Thank you

Your download is on the way.

You can also get it right now below.

Who's This Perfect For?

Any company touching DoD/DoW contracts

Aerospace Manufacturing

Machine Shops

Electronics Manufacturing

Construction

Logistics

Ammunition

Tactical Gear

Medical Devices

Simulation Training

Still Curious about cmmc?

Frequently Asked Questions

Question 1: What is the purpose of the CMMC program?

The Cybersecurity Maturity Model Certification (CMMC) program verifies that DoD contractors and subcontractors have implemented cybersecurity measures to safeguard Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) on their information systems.

Question 2: What is required to achieve CMMC Level 2 compliance?

To achieve CMMC Level 2, an organization must implement all 110 security requirements from NIST SP 800-171 Rev 2, which apply to systems handling CUI. Compliance can be shown via:

- A certification assessment by a C3PAO (Certified Third-Party Assessment Organization).

Question 3: Who conducts CMMC Level 2 certification assessments?

Only C3PAOs accredited by the Cyber AB and overseen by the DoD can conduct Level 2 certification assessments. These assessments verify conformance to NIST SP 800-171 and CMMC-specific rules.

Question 4: How often are CMMC assessments required?

- CMMC Level 1 and Level 2 self-assessments must be conducted annually.

- CMMC Level 2 certification assessments must be conducted every three years by a C3PAO.

- Affirmations of continued compliance must be submitted annually into the Supplier Performance Risk System (SPRS).

Question 5: What is the process for a CMMC Level 2 certification assessment?

The process is structured into phases:

1. Pre-Assessment – Review System Security Plan (SSP), confirm scope, evidence readiness.

2. Assessment Execution – Evaluate implementation of controls through interviews, artifact reviews, and testing.

3. Reporting – Assessment team compiles findings and scoring.

4. Post-Assessment – Certification is issued if all requirements are met, or a Plan of Action and Milestones (POA&M) may be permitted under specific conditions.

Question 6: What happens if a contractor does not meet all Level 2 requirements during assessment?

The organization may be granted a Conditional Level 2 CMMC Status if it achieves at least 80% of requirements and the remaining unmet ones are allowable under a POA&M. These must be remediated within 180 days, followed by a POA&M closeout assessment to achieve Final Level 2 status.

Question 7: How is the assessment scope defined for CMMC Level 2?

The CMMC Assessment Scope includes all assets that process, store, or transmit CUI. These are categorized into asset types (e.g., CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, etc.) as defined in 32 CFR § 170.19(c). The assessment scope must be clearly documented in the SSP and asset inventory.

Question 8: What are the cost estimates for CMMC Level 2 compliance?

Describe the item or answer the question so that site visitors who are interested get more information. You can emphasize this text with bullets, italics or bold, and add links.

Question 9: Can subcontractors be subject to CMMC requirements?

Yes. Prime contractors are responsible for ensuring that subcontractors handling FCI or CUI also meet the appropriate CMMC Level and assessment requirements. The CMMC DFARS clause must be flowed down to subcontractors.

Question 10: What is the difference between CMMC Levels 1, 2, and 3?

- Level 1 protects FCI with 15 basic controls (FAR 52.204-21) and requires only a self-assessment.

- Level 2 protects CUI using 110 controls (NIST SP 800-171) and requires a C3PAO certification, depending on the contract.

- Level 3 applies to more critical environments and includes 24 additional enhanced controls from NIST SP 800-172. It must be assessed by DCMA DIBCAC, not a C3PAO.

MEET THE FOUNDER & CEO

Hey, I'm Humberto Correa!

I helped guide Brea Networks through our official CMMC Level 2 assessment and led the team to a perfect score of 110 out of 110 from a certified C3PAO. That experience shaped how I approach every project. I believe compliance should be clear, simple, and achievable for any defense contractor, no matter their size.

My focus is on building secure systems, supporting mission-critical operations, and helping companies stay audit ready under the new DoD and DoW rules. I work hands-on with our clients to protect CUI, modernize their environments, and create long-term stability in a fast-changing federal landscape.

KEY EXPERTISE:

CMMC Level 2 implementation with a perfect 110 score

Secure cloud and GCC High migration

Federal contractor cybersecurity programs

IT modernization and infrastructure leadership

Compliance strategy for DoD/DoW contractors

California HQ

(West Coast)

451 W. Lambert Rd Suite 214
Brea, CA 92821
714-592-0063

Virginia

(East Coast)

1750 Tysons Blvd, #1500
Tysons Corner, VA 22102
202-838-3111

© Copyright 2026. Brea Networks, LLC. All Rights Reserved.