CMMC is now a contractual requirement where applicable. The Department of Defense began incorporating CMMC requirements into applicable solicitations on November 10, 2025, and Phase I self-assessment requirements remain in effect. In July 2026, the Department suspended the planned Phase II rollout of mandatory Level 2 third-party assessments while it reviews the program. Level 2 applies to organizations whose contracts require protection of Controlled Unclassified Information (CUI) and is based on 110 security requirements in NIST SP 800-171 Revision 2. Vancord is a Registered Practitioner Organization that provides non-certified CMMC preparation and advisory support. Vancord can help assess the current environment, build documentation and evidence, remediate gaps, and maintain the cybersecurity practices that support ongoing readiness.
If you hold DoD contracts, the schedule has already started
CMMC is no longer a distant planning topic for the defense supply chain. The Department of Defense’s final acquisition rule took effect November 10, 2025, and Level 1 and Level 2 self-assessment requirements are already appearing in new solicitations. The Department of Defense has suspended the planned November 10, 2026 Phase II rollout of mandatory Level 2 third-party assessments. The CMMC program is currently paused in Phase I, where applicable Level 1 and Level 2 self-assessment requirements remain in effect.
For a New England contractor, the practical question is no longer whether CMMC matters. The better question is whether the organization understands its applicable requirements, has completed the required self-assessment, and is maintaining the security practices and documentation needed for current contracts and future CMMC changes.
Starting late makes the work harder. A contractor that prepares early can treat CMMC as a managed project. A contractor that waits until a contract opportunity forces the issue often has to deal with security gaps, missing documentation, unclear scope, and leadership pressure all at once.
The work is substantial, but it is manageable when it is broken into the right steps.
What CMMC actually requires
CMMC defines three levels, scaled to the sensitivity of the information a contractor handles. Level 2 applies to contracts that require protection of Controlled Unclassified Information (CUI). It is based on 110 security requirements in NIST SP 800-171 Revision 2. Under the current Phase I implementation, applicable Level 2 organizations complete a self-assessment every three years with an annual affirmation of compliance. The planned Phase II requirement for mandatory third-party C3PAO assessments has been suspended.
One distinction matters here, and organizations confuse it often. Vancord provides non-certified CMMC preparation and advisory support. The two roles stay separate by design, because the organization that prepares a contractor cannot also certify that contractor’s readiness. Vancord is an RPO. Vancord gets an organization ready for assessment and is direct about that boundary, since blurring it would create real compliance risk for the contractor.
Controlled unclassified information, and why scope matters
CMMC exists to protect controlled unclassified information, often shortened to CUI. CUI can include technical drawings, specifications, controlled project information, and other sensitive material shared by the Department of Defense or passed through the supply chain.
The first practical step in a CMMC effort is figuring out where CUI lives. Which systems store it? Which users access it? Which vendors touch it? Which workflows move it from one place to another?
That scope shapes the entire project. Systems that store, process, or transmit CUI usually fall inside the assessment boundary. Systems that never touch CUI may be handled differently. A careful scope can keep the effort focused and prevent the organization from spending time and budget on systems that do not need to be inside the CMMC boundary.
Scope is not paperwork. It is where the project starts to become real.
The New England defense base
New England has a deep defense manufacturing and supplier footprint. General Dynamics Electric Boat operates in Groton. Raytheon has a major presence across Massachusetts and the region. BAE Systems operates in New Hampshire. Sikorsky builds in Stratford. Bath Iron Works supports naval construction in Maine. Around each of those organizations is a wider supplier base.
CMMC can reach prime contractors, subcontractors, and lower-tier suppliers when applicable DoD contract requirements flow down and the organization handles FCI or CUI. A smaller company deep in the supply chain should not assume it is outside the requirement.
That is where many contractors get caught off guard. They may not think of themselves as a defense contractor in the same way a prime does. But if controlled information passes into their systems, CMMC readiness may become part of doing the work.
How Vancord helps with CMMC readiness
Vancord delivers CMMC preparation as a defined sequence of work, from the first assessment of current state through the operations that keep compliance in place after certification.
- CMMC gap assessment. Vancord maps your current environment against all 110 NIST SP 800-171 controls and identifies what is missing, what is partially in place, and what is documented incorrectly.
- Remediation planning. The firm builds a prioritized roadmap that establishes what to fix first, what the organization can defer, and which gaps a policy change can close rather than a technology purchase.
- Evidence and SSP development. Vancord helps develop the documentation, policies, and System Security Plan needed to support current CMMC self-assessment requirements and future assessment requirements.
- Readiness review. The firm reviews the organization’s controls, documentation, and evidence against applicable CMMC requirements so gaps can be identified and addressed before the organization completes its required assessment or faces future assessment requirements.
- Ongoing compliance operations. Vancord runs the monitoring, logging, and incident response that keep the controls genuinely in place between assessments, because CMMC compliance decays without maintenance.
Your SPRS score and the plan of action
CMMC preparation produces two figures that a defense contractor should understand early. The first is the score recorded in the Supplier Performance Risk System, generally called SPRS. An organization that has assessed itself against the 110 controls of NIST SP 800-171 calculates a score by a defined method, and that score becomes part of how the Department of Defense views the organization’s readiness. For applicable Level 2 self-assessments, the assessment results are entered into the Supplier Performance Risk System (SPRS).
The second figure concerns the controls an organization has not yet met. A Plan of Action and Milestones, known as a POA&M, documents each open gap, the steps to close it, and the date by which the organization commits to closing it. A POA&M is not a way to avoid the work. It is a structured account of remaining work with deadlines attached. Vancord can help organizations perform and document the self-assessment, understand the resulting score, and develop a POA&M for permitted gaps.
The gaps organizations most often discover
A CMMC gap assessment tends to surface the same categories of weakness across many organizations, and knowing them in advance helps a contractor plan. Documentation is the most common gap. Many organizations operate reasonable controls but have never written them down in the form an assessment requires, and the System Security Plan is missing or incomplete.
Access control is another frequent finding. Organizations often grant broader access than any individual role needs, and they lack the multi-factor authentication the framework expects. Audit logging is a third. Systems generate logs, but no one collects, retains, or reviews them in the way the controls describe. Incident response rounds out the list, since many organizations have no documented procedure for handling a breach. None of these gaps is unusual, and none is insurmountable, but each takes time to close, which is the argument for beginning the assessment early.
Underestimating the documentation effort is the single most common scheduling mistake. Operating a control and evidencing it to an assessor’s standard are different tasks, and the second one consumes more time than most organizations expect. A gap assessment that runs early gives the organization an honest account of that effort while there is still time to plan around it rather than rush it.
Why Vancord
Vancord is a CMMC Registered Practitioner Organization. That credential means the firm is formally registered and authorized to perform CMMC preparation work. Not every firm that describes itself as a CMMC consultant carries that registration, and a contractor should verify the status of anyone it considers for this work.
Vancord is also a New England company that understands the contractors and the supply chains across this region. Because the firm provides managed detection, incident response, and penetration testing alongside CMMC preparation, an organization can keep its readiness work and its daily security operations with one provider. A CMMC project treated as a one-time documentation exercise does not produce sustainable readiness. Continuity of the team that built the program does.
Confidentiality and controlled information
A CMMC engagement involves sensitive information about your environment. It may also involve controlled unclassified information. Both need careful handling.
Vancord handles that material under confidentiality and applies the operational discipline expected in defense environments. What we learn about your systems, controls, gaps, and documentation stays protected and is shared only with the people you designate.
The goal of CMMC is to protect sensitive defense information. The readiness process should reflect that from the beginning.
Related Vancord services and resources
Readers who need the next layer of support can move directly to DoD Cybersecurity Compliance for Manufacturers, Privacy and Compliance Audits, Cybersecurity Readiness and Risk Assessments, Penetration Testing Services, Managed Detection and Response (MDR), and What Is CMMC?.
Questions organizations ask
Does CMMC apply to subcontractors, or only to prime contractors?
CMMC can apply to prime contractors, subcontractors, and lower-tier suppliers when applicable DoD contract requirements flow down and the organization handles FCI or CUI. The exact level depends on the contract and the information handled.
What level of CMMC does our organization need?
Organizations whose contracts require protection of Controlled Unclassified Information (CUI) may be subject to Level 2 requirements, which are based on the 110 security requirements in NIST SP 800-171 Revision 2. The applicable level and assessment requirements depend on the contract, the information involved, and the CMMC requirement included in the solicitation or contract.
Can Vancord certify our organization for CMMC?
No, and the distinction is deliberate. Vancord is a Registered Practitioner Organization, which prepares and guides organizations for assessment. A separate Certified Third-Party Assessment Organization conducts the assessment, because the firm that prepares a contractor cannot also certify it.
How long does CMMC preparation take?
The timeline depends on the gap between current state and the 110 required controls. A gap assessment establishes that distance, after which the remediation roadmap sets a realistic schedule. Organizations that start early manage the work as a planned project.
How is our controlled information protected during the engagement?
Vancord handles CUI and security posture information under confidentiality and applies the operational discipline defense environments require. Findings and documentation are shared only with the people you designate.
