Controls Are Half of It. Proof Is the Other Half.
The half everyone underestimates
Buying and configuring the technology is the visible half of this phase and the easier one. The half that decides your score is documentary: a System Security Plan that describes how each of the 110 practices is actually met in your environment, a POA&M for what is not met yet, policies and procedures people genuinely follow, and an evidence framework that produces artifacts continuously rather than in a panic before an assessment.
We have seen environments with excellent tooling score badly, because nothing was written down in a form an assessor could examine. The assessor is not evaluating your intentions. They are evaluating your evidence.
What gets built
- Microsoft 365 GCC High enclave — tenant, sovereign identity, conditional access, MFA enforcement, device management
- Security control implementation — endpoint detection and response, application control, logging and log retention, patch and vulnerability management
- Commercial-side containment — data loss prevention, mail flow and spillage controls, external sharing lockdown on the environment that sits outside the boundary
- System Security Plan — mapped to all 110 NIST SP 800-171 practices
- Plan of Action & Milestones — with the POA&M eligibility rules applied correctly
- Policies, procedures and the evidence framework — including the Change Advisory Board that keeps them alive
A word on what can sit on a POA&M
Not everything can. Conditional status at Level 2 requires a score of at least 88 out of 110, no requirement on a POA&M may carry a point value above 1 — with a single narrow exception for CUI encryption where encryption is employed but not FIPS validated — and six requirements are never eligible whatever their point value. Three of those six are physical: escorting visitors, physical access logs, and control of keys, locks and card readers.
This matters commercially, not just technically. A provider who plans to POA&M their way to a passing score without checking eligibility is going to hand you a number that does not survive contact with an assessor. We work from the text of 32 CFR 170.21, not from memory.
Sequencing that does not stop production
Control friction is real. Default-deny application control, ticketing discipline, conditional access — these change how people work, and they are mandated by the framework rather than chosen by us. What we control is the sequencing. Application control runs in learning mode before enforcement. Network cutovers happen after hours and on weekends. Nobody finds out on Monday morning that their machine no longer runs the software they need.
Book a CMMC Readiness Call
Thirty minutes. We review your contract requirements, identify your top compliance gaps, and give you a realistic timeline to audit readiness. No pitch decks, no obligation.
Book Your Call →