GET A QUOTE

CMMC Compliance –  Los Angeles (CA)

Los Angeles and California Department of Defense (DoD) contractors and subcontractors will soon be required to comply with the new Cybersecurity Maturity Model Certification (CMMC) 2.0 standard. The new standard is designed to help counteract the significant increase in the compromises of sensitive defense information which is shared across the defense industrial base.

In the past, DoD contractors have been responsible for maintaining certain cybersecurity practices, but under the emerging CMMC requirements contractors must undergo third-party compliance assessments and implement additional security protections. Once implemented contractors and subcontractors will need to be compliant to be awarded contract work.

Three CMMC Maturity Levels (ML)

Once implemented, DoD contract solicitations will indicate the required maturity level for the winning contractor. If a contractor does not have the appropriate certification in the DoD’s Supplier Performance Risk System (SPRS), then the contractor will be ineligible for contract award.

CMMC Level 1 will be added to contracts where FCI only will be received or generated by the contractor. Level 1 will require organizations to annually self-assess and affirm their compliance with the 17 Level 1 practice requirements, which are composed of 59 assessment objectives.

CMMC Level 2 requires a triennial third-party assessment and annual affirmation of compliance with 110 practice requirements, which are composed of 320 assessment objectives. Level 2 also expands the type of information system assets that are in scope for assessment, compared to Level 1.

CMMC Level 3 requires an existing Level 2 certification, and contractors will be assessed by the DoD for compliance against an additional 24 practice requirements. Level 3 also expands the type of information system assets that are in scope for assessment, compared to Level 2.

Readiness Preparation

By most estimates, organizations are likely to require 12-18 months to prepare for a Level 2 assessment. With the CMMC final rule likely taking effect during the first half of 2025, California DoD contractors who wish to participate on new DoD contracts should start preparing as soon as possible.

California Top DoD Spending Locations

Los Angeles CMMC Services

Many Los Angeles DoD contractors will need assistance performing initial assessments to uncover issues, establish corrective actions, and to chart a path towards CMMC readiness.

The CMMC is complex. ML 3 contains 381 discrete cybersecurity requirements spread among 130 practices, and 310 policy/procedure requirements spread among 51process maturity requirements. The requirements are complex, and our team has almost 20 years of experience providing cybersecurity compliance services across many complex frameworks such as NIST SP 800-171, NIST SP 800-53, HIPAA, and others. As a CMMC Registered Provider Organization (RPO), our team can help DoD prime and subcontractors with the following:

  • Readiness Assessments and Gap Analyses Against the CMMC Framework
  • Assistance with Remediating Gaps Identified during Readiness Assessment
  • Assistance with NIST SP 800-171 Self-Assessment that is recorded in Supplier Performance Risk System
  • Creating System Security Plans (SSP)
  • Creating Plans of Action and Milestones (POA&M)

CMMC Readiness: De-Risk Your Compliance

Security Compliance = Secure Client Base

Scott McAuliffe and Chris Moschella provide an overview of the CMMC requirements and share readiness strategies that can help you reduce noncompliance risk, regardless of where you are in your readiness process.

December 18th, 2024 Webinar Recording

Contact Our CMMC Team

Keiter provides CMMC readiness assessments and remediation services to DoD contractors across Los Angeles and the State of California. If you are interested in learning how we can assist your organization, complete the form below and a team member will follow up promptly.

"*" indicates required fields

We'll never share your email with anyone else.
This field is for validation purposes and should be left unchanged.

 

About California’s DoD Contractors

City of L.A. LogoCalifornia’s Department of Defense (DOD) contractors are instrumental in strengthening national security and driving technological innovation. The state hosts a diverse and extensive community of defense contractors, specializing in various fields such as aerospace, technology, cybersecurity, and advanced manufacturing.

These contractors collaborate closely with DOD agencies and military installations, including Naval Base San Diego, Edwards Air Force Base, and Vandenberg Space Force Base. They are at the forefront of developing cutting-edge defense technologies, systems, and solutions, significantly enhancing the nation’s defense capabilities.

California’s DOD contractors also have a substantial economic impact on the state by creating jobs and fostering innovation. Their commitment to excellence and their partnership with the military ensure that the United States remains a leader in military technology and readiness. California’s defense contractors play a pivotal role in supporting national defense efforts while driving economic growth and technological advancement within the state. The area codes used in Los Angeles (CA) are 213, 323, 424, 747, 818, and 626.

National Reach

We also provide CMMC services to Department of Defense Contractors in Alabama, Arizona, Colorado, Florida, Hawaii, Illinois, Mississippi, New Hampshire, Pennsylvania, New Jersey, Maine, Massachusetts, New York, North Carolina, South Carolina, Texas, Vermont, the State of Washington, and Washington D.C.

 

Contact Us