Cybersecurity Maturity Model Certification (CMMC) Consulting
In an effort to simplify the requirements, the Department of Defense (DoD) introduced a new standard called the Cybersecurity Maturity Model Certification (CMMC). This new umbrella standard includes requirements from NIST 800-171, the Federal Acquisition Requirements (FAR) document 52.204-21 and beyond. CMMC is replacing NIST 800-171 on DoD RFIs and RFPs and most organizations that do business with the Department of Defense will be required to undergo an audit by an authorized auditing entity before bidding on a contract or subcontracting to a prime.
Due to our status as a CMMC Registered Provider Organization™ (CMMC-RPO), Ecuron can perform pre-assessment services which include CMMC Gap Analysis, CMMC Implementation Help, CMMC Pre-Assessments.
We do not conduct the final Certification Assessments.
We offer CMMC Consulting Services to get you CMMC compliant in 4 Steps:
-
CMMC Gap Analysis / CMMC Gap Assessment
See where your organization stands and what it takes to achieve compliance -
CMMC Implementation Help
Based on the results of the first phase we will help you to close existing gaps by implementing suitable controls and any missing requirements. This includes developing and writing the extensive documentation required. -
CMMC Pre-Assessment
Think of it as a mock audit. We will verify that everything is in place and can be proven to an auditor. If we find issues we will help you fix them. Once we are confident that you are ready for the CMMC Assessment by a C3PAO we will recommend to schedule the certification audit. -
CMMC Assessment Support
We help you prepare for the certification audit, gather & organize evidence for a smooth assessment by the C3PAO. We will be at your side throughout the process.
For a general overview of the CMMC certification process and rough time estimates see this flowchart.
Our free report about the cybersecurity requirements for DoD contractors is available here: https://www.ecuron.com/dib-report/