CMMC Pathfinder
Your Results
Based on the information you provided, our recommendations for you to become CMMC compliant are below along with cost estimates to help with budgeting projections. A link to these results has been sent to the email you provided so you can reference this later.
Recommendations:
- CMMC Level Recommendation: Your recommended CMMC level is Level 1.
- CMMC Level Recommendation: Your recommended CMMC level is Level 2.
- CUI Scoping Recommendation: We Recommend A CUI Scoping Project.
- CUI Scoping Recommendation: It looks like your CUI is scoped. Good job!
- Recommended Technical Design: We recommend a CMMC Enclave.
- Recommended Technical Design: We recommend the All-In approach.
- Recommended Cloud Service for CMMC: We recommend you go with Microsoft Government Community Cloud (GCC).
- Recommended Cloud Service for CMMC: We recommend you make the investment in Microsoft Government Community Cloud (GCC) High.
- Managed Services Recommendation: We recommend you grade your Managed Service Provider.
- Managed Services Recommendation: We recommend you go with Guardian + Vigilance (Managed Services + Managed Security Services).
- Our Recommendation for Preparing for Your CMMC Assessment
CMMC Cost Estimation
Whether you’re a business leader, IT professional, or compliance officer, the information below from our webinar will equip you with the knowledge to make informed decisions about your cybersecurity investments: How to Budget for CMMC





Here’s a podcast episode where our experts estimate the cost of CMMC based on government-provided ranges: Estimating the Cost of NIST SP 800-171
Finally, here’s a Cost Benefit Analysis for Using A MSP / MSSP.
Step 1: Your Recommended CMMC Level
Your CMMC level is Level 1.
CMMC Level 1 certification is necessary for those who want to bid on DoD contracts that handle only Federal Contract Information (FCI). For this reason, your organization must meet all 15 requirements found in the FAR 52.204-21 (17 CMMC Practices).
If the FAR 52.204-21 Requirement is in your current contracts, you are most likely in the CMMC Level 1 category. Level 1 consists of 17 basic cybersecurity practices. The requirement states that all contractors must implement these safeguard controls.
*As of the writing of this document, CMMC Level 1 will not require a third-party assessment, only self-attestation.
Your CMMC level is Level 2.
CMMC Level 2 compliance requires all 110 security controls from NIST 800-171.
CMMC Level 2 certification may be necessary for those who want to bid on DoD contracts that handle the following:
- Controlled Unclassified Information (CUI) / Controlled Defense Information
- Controlled Technical Information (CTI)
- ITAR or export-controlled data that is also CUI
If the DFARS 252.204-7012 requirement is in your current contracts, you are most likely in the Level 2 category.
Step 2: CUI Scoping Recommendation
We recommend a CUI Scoping Project.
When it comes to current compliance mandates for the DoD supply chain, identifying assets and data in your existing IT environment can be a challenge because of the potential areas in which contract information (FCI) and sensitive data (CUI) can flow.
Ask the following questions to drive the asset identification conversation:
- How does data flow in and out of our current environment?
- Do we know where our FCI/CUI is stored, processed and transmitted, or possibly could be
- Do we have control over the systems holding contract information/sensitive data?
It looks like your CUI is scoped! Good job!
Remember: It is critical that you inventory your devices, repositories, systems and people and assign them to their respective areas or buckets.
This step will save organizations a significant amount of time and energy preparing for a CMMC assessment.
Many small to medium-sized businesses in the DIB are relying on Microsoft’s suite of security products to prepare for CMMC Level 1 and CMMC Level 2, leveraging Microsoft Purview, to identify assets for CMMC compliance.
Microsoft Purview holds a feature called “Content search” that is not only beneficial to contractors trying to identify their data landscape and assessment scope, but it can also validate their data flow control capabilities already implemented.
Step 3: Recommended Technical Design For CMMC
We recommend the “All In” approach.
All In” is a lift of your existing infrastructure, and a shift into a virtualized / compliant infrastructure.
Because of the widespread sensitive data flow, your organization must be able to extend the security benefits of their cloud service offering to all assets in their information system deemed to be “in scope”.
When implementing an All In approach, it is important for your organization to ensure the shift taking place is happening on a compliant platform, such as Microsoft GCC or GCC High.
If sensitive data only flows to a small representation of your information system and can be easily isolated, then the cloud enclave could be an ideal solution. But if there is a large percentage of assets within your CMMC assessment scope, we recommend the “All-In” approach.
We recommend a CUI Enclave.
Cloud enclaves are cloud-based, stand-alone information systems that provide a software-defined perimeter around their included resources.
Organizations who confirm limited CUI data flow exposure on their information system can choose this method to avert workload constraints associated with the full infrastructure migration of an All In approach.
Since sensitive data only flows to a small representation of your information system and can be easily isolated, then the cloud enclave could be an ideal solution.
However, if there is a large percentage of assets discovered to be within the CMMC assessment scope, the enclave approach should not be considered, and could potentially do more harm than good.
Step 4: Recommended Cloud Service For CMMC
We recommend you use Microsoft Government Community Cloud (GCC).
The Microsoft 365 GCC environment segregates government data from the data used by organizations with Microsoft 365 commercial tenants and therefore helps organizations satisfy DFARS 7012, NIST-800-171, and CMMC 2.0 requirements if the organization does not handle export-controlled data such as ITAR and EAR.
Benefits of Microsoft GCC:
- Budgeting: Most are aware that GCCH currently costs 30-50% more than Commercial and GCC. Also, GCC offers the opportunity for monthly billing rather than annual.
- Teams and Collaboration: GCC provides native audioconferencing and voice capabilities without the need for additional projects or configuration. Also, B2B with Commercial is fully functioning.
- Equal Compliance Footing: Outside of the issues mentioned above, GCC is FedRAMP High certified and can now meet DFARS 7012 flowdown requirements.
- Feature Parity: Feature parity should become less of an n the future; however, currently many capabilities are lagging and unfortunately some relate to security such as features on the platform.
We recommend you make the investment in Microsoft Government Community Cloud (GCC) High.
Microsoft 365 GCC High is built on Azure Government, within dedicated US data centers.
GCC High is the only Microsoft offering – besides the DoD dedicated Microsoft 365 – that insures all data resides in U.S. data centers and is supported by background-checked U.S. persons.
Those attributes make GCC High the compliant option for ITAR and EAR data.
Additionally, Microsoft 365 GCC High is a suitable cloud platform to house CUI corporately and on behalf of the Government, which requires DISA IL 4 or greater. GCC High is rated at DISA IL 5 and is FedRAMP High equivalent.
Benefits of Microsoft GCC High
#1: Microsoft Recommends GCC High for CMMC 2.0 Levels 2-3
Despite Microsoft’s inclusion of GCC in its accreditation boundary for GCC, Microsoft still believes CUI is best handled in GCC High. Microsoft suggests GCC for Level 1.
#2: US Person Support
Microsoft 365 Commercial and GCC have a follow-the-sun support model, meaning the frontline and administrative backend support tickets can go to an individual that resides and holds citizenship in a foreign nation.
#3: Collaboration with Microsoft 365
DoD Microsoft has not enabled communication or collaboration (B2B) between M365 DoD and either Commercial or GCC. GCCH is the only version of the platform capable of B2B with DoD.
#4: ITAR or NOFORN Data
Companies cannot handle or store ITAR data on Commercial or GCC because the data may be accessed by non-US persons as a part of Microsoft’s administrative activities and can create an unlawful and unintended export.
#5: Prime Contractors
Most of the major/large prime contractors are moving, or have moved, to GCCH. Many of these primes will more easily collaborate and communicate with subs that are also on GCCH. Moreover, many primes prefer and trust companies on the same platform.
#6: 2x Migration, Configuration, and Assessment
GCCH is the sure thing for long term compliance. If a company wins a single contract or task order that includes ITAR data, then the company would need to make the difficult decision to turn down the award or go through a second migration and security implementation.
Step 5: Managed Services Recommendation
We recommend you go with Guardian + Vigilance (Managed Services + Managed Security Services).
Guardian is Summit 7’s basic Managed Service offering.
We partner with organizations as an outsourced IT provider that focuses on basic internal IT provisioning and management to support your business and its everyday productivity and financial objectives.
Vigilance is Summit 7’s advanced Managed Security Service offering. We provide a more advanced MSP option that supports external IT security functions such as (but not limited to):
- Incident detection
- Incident response
- Security monitoring
- Scans for new threats and vulnerabilities for your business
Try our MSP Grader for CMMC tool to get insight into the scope and quality of services you need from an MSP.
Steps 6 & 7: Recommendation for Preparing for Your CMMC Assessment
Preparing and documenting for a CMMC assessment can be the Achilles heel for defense contractors in their CMMC compliance journey.
Documentation will be a large part of what the Cyber AB C3PAOs (CMMC assessors) review to validate the implementation of controls.
Failing to properly map CMMC documentation to the correct standards could result in a failed assessment and the loss of contracts for organizations in the Defense Industrial Base (DIB).
How to prepare and document for CMMC compliance:
- Incorporate CMMC/NIST 800-171A into the Systems Security Plan (SSP)
- Update infrastructure maps and data flow diagrams
- Generate asset inventory lists by category for CMMC Level 2
- Ensure your self-assessment report and POA&M are completed for review
- Define organizational responsibilities vs. those of your managed service provider, or those that are shared between yourself and your service provider.
- Gather FIPS 140-2 validated URLs and screenshots
Having a proper CMMC assessment completed is the final, and obviously most critical step in a company’s journey to CMMC certification.
The C3PAO will likely provide a readiness checklist of items that will be reviewed to ascertain whether your team has prepared to proceed with a formal CMMC Level Assessment.

Contact
Speak With Our Team
Our team of compliance and cybersecurity experts are on standby and ready to help. We’ll walk you through what you need and what to expect.
