Skip to content

Federal & Defense

CMMC

DoD contractors handling FCI and CUI.

The Cybersecurity Maturity Model Certification program applies cybersecurity requirements to organizations in the Defense Industrial Base that handle Federal Contract Information or Controlled Unclassified Information. Requirements differ by level, and the assessment expectations differ with them.

Level 1 addresses basic safeguarding of FCI. Level 2 addresses the protection of CUI and aligns with the security requirements in NIST SP 800-171. Scoping, evidence expectations, and assessment rigor increase accordingly.

CyberComply is software that helps an organization organize and manage its CMMC compliance program. It does not certify an organization, and it does not replace a third-party assessment.

CyberComply / system scopingProduct UI
CyberComply system scoping screen showing CMMC scoping readiness checks and a system identification form with CMMC target level, CAGE code, UEI, and FIPS 199 categorization
System scoping: identification, boundary sections, and CMMC scoping readiness checks. Sample environment.

Who it applies to

  • Prime contractors and subcontractors in the Defense Industrial Base
  • Organizations that receive, process, store, or transmit FCI or CUI
  • Suppliers receiving flow-down requirements from a prime contractor
  • Consultants and service providers supporting DIB clients

Reporting and visibility

  • Requirement coverage by level
  • Objective-level status
  • Open findings and their severity
  • POA&M items with owners and target dates
  • Evidence gaps by requirement
  • Overdue remediation work

Challenges

What makes this framework hard to manage

Scoping is contested

Deciding which systems, people, and facilities are in scope drives the size of the entire program, and the reasoning is rarely documented.

Objectives, not just practices

Assessment happens at the objective level. A practice that looks complete can fail on a single objective.

Evidence gaps surface late

Teams frequently discover missing or stale evidence during assessment preparation rather than months earlier.

SSP and POA&M drift

Both documents are written once and then diverge from how the environment actually operates.

No single owner

Work spreads across IT, security, contracts, and leadership without a shared record of status.

How CyberComply helps

Supporting CMMC work

Scope definition

Record the systems, environments, and assets that define your boundary so scoping decisions are explicit and reviewable.

Practices and objectives

Work at the requirement and objective level, with status and rationale on each.

Evidence

Associate supporting artifacts with the requirements they substantiate, with owners and review state.

SSP information

Organize the system and implementation information needed to develop and maintain the plan.

POA&M tracking

Carry each deficiency through corrective action, ownership, target date, and evidence of closure.

SPRS score support

Maintain the underlying requirement status information your team uses when determining and reporting a self-assessment score.

Findings and remediation

Convert findings into prioritized, owned, dated work items.

Ongoing maintenance

Keep the program current after the initial assessment rather than rebuilding it each cycle.

Workflow

A structured path for this framework

  1. Scope
  2. Assess
  3. Identify Gaps
  4. Remediate
  5. Document
  6. Prepare
  7. Maintain

FAQ

CMMC questions

Does CyberComply certify my organization for CMMC?

No. CyberComply is software that supports readiness and compliance management. Certification is issued through the formal assessment process conducted by an authorized assessment organization.

Is Armada Cyber Defense a C3PAO?

Nothing on this site should be read as a claim of C3PAO or assessor authorization. CyberComply supports the software side of managing a compliance program.

Does CyberComply support Level 1 and Level 2?

The platform organizes requirements, objectives, evidence, and remediation for the CMMC program. Which requirements apply to your organization depends on your level and scope.

Can CyberComply help with our SPRS self-assessment score?

CyberComply maintains the requirement status information your team relies on when determining and reporting a score. The determination and submission remain your organization's responsibility.

CyberComply supports readiness and compliance management. It does not certify an organization. Formal CMMC assessment and certification are performed by authorized third-party assessment organizations, which is a separate activity from the software-supported readiness work described here.

CyberComply is a software platform that assists organizations in managing governance, risk, compliance, documentation, and readiness activities. Using CyberComply does not by itself guarantee regulatory compliance, certification, authorization, or a successful assessment.

Related frameworks

Often managed alongside this one

Ready to bring your compliance program together?

See how CyberComply can help centralize requirements, evidence, risks, remediation, documentation, and assessment readiness.