
CMMC READINESS · DOD CONTRACTORS · DMV
CMMC Compliance Support for Defense Contractors in DC, Maryland & Virginia
DCI TECH USA helps defense contractors and subcontractors prepare the people, systems, security controls and documentation needed for CMMC requirements. We support organizations across Washington, DC, Maryland and Northern Virginia with CMMC readiness, NIST SP 800-171 remediation, cybersecurity and managed IT.
Readiness and remediation support — not a substitute for the official assessment path required by your DoD solicitation or contract.
CURRENT CMMC FRAMEWORK
Know the level your contract requires.
The required CMMC status depends on the information your systems handle and the level specified in the solicitation.
L1
FCI · 15 safeguards
Annual self-assessment
L2
CUI · 110 requirements
Self or C3PAO as specified
L3
24 enhanced requirements
DCMA DIBCAC assessment
Level 3 requires Final Level 2 (C3PAO) status for the applicable assessment scope before the Level 3 assessment begins.
FCI → Level 1
Basic safeguarding for contractor systems that process, store or transmit Federal Contract Information.
CUI → Level 2
NIST SP 800-171 Rev. 2 requirements apply to the Level 2 assessment scope.
DMV Support
Washington DC, Maryland and Northern Virginia with remote and local on-site support.
Readiness + Remediation
Scope the environment, identify gaps, implement controls, organize evidence and maintain the environment.
WHO CMMC AFFECTS
If DoD contract data touches your systems, the requirement can follow the data.
CMMC requirements can apply to prime contractors and subcontractors when covered systems process, store or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). The required status and assessment type are identified in the applicable solicitation or contract.
01 · PRIME CONTRACTORS
Direct DoD contractors
If systems used for a DoD contract handle FCI or CUI, the solicitation can require a current CMMC status before award and throughout performance.
02 · SUBCONTRACTORS
Suppliers in the defense supply chain
CMMC requirements can flow down when a subcontractor's systems process, store or transmit the FCI or CUI needed to perform the work.
03 · GROWING DIB FIRMS
Organizations preparing for future DoD work
Preparing before a solicitation arrives can reduce last-minute remediation by clarifying scope, documentation and technical security gaps early.
WHAT HAPPENS NEXT
Three levels. Different data. Different assessment paths.
The first step is not buying more security tools. It is determining the assessment scope, the information handled, and the CMMC status required by the solicitation.
01
LEVEL 1 · SELF
Foundational protection for FCI
Level 1 uses the 15 safeguarding requirements in FAR 52.204-21 for covered contractor information systems handling FCI.
-
All Level 1 requirements must be MET.
-
No POA&M is permitted for Level 1.
-
Self-assessment and affirmation are required annually.
Assessment results are submitted in SPRS.
02
LEVEL 2 · SELF OR C3PAO
Protecting Controlled Unclassified Information
Level 2 uses the 110 NIST SP 800-171 Rev. 2 security requirements for CUI environments.
-
The solicitation specifies Self or C3PAO.
-
Final status is generally current for three years.
-
Affirmation of continuous compliance is required annually.
Conditional status and limited POA&M use are governed by 32 CFR Part 170.
03
LEVEL 3 · DIBCAC
Enhanced protection for the highest-priority programs
Level 3 adds 24 selected NIST SP 800-172 enhanced security requirements for designated programs.
-
Final Level 2 (C3PAO) is a prerequisite.
-
DCMA DIBCAC performs the Level 3 assessment.
-
Level 3 certification assessment is performed every three years.
Level 2 certification must also remain current for the Level 3 assessment scope.

!
Important: CMMC is contract-specific. Do not assume your organization needs a particular level based only on company size or industry. Review the solicitation, the FCI/CUI flow and the systems that will perform the work.

START WITH THE ENVIRONMENT YOU HAVE TODAY
Know what needs to change before the assessment becomes urgent.
Talk with DCI TECH USA about your contract requirements, current IT environment and CMMC readiness priorities. We can help turn the gaps into a practical remediation and ongoing support plan.
dcitech.us · Washington DC · Maryland · Northern Virginia