Defense Contractors
Keep bidding when the clause shows up
A solicitation you have won for years now carries a cybersecurity requirement, and your options are to meet it, subcontract around it, or stop bidding.
The requirement arrives through the contract. Defense Federal Acquisition Regulation Supplement clause 252.204-7012 obliges you to protect controlled unclassified information — the technical drawings, specifications and program data you handle for the Department of Defense — using the 110 security requirements in National Institute of Standards and Technology Special Publication 800-171. The Cybersecurity Maturity Model Certification (CMMC) program is the mechanism that verifies you actually did, rather than taking your word through a self-reported score.
Two mistakes cost small contractors the most money. The first is scoping the whole company. If controlled information touches four workstations, a file share and one engineer’s laptop, certifying your entire network is an expensive way to solve a small problem. A separated environment — an enclave — keeps the requirement contained. The second is treating documentation as a writing exercise. The System Security Plan describes how each requirement is met at your company. An assessor reads it, then goes looking for the evidence. Plans that describe intentions rather than operating controls fail on contact.
IT21 is not a certification body. We are the consultant that gets you ready — scoping, the gap assessment, the environment design, the remediation, the documentation — and stays alongside you through the independent third-party assessment that grants the certification. This overview covers the market; the individual pieces — enclave design, the plan documents, assessment preparation — have their own pages.
What you get:
- A scoping decision that establishes which systems and people actually touch controlled information, so you are not certifying your whole company
- A gap assessment against the 110 security requirements in NIST Special Publication 800-171
- A System Security Plan and Plan of Action and Milestones that are accurate, current, and defensible
- A score in the Supplier Performance Risk System supported by evidence rather than optimism
- A remediation sequence built around your contract dates, not a generic timeline
Assess establishes scope and the honest gap list. Transform is the technical build and the remediation, ordered so the items that block a bid come first. Optimize is the ongoing evidence discipline, because certification is a point-in-time judgment about a program that has to keep running afterward.
General framework work — COBIT, NIST, ISO, System and Organization Controls — sits under Risk and Compliance. This page is specifically the defense path: the clause, the enclave, the Department of Defense portal, the assessment.
Preparing for an assessment and going through one are different jobs, and the discipline that makes the first go well comes from having spent a career on the testing side of the table. Documentation written by someone who has watched evidence get rejected reads differently.
[PROOF: CMMC readiness engagement — sector, region, scope, outcome — supply]
The IT Risk & Readiness Assessment is the low-cost way to find out where you stand before committing to a certification budget. It will tell you what your real scope is, which is usually the single most valuable number in this process.
- Assess
- Transform
- Optimize
Oscar Chacon, CISA
Certified Information Systems Auditor since 1997
Not sure where you stand? Start with the assessment.
Request the AssessmentWhere to go next
CMMC readiness — a field guide
Scoping, the NIST SP 800-171 gap, the SSP and POA&M, SPRS scoring, and where small contractors get stuck.
Get the PDF — enter your email
HubSpot form — assessment-request — not configured
Set portalId and forms.assessment-request in src/lib/hubspot.ts.
Start with the IT Risk & Readiness Assessment
A defined engagement, measured against a recognized control framework, that shows you which controls exist, which are documented but not operating, and which are absent — before you commit a budget.

