Federal Readiness

CMMC Readiness & RPO Advisory

Practical, evidence-based preparation for CMMC Level 1 through 3, from an advisor, not the assessor who certifies you.

TandT LLC helps defense industrial base contractors prepare for CMMC Level 1, 2, and 3 as a Registered Practitioner Organization (RPO), closing the gap between “we think we’re compliant” and evidence a C3PAO assessor will actually accept.

What We Deliver

  • Gap Assessment Against NIST SP 800-171: A control-by-control review of your environment against the 110 required practices.
  • System Security Plan (SSP) & POA&M Development: Documentation built to withstand assessor scrutiny, not just internal sign-off.
  • Scoping & Enclave Strategy: Right-sizing your CUI boundary so you are not over-scoping cost or under-scoping risk.
  • Mock Assessment: A dry run of the C3PAO assessment experience so surprises surface on our clock, not the assessor's.

Our Role: Registered Practitioner Organization (RPO) Advisory

TandT LLC provides CMMC readiness and advisory support as a Registered Practitioner Organization. This is distinct from the independent Level 2 assessment performed by an authorized C3PAO (Certified Third-Party Assessment Organization). We help you prepare; we do not certify your CMMC status.

Preparing for CMMC? Start with a clear view of where you stand.

CMMC affects organizations across the Defense Industrial Base that handle Controlled Unclassified Information (CUI). Readiness means knowing exactly where your environment stands against the requirements, and having evidence that holds up when it's actually reviewed.

TandT supports readiness as a Registered Practitioner Organization: scoping your CUI boundary, closing gaps against NIST SP 800-171, and building the documentation an assessment actually requires.

Note: on July 13, 2026, the Department of Defense (which now also uses the public title "Department of War") paused the rollout of CMMC's mandatory third-party (C3PAO) assessment phase pending a program review. The underlying obligation to implement NIST SP 800-171 and complete an annual self-assessment affirmation in SPRS was not affected. Confirm current program status at cyberab.org or dodcio.defense.gov/CMMC before making contract decisions.

Where CMMC risk hides

  • An unclear or over-broad CUI boundary
  • Self-assessment scores that would not survive a closer look
  • Policies that describe controls nobody actually follows
  • Evidence gaps that only surface during the real assessment

This service may be relevant if you are:

  • A defense contractor or subcontractor handling CUI
  • Uncertain whether your current SPRS self-assessment score would hold up
  • Preparing for a Level 1, 2 or 3 requirement
  • Need an advisor distinct from the C3PAO that ultimately certifies you
CMMC 2.0

Three levels. Not every organization needs the same one.

Which level applies depends on the contract and the information involved, not a choice the organization makes on its own.

  1. 1 Level 1 Foundational

    Focus: Basic safeguarding requirements for Federal Contract Information (FCI): the 15 practices in FAR 52.204-21.

    Applies to: Organizations that handle FCI but not CUI.

    Assessed by: Annual self-assessment, with a senior official affirmation submitted to SPRS. No third-party assessment.

  2. 2 Level 2 Advanced

    Focus: The 110 security requirements in NIST SP 800-171 Rev 2, protecting Controlled Unclassified Information (CUI).

    Applies to: Organizations that handle CUI as part of a DoD contract or subcontract.

    Assessed by: Self-assessment for a limited set of programs; third-party (C3PAO) assessment for most CUI contracts. The C3PAO assessment requirement has been paused pending program review. See the note below.

  3. 3 Level 3 Expert

    Focus: Level 2's requirements plus a subset of enhanced requirements from NIST SP 800-172, for the most sensitive programs.

    Applies to: A small percentage of contractors, designated by the DoD based on program sensitivity.

    Assessed by: Government-led assessment (DIBCAC).

Program details and rollout timelines have changed since CMMC 2.0 was finalized and continue to be reviewed. This page reflects our understanding as of publication. Always confirm current requirements at dodcio.defense.gov/CMMC before making a contracting decision.

What We Do

Capabilities

  1. 01
    Gap Assessment Against NIST SP 800-171 A control-by-control review of your environment against the 110 required practices.
  2. 02
    SSP & POA&M Development Documentation built to withstand assessor scrutiny, not just internal sign-off.
  3. 03
    Scoping & Enclave Strategy Right-sizing your CUI boundary so you are not over-scoping cost or under-scoping risk.
  4. 04
    Mock Assessment A dry run of the C3PAO assessment experience so surprises surface on our clock, not the assessor's.
How It Works

A clear path from understanding to action.

  1. 01 Scope Define your CUI boundary and applicable assessment level.
  2. 02 Assess Evaluate current practices against all 110 NIST SP 800-171 controls.
  3. 03 Identify Gaps Document exactly where practices fall short of requirements.
  4. 04 Remediate Prioritize and close gaps with a clear POA&M.
  5. 05 Validate Run a mock assessment to test readiness before the real one.
  6. 06 Prepare for Assessment Finalize evidence and documentation ahead of your C3PAO.
Framework

The TandT Approach

01 Scope
02 Assess
03 Identify Gaps
04 Remediate
05 Validate
06 Prepare for Assessment
An Important Distinction

Readiness support and formal assessment are not the same thing.

What TandT Does

Readiness Support (RPO)

  • Help you understand which requirements apply to your environment
  • Identify gaps against NIST SP 800-171
  • Help prepare evidence and documentation (SSP, POA&M)
  • Advise on improving controls and practices
  • Develop a prioritized remediation plan
  • Run a mock assessment to prepare you for the real one
What Only an Authorized Assessor Does

Formal Assessment / Certification

  • Perform the official third-party (C3PAO) or government-led (DIBCAC) assessment
  • Issue a CMMC certification or assessment result
  • Determine your organization's certified CMMC status

TandT LLC is a Registered Practitioner Organization (RPO), not a Certified Third-Party Assessment Organization (C3PAO). TandT does not perform official CMMC assessments and cannot certify your organization's CMMC status.

Common Pitfalls

Where CMMC readiness efforts commonly go wrong.

Starting with documentation instead of scope Writing policies before knowing what systems, data and people are actually in scope means rewriting them later.
Treating CMMC as a one-time project Requirements call for maintained practices and annual affirmation, not a single push to a finish line.
Assuming tools equal compliance A security product can support a requirement; it doesn't satisfy one on its own without the process and evidence behind it.
Ignoring evidence until the end A control that isn't documented, or documented but never actually followed, tends to surface late, usually during the assessment itself.
Not involving system owners early The people who actually run the systems in scope often know about gaps that a policy review alone would miss.
Underestimating remediation dependencies Some fixes depend on other fixes, budget cycles, or vendor timelines, and a flat checklist doesn't capture that.
What You Receive

Deliverables

  • System Security Plan (SSP)
  • Plan of Action & Milestones (POA&M)
  • CUI boundary / scoping documentation
  • Mock assessment findings
What You Gain

Outcomes

Readiness
A clear, prioritized path to the assessment.
Defensibility
Evidence and documentation that hold up under scrutiny.
Confidence
Know where you stand before the assessor tells you.
Technology Ecosystem

Platforms that commonly appear in CMMC-scoped environments.

These are examples of the kinds of cloud, security and monitoring platforms our CMMC readiness work regularly encounters. They are not an endorsement or compliance guarantee for any of them.

Networking and security infrastructure used across enterprise and service-provider environments.

Data platform for security monitoring, observability and operational analytics.

Enterprise cloud, productivity and technology infrastructure supporting modern business environments.

A Microsoft 365 cloud environment built for U.S. government and defense-industrial-base compliance requirements.

Cloud infrastructure and platform services used across enterprise and government environments.

Monitoring and observability platform for cloud-scale applications and infrastructure.

Technology can support CMMC implementation, but no platform by itself makes an organization compliant. Compliance depends on the organization's actual environment, controls, processes, scope and documented evidence.

Why TandT

What makes this different.

Clear Role Separation As an RPO we help you prepare; we are not the C3PAO that certifies you. No conflict of interest.
Evidence-First We do not sign off on a control we have not verified.
Keep Learning

Continue exploring CMMC.

Explore More

Related services

FAQ

Common questions

What is CMMC?

The Cybersecurity Maturity Model Certification (CMMC) is a Department of Defense (DoD) program that verifies defense contractors and subcontractors have implemented required cybersecurity practices to protect Federal Contract Information and Controlled Unclassified Information.

Who does CMMC apply to?

Organizations in the Defense Industrial Base that process, store or transmit FCI or CUI as part of a DoD contract or subcontract. Applicability and the specific level required depend on the contract, not a choice the organization makes. Review your contract requirements or ask your contracting officer.

What is the difference between CMMC readiness and formal assessment?

Readiness is the preparation work: scoping, gap analysis, remediation, documentation, that gets an organization ready. Formal assessment is the official review performed by an authorized C3PAO (for most Level 2 requirements) or the government (DIBCAC, for Level 3) that actually determines certified status. TandT provides readiness support as an RPO; it is not a C3PAO and does not perform or issue certification.

What is the difference between the CMMC levels?

Level 1 (Foundational) covers 15 basic safeguarding practices for FCI, self-assessed annually. Level 2 (Advanced) covers the 110 requirements in NIST SP 800-171 for CUI. Level 3 (Expert) adds a subset of NIST SP 800-172 requirements for the most sensitive programs, assessed by DIBCAC.

What does a CMMC readiness engagement involve?

Typically a scoping exercise to define the CUI boundary, a control-by-control gap assessment against NIST SP 800-171, prioritized remediation, and a mock assessment before the formal review.

What evidence should organizations prepare?

A System Security Plan, a Plan of Action & Milestones for any open gaps, and documented evidence (policies, configurations, logs) that each implemented control is actually operating as described.

Is the CMMC third-party assessment requirement currently in effect?

The underlying obligation to implement NIST SP 800-171 and submit an annual self-assessment affirmation in SPRS remains in effect. On July 13, 2026, the Department of Defense (which now also uses the public title "Department of War") paused the rollout of the mandatory third-party (C3PAO) assessment phase pending a program review. Confirm current status at dodcio.defense.gov/CMMC before making contract decisions.

How does TandT support organizations preparing for CMMC?

As a Registered Practitioner Organization, TandT provides gap assessments, SSP/POA&M development, scoping guidance and mock assessments, distinct from the independent C3PAO assessment that ultimately certifies compliance.

Start a CMMC Readiness Conversation

Walk through your current scope, environment and readiness gaps with a senior partner.

Talk to a CMMC Advisor

Your information is used to respond to your request and is not used for unrelated marketing without your consent.