn’t come without costs, however. You’ll need to undertake a data migration project to move everything to the new environment, which will come with some significant impacts to your users. It also involves a larger initial investment and a more complex implementation process. Your users will be more locked down in terms of permissions and may not be able to use some applications because they aren’t approved for this highly controlled environment.

2. Deploy Technical Solutions

After building your strategy based on your business requirements and deciding whether you are using an enclave or all-in system boundary, the next key is to implement the technical solutions that align with your chosen approach. To do this, you’ll need to define in scope systems and establish clear boundaries and data flows, identify authorized users, and ensure that you are using FedRAMP moderate systems (or the equivalent) as or when required.  

You’ll also need to make certain that your asset configurations match your policies, and all the requirements outlined in the National Institute of Standards and Technology (NIST) Special Publication 800-171A Rev 2. You may need to consider operational technology (OT) and the Internet of Things (IoT), as well, which are not assessed against NIST 800-171, but still must be documented in your asset inventory and diagrams. Plus, remember to assess your security protection assets against the relevant controls for what the asset does or how it can act in the environment, depending on whether it stores, processes, or transmits CUI.  

The 32 CFR specifically designated Rev 2 in the rule rather than using a term such as “most recent revision.” 

3. Manage Environment(s)

In the rush to achieve CMMC compliance, it’s important to keep in mind that this is not a one-time achievement but an ongoing process. In addition to the traditional requirements for managing an environment, such as maintenance, patching, and updates, you’ll still need to handle incidents, support requests, and change authorization for users based on moves, changes, and adding new users. And there are always budgeting decisions to make and technical upgrades to plan.  

To maintain a CMMC-compliant environment, you’ll need to map your standard processes to NIST 800-171a, ensure that every action is captured as an artifact, and report on and review configurations, whitelists, and access controls. Compliant IT management also requires a robust change management process that includes reviews and approvals, documenting the execution of changes. Inevitably, you’ll also need to say no to some application requests from users because the applications don’t meet your compliance requirements for your environment.

4. Monitor Security

In addition to establishing these procedures for day-to-day operations, you need to have security monitoring. Often, this piece is outsourced to a Managed Security Service Provider (MSSP), whose role is to detect, stop, and prevent unauthorized access. Either your MSSP or an internal team will be responsible for detecting unauthorized access and activity, then investigate and triage it. There must be a clear escalation path to remediation for any detected threats, with a test incident response plan in place to follow. Your environment must also be scanned for vulnerabilities, and your security plan must include threat hunting and an annual incident response tabletop exercise to test your ability to respond quickly (and effectively) to an incident.

5. Manage Compliance

The final key to CMMC success is developing a comprehensive compliance management program. All the work you’ve done in the four previous steps build a system that will enable your organization to pass the CMMC assessment. This effort must be continuously maintained through: 

  • Policies and procedures, including an up-to-date incident response plan and periodic risk assessments 
  • A system security plan 
  • Regular reviews to ensure documentation is up to date 
  • Up-to-date system diagrams and dataflows, collection of artifacts, and an operational plan of action  

A CMMC assessment isn’t a one-and-done event; you’ll need to maintain this effort and ensure your controls and documentation are continually updated to ensure your ability to protect sensitive information effectively.  

Ready for CMMC Success? 

By focusing on these five key steps — building a strategy, deploying technical solutions, managing your environment(s) on an ongoing basis, conducting security monitoring, and managing compliance — defense contractors can position themselves for success in achieving CMMC compliance.  

To dive into a detailed discussion of each step, explore the shared responsibility matrix, and get some tips on how to prepare for your CMMC assessment, watch this webinar on demand: Five Keys to CMMC Success 

Meet the Author

Bill Wootton

Bill Wootton

Chief Growth Officer

Bill Wootton is a co-Founder and Chief Growth Officer of C3, a full-service IT provider that accelerates CMMC compliance by designing, implementing, and managing IT & cybersecurity solutions purpose-built for the U.S. Defense Industrial Base. Through its C3 Suite of CMMC Solutions, C3 delivers an expertly managed environment that brings together everything contractors require to confidently meet CMMC requirements. A graduate of Drexel University and Georgetown McDonough School of Business, Bill is passionate about bringing cyber awareness and maturity to the DIB, working with clients to help them achieve CMMC and NIST 800-171 compliance. Bill lives in Arlington with his partner Sharon and their dogs Brooks and Lemmy.