top of page
ChatGPT Image Aug 5, 2026, 08_25_06 PM (1).png

CMMC READINESS · DOD CONTRACTORS · DMV

CMMC Compliance Support for Defense Contractors in DC, Maryland & Virginia

DCI TECH USA helps defense contractors and subcontractors prepare the people, systems, security controls and documentation needed for CMMC requirements. We support organizations across Washington, DC, Maryland and Northern Virginia with CMMC readiness, NIST SP 800-171 remediation, cybersecurity and managed IT.

Readiness and remediation support — not a substitute for the official assessment path required by your DoD solicitation or contract.

CURRENT CMMC FRAMEWORK

Know the level your contract requires.

The required CMMC status depends on the information your systems handle and the level specified in the solicitation.

L1

FCI · 15 safeguards

Annual self-assessment

L2

CUI · 110 requirements

Self or C3PAO as specified

L3

24 enhanced requirements

DCMA DIBCAC assessment

Level 3 requires Final Level 2 (C3PAO) status for the applicable assessment scope before the Level 3 assessment begins.

FCI → Level 1

Basic safeguarding for contractor systems that process, store or transmit Federal Contract Information.

CUI → Level 2

NIST SP 800-171 Rev. 2 requirements apply to the Level 2 assessment scope.

DMV Support

Washington DC, Maryland and Northern Virginia with remote and local on-site support.

​Readiness + Remediation

Scope the environment, identify gaps, implement controls, organize evidence and maintain the environment.

WHO CMMC AFFECTS

If DoD contract data touches your systems, the requirement can follow the data.

CMMC requirements can apply to prime contractors and subcontractors when covered systems process, store or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). The required status and assessment type are identified in the applicable solicitation or contract.

01 · PRIME CONTRACTORS

Direct DoD contractors

If systems used for a DoD contract handle FCI or CUI, the solicitation can require a current CMMC status before award and throughout performance.

02 · SUBCONTRACTORS

Suppliers in the defense supply chain

CMMC requirements can flow down when a subcontractor's systems process, store or transmit the FCI or CUI needed to perform the work.

03 · GROWING DIB FIRMS

Organizations preparing for future DoD work

Preparing before a solicitation arrives can reduce last-minute remediation by clarifying scope, documentation and technical security gaps early.

WHAT HAPPENS NEXT

Three levels. Different data. Different assessment paths.

The first step is not buying more security tools. It is determining the assessment scope, the information handled, and the CMMC status required by the solicitation.

01

LEVEL 1 · SELF

Foundational protection for FCI

​Level 1 uses the 15 safeguarding requirements in FAR 52.204-21 for covered contractor information systems handling FCI.

  • All Level 1 requirements must be MET.

  • No POA&M is permitted for Level 1.

  • Self-assessment and affirmation are required annually.

Assessment results are submitted in SPRS.

02

LEVEL 2 · SELF OR C3PAO

Protecting Controlled Unclassified Information

Level 2 uses the 110 NIST SP 800-171 Rev. 2 security requirements for CUI environments.

  • The solicitation specifies Self or C3PAO.

  • Final status is generally current for three years.

  • Affirmation of continuous compliance is required annually.

Conditional status and limited POA&M use are governed by 32 CFR Part 170.

03

LEVEL 3 · DIBCAC

Enhanced protection for the highest-priority programs

Level 3 adds 24 selected NIST SP 800-172 enhanced security requirements for designated programs.

  • Final Level 2 (C3PAO) is a prerequisite.

  • DCMA DIBCAC performs the Level 3 assessment.

  • Level 3 certification assessment is performed every three years.

Level 2 certification must also remain current for the Level 3 assessment scope.

05.png

!

Important: CMMC is contract-specific. Do not assume your organization needs a particular level based only on company size or industry. Review the solicitation, the FCI/CUI flow and the systems that will perform the work.

012.png

START WITH THE ENVIRONMENT YOU HAVE TODAY

Know what needs to change before the assessment becomes urgent.

Talk with DCI TECH USA about your contract requirements, current IT environment and CMMC readiness priorities. We can help turn the gaps into a practical remediation and ongoing support plan.

dcitech.us · Washington DC · Maryland · Northern Virginia

bottom of page