With the publication of CMMC 2.0 and changes from CMMC 1.0, there are now 3 levels within the CMMC Model. The model, along with its supporting documentation like assessment guides and scoping guides, does an excellent job presenting the domains and practices in a variety of digestible ways. There are some details that should be paid specific attention to within the information provided in the CMMC Model, including the different levels and their particulars.
Marci Womack is a Managing Director and leader in Schellman’s CMMC practice. Marci has eight years of information security experience across various industries – cloud services, government, and financial services.
Whether it is an ISO 27001 certification, SOC 2 examination or a FedRAMP assessment, companies are often challenged by the need to address customer requirements while ensuring a return on compliance investment.
The most important factor in scoping a potential assessment is understanding what deliverable the recipient (i.e. your customer or partner) is expecting.
Once we have scoped your environment and needs, there are several factors that contribute to Schellman’s pricing: