CMMC is not determined by how many employees you have.
CMMC is not limited to manufacturers or to companies that build physical products. Consulting and professional services firms handle Controlled Unclassified Information (CUI) without ever touching a part or a drawing: acquisition data, pricing, program documents, government reports. The firms are often small, run on Microsoft 365 and laptops from home offices, and staffed by very capable people who have never had to keep a security program on paper.
CMMC isn't determined by how many employees you have. What matters is the information you are contractually required to protect and the systems that handle it.
What CUI may look like here.
Examples of information that may constitute CUI when appropriately designated or contractually identified include:
- Contract deliverables
- Acquisition information
- Procurement information
- Pricing information
- Program documentation
- Government reports
- Government-furnished information
- Analysis and technical documentation
- Certain personnel-related information
The path a file takes.
- Government
- Email/Teams
- Consultant Laptop
- SharePoint
- Deliverable
Where it goes wrong.
The whole company is the environment by default
Relatively small organizations operating almost entirely through Microsoft 365, laptops, software-as-a-service (SaaS) applications and home offices tend to have one environment for everything. Controlled work and ordinary work share the same tenant, the same devices and the same accounts, so the assessed boundary becomes the entire firm unless someone decides otherwise.
Capable people, no formal governance
The staff are experienced and careful. What is missing is not competence but structure: written policies, a defined owner for security, a record of who has access to what, and a habit of collecting evidence. When an assessor asks how a control is met, "our people know better than to do that" is true and insufficient.
Documentation and evidence were never anyone’s deliverable
Consulting firms produce documents for a living and rarely produce them about themselves. There is no System Security Plan (SSP), no asset inventory, no access review on file, because none of those was ever a client requirement. Under CMMC they are the requirement.
Home offices and personal devices
Work happens wherever the consultant is. A personal laptop with the client’s files on it, a home network nobody manages and a phone with the corporate mailbox are each an endpoint holding CUI, and the program has to either bring them under management or keep controlled work off them.
"We're only a small consulting company."
CMMC is not determined by how many employees you have. What matters is the information you are contractually required to protect and the systems that handle it. A small firm holding acquisition or pricing information under a contract that carries the clause has the same obligation as a large plant. The scale of the program is different; the requirement is not.
Being small is also the opportunity. A firm this size can decide where CUI is allowed to live and keep everything else out of scope. That is what a properly designed CUI enclave is: a defined set of accounts, devices and services for controlled work, with the rest of the company left outside the boundary. Appropriate scoping is the single decision that most affects what the program costs to build and to keep, and it is available to a small consultancy in a way it is not to a large integrated manufacturer.
An environment that holds.
- 01
- A CUI enclave in Microsoft 365 GCC High or an equivalent — A tenant, or a segregated part of one, that holds only controlled work: named sites, named accounts, its own sharing rules. Ordinary business email and files stay outside it. The enclave is the boundary the SSP describes, and it is small enough to describe completely.
- 02
- Managed laptops for anyone who touches the enclave — Company-owned, enrolled, encrypted, patched and monitored, with the enclave reachable only from them. Personal devices are not banned from the company; they are kept out of the enclave.
- 03
- Multifactor authentication on every identity — Every account that can reach controlled information requires multifactor authentication (MFA), with access granted per project and reviewed on a schedule. In a firm with no data centre, identity is the perimeter.
- 04
- A defined SaaS list — A short, written inventory of the cloud applications allowed to process CUI, and a rule that nothing else does. The list is what stops controlled material drifting into a note-taking tool, a personal file-sync folder or an AI assistant nobody evaluated.
- 05
- Governance a small firm can sustain — A named owner, a compact set of policies, an evidence folder with a collection calendar, and a Plan of Action and Milestones (POA&M) for whatever is not finished. Enough to answer a Certified Third-Party Assessment Organization (C3PAO); little enough to survive a busy quarter.
The order we do it in.
- 01
Discover CUI
- 02
Define Scope
- 03
Identify Gaps
- 04
Design Controls
- 05
Implement
- 06
Collect Evidence
- 07
Prepare for Assessment
- 08
Maintain Compliance
This is the CMMCg Method applied to your environment. Read the Method →
Open these first.
The working documents from the CMMCg Resource Library that fit this kind of organization, in the order to use them.
CUI Identification Worksheet
Worksheet to list the information your organization receives, creates, processes or transmits that may constitute CUI, with origin, access, storage and marking.
Open →CUI Flow Mapping Template
Template to trace each CUI type from receipt through processing, storage, transmission, sharing and disposition, and mark where it leaves your boundary.
Open →CMMC Scoping Worksheet
Worksheet to sort people, systems, endpoints, networks, cloud services, facilities and providers into CMMC asset categories, and defend every exclusion.
Open →CMMC Technology Inventory
Inventory of endpoints, servers, network, identity, cloud, security products, SaaS and external services with owner, location, scope status and CUI handling.
Open →CMMC Level 2 Readiness Checklist
High-level readiness review across all 14 NIST SP 800-171 Rev 2 requirement families that CMMC Level 2 assesses, 3 to 5 review prompts per family.
Open →
Further along than that? The path continues with the Evidence Collection Tracker, the Gap & POA&M Tracker (a POA&M is a Plan of Action and Milestones) and the Assessment Preparation Checklist.
Does this look like your environment?
The readiness call starts from where your information actually goes, not from a template. An engineer runs it.
- Your CUI boundary sketched on the call
- The requirements costing you the most points, named
- A written summary afterward, yours to keep
NDA signed before anything technical. No cost, no obligation.