CMMC Compliance Assessment Services

Certified CMMC Assessor

If CMMC or NIST SP 800-171 compliance matters to your organization's future, Linford & Company LLP can guide you through it — from defining scope, through readiness and remediation, to assessment.

Get a CMMC Compliance Assessment

Service Page Contact Form TOP

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Name
Privacy Policy*

CMMC & NIST 800-171 Compliance Assessment Services

CMMC icon

What is CMMC and NIST 800-171?

The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense’s framework for verifying that contractors protect sensitive federal information. The program is codified at 32 CFR Part 170 and reaches defense contracts through DFARS clause 252.204-7021.

CMMC does not invent new security requirements — it verifies existing ones. Level 1 draws on the 15 basic safeguarding requirements in FAR clause 52.204-21. Level 2 draws on the 110 security requirements in NIST Special Publication 800-171 Revision 2. Level 3 adds a selected subset of the enhanced requirements in NIST SP 800-172.

NIST SP 800-171 reaches well beyond the defense sector. Organizations in energy, manufacturing, research, and healthcare increasingly adopt it — and cite it in their own agreements — as an established baseline for handling sensitive information shared between organizations.

Who does CMMC and NIST 800-171 apply to?

CMMC applies to organizations in the Defense Industrial Base that process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) — prime contractors and subcontractors alike. The required level and assessment type are specified in the solicitation and flow down through the supply chain, so a subcontractor’s obligation depends on the information it actually handles rather than on its distance from the contracting agency.

NIST SP 800-171 applies more broadly. Federal civilian agencies, state governments, universities, and private companies routinely require conformance with it in agreements involving sensitive but unclassified information.

What is Controlled Unclassified Information?

CUI is information that the government requires to be safeguarded or disseminated under controls, but which is not classified. Executive Order 13556 established the CUI Program in 2010 and designated the National Archives and Records Administration (NARA) as its Executive Agent.

NARA maintains the CUI Registry, which organizes roughly 80 categories of CUI into about 20 organizational index groupings — ranging from export-controlled technical data and critical infrastructure information to personally identifiable information and protected health information.

Two distinctions matter in practice. First, CUI is not the same as Federal Contract Information. FCI is information provided by or generated for the government under a contract and not intended for public release; FCI alone points to Level 1, while CUI points to Level 2 or above. Second, because the CUI definition is broad, many organizations outside the defense sector — energy production and distribution, for example — use NIST SP 800-171 to demonstrate that they handle sensitive information safely.

Comparison graphic showing CMMC Model 1.0 with five maturity levels mapped to CMMC Model 2.0 with three levels, including practice counts and assessment requirements.

How CMMC Works

CMMC is a three-level model. The level your organization needs, and whether you may assess yourself or must be assessed by a third party, is determined by the contract and by the type of information you handle.

What is the purpose of CMMC?

Defense contractors have long been required to protect sensitive information, but for years they attested to their own compliance and the government had limited means to verify it. CMMC was created to close that gap by tying verified cybersecurity practices to contract eligibility.

The program was first released in 2020 and restructured in 2021 to reduce the number of levels and align them directly with existing NIST standards rather than a separate maturity scale. It was then finalized through federal rulemaking: the program rule at 32 CFR Part 170, and the acquisition rule that added the CMMC requirement to the DFARS.

What is CMMC Certification?

A CMMC status is the outcome of an assessment against a defined set of requirements, evaluated using the assessment objectives published in NIST SP 800-171A.

  • Level 1 — Basic safeguarding of FCI. The 15 requirements in FAR clause 52.204-21, verified by annual self-assessment. Plans of Action and Milestones are not permitted at this level.
  • Level 2 — Broad protection of CUI. The 110 security requirements in NIST SP 800-171 Rev 2. Depending on what the contract specifies, Level 2 is satisfied either by self-assessment or by a certification assessment performed by an authorized CMMC Third-Party Assessment Organization (C3PAO). A Level 2 status is valid for three years.
  • Level 3 — Protection against advanced persistent threats. The Level 2 requirements plus a selected subset of NIST SP 800-172, assessed by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).

Assessment results are recorded in the Supplier Performance Risk System (SPRS), and a senior company official must submit an affirmation of continuing compliance there after each assessment and annually thereafter. Limited Plans of Action and Milestones are permitted at Levels 2 and 3 for certain requirements and must be closed within 180 days.

How do I get CMMC certified?

Start with the information, not the paperwork. Determine whether your environment handles FCI, CUI, or both, then define the boundary of the systems, people, and service providers that touch it. Scope drives everything downstream — cost, duration, and difficulty.

From there, the path is straightforward:

  1. Confirm the level and assessment type your contracts require.
  2. Assess your current state against NIST SP 800-171 Rev 2, using the objectives in NIST SP 800-171A.
  3. Remediate the gaps, and document what you cannot yet close.
  4. Complete the required assessment.
  5. Record your results and submit the required affirmation in SPRS.

The Cyber AB accredits C3PAOs and certifies the individual assessors who staff them. It does not issue your CMMC status — that follows from the assessment itself and is reflected in SPRS.

How CMMC Assessments Work

  • Step One: OSC (Organization Seeking Certification) defines scope — identify where FCI and CUI live and which systems, people, and providers fall inside the assessment boundary.
  • Step Two: OSC conducts a readiness assessment against NIST SP 800-171 Rev 2 and the assessment objectives in NIST SP 800-171A.
  • Step Three: OSC remediates gaps and prepares evidence and documentation.
  • Step Four: OSC engages a C3PAO.
  • Step Five: OSC kickoff and scoping with C3PAO.
  • Step Six: OSC submits documentation to C3PAO for review.
  • Step Seven: C3PAO conducts a mock assessment (This step is not required by highly recommended)
  • Step Eight: OSC makes required documentation updates and resubmits to C3PAO for review.
  • Step Nine: CMMC Assessment – Phase 1: C3PAO documentation review and evidence review.
  • Step Ten: CMMC Assessment – Phase 2: C3PAO conducts interviews and technical validation exercises with OSC.
  • Step Eleven: If required – OSC able to provide additional supporting evidence during 10-day window
  • Step Twelve: If required – CMMC Assessment – Phase 3: Final close-out, remediation validated.
  • Step Thirteen: Certification – C3PAO uploads CMMC L2 certificate to eMASS.

What is the cost for CMMC certification?

Cost depends far more on your environment than on the assessment itself. The main drivers are:

  • Scope. How many systems, locations, and people touch CUI. Narrowing the boundary — for example, by consolidating CUI into a defined enclave — is usually the single largest lever on total cost.
  • Remediation. Closing gaps in your existing control set, including any technology you need to acquire or replace.
  • Readiness work. Gap assessment, System Security Plan development, and evidence preparation.
  • The assessment. C3PAO fees for a certification assessment, or internal effort and time for a self-assessment.
  • Ongoing maintenance. Annual affirmations, continuous monitoring, and preparing for reassessment.

The Department of Defense published cost estimates by level and organization size in the rulemaking record, but those are averages across the industrial base. A scoped estimate for your actual environment will tell you far more, and we are glad to walk through one.

What is a C3PAO?

A CMMC Third-Party Assessment Organization, or C3PAO, is a firm accredited to perform CMMC Level 2 certification assessments. C3PAOs are accredited by the Cyber AB against ISO/IEC 17020, and the assessors who staff their engagements hold individual certification.

A C3PAO is not the same as a FedRAMP 3PAO. The designations sound alike and the acronyms invite confusion, but accreditation as a FedRAMP 3PAO does not authorize a firm to perform CMMC assessments; the two programs have separate requirements and separate oversight.

Linford & Co LLP is proud to be an officially Authorized CMMC Third-Party Assessment Organization (C3PAO). Having successfully met all established requirements of the Cybersecurity Maturity Model Certification (CMMC) Program, our firm and certified Assessment Team are fully authorized by The Cyber AB to conduct CMMC Level 2 certification assessments.

Our Certified CMMC Assessors

Certified CMMC Assessor

Richard Rieben

Partner | CISSP, CCSFP, GSNA

Lois Colby

Partner | CPA, CIA, CISA, CCSK

Mark Larson

Partner | CISSP, CISA

Naomi Bell

Managing Director | CPA | CISA | PMP

Big 4 IT Auditors

Our highly-experienced auditors simplify complex NIST requirements while delivering thorough CMMC assessments in an efficient manner.

Why Choose Linford & Company LLP?

Achieve CMMC Compliance

Demonstrate CMMC compliance and achieve certification by partnering with an authorized assessor firm that employs only experienced auditors with experience in DoD and government certifications.

Flexible and Tailored Approach

Linford & Company tailors the audit process to meet the needs of our clients, and we leverage our own tools or our client’s chosen GRC platform to perform assessments.

Support from Professionals

Our auditors have worked with dozens of clients to help them navigate the complexities of assessments based on NIST requirements including NIST 800-53 and 800-171, the standards that CMMC compliance is based on.

Ready for a CMMC Compliance Assessment?

Fill out the form and we’ll put you in touch with one of our experienced auditors. Your contact information stays with us and is only used to talk with you about your CMMC or NIST 800-171 audit — we do not sell or share your contact information with anyone.

Get a CMMC Compliance Assessment

Service Page Contact Form BOTTOM

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Name
*

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
I understand and agree to the Linford & Company LLP privacy policy.**