CMMC 2.0 · DEFENSE INDUSTRIAL BASE

CMMC 2.0 Compliance
Defence Industrial Base Security

CMMC 2.0 is mandatory for US Department of Defense contractors handling Controlled Unclassified Information (CUI). Canadian companies in the US/Canada defence supply chain - including NORAD, NATO, and DND contractors - increasingly face CMMC requirements. ThreeShield delivers CMMC gap assessments backed by government audit experience.

CMMC 2.0 Level Structure

Level 1 - Foundational (17 practices)

Basic cyber hygiene. Annual self-assessment. Covers Federal Contract Information (FCI) only. Maps to 15 NIST SP 800-171 practices.

Level 2 - Advanced (110 practices)

Aligns to NIST SP 800-171 in full. Required for contracts involving CUI. Triennial third-party assessment (C3PAO) for critical programs; annual self-assessment for others.

Level 3 - Expert (110+ practices)

NIST SP 800-172 additional requirements for highest-value DoD programs. Government-led assessments by DCSA. For organizations protecting the most sensitive DoD programs.

CUI Scoping

The most critical step in CMMC compliance is defining what CUI you handle and where it lives. Overly broad scoping creates unnecessary compliance burden; too narrow creates risk of non-compliance. ThreeShield delivers formal CUI scoping exercises.

System Security Plan (SSP)

CMMC Level 2 requires a documented SSP describing how each NIST SP 800-171 control is implemented. The SSP is the primary document the C3PAO assessor reviews. ThreeShield develops SSPs grounded in your actual technical environment, not templates.

POAM Management

Plan of Action and Milestones (POAM) documents known gaps and remediation timelines. A well-managed POAM demonstrates compliance maturity even when not all controls are fully implemented. ThreeShield maintains POAM tracking continuously.

CMMC as a Contract Requirement

CMMC certification is a condition of contract award for affected DoD contracts. Non-certified organizations cannot compete for contracts requiring CMMC Level 2 or 3. The DoD has committed to phased CMMC requirements in all new contracts - organizations that aren't certified will lose eligibility for defence contracts they currently hold.

US DoD Prime Contractors DoD Subcontractors Canadian NORAD / NATO Contractors DND Supply Chain Aerospace & Defence Manufacturers Defence Software Providers

Frequently Asked Questions

Yes, if you're in the US Department of Defense supply chain - either as a prime contractor with US government contracts, or as a subcontractor to a US prime. Canadian companies building components for US defence programs (aerospace parts, software, services) increasingly face CMMC requirements passed down through their prime contractor's flow-down clauses. NORAD and NATO involvement can also trigger requirements.

It depends on your contract category. Level 1 still allows annual self-assessment. Level 2 for most programs now requires a third-party assessment (C3PAO) on a triennial basis. The self-attestation model that was common under DFARS 252.204-7012 is being replaced by formal CMMC certification. ThreeShield helps you understand which level applies and what certification looks like.

CMMC governs cybersecurity controls for protecting CUI. ITAR (International Traffic in Arms Regulations) and EAR (Export Administration Regulations) govern the export of defence-related technology and information. They're separate regulatory regimes that often apply simultaneously to defence contractors. ThreeShield focuses on the CMMC cybersecurity requirements; ITAR/EAR compliance involves additional export control expertise.

Three Ways to Engage - DIY to Done-for-You

ThreeShield meets you at your current security maturity. Every level includes Lavawall®.

Self-Serve

DIY via Lavawall®

For lean IT teams and cost-conscious organizations with internal security capacity

  • Lavawall® GRC with CMMC control mapping
  • Continuous automated evidence collection
  • Live compliance dashboard and score
  • Policy template library
  • AI-generated compliance status reports
Start with Lavawall®
Recommended for MSPs & Lean IT

Supported

Expert guidance alongside your team - ideal for MSPs and organizations with some internal IT capacity

  • Everything in DIY tier
  • CISSP/CISA gap assessment
  • Prioritized remediation roadmap
  • Policy and procedure development
  • Quarterly compliance review calls
  • MSP white-label available
Get Supported Engagement
Fully Managed

Done-for-You

Full compliance delivery - ThreeShield manages the entire program end to end

  • Everything in Supported tier
  • Full compliance program management
  • CISSP/CISA-executed formal assessment
  • findings methodology (typically 200+ findings)
  • Complete documentation package
  • Annual reassessment included
Book Done-for-You

Ready to Get Compliant?

Choose your engagement model: DIY via Lavawall®, supported by ThreeShield's CISSP/CISA team, or fully done-for-you. Every model includes continuous monitoring so you stay compliant year-round.

Book a Scoping Call

DIY · Supported · Done-for-You · Available globally