For years, defense-supply-chain security ran on self-attestation: check the box in the contract file, keep a policy binder somewhere findable. That era is ending. Primes are pushing CMMC 2.0 requirements into new awards and down through their subcontract chains — the pace varies by program, but the direction doesn’t. The question has changed from “do you have a security policy” to “show us your System Security Plan and your current self-assessment.”
For a small or mid-size contractor, that’s an enterprise-grade obligation landing on a team with no security department. The requirements assume someone owns scoping, documentation, remediation, and the assessment itself — a role that’s a fraction of a job in workload but an executive’s worth of accountability. Which is exactly the shape a fractional CISO is built for.
Agency pairs the named leader with engineers who produce the artifacts assessors actually read — people who’ve internalized that in this world, the documentation isn’t paperwork about the program. It is the program.
Spelled out, because the acronyms hide how much writing is involved.
The SSP: how your environment meets each NIST 800-171 requirement, written against your real systems. Assessors read it first and test everything else against it, so honesty beats polish.
The POA&M: every gap, with an owner, a remediation approach, and a date — maintained as a living document, because a stale one reads as an admission that nobody is driving.
Where Controlled Unclassified Information enters, where it’s stored and marked, who can touch it — and how to shrink that boundary, since every system pulled out of scope is work you never do again.
Your NIST 800-171 self-assessment, scored honestly and kept current — the number your primes can check, and the one you least want to be creative with.
Defense contracts carry rapid-reporting obligations when incidents touch covered systems — so the plan, the contacts, and the evidence trail have to exist before anything happens.
If you have subs of your own, the obligations keep flowing: their assessments and agreements become part of your file, reviewed like the supply-chain risk they are.
Three regimes get conflated constantly. NIST 800-171 is the control set: it applies when Controlled Unclassified Information touches your systems under a covered contract, and it’s what you self-assess against today. CMMC 2.0 is the verification layer on top — levels tiered to the sensitivity of what you handle, with third-party assessment entering the picture as requirements phase in. If you hold CUI, this pair is your track.
FedRAMP is a different track entirely: it governs cloud services sold to federal agencies, it’s an authorization rather than a certification, and it’s a substantially heavier lift that only makes sense with agency demand in hand. Plenty of contractors eventually need both tracks — in which case running them on a common control map is the only sane approach. A vCISO’s first deliverable is often just this: which regime, which level, in what order, and what your contract clauses actually obligate you to.
Assessment-driven programs reward a specific temperament: documentation-first, evidence-always, no improvisation. The best public proof that Agency operates that way is CloudCover, an IT services company whose ISO 27001 audit closed with zero findings — a different framework, the same discipline defense assessors look for. Outcomes like that come from running the program all year, not from heroics in assessment week.
If your revenue includes federal work — prime or sub, defense or civilian — the security program has to serve the contract file first. That’s the specialty of Agency’s government practice, alongside aerospace and aviation, where the same flow-downs dominate. And if the trigger was a letter from your prime: the right time to start was before the letter, and the second-best time is this quarter.
Your contracts decide, not your ambitions. The level tracks what information you handle — Federal Contract Information at the low end, Controlled Unclassified Information above it — and the specific clauses your primes flow down. Reading those clauses against your data flows is step one of any engagement; guessing a level and building toward it is how contractors buy the wrong program.
It depends on your level and your contracts — lower tiers run on self-assessment, higher tiers bring third-party assessment as CMMC phases in. The constant across all of them: the score you submit must be defensible, because primes can see it and assessors can test it. An inflated score is a liability, not a shortcut.
Someone who knows both your environment and the framework — which is why bought templates fail. An SSP describing controls you don’t run is worse than a gap, because assessors test against it. Agency’s engineers write yours from your actual systems and keep it synchronized as the environment changes.
Selling cloud software to agencies is FedRAMP territory; CMMC governs how you handle defense information inside your own environment as a contractor. Some companies genuinely need both — SaaS sold to agencies plus CUI under defense contracts — and the move is one control foundation mapped to both, never two parallel programs.