CMMC compliance
Your DoD contract requires Level 3. We get you there — and keep you there.
Where does your contract fall?
CMMC 2.0 has three levels. Most DoD prime and subcontractor small businesses handling CUI require Level 2 or Level 3. If your contract involves Advanced Persistent Threat (APT) programs, you’re Level 3.
Basic cyber hygiene
- Practices: 17
- Assessment: Annual self-assessment with affirmation to DoD
- Scope: Federal Contract Information (FCI) only — not CUI
- Who it applies to: Contractors who receive FCI but do not process, store, or transmit CUI
If your contract involves CUI, Level 1 is not sufficient. Most active DoD subcontractors need Level 2 or higher.
What’s at stake
Non-compliance is not a paperwork problem. Here’s what happens on each path.
Without compliance
- Contract terminated or not awarded
- False Claims Act liability if SPRS score was self-attested inaccurately
- Removal from DoD supplier base
- Reputational damage with prime contractors
- CUI breach triggers mandatory DFARS 252.204-7012 reporting
With GreylineOps
- Audit-ready posture maintained continuously
- Accurate SPRS score submitted to DoD
- POA&M managed and closed on schedule
- C3PAO / DCSA assessment passed with confidence
- Incident response and 72-hour reporting handled
All 14 CMMC practice domains
NIST SP 800-171 is organized into 14 domains. Level 3 requires full compliance across all of them, plus additional practices from NIST SP 800-172. GreylineOps covers every domain.
| Domain | Abbreviation | Practices (L2/L3) |
|---|---|---|
| Access Control | AC | 22 |
| Awareness & Training | AT | 3 |
| Audit & Accountability | AU | 9 |
| Configuration Management | CM | 9 |
| Identification & Authentication | IA | 11 |
| Incident Response | IR | 3 |
| Maintenance | MA | 6 |
| Media Protection | MP | 9 |
| Physical Protection | PE | 6 |
| Personnel Security | PS | 2 |
| Risk Assessment | RA | 3 |
| Security Assessment | CA | 4 |
| System & Communications Protection | SC | 16 |
| System & Information Integrity | SI | 7 |
| Total | 110 |
Common questions
How long does CMMC Level 3 certification take?
We’re a 12-person company. Is CMMC Level 3 even achievable for us?
What is a SPRS score and why does it matter right now?
Do we need to move to a GovCloud or DoD-specific cloud environment?
What’s the difference between a C3PAO and a DCSA assessment?
- Level 2 (critical): A certified Third Party Assessment Organization (C3PAO) conducts your assessment every three years.
- Level 3: The Defense Contract Security Agency (DCSA) conducts a government-led assessment — a higher bar with more rigorous scrutiny.
GreylineOps prepares clients for both, with mock assessments designed to mirror whichever path your contract requires.
Can we start with Level 2 and upgrade to Level 3 later?
Ready to get assessed?
Most DIB contractors are one audit away from a lost contract. A free gap assessment tells you exactly where you stand — no pressure, no pitch, just a clear picture of your compliance posture.
Free CMMC gap assessment — we review your current posture against all 110 controls, calculate your SPRS score, and give you a prioritized remediation roadmap. No obligation.
Schedule your assessment → HERE
GreylineOps is a veteran-owned small business specializing in CMMC compliance and managed security for Defense Industrial Base contractors. greylineops.com