CMMC, without the panic.
RMON works with defense-supply-chain clients as an External Service Provider (ESP) under CMMC: we implement and document the controls in our scope and provide the documentation your assessor needs to evaluate it. RMON has engaged an independent auditing firm to audit its own NIST 800-171 compliance and perform a SOC 2 Type 2 examination. If a prime just asked for your SPRS score or a contract clause says CMMC Level 2, this page is for you.
- External Service Provider (ESP)
- NIST 800-171 support
- Defense suppliers in NH, ME & MA
- Independent 800-171 & SOC 2 audits underway
Who this is for
Machine shops, contract manufacturers, engineering firms, and suppliers anywhere in the defense industrial base. The tell is in your paperwork: DFARS 252.204-7012, 7019, or 7020 clauses in your contracts, or a prime asking for your score.
CMMC in plain English
Level 1. For businesses handling Federal Contract Information (FCI): a smaller set of basic safeguards that you self-assess. If government contract data passes through your systems at all, this is your floor.
Level 2. Where most suppliers handling Controlled Unclassified Information (CUI) land. It is assessed against the 110 controls of NIST SP 800-171, and the documentation of how each control is met matters as much as the control itself.
Level 3. A small set of contractors on the most sensitive programs, with additional controls on top of Level 2. If Level 3 applies to you, you already know it.
The alphabet, decoded
Five terms that carry most of the conversation, in plain words.
SSP
System Security Plan: the document that says how each control is met. Assessors start here.
POA&M
Plan of Action & Milestones: the honest list of what is not done yet and the plan to finish it.
SPRS
Supplier Performance Risk System: where your self-assessment score is submitted. Primes can see it.
CUI vs FCI
Which data you hold decides which level you need: Controlled Unclassified Information points to Level 2; Federal Contract Information alone points to Level 1.
ESP
External Service Provider: an outside provider inside your compliance scope, like RMON, whose services and documentation your assessor evaluates as part of your assessment.
What RMON does
RMON works with defense-supply-chain clients as an External Service Provider (ESP) under CMMC: we implement and document the controls in our scope and provide the documentation your assessor needs to evaluate it. RMON has engaged an independent auditing firm to audit its own NIST 800-171 compliance and perform a SOC 2 Type 2 examination.
Concretely: we implement and document the controls in our scope, maintain the documentation your assessor needs, run compliance-readiness projects when there is ground to cover, and keep managed security running underneath it all. IT Consulting & vCIO →
The security layer itself, monitoring, identity, backup, and response, is the same managed practice that protects every RMON client. Cybersecurity services →
The shared-responsibility truth. CMMC is not something a provider can do TO your business. The controls live in how your people and systems handle CUI every day. We carry our scope and prepare you to carry yours.
Why an ESP that is doing it too
RMON is walking the same road, and we invited the referee: an independent auditing firm is auditing our own NIST 800-171 compliance and performing a SOC 2 Type 2 examination. We are not selling you a framework we have never lived with.
What SOC 2 Type 2 means. An independent audit of how our own controls actually operate over time, not just how they look on paper.
CMMC questions, answered plainly
Can you help with NIST 800-171 or CMMC?
What is an ESP, and does using one help?
Do we need CMMC if we only handle FCI?
What does an assessor actually look at from RMON?
Can RMON get us certified?
Start with the clause in front of you.
Bring the contract clause or the prime’s email. We will tell you plainly what it means for you.