CMMC Compliance for DFW Defense Contractors.
NIST 800-171 and CMMC Level 1 / Level 2 implementation for Dallas–Fort Worth suppliers to the DoD. Enclave scoping, control implementation, and evidence work — from someone with an active C3PAO Level 2 client on the books.
Most MSPs Don't Know What CUI Is.
CMMC isn't a checklist — it's a technical scoping problem wrapped in a compliance regime. If your MSP doesn't understand what Controlled Unclassified Information actually is, they'll either scope everything (turning your whole network into a controlled environment you can't afford) or scope nothing (and hand you documents that won't survive an assessor's first hour).
The right answer is almost always an enclave: a scoped, hardened environment where CUI lives and works, walled off from the rest of your business. Cheaper to build. Cheaper to maintain. Actually defensible under 32 CFR Part 170 assessment.
Building it correctly — GCC High or on-prem, Azure AD Government or commercial, endpoint whitelisting, hardware inventory, media handling, incident reporting to DIBNet — is a project a general-practice MSP has never done before. We have.
MSP without CMMC pedigree
- "We'll just apply the 110 controls"
- No enclave — whole tenant in scope
- GCC High confusion (or wrong tier)
- Policies that don't survive assessor Q&A
48 Technologies CMMC
- Enclave-first scoping strategy
- Only CUI-touching systems in scope
- Tier selection you can defend
- Policies + configs written to assessor standard
Four Workstreams to Assessment-Ready.
CMMC L2 is 110 controls across 14 domains. We collapse them into four operational workstreams — each with its own owner, evidence pack, and timeline.
Scoping & enclave design
- CUI flow analysis (in, through, out)
- Enclave vs. whole-tenant decision
- GCC High vs. commercial tier
- System Security Plan (SSP) draft
Technical controls
- Identity, MFA, conditional access
- Endpoint hardening & FIPS crypto
- Media handling & sanitization
- Audit logging & 90-day retention
Policy & documentation
- 14 domain policies, all mapped
- Plan of Action & Milestones (POA&M)
- Incident response plan for DIBNet
- Assessor-ready evidence binder
SPRS score & affirmation
- Self-assessment score submission
- Annual senior-official affirmation
- Continuous monitoring cadence
- C3PAO coordination for L2
From SPRS Score to C3PAO-Ready.
A CMMC Level 2 engagement runs 4–9 months depending on where you start. Level 1 is faster. Every phase has a written deliverable so you always know where you stand.
Design the enclave. Draft the SSP.
CUI flow mapping. Enclave design decision. Tier selection (commercial or GCC High). System Security Plan drafted. You end this phase with a clear picture of what's in scope and what isn't.
- CUI flow analysis
- Enclave design decision
- Commercial vs. GCC High tier
- System Security Plan (SSP) draft
Stand up controls. Collect evidence as we go.
Technical controls stood up. Policies written and signed. Evidence collected as each control goes live. Monthly progress against the POA&M so the whole path is visible.
- All 110 controls implemented (L2)
- Policies signed and mapped
- Evidence collected per control
- Monthly POA&M progress reports
Mock assessment. Then the real one.
Mock assessment against L2 rubric. Gaps closed. Assessor binder finalized. C3PAO scheduled for L2 clients. For L1, self-affirmation submitted to SPRS with senior-official sign-off.
- Mock assessment against L2 rubric
- Gap remediation
- Assessor binder finalized
- C3PAO scheduled (L2) or SPRS affirmation (L1)
Level and Scope Set the Number.
CMMC Level 1 (17 controls, self-assessed) is a fundamentally smaller engagement than Level 2 (110 controls, C3PAO-assessed). Level 1 engagements typically run $8,000–$18,000 delivered in 60–90 days. Level 2 engagements typically run $45,000–$110,000 across 4–9 months, plus ongoing maintenance retainer. This is what our active C3PAO client is running through.
-
1. 1. Level (1 or 2)L1 is 17 controls, self-assessed. L2 is 110 controls, C3PAO-assessed. The math on scope, cost, and timeline is fundamentally different between the two.
-
2. 2. Enclave vs. whole-tenantA tight enclave with 5 CUI-touching endpoints is dramatically cheaper than pushing controls across a 100-endpoint tenant. We design for minimum defensible scope.
-
3. 3. Existing environment maturityA tenant with Microsoft 365 GCC and modern identity is halfway there. A commercial tenant with legacy hybrid AD is a much bigger lift. We credit what's in place.
DIY vs. 48 Technologies vs. Big Federal Contractor
Three ways to get CMMC done. Only one of them fits a 15–150 person DFW defense supplier without absorbing the business.
DIY CMMC
- Nobody in-house has run this before
- Templates don't match live tenant
- Enclave scoping usually wrong
- Fails first C3PAO assessment
- Prime freezes purchase orders
- Restart from zero with a consultant
48 Technologies CMMC
- Enclave-first, minimum defensible scope
- L1 or L2 — we quote what you actually need
- Active live C3PAO Level 2 client
- $45K–$110K L2 (vs. $200K+ elsewhere)
- Fractional CTO-level supervision
- Ongoing maintenance retainer available
Big Federal Contractor
- $200K–$500K+ minimum
- Optimized for prime-level enterprises
- Long sales cycle before work starts
- You are engagement #83 this year
- Great — if you have 1,000+ endpoints
- Prices assume prime-level budget
I'm running an active Level 2 assessment for a DFW defense supplier right now. It's an enclave build with a real POA&M, not a folder of PDFs. That's what this looks like when it's done right.
DFARS Clause in a Purchase Order? Let's Talk Before You Sign.
30 minutes on the phone. Tell us what your prime is asking for. We'll tell you what level you actually need and what the shortest path to it looks like.