Supply Chain Toolkit

Know what’s expected. Prove you’re ready.

The CMMC Supply Chain Toolkit helps defense contractors understand prime contractor expectations, prepare for compliance requirements, and navigate the path toward CMMC readiness.

Executive Summary / TL;DR

With the advent of CMMC, primes are under immense pressure to secure themselves and their supply chains; they are not only responsible for themselves but also for ensuring all flow down requirements are met. As a result, primes are holding their subcontractors to higher standards than ever.

This toolkit will give you insight into what primes are looking for when selecting a subcontractor and how to rise to the occasion, winning you contracts.

Prime Notices

What do primes expect from their supply chain? Some major players in the Defense Industrial Base have explicitly said what they’re looking for through notices and memos.

Prime contractor updates and notices include:

  • Parsons
  • Boeing
  • Elbit America
  • Lockheed Martin
  • Northrop Grumman

Prime Interviews / Additional Viewing

Additional viewing if you’d like to hear more from primes and industry leaders interviewed by Summit 7.

Featured discussions:

  • Securing the Supply Chain with Elbit America
  • Herding Compliance Supply Chain Cats with Kellie Tomeo at Montrose Environmental
  • Boeing Principal CMMC with Brett Cox
  • CMMC & Supply Chain Requirements

Meeting Prime Expectations in 7 Steps

A roadmap for meeting prime contractor expectations through seven key CMMC preparation steps.

Step 1: Determine Your Required CMMC Level

Determine the CMMC level required for your organization based on your contracts, data handling requirements, and DoD obligations.

Step 2: CUI Scoping

Understand where Controlled Unclassified Information (CUI) exists within your environment and determine the appropriate scope for compliance.

Step 3: Choosing a Technical Design

Choose the appropriate technical architecture and strategy to achieve CMMC compliance.

Step 4: Choosing a Cloud Service Provider

For CMMC, there is really only one question you have to answer:

Is ALL of my CUI protected ALL of the time?

Selecting the correct cloud environment is critical to maintaining compliance.

Step 5: Choosing an MSP

Selecting the right Managed Service Provider (MSP) or Managed Security Service Provider (MSSP) can simplify compliance efforts and provide expert support.

Step 6: Prepare for a CMMC Assessment

Prepare documentation and evidence required for assessment success.

Key preparation areas include:

  • Understanding Plans of Action and Milestones (POAMs)
  • Developing a System Security Plan (SSP)
  • Preparing documentation for assessment activities

Step 7: Complete a CMMC Assessment

Complete your CMMC assessment by working with assessors and validating that your security practices meet requirements.

Budgeting

Budgeting is a critical part of CMMC preparation, including getting leadership approval and identifying the costs associated with different compliance approaches.

Your Compliance Path in Under 5-Minutes

Get your custom path to CMMC compliance with the free Summit 7 Pathfinder tool.

How it works:

  • Answer a few simple questions.
  • Get your custom 7-step path to CMMC compliance.

How Can We Help?

We’ve helped hundreds of subcontractors in the Defense Industrial Base:

  • Migrate to the GovCloud
  • Architect secure and compliant environments
  • Prepare for CMMC and NIST audits
  • Over 80+ passed CMMC Level 2 assessments
  • The largest team of certified experts in the DIB
  • Trust from 8 of the top prime DoD contractors

Scroll to Top