Start Your CMMC Readiness Review Now
Cybersecurity Maturity Model Certification
The U.S. Department of Defense will require Cybersecurity Maturity Model Certification (CMMC) for defense contractors. Your path to certification begins with a Readiness Review.Expedite Compliance with a Readiness Review
To prepare for an official CMMC audit, many companies execute a CMMC Readiness Review to help them assess their progress toward successfully achieving a CMMC Level. Working hand-in-hand with a third-party assessor you trust, the results of your Readiness Review will provide a sound understanding of where your program is and where it should be.
CMMC Readiness Reviews assess the following areas:
- System Security Plan (SSP) controls and objectives
- Controlled Unclassified Information (CUI) data flow
- Network topology and diagram
- Hardware/software asset list
- Plan of Action and Milestone (POA&M) confirmation
Start Your Review Today
CMMC Assessment
ABS QE is ready to help your organization meet CMMC 2.0 requirements. As a Certified Third-Party Assessor Organization (C3PAO), our team of cybersecurity experts can provide gap assessments, readiness reviews, training services and assistance with the Joint Surveillance Voluntary Assessment Program (JSVAP).
CMMC Questions? Join Our Experts for Free Guidance
Join us on August 8th at 10 am CDT, in the webinar "Everything You Need to Know About the CMMC Ecosystem (Part One)". Our team of experts will explore a holistic overview of the CMMC ecosystem today, including the current state, ongoing timeline, and revised CMMC model.
Why ABS Quality Evaluations?
We're a global leader in Certified Performance.
ABS QE is a Certified Third-Party Assessor Organization (C3PAO) authorized by the Cyber Accreditation Body (Cyber AB) and a licensed training provider (LTP) certified by the Cybersecurity Assessor and Instructor Certification Organization (CAICO) to provide CMMC assessment services and training.
Our cybersecurity services include CMMC training, self-assessments, readiness reviews, gap assessments, Joint Surveillance Voluntary Assessment Program (JSVAP) assistance and certifications for ISO/IEC 20000, ISO/IEC 27001, ISO/IEC 27002, ISO/IEC 27017, ISO/IEC 27018 and ISO/IEC 27701, among others.
Frequently Asked Questions (FAQ)
Should we just complete Level 1 certification because it is easier?
The level of compliance is dependent upon the type of information your organization is protecting and should be indicated in contractual documents and requirements. However, Level 2 certification is the most common level for DIB contractors and better prepares your organization for the future.
Should we just complete Level 1 certification because it is easier?
Why do we need a third party if we can conduct a self-assessment internally?
While self-assessments are an option, they leave room for critical errors that can ultimately bring your business and operations to a costly halt. Ask yourself: can you ensure your people are qualified and have the bandwidth to conduct an independent, impeccable self-assessment while maintaining operations? A C3PAO will have the independence, experience and competencies necessary to provide an unbiased and accurate assessment.
Why do we need a third party if we can conduct a self-assessment internally?
We already have good cybersecurity systems in place; why do we need an assessment?
Although your organization may have a substantial cybersecurity system in place, CMMC 2.0 requirements are complex and time-consuming. Becoming an early adopter and identifying areas for remediation now is better than when you are pursuing certification as you would have to go back and fix them, potentially slowing your day-to-day operations. If you are found non-compliant or submit a false Supplier Performance Risk System (SPRS) score due to an insufficient self-assessment, you could be subject to fines, penalties, suspension or loss of contracts and also be found in violation of the False Claims Act.
We already have good cybersecurity systems in place; why do we need an assessment?
Why do I need to start my CMMC assessment now - don't we have a few years to comply?
Between fiscal years 2019 and 2020, DIBCAC assessed 110 companies to test their compliance with CMMC. Of those companies, only 16% met their satisfactory level. As of October 2021, the number has increased, but only to 22%. Starting the process now will allow you and your organization to identify areas for improvement before you attempt to achieve certification. Becoming an early adopter removes the strain and potential monetary consequences of needing to wait in a very long line for compliance.
Why do I need to start my CMMC assessment now - don't we have a few years to comply?
What is a CMMC Gap Assessment and what steps are included?
ABS QE can perform a Gap Assessment related to CMMC compliance. The Gap Assessment will be a mock assessment. An Executive Summary and Assessment Report will be provided as deliverables addressing each of the 110 security controls as part of the standard. No advice or remediation recommendations are provided. During the assessment, controls will be marked as "met", "not met" or "N/A" with no additional advice provided. It will be up to the organization to remediate its own environment. This option allows ABS QE to later perform a CMMC Certification audit if desired.
The assessment will consist of the following steps:
- Validate CMMC Assessment Scope
- Create an inventory of cybersecurity practices against the CMMC model
- Collect, examine and analyze evidence
- Conduct interviews and assess responses
- Observe tests and analyze results
- Identify and document evidence gaps
- Score organization's practices and validate preliminary results
- Determine final practice results
- Create, finalize and record recommended final findings
What is a CMMC Gap Assessment and what steps are included?
What is a CMMC Readiness Review and what areas are assessed?
ABS QE can perform a basic readiness review related to CMMC compliance. Compared to a gap assessment, a readiness review is more limited in scope as it does not review controls and evidence for compliance but for completion. During the review, items will be marked as "met", "not met" or "N/A" with no additional advice provided. This option allows ABS QE to later perform a CMMC certification audit.
During the review, the following areas will be assessed:
- System Security Plan (SSP) review against the 110 CMMC controls and objectives
- Controlled Unclassified Information (CUI) data flow
- Network topology and diagram review
- Hardware and software asset list review
- Confirm a Plan of Action & Milestones (POA&M)
- Define and complete the verification of the CMMC scope
- Shared responsibility matrix review
- Ensure roles are defined and assigned
- SPRS confirmation
What is a CMMC Readiness Review and what areas are assessed?