SERVING VIRGINIA BEACH, VA ยท NORFOLK ยท CHESAPEAKE ยท TOWN CENTER ยท OCEANFRONT

CMMC Compliance in Virginia Beach Keep Your Contracts. Pass Your Assessment.

CMMC deadlines are contract deadlines: no certification, no award. We take Virginia Beach contractors from gap assessment through remediation to assessment-ready โ€” SSP, POA&M, and evidence included.

15+
YEARS
1,000+
BUSINESSES
<30 min
RESPONSE
4.9★
GOOGLE
  • Gap assessment against the full framework
  • Remediation done for you, not just flagged
  • Evidence collection & audit-ready binders
  • Continuous monitoring after certification

Free · Takes 3 minutes · No sales call required

What We Do

CMMC Compliance Services: Six Capabilities That Build an Assessment-Ready Program

Each service below maps directly to a CMMC or NIST 800-171 requirement — and to the specific gap that prime contractor audits and C3PAO assessments most commonly uncover in the Hampton Roads defense industrial base. We build programs that hold up when an assessor asks for documentation, not programs that look compliant until someone looks closely.

Level 1 and Level 2 Gap Assessment

CMMC Gap Assessment — Map Every Control Before Anyone Else Does

We map your current security controls and configurations against CMMC Level 1 (17 practices from FAR 52.204-21) or Level 2 (110 practices from NIST SP 800-171 Rev 2), identifying which practices are fully implemented, partially implemented, or not implemented. The assessment covers your IT environment, CUI data flows, cloud service providers, endpoint devices, access control architecture, and documentation baseline. You receive a written gap report that names every unmet practice, rates the remediation effort, and sequences the remediation priority for your specific contract timeline.

What it prevents: discovering gaps during a C3PAO third-party assessment — when the cost is a failed assessment — or during a prime contractor audit, when the cost is a contract suspension. Every gap found before assessment is a gap you control; every gap found during assessment is a gap that controls your contract status.

Without it: you are guessing at your readiness. The self-attestation scenario above — nine of 17 practices covered — is the most common outcome when Hampton Roads contractors assume compliance without verifying it control by control.

NIST 800-171 Required for Level 2

System Security Plan (SSP) Development — The Required Compliance Baseline

A System Security Plan documents how your organization implements each of the 110 NIST SP 800-171 practices — including a description of the system boundary, the CUI environment, each control’s implementation status, and the responsible parties for each control. The SSP is required for CMMC Level 2 and is the primary document a C3PAO assessor reviews. Capital Techies develops SSPs that are practice-specific, evidence-backed, and formatted to meet DoD assessment standards — not generic templates that name controls without describing how they are actually implemented in your Hampton Roads environment.

What it prevents: arriving at a C3PAO assessment without a completed SSP — which immediately fails the assessment — or submitting an SSP that describes controls theoretically rather than operationally, creating contradictions when assessors test the actual environment against the documented claims.

Without it: you have no documented compliance baseline and cannot pass a CMMC Level 2 assessment. An undocumented control is treated as a non-implemented control during assessment, regardless of whether the technical control exists in your environment.

Required Alongside SSP

Plan of Action and Milestones (POA&M) — Document Gaps Before Assessors Find Them

A Plan of Action and Milestones documents every CMMC practice not yet fully implemented — including the gap description, planned remediation steps, responsible party, and target completion date. The POA&M is required alongside the SSP for CMMC Level 2 and must be actively maintained. Capital Techies develops POA&Ms that satisfy DoD expectations: specific enough to demonstrate that gaps are actively managed, with realistic timelines and actual remediation steps rather than generic placeholders. We also advise on which POA&M items create assessment risk versus which can be openly documented without affecting the assessment outcome.

What it prevents: assessors discovering undocumented gaps during the assessment — which treats those gaps as both a technical failure and a documentation failure. A properly documented POA&M demonstrates program management discipline even when controls are not yet fully implemented.

Without it: assessors find gaps that are undocumented, which creates a more severe finding than a gap that is documented and actively being remediated. The absence of a POA&M is itself a program management failure that assessors note independently of the underlying technical gaps.

MFA ยท Encryption ยท Access Control ยท Audit Logging

NIST SP 800-171 Technical Control Implementation

Implementing the 110 NIST 800-171 practices requires building and configuring the actual security controls across your environment — not just documenting them. Capital Techies implements multi-factor authentication enforcement for all CUI system access, full-disk encryption on endpoints handling CUI, role-based access control limiting CUI access to minimum necessary, comprehensive audit logging across all systems in the CUI environment, media sanitization procedures for portable storage, configuration management baselines, and incident response capability mapped to the DFARS 252.204-7012 72-hour reporting requirement. Every implemented control is documented with evidence in a format that satisfies C3PAO assessment evidence requirements.

What it prevents: the most common assessment failure mode — controls that are documented in the SSP but not actually implemented in the environment. Assessors test controls; they do not take documentation at face value. Gaps between SSP claims and technical reality create the most severe assessment findings.

Without it: gaps remain unaddressed regardless of how thoroughly they are documented. A completed SSP describing controls that are not implemented is worse than no SSP — it creates a contradiction that assessors must formally note as a false representation.

GCC ยท GCC High ยท DFARS 252.204-7012

Microsoft 365 GCC and GCC High Migration — CUI-Compliant Cloud for Hampton Roads

Many Hampton Roads defense contractors currently store CUI in standard commercial Microsoft 365 tenants that do not meet the FedRAMP Moderate authorization required by DFARS 252.204-7012. Microsoft 365 Government Community Cloud (GCC) meets FedRAMP Moderate and satisfies DFARS 252.204-7012 for most defense contractors. GCC High meets FedRAMP High and is required for ITAR-controlled information and other sensitive CUI categories. Capital Techies manages the full GCC migration: tenant provisioning, data migration, conditional access policy configuration, MFA enforcement, audit logging, and DLP policy implementation for CUI — plus documentation of the CSP authorization status required by DFARS 252.204-7012 for your compliance record.

What it prevents: the scenario above — CUI stored in an unauthorized cloud environment for the duration of active contracts, creating retroactive DFARS violations and mandatory incident reporting obligations that apply from the moment CUI entered the unauthorized system.

Without it: CUI stored in commercial M365 violates DFARS 252.204-7012 from day one. Prime contractor audits routinely check CSP authorization status for subcontractor environments, and commercial M365 fails that check automatically — as the Chesapeake scenario above illustrates.

vCISO ยท Annual Review ยท C3PAO Readiness

Ongoing CMMC Advisory and vCISO — Compliance That Does Not Drift

CMMC compliance is not a one-time implementation. It requires continuous monitoring, annual SSP review, POA&M maintenance, and tracking of contract-specific CMMC requirements across your active DoD contracts. Capital Techies serves as vCISO (virtual Chief Information Security Officer) for Hampton Roads defense contractors who need ongoing CMMC program management without a full-time hire. Services include quarterly compliance reviews, audit log analysis, annual SSP updates, new contract CMMC scoping, staff security awareness training (a Level 2 control requirement), incident response retainer with DFARS-mapped 72-hour reporting procedures, and annual gap assessment to verify that implemented controls have not drifted from their documented state.

What it prevents: the most common post-initial-compliance failure mode — controls properly implemented at assessment time that drifted over the following 12 to 24 months as staff changed, systems were updated, and configurations were modified without security review.

Without it: controls drift after initial implementation. Staff turnover removes institutional knowledge of why specific configurations exist. New systems are added without CMMC scoping. The next contract renewal finds a degraded compliance posture that requires remediation all over again — at the worst possible time.

Hampton Roads Defense Verticals

CMMC Compliance for Every Hampton Roads Defense Contractor Sector

Hampton Roads is the most heavily militarized metro in the United States. Defense-related activities account for roughly 40% of the region’s gross regional product, and the supply chains feeding the installations and primes here span every industry category below. Each vertical has specific CMMC scoping challenges that a generalist IT provider is not positioned to address.

CMMC Level 1 and Level 2

HII and Newport News Shipbuilding Supply Chain Subcontractors

Huntington Ingalls Industries and Newport News Shipbuilding — the sole designer, builder, and refueler of U.S. Navy aircraft carriers, and one of only two providers of nuclear-powered submarines — employ over 26,000 people in Newport News and anchor a supply chain of hundreds of subcontractors across the seven cities. These suppliers receive technical drawings, specifications, and contract performance data that constitute CUI under CMMC Level 2. Many are small firms without dedicated security staff, operating under long-standing subcontracts that are now being renewed with CMMC flowdown requirements. The most common scenario: a subcontractor whose prime has begun requiring CMMC Level 2 attestation as a contract condition for renewal, with 30 to 90 days to demonstrate compliance they have never built. Capital Techies has designed a rapid CMMC Level 1 and Level 2 implementation program specifically for NNS supply chain subcontractors facing contract renewal deadlines.

CUI — Technical Specs and Contract Performance

Aerospace and Marine Engineering Firms

Companies supplying parts, components, subassemblies, and engineering services to defense primes across Hampton Roads routinely receive and handle CUI in the form of technical drawings, material specifications, and contract performance data. These firms often have robust production controls but inadequate IT security — a combination that creates CUI exposure in the administrative and engineering environment feeding their manufacturing operations. CMMC Level 2 applies to the full system boundary that processes CUI, not just production floor systems. Capital Techies scopes the CUI environment specific to aerospace and marine engineering workflows — separating the CUI system boundary from production systems where CUI does not flow — to minimize the compliance footprint while ensuring every system that touches CUI is fully covered.

Machine Shops and Precision Manufacturing

DoD Fabrication and Manufacturing Subcontractors

Machine shops, metal fabricators, and precision parts manufacturers serving the Hampton Roads defense industrial base frequently receive CUI in the form of drawings, tolerances, and material composition requirements from their prime contractors. These firms are often small — under 50 employees — with a single generalist IT support arrangement that has no CMMC experience. The CMMC flowdown obligation does not exempt small subcontractors: if the work involves CUI, the CMMC requirement applies regardless of company size. Capital Techies builds right-sized CMMC programs for small manufacturing firms: a scoped CUI environment limited to the systems that actually touch defense drawings and specifications, with implementation timelines matched to the firm’s contract renewal calendar rather than an arbitrary 18-month horizon.

IT and Professional Services Supporting DoD

Technology and Professional Services Firms with DoD Contracts

IT providers, engineering consultants, cybersecurity firms, and professional services companies with DoD contracts are themselves subject to CMMC — and their access into client systems may make them an out-of-scope risk to the defense contractors they serve if their own CMMC posture is not documented. SAIC, Leidos, Booz Allen Hamilton, L3Harris, and DXC Technology all have Hampton Roads presences, and the subcontractor and sub-tier service provider ecosystem around them is large. MSPs and IT providers who remotely manage or monitor systems containing FCI or CUI must achieve their own compliance before serving defense contractor clients without creating a compliance gap for those clients. Capital Techies has built its own CMMC-aligned security architecture to serve defense contractor clients without creating compliance exposure for them.

CMMC Applies Near All Seven Installations

Firms Near Naval Station Norfolk, NAS Oceana, and JEB Little Creek

The concentration of military installations across the Hampton Roads seven cities — Naval Station Norfolk (world’s largest naval station, with 67,000 on-installation personnel), NAS Oceana (East Coast Master Jet Base), Joint Expeditionary Base Little Creek-Fort Story, Joint Base Langley-Eustis, and Norfolk Naval Shipyard — creates a dense commercial ecosystem of defense-adjacent businesses that may not recognize their own CMMC obligations. Businesses providing facilities services, technical staffing, logistics support, or IT services to these installations or to their contractors may be handling FCI or CUI without having ever formally assessed their CMMC scope. Capital Techies conducts CUI scoping engagements for installation-adjacent businesses to determine their CMMC level before a contract renewal makes the question urgent.

DFARS 252.204-7021 Flowdown Required

Sub-Tier Subcontractors and Second-Tier Suppliers

DFARS 252.204-7021 requires prime contractors to flow down CMMC requirements to subcontractors at all tiers whose work involves FCI or CUI — meaning a second-tier supplier to an HII Tier 1 supplier may carry the same CMMC obligation as the Tier 1 firm. Many second and third-tier Hampton Roads suppliers have never been formally audited by a prime and have assumed their CMMC obligations were limited or nonexistent. The increase in prime contractor supply chain cybersecurity audits, driven by the Phase 1 enforcement environment, is now surfacing CMMC gaps at sub-tiers that have operated without oversight for years. Capital Techies works with sub-tier suppliers to assess their actual CUI scope, determine the applicable CMMC level, and build a program that satisfies flowdown verification before the prime’s auditors request it.

CMMC Enforcement in the Hampton Roads Defense Industrial Base

Four CMMC Compliance Failures Hitting Hampton Roads Defense Contractors Right Now

These are not hypotheticals. Each scenario below reflects specific fact patterns that CMMC Phase 1 enforcement, prime contractor audits, and DFARS 252.204-7012 obligations are already surfacing across the Naval Station Norfolk corridor, the HII and Newport News Shipbuilding supply chain, NAS Oceana, and the seven cities.

The Newport News HII Subcontractor With a 72-Hour Clock and No Incident Report

A Newport News engineering firm had been a Huntington Ingalls subcontractor for eleven years. When a phishing email arrived appearing to come from an NNS program office address — complete with an HII logo and a legitimate-looking invoice portal link — a junior account manager clicked through and entered her credentials. Within hours, the threat actor was inside the firm’s network, mapping the file shares where drawings and technical specs tagged with CUI markings were stored. Under DFARS 252.204-7012, the firm had 72 hours to report the incident to the DoD Cyber Crimes Center at dibnet.dod.mil — a requirement most of their staff had never heard of. When their prime contract officer called asking for the incident report number, they had none. Data preservation for 90 days was also required. None of it had been configured.

Consequence: DFARS 252.204-7012 reporting violation, potential False Claims Act exposure for failing to report, and a CMMC Level 2 certification timeline that takes 12 to 18 months to complete — time they no longer had before contract renewal. Source: DFARS 252.204-7012; DoD CMMC Program Rule (32 CFR Part 170), effective December 16, 2024.

The Defense Subcontractor Storing CUI in Commercial Microsoft 365

A Chesapeake defense subcontractor supporting Naval Station Norfolk operations stored Controlled Unclassified Information — contract performance data, technical specifications, and program correspondence — in a standard Microsoft 365 Business tenant their IT provider had set up three years earlier. No one had told them that commercial M365 does not meet the FedRAMP Moderate authorization required by DFARS 252.204-7012 for cloud service providers handling covered defense information. When a prime contractor conducted a supply chain cybersecurity audit ahead of contract renewal, the subcontractor’s tenant configuration was the first thing checked. Commercial M365 fails that check automatically. The subcontractor was given 60 days to migrate to a GCC-authorized environment and produce documentation showing CUI had been remediated — or lose the contract.

Consequence: 60-day remediation ultimatum from the prime, emergency GCC migration, and retroactive DFARS 252.204-7012 violation for every day CUI had been stored in an unauthorized cloud environment. Source: DFARS 252.204-7012; FedRAMP Marketplace (fedramp.gov).

The Self-Attestation That Covered Nine of Seventeen Level 1 Practices

A Hampton Roads defense subcontractor completed a CMMC Level 1 self-attestation affirming compliance with all 17 practices from FAR 52.204-21. The self-attestation was filed in good faith — the contractor’s leadership believed their IT provider had verified the controls. During a prime contractor audit as part of supply chain due diligence, it was found that the self-attestation covered 9 of the 17 required practices. Eight practices — including media sanitization, physical access controls to FCI-processing systems, and configuration management for portable storage devices — had never been implemented. The false attestation, even if unintentional, triggered a contract review under the DoD Cyber Fraud Initiative. False CMMC self-attestations can expose contractors to False Claims Act liability with treble damages — three times the contract value.

Consequence: contract review and suspension pending remediation. Eight unimplemented Level 1 practices identified. Potential False Claims Act exposure for the period of the inaccurate self-attestation. Two-month operational disruption while controls were implemented and reverified. Source: DoD Cyber Fraud Initiative; 31 U.S.C. 3729-3733 (False Claims Act).

The Aerospace Supplier That Was Not Assessment-Ready at Contract Renewal

A Virginia Beach aerospace and defense parts supplier received contract renewal paperwork from a prime contractor in Q1 2026 requiring documented CMMC Level 2 attestation and, under the prime’s flow-down requirements, evidence of progress toward C3PAO readiness. The supplier’s managed service provider — a general IT firm without DoD cybersecurity experience — had never heard of NIST SP 800-171. The supplier had no System Security Plan, no documented access controls, no audit logging configured on any system, and no evidence of any of the 110 required Level 2 practices. The prime could not renew the subcontract without CMMC verification. The supplier lost a contract that represented 35% of their annual revenue — and the C3PAO readiness process they should have started 18 months earlier had not begun.

Consequence: lost contract renewal representing 35% of annual revenue. No SSP, no POA&M, zero documentation of Level 2 practices. Root cause: IT provider had no CMMC or NIST 800-171 knowledge. Remediation began after the contract was already lost. Source: CMMC Acquisition Rule, DFARS 252.204-7021, effective November 10, 2025.

Definition

What Is CMMC and Who Needs It?

CMMC — Cybersecurity Maturity Model Certification — is the U.S. Department of Defense’s unified framework for verifying that defense contractors and subcontractors have implemented the cybersecurity practices required to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). CMMC 2.0 applies to all organizations in the Defense Industrial Base whose contracts involve FCI or CUI — estimated at more than 300,000 organizations nationally. For Hampton Roads, that number is disproportionately concentrated here: the HII and Newport News Shipbuilding supply chain, Naval Station Norfolk, NAS Oceana, Joint Base Langley-Eustis, Joint Expeditionary Base Little Creek-Fort Story, and Norfolk Naval Shipyard create a density of CMMC-obligated small businesses unmatched on the East Coast. DoD spends approximately $28.6 billion annually in this region — 5th among all U.S. metros — and all 10 of the top U.S. defense prime contractors have a presence here. Every one of their subcontractors is a potential CMMC obligation in the making.

The two rules that make CMMC enforceable today: The CMMC Program Rule (32 CFR Part 170) became effective December 16, 2024. The CMMC Acquisition Rule (DFARS 252.204-7021) became effective November 10, 2025. Together they constitute the enforcement framework. Phase 1 is active now: CMMC Level 1 and Level 2 self-assessment requirements are appearing in solicitations. Phase 2 begins November 10, 2026, when mandatory C3PAO third-party certification for Level 2 CUI contracts becomes required. The process to achieve C3PAO readiness takes 6 to 18 months for most unprepared contractors. That timeline means Phase 2 readiness work should have started already.

CMMC 2.0 Framework — Three Levels: Level 1 covers 17 security practices from FAR 52.204-21, required for all DoD contractors handling Federal Contract Information. Level 1 permits annual self-attestation by a senior company official without third-party assessment. Level 2 encompasses all 110 security practices from NIST SP 800-171 Rev 2, organized across 14 security requirement families. Most Level 2 programs require third-party assessment by a Certified Third-Party Assessment Organization (C3PAO) prior to contract award; a subset of non-critical programs may permit self-attestation at the Secretary of Defense’s discretion. Level 3 incorporates practices from NIST SP 800-172, assessed by the Defense Contract Management Agency, and applies to the most sensitive DoD programs.

FCI vs. CUI — the scoping question every Hampton Roads contractor must answer: Federal Contract Information (FCI) is information provided by or generated for the Government under a contract, not intended for public release. FCI triggers CMMC Level 1 (17 practices). Controlled Unclassified Information (CUI) is information requiring safeguarding under law, regulation, or government-wide policy — technical drawings, specifications, contract performance data, export-controlled information, and sensitive program data. CUI triggers CMMC Level 2 (110 practices). In the Hampton Roads defense industrial base, the most common misclassification is a subcontractor assuming they handle only FCI when their technical deliverables, specifications received from primes, or program correspondence actually contain CUI. A formal scoping exercise frequently reveals Level 2 obligations in organizations that believed they were Level 1. If you are part of the HII or NNS supply chain, assume CUI until your scope analysis proves otherwise.

DFARS 252.204-7012 is already active in your existing contracts: DFARS 252.204-7012 — Safeguarding Covered Defense Information and Cyber Incident Reporting — applies independently of CMMC and is already a contract clause in most active DoD subcontracts. It requires: implementation of NIST SP 800-171 Rev 2 (or documented POA&M for gaps); reporting of cyber incidents to the DoD Cyber Crimes Center (DC3) at dibnet.dod.mil within 72 hours of discovery; preservation of data for 90 days following the report; and use of only FedRAMP Moderate-authorized cloud service providers for any covered defense information. Commercial Microsoft 365 does not meet the FedRAMP Moderate requirement. GCC (Microsoft 365 Government Community Cloud) does. GCC High is required for ITAR-controlled CUI categories. If your organization stores, processes, or transmits covered defense information today, DFARS 252.204-7012 compliance is a current obligation — not a future one.

What CMMC compliance is not: a one-time software purchase, a checklist to sign, or a task that a general IT provider without DoD cybersecurity experience can complete. CMMC compliance is a documented security program — one that an independent assessor or prime contractor auditor will examine evidence for. The self-attestation scenario above — nine of 17 practices covered, eight never implemented — is the most common outcome when contractors assume compliance without verifying it practice by practice. A false or inaccurate self-attestation creates False Claims Act exposure rather than eliminating contract risk. For Hampton Roads defense contractors, the question is not whether to comply — it is whether to start now or explain the gap at contract renewal.

The Data

CMMC Numbers Every Hampton Roads Defense Contractor Needs to Know

Every figure below is sourced and attributable. These are the numbers your contracts manager, CFO, and executive team need to understand before the next solicitation arrives with a CMMC requirement attached.

Phase 1
Active since November 10, 2025: CMMC Level 1 and Level 2 self-assessment requirements now appearing in applicable DoD solicitations. The CMMC Acquisition Rule (DFARS 252.204-7021) is in effect now — not a future deadline
Source: CMMC Acquisition Rule, 90 Fed. Reg. 59532 (Sept. 10, 2025); effective November 10, 2025

Nov 10, 2026
Phase 2 start: mandatory C3PAO third-party certification for CMMC Level 2 CUI contracts. The readiness process takes 6 to 18 months for unprepared contractors — work should begin now
Source: CMMC Acquisition Rule phased implementation schedule; DoD CMMC Program Office

110
Security practices in NIST SP 800-171 Rev 2 that form the complete basis of CMMC Level 2, across 14 requirement families from Access Control to System and Information Integrity
Source: NIST SP 800-171 Rev 2 (NIST.gov)

72 hours
DFARS 252.204-7012 requirement to report a cyber incident involving covered defense information to the DoD Cyber Crimes Center (DC3) at dibnet.dod.mil — in addition to 90-day data preservation. Already required in active contracts
Source: DFARS 252.204-7012(c); DoD DC3 (dc3.mil)

$28.6B
Annual DoD spending in the Hampton Roads region, the 5th-largest metro for direct DoD spending in the United States — all 10 top U.S. defense prime contractors have a presence here
Source: Hampton Roads Alliance, Defense Cluster Report, 2024

10 of 10
Top U.S. defense prime contractors present in Hampton Roads, including Huntington Ingalls Industries, Northrop Grumman, Lockheed Martin, General Dynamics, Raytheon, and Booz Allen Hamilton — each with subcontractor supply chains flowing CMMC requirements down
Source: Hampton Roads Alliance, 2024; BuiltIn Hampton Roads Defense Companies, 2025

Regulatory Frameworks

CMMC and DoD Cybersecurity Frameworks Capital Techies Implements in Hampton Roads

CMMC does not operate in isolation — it is built on NIST SP 800-171, enforced through DFARS contract clauses, and layered with CUI handling requirements and cloud authorization obligations that apply independently of CMMC certification level. Capital Techies implements all of these frameworks as an integrated program for Hampton Roads defense contractors.

Framework Who Needs It What Capital Techies Does Deliverable
CMMC Level 1 All DoD contractors handling Federal Contract Information — the baseline requirement for any DoD contract or subcontract flowing down FAR 52.204-21. Applies to every business in the Hampton Roads defense supply chain, regardless of size or tier 17-practice gap assessment mapped to FAR 52.204-21, control implementation for all unmet practices, annual self-attestation preparation for senior official signature, documentation package for prime contractor supply chain audits, annual review to maintain attestation currency Written gap assessment report, implemented and verified controls across all 17 practices, self-attestation documentation package, evidence binder for prime audit requests, annual review schedule
CMMC Level 2 (Self-Attestation) Non-critical DoD programs at Secretary of Defense discretion — a limited subset of Level 2 programs designated eligible for contractor self-attestation rather than C3PAO third-party assessment. Contractors must confirm their program falls into this subset before assuming self-attestation is permissible All 110 Level 2 practices documented and implemented, SSP developed with practice-specific implementation descriptions, POA&M developed for any gaps with remediation timelines, evidence package assembled for senior official self-attestation, annual review for attestation renewal, False Claims Act risk counseling for self-attestation accuracy SSP covering all 110 NIST 800-171 practices, POA&M with remediation tracking, evidence package supporting self-attestation, annual compliance review report
CMMC Level 2 (C3PAO Assessment) Most CMMC Level 2 programs — contractors handling CUI on critical DoD programs who must undergo third-party assessment by an accredited C3PAO prior to contract award or renewal. Required from November 10, 2026 (Phase 2) for most CUI contracts in the Hampton Roads defense industrial base Full 110-practice gap remediation across all 14 NIST 800-171 requirement families, SSP and POA&M development to C3PAO assessment standards, pre-assessment readiness review simulating C3PAO evidence requests, pre-assessment gap closure, evidence package organization for each practice, C3PAO selection guidance from the Cyber AB marketplace, and assessment coordination support C3PAO-ready evidence package with documentation for all 110 practices, remediated technical controls with configuration exports, SSP and POA&M in assessment-ready format, pre-assessment readiness report identifying any remaining risk items
NIST SP 800-171 Rev 2 All CMMC Level 2 contractors — the 110 practices of NIST 800-171 Rev 2 are the technical foundation of CMMC Level 2, organized across 14 security requirement families. Also required for DFARS 252.204-7012 compliance in active contracts Control implementation mapped to all 14 NIST families: Access Control (AC), Awareness and Training (AT), Audit and Accountability (AU), Configuration Management (CM), Identification and Authentication (IA), Incident Response (IR), Maintenance (MA), Media Protection (MP), Personnel Security (PS), Physical Protection (PE), Risk Assessment (RA), Security Assessment (CA), System and Communications Protection (SC), System and Information Integrity (SI) NIST 800-171 SSP with implementation description and evidence for each of the 110 controls, organized by requirement family, with practice-level compliance status documentation
DFARS 252.204-7012 All DoD contractors with covered defense information — applies independently of CMMC and is already a clause in most active DoD contracts and subcontracts in the Hampton Roads defense industrial base. Requires immediate action, not future planning Cloud service provider verification and documentation (FedRAMP Moderate minimum for CDI/CUI — GCC or GCC High configuration for M365 environments), 72-hour DoD DC3 incident reporting capability and runbook, 90-day data preservation procedure, media sanitization procedure implementation, adequate security verification across the covered defense information environment, and DFARS flowdown verification for subcontractor relationships DFARS compliance documentation package including CSP authorization records, incident reporting runbook with 72-hour DC3 notification procedures and contact information, 90-day data preservation policy, media sanitization log templates, covered defense information environment boundary map
FedRAMP / GCC Requirement for CUI Any Hampton Roads defense contractor using a cloud service provider to store, process, or transmit covered defense information. Commercial Microsoft 365, Google Workspace, Dropbox, and similar platforms do not qualify. GCC or GCC High is required for M365 environments handling CUI Current CSP authorization assessment, GCC or GCC High tenant provisioning and migration, conditional access policy configuration, DLP policy for CUI, MFA enforcement, audit logging, and documentation of the CSP’s FedRAMP authorization status for inclusion in the contractor’s DFARS compliance record GCC or GCC High tenant configuration with documented FedRAMP Moderate or High authorization, data migration completion report, access control and DLP policy documentation, DFARS CSP authorization record
Cyber Insurance Alignment Any Hampton Roads defense contractor maintaining cyber insurance — insurers increasingly audit CMMC and NIST 800-171 controls at renewal and deny claims when documented controls were absent or misrepresented at policy issuance. CMMC compliance documentation directly supports the evidence trail insurers require Control mapping from CMMC and NIST 800-171 implementation to cyber insurance application requirements, evidence documentation aligned to carrier audit standards, MFA and backup verification documentation, and annual control review timed to policy renewal to ensure documentation currency Insurance-aligned control documentation package, MFA and backup verification records, annual compliance review report timed to policy renewal, evidence binder formatted for carrier audit review

Free CMMC Gap Assessment

Find Out Exactly Where Your CMMC Gaps Are — Before Your Next Contract Renewal

Most Hampton Roads defense contractors do not know their CMMC level or gap count until a contract renewal forces the question. Our free CMMC Gap Assessment gives you a written summary of where you stand across Level 1 and Level 2 practices — no obligation.

  • 15-minute call with a Capital Techies CMMC advisor, not a salesperson
  • We map your current controls against CMMC Level 1 (17 practices) and Level 2 (110 practices) as applicable
  • We identify your highest-risk gaps — missing SSP, unimplemented controls, non-authorized cloud services, DFARS reporting gaps
  • You receive a written gap summary whether or not you become a client
  • No contract required, no pressure, no obligation — Hampton Roads defense contractors served across the seven cities

Start My Free CMMC Gap Assessment

For Hampton Roads and Virginia Beach defense contractors, aerospace suppliers, and DoD subcontractors. Response within 30 minutes.













No spam. No contract required. Your information is used only to prepare for your assessment call.

Thank you — a Capital Techies CMMC advisor will contact you within 30 minutes to schedule your free gap assessment. You will receive a written gap summary within 24 hours of the call.
Something went wrong submitting the form. Please email us directly at info@capitaltechies.com or call 571-982-6000.

Client Feedback

What Our Clients Say

Real reviews from Capital Techies clients on Google.

Frequently Asked Questions

CMMC Compliance Questions from Hampton Roads Defense Contractors

Authoritative answers to the questions Virginia Beach, Norfolk, Newport News, and Hampton Roads defense contractors, aerospace suppliers, and DoD subcontractors ask most often about CMMC compliance, NIST SP 800-171, and what the Phase 1 and Phase 2 enforcement timeline means for their contracts.

What is CMMC and who needs to comply?

CMMC — Cybersecurity Maturity Model Certification — is the Department of Defense’s framework for verifying that companies in the defense supply chain have implemented cybersecurity practices appropriate to the sensitivity of the government information they handle. CMMC 2.0 applies to all DoD contractors and subcontractors whose contracts involve Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), estimated at more than 300,000 organizations across the Defense Industrial Base. The framework establishes three certification levels: Level 1 (17 practices, for FCI), Level 2 (110 practices from NIST SP 800-171, for CUI), and Level 3 (advanced practices from NIST SP 800-172, for the most sensitive programs). CMMC requirements flow down from prime contractors to subcontractors at all tiers. Hampton Roads has one of the densest concentrations of CMMC-obligated small businesses on the East Coast, concentrated around the HII and Newport News Shipbuilding supply chain and the installations across the seven cities — Naval Station Norfolk, NAS Oceana, JBLE Langley-Eustis, Joint Expeditionary Base Little Creek, and Norfolk Naval Shipyard.

What is the difference between CMMC Level 1 and Level 2?

CMMC Level 1 covers 17 basic safeguarding practices derived from FAR 52.204-21 and applies to DoD contractors handling Federal Contract Information (FCI). Level 1 compliance is demonstrated through annual self-attestation by a senior company official and does not require third-party assessment. CMMC Level 2 encompasses all 110 security practices from NIST SP 800-171 Rev 2, organized across 14 security requirement families, and applies to DoD contractors handling Controlled Unclassified Information (CUI). For most Level 2 programs, compliance must be demonstrated through third-party assessment by an accredited C3PAO prior to contract award — not self-attestation. Level 2 also requires a documented System Security Plan (SSP) and a Plan of Action and Milestones (POA&M) maintained throughout the contract period. The practical difference for a Hampton Roads defense subcontractor is significant: Level 1 is a 17-practice self-attestation program implementable in 60 to 90 days for a prepared organization; Level 2 is a 110-practice independently assessed program requiring 6 to 18 months for an unprepared contractor, a completed SSP, and a C3PAO assessment before the contract can be awarded.

When does CMMC Phase 2 start and what does it mean for Hampton Roads defense contractors?

CMMC Phase 1 became active November 10, 2025, when the CMMC Acquisition Rule (DFARS 252.204-7021) took effect. DoD began including CMMC Level 1 and Level 2 self-assessment requirements in applicable solicitations. Phase 2 begins November 10, 2026, when mandatory C3PAO third-party certification for Level 2 CUI contracts becomes required. For Hampton Roads contractors, this is not a future deadline — it is the current enforcement environment. Solicitations issued since November 2025 may already require CMMC compliance at contract award, and subcontractors face the same requirements through flowdown provisions from primes. Contractors without existing NIST 800-171 controls who need Level 2 readiness and begin the process in mid-2026 may not be assessment-ready before Phase 2 — potentially missing contract renewal windows with no ability to accelerate. The CMMC Program Rule (32 CFR Part 170) that established the certification framework became effective December 16, 2024.

Does commercial Microsoft 365 meet CMMC requirements for CUI?

No. Standard commercial Microsoft 365 — including M365 Business Basic, Business Premium, E1, E3, and E5 — does not meet the cloud service provider requirements for handling Controlled Unclassified Information under DFARS 252.204-7012. DFARS 252.204-7012 requires that cloud service providers used to store, process, or transmit covered defense information meet security requirements equivalent to the FedRAMP Moderate baseline at minimum. Commercial M365 does not hold FedRAMP Moderate authorization and does not meet DoD data residency, personnel security, or audit requirements for CUI. Microsoft 365 Government Community Cloud (GCC) meets FedRAMP Moderate and satisfies DFARS 252.204-7012 for most defense contractors. Microsoft 365 GCC High meets FedRAMP High and is required for ITAR-controlled information and other sensitive CUI categories. If your Hampton Roads organization stores CUI in a commercial M365 tenant today, you are out of compliance with DFARS 252.204-7012 from the date the first piece of CUI entered that environment. Capital Techies manages the full GCC migration for Hampton Roads defense contractors, including tenant provisioning, data migration, and configuration of required access controls and audit logging.

How much does CMMC compliance cost for a small Hampton Roads defense contractor?

The cost of CMMC compliance for a small Hampton Roads defense contractor depends on the CMMC level required, the contractor’s starting security posture, and the scope of the CUI environment. For CMMC Level 1, small contractors typically spend $5,000 to $20,000 on gap assessment, control implementation, and self-attestation documentation preparation, plus ongoing annual maintenance. For CMMC Level 2, the investment is larger: gap assessment and advisory services range from $15,000 to $50,000 depending on scope; technical control implementation including GCC migration ranges from $20,000 to $80,000; C3PAO assessment fees range from $5,000 to $50,000 depending on the C3PAO and CUI environment complexity; and ongoing compliance maintenance adds $10,000 to $30,000 per year. These ranges are wide because the primary cost driver is the contractor’s starting posture — a firm with existing NIST 800-171 controls and a GCC environment spends far less than one starting from a standard commercial IT baseline with no security documentation. Capital Techies provides a free initial CMMC Gap Assessment so Hampton Roads contractors understand their specific gap count and cost range before any engagement begins.

Do subcontractors need CMMC or only prime contractors?

Subcontractors need CMMC when their subcontract involves Federal Contract Information or Controlled Unclassified Information — and prime contractors are required to flow down CMMC requirements to subcontractors under DFARS 252.204-7021. This means the obligation flows to any subcontractor, at any tier, whose portion of the work involves FCI or CUI. For Hampton Roads defense subcontractors supporting Huntington Ingalls, Newport News Shipbuilding, Northrop Grumman, Lockheed Martin, General Dynamics, or any of the other top-10 defense prime contractors with a regional presence, the question is whether your specific scope of work involves FCI or CUI. Technical drawings received from the prime, specifications you generate as deliverables, contract performance data, and project correspondence referencing sensitive program information are all common CUI categories that many subcontractors have never formally identified. If you are uncertain, the safe assumption is that your subcontract involves CUI — and that your prime will be required to verify your CMMC compliance before their own contract renewal. The NNS and HII supply chain is precisely the environment where this is already happening.

What is a System Security Plan (SSP) and is it required for CMMC?

A System Security Plan (SSP) is a formal document that describes the information system’s environment, the CUI it handles, the security requirements applicable to the system, and how each security requirement is implemented. For CMMC Level 2, the SSP is required — it is the primary document a C3PAO assessor reviews when conducting a third-party assessment. The SSP must describe how each of the 110 NIST SP 800-171 practices is implemented in the contractor’s specific environment, including the system boundary, the CUI data flows, the responsible parties for each control, and the implementation status. Critically, the SSP must reflect how controls are actually implemented — not how you intend to implement them or how a generic template describes them. Assessors test the controls described in the SSP against the actual technical environment; gaps between the SSP and actual configuration are more serious findings than simply not having implemented a control. Capital Techies develops SSPs that are environment-specific, practice-specific, and aligned to actual control implementations.

What happens if a Hampton Roads contractor submits a false CMMC self-attestation?

False or inaccurate CMMC self-attestations — even those filed in good faith based on an IT provider’s incorrect assessment — expose contractors to significant legal risk. The DoD Cyber Fraud Initiative, established in 2021, actively pursues False Claims Act referrals for contractors who submit materially false CMMC self-attestations to obtain DoD contracts. False Claims Act liability can include treble damages — three times the contract value — plus civil penalties per false claim, and can result in suspension or debarment from future DoD contracting. The enforcement pattern Hampton Roads contractors should understand is this: a failed honest assessment creates a remediation problem; a false self-attestation creates a legal problem that is qualitatively different in both severity and outcome. The self-attestation scenario above — nine of 17 practices actually implemented when all 17 were attested — illustrates the gap that prime contractor audits are now finding. Verify before attesting.

What is DFARS 252.204-7012 and how does it relate to CMMC?

DFARS 252.204-7012 — Safeguarding Covered Defense Information and Cyber Incident Reporting — is a Defense Federal Acquisition Regulation Supplement clause requiring DoD contractors to: implement NIST SP 800-171 Rev 2 (or documented POA&M for gaps); report cyber incidents to the DoD Cyber Crimes Center within 72 hours of discovery; preserve images of compromised systems and data for 90 days; and use only FedRAMP Moderate-authorized cloud service providers for covered defense information. DFARS 252.204-7012 predates CMMC and applies independently — meaning it is already a contract requirement for most Hampton Roads defense contractors regardless of whether their contract includes a CMMC requirement. CMMC Level 2 builds on DFARS 252.204-7012 by adding the full 110-practice NIST 800-171 framework on top of these baseline requirements. For Hampton Roads contractors, DFARS compliance — particularly the CSP authorization requirement and the 72-hour incident reporting obligation — is an immediate, live requirement under existing contracts that cannot be deferred until CMMC phasing begins.

How long does it take to become CMMC Level 2 compliant?

The timeline for CMMC Level 2 readiness varies significantly based on the contractor’s starting point. Organizations with an existing NIST 800-171 implementation, a documented SSP, and mature security controls can typically achieve C3PAO assessment readiness in 3 to 6 months. Organizations starting from a minimal security baseline — no SSP, no documented controls, commercial IT environment — should plan for 9 to 18 months before they are assessment-ready. This timeline accounts for technical control implementation, SSP development across all 110 practices, POA&M development and active remediation, and the time required to accumulate assessment evidence — many controls require 30 to 90 days of operational history before there is meaningful evidence to show an assessor. With Phase 2 beginning November 10, 2026, Hampton Roads contractors facing Level 2 requirements should begin the readiness process immediately. Capital Techies conducts a rapid gap assessment in the first week of any engagement to provide an accurate readiness timeline for the specific contract calendar.

Can Capital Techies serve as our CMMC advisor and managed IT provider for our Hampton Roads firm?

Yes. Capital Techies serves Hampton Roads defense contractors as both CMMC advisor and managed IT provider, with our own infrastructure and access procedures aligned to CMMC and NIST 800-171 requirements. As a managed IT provider with access to client systems containing FCI or CUI, Capital Techies has built its own security architecture accordingly: GCC environment for client communications involving CUI, MFA enforcement for all remote access, documented access control procedures, and audit logging for all client system access. We operate as vCISO for defense contractor clients who need ongoing CMMC program management, and as managed IT provider for those who want a single partner handling both the security architecture and the compliance documentation. Capital Techies is not a C3PAO and does not conduct the independent third-party assessment required for CMMC Level 2 — we prepare you for that assessment and assist in selecting an accredited C3PAO from the Cyber AB marketplace. Call us at 571-982-6000 or complete the form above to schedule your free CMMC Gap Assessment.

How Exposed Is Your Business Right Now?

Get your free Cyber Risk Score in under 3 minutes. We check for exposed credentials, email spoofing gaps, dark web leaks, and unpatched systems. You get a letter grade and a plain-English report. No sales call required.

Get Your Free Cyber Risk Score →

Free · Takes 3 minutes · No sales call required