Skip to content
CMMC Guidance
← Industries
Professional Services & Consulting

CMMC is not determined by how many employees you have.

CMMC is not limited to manufacturers or to companies that build physical products. Consulting and professional services firms handle Controlled Unclassified Information (CUI) without ever touching a part or a drawing: acquisition data, pricing, program documents, government reports. The firms are often small, run on Microsoft 365 and laptops from home offices, and staffed by very capable people who have never had to keep a security program on paper.

CMMC isn't determined by how many employees you have. What matters is the information you are contractually required to protect and the systems that handle it.

01 · What CUI Looks Like in Your Industry

What CUI may look like here.

Examples of information that may constitute CUI when appropriately designated or contractually identified include:

  • Contract deliverables
  • Acquisition information
  • Procurement information
  • Pricing information
  • Program documentation
  • Government reports
  • Government-furnished information
  • Analysis and technical documentation
  • Certain personnel-related information
02 · Where Your CUI Typically Travels

The path a file takes.

  1. Government
  2. Email/Teams
  3. Consultant Laptop
  4. SharePoint
  5. Deliverable
A government client sends material by email or shares it in Teams. A consultant opens it on a laptop, often at home, works on it, saves it to SharePoint, and produces a deliverable that goes back. Short path, few systems, and every one of them is in scope, including the laptop on the kitchen table.
03 · Where Organizations Like Yours Commonly Get Into Trouble

Where it goes wrong.

01

The whole company is the environment by default

Relatively small organizations operating almost entirely through Microsoft 365, laptops, software-as-a-service (SaaS) applications and home offices tend to have one environment for everything. Controlled work and ordinary work share the same tenant, the same devices and the same accounts, so the assessed boundary becomes the entire firm unless someone decides otherwise.

02

Capable people, no formal governance

The staff are experienced and careful. What is missing is not competence but structure: written policies, a defined owner for security, a record of who has access to what, and a habit of collecting evidence. When an assessor asks how a control is met, "our people know better than to do that" is true and insufficient.

03

Documentation and evidence were never anyone’s deliverable

Consulting firms produce documents for a living and rarely produce them about themselves. There is no System Security Plan (SSP), no asset inventory, no access review on file, because none of those was ever a client requirement. Under CMMC they are the requirement.

04

Home offices and personal devices

Work happens wherever the consultant is. A personal laptop with the client’s files on it, a home network nobody manages and a phone with the corporate mailbox are each an endpoint holding CUI, and the program has to either bring them under management or keep controlled work off them.

04 · "But We..."

"We're only a small consulting company."

CMMC is not determined by how many employees you have. What matters is the information you are contractually required to protect and the systems that handle it. A small firm holding acquisition or pricing information under a contract that carries the clause has the same obligation as a large plant. The scale of the program is different; the requirement is not.

Being small is also the opportunity. A firm this size can decide where CUI is allowed to live and keep everything else out of scope. That is what a properly designed CUI enclave is: a defined set of accounts, devices and services for controlled work, with the rest of the company left outside the boundary. Appropriate scoping is the single decision that most affects what the program costs to build and to keep, and it is available to a small consultancy in a way it is not to a large integrated manufacturer.

05 · What a Practical CMMC Environment Looks Like

An environment that holds.

01
A CUI enclave in Microsoft 365 GCC High or an equivalentA tenant, or a segregated part of one, that holds only controlled work: named sites, named accounts, its own sharing rules. Ordinary business email and files stay outside it. The enclave is the boundary the SSP describes, and it is small enough to describe completely.
02
Managed laptops for anyone who touches the enclaveCompany-owned, enrolled, encrypted, patched and monitored, with the enclave reachable only from them. Personal devices are not banned from the company; they are kept out of the enclave.
03
Multifactor authentication on every identityEvery account that can reach controlled information requires multifactor authentication (MFA), with access granted per project and reviewed on a schedule. In a firm with no data centre, identity is the perimeter.
04
A defined SaaS listA short, written inventory of the cloud applications allowed to process CUI, and a rule that nothing else does. The list is what stops controlled material drifting into a note-taking tool, a personal file-sync folder or an AI assistant nobody evaluated.
05
Governance a small firm can sustainA named owner, a compact set of policies, an evidence folder with a collection calendar, and a Plan of Action and Milestones (POA&M) for whatever is not finished. Enough to answer a Certified Third-Party Assessment Organization (C3PAO); little enough to survive a busy quarter.
06 · How CMMCg Approaches It

The order we do it in.

  1. 01

    Discover CUI

  2. 02

    Define Scope

  3. 03

    Identify Gaps

  4. 04

    Design Controls

  5. 05

    Implement

  6. 06

    Collect Evidence

  7. 07

    Prepare for Assessment

  8. 08

    Maintain Compliance

This is the CMMCg Method applied to your environment. Read the Method →

Does this look like your environment?

The readiness call starts from where your information actually goes, not from a template. An engineer runs it.

  • Your CUI boundary sketched on the call
  • The requirements costing you the most points, named
  • A written summary afterward, yours to keep
Book the readiness call

NDA signed before anything technical. No cost, no obligation.