Services / CMMC & NIST 800-171

CMMC, without the panic.

RMON works with defense-supply-chain clients as an External Service Provider (ESP) under CMMC: we implement and document the controls in our scope and provide the documentation your assessor needs to evaluate it. RMON has engaged an independent auditing firm to audit its own NIST 800-171 compliance and perform a SOC 2 Type 2 examination. If a prime just asked for your SPRS score or a contract clause says CMMC Level 2, this page is for you.

  • External Service Provider (ESP)
  • NIST 800-171 support
  • Defense suppliers in NH, ME & MA
  • Independent 800-171 & SOC 2 audits underway

Who this is for

Machine shops, contract manufacturers, engineering firms, and suppliers anywhere in the defense industrial base. The tell is in your paperwork: DFARS 252.204-7012, 7019, or 7020 clauses in your contracts, or a prime asking for your score.

CMMC in plain English

Level 1. For businesses handling Federal Contract Information (FCI): a smaller set of basic safeguards that you self-assess. If government contract data passes through your systems at all, this is your floor.

Level 2. Where most suppliers handling Controlled Unclassified Information (CUI) land. It is assessed against the 110 controls of NIST SP 800-171, and the documentation of how each control is met matters as much as the control itself.

Level 3. A small set of contractors on the most sensitive programs, with additional controls on top of Level 2. If Level 3 applies to you, you already know it.

The alphabet, decoded

Five terms that carry most of the conversation, in plain words.

SSP

System Security Plan: the document that says how each control is met. Assessors start here.

POA&M

Plan of Action & Milestones: the honest list of what is not done yet and the plan to finish it.

SPRS

Supplier Performance Risk System: where your self-assessment score is submitted. Primes can see it.

CUI vs FCI

Which data you hold decides which level you need: Controlled Unclassified Information points to Level 2; Federal Contract Information alone points to Level 1.

ESP

External Service Provider: an outside provider inside your compliance scope, like RMON, whose services and documentation your assessor evaluates as part of your assessment.

What RMON does

RMON works with defense-supply-chain clients as an External Service Provider (ESP) under CMMC: we implement and document the controls in our scope and provide the documentation your assessor needs to evaluate it. RMON has engaged an independent auditing firm to audit its own NIST 800-171 compliance and perform a SOC 2 Type 2 examination.

Concretely: we implement and document the controls in our scope, maintain the documentation your assessor needs, run compliance-readiness projects when there is ground to cover, and keep managed security running underneath it all. IT Consulting & vCIO →

The security layer itself, monitoring, identity, backup, and response, is the same managed practice that protects every RMON client. Cybersecurity services →

The shared-responsibility truth. CMMC is not something a provider can do TO your business. The controls live in how your people and systems handle CUI every day. We carry our scope and prepare you to carry yours.

Why an ESP that is doing it too

RMON is walking the same road, and we invited the referee: an independent auditing firm is auditing our own NIST 800-171 compliance and performing a SOC 2 Type 2 examination. We are not selling you a framework we have never lived with.

What SOC 2 Type 2 means. An independent audit of how our own controls actually operate over time, not just how they look on paper.

CMMC questions, answered plainly

Can you help with NIST 800-171 or CMMC?
Yes. RMON works with defense-supply-chain clients as an External Service Provider (ESP) under CMMC: we implement and document the controls in our scope and provide the documentation your assessor needs to evaluate it. RMON has engaged an independent auditing firm to audit its own NIST 800-171 compliance and perform a SOC 2 Type 2 examination.
What is an ESP, and does using one help?
An External Service Provider is an outside provider inside your compliance scope, like RMON: our services and documentation are evaluated as part of your assessment. It helps when the provider carries its scope well, with implemented controls, current documentation, and answers your assessor can use. It does not remove your side of the work.
Do we need CMMC if we only handle FCI?
Handling only Federal Contract Information generally points to Level 1, the smaller self-assessed set of safeguards. The honest first step is confirming what data you actually hold; plenty of suppliers discover CUI in places nobody had labeled.
What does an assessor actually look at from RMON?
Our documentation of the controls in our scope: how each one is implemented, where it lives, and the evidence behind it. That is the ESP model, and it is why the documentation is maintained continuously instead of assembled the week before an assessment.
Can RMON get us certified?
No provider can promise that. Certification is between you and your assessor. What we do is prepare the environment and the documentation so you walk into the assessment prepared, and carry the controls in our scope so you do not have to.

Start with the clause in front of you.

Bring the contract clause or the prime’s email. We will tell you plainly what it means for you.