CMMC 2.0 Level 2 readiness
Architecture review against the 110 NIST 800-171 controls. Gap assessment. Remediation roadmap. Evidence and documentation preparation that matches what an assessor will actually look at.
Search hans.study
Indexed across articles, news, KB updates, knowledge base, books, learning, and tools. Press Esc to close.
// DEFENCE AND CMMC · HANS STUDY
CMMC 2.0 in the United States. CPCSC in Canada. NIST SP 800-171 underneath both. Independent technical advisory for defence contractors and subcontractors who need the architecture, the controls, and the documentation in a state that survives an assessment, not just an internal review.
This is technical advisory for defence industrial base organizations preparing for CMMC 2.0 in the US, CPCSC in Canada, or NIST SP 800-171 alignment in either country. The work focuses on the technical layer that the framework actually depends on. Network segmentation. Identity and access management. Logging and audit. Backup and recovery. Endpoint and server hardening. Boundary protection. The controls that fail an assessment when the documentation does not match what the network is doing.
This is not a paper-only compliance shop. The deliverable is an environment that holds up technically, with documentation that accurately describes it.
Architecture review against the 110 NIST 800-171 controls. Gap assessment. Remediation roadmap. Evidence and documentation preparation that matches what an assessor will actually look at.
Canadian Program for Cyber Security Certification advisory for organizations doing or pursuing defence work in Canada. Architecture, controls, and documentation aligned to the framework.
Independent assessment against all 14 control families (Rev 2). Realistic reading on which controls are met, partially met, or not met, and a roadmap that prioritizes the ones that actually move the assessment.
Network segmentation for controlled unclassified information. Boundary design between CUI and non-CUI environments. Practical answers for organizations where the entire network does not need to be in scope.
Active Directory architecture, Windows Server hardening, Group Policy and security baselines, Microsoft 365 in CUI-aware configurations. Detailed work on the Microsoft side, where most CMMC environments live.
System Security Plan and Plan of Action and Milestones documentation that accurately describes the environment, identifies open gaps, and stands up to the level of scrutiny an assessment applies.
Last reviewed October 2026: CMMC Phase 2 suspended July 13, 2026; CPCSC Level 1 in select contracts since summer 2026; Level 2 from spring 2027.
I have worked across federal infrastructure, defence environments, and organizations supporting Canadian and US defence supply chains. The advisory is built from NIST SP 800-171 and CMMC readiness work with small defence suppliers since 2019, the network architecture that determines what is in scope, and the operational reality of running a CUI enclave at a small or mid-size organization without taking the rest of the business offline.
For organizations that are early in the process, an architecture review and gap assessment is usually the right first engagement. For organizations close to assessment, the focus is on closing the highest-impact gaps and aligning documentation to actual technical state.
A lot of Level 1 work you can do yourself. These are free, and they're what I'd hand a client first.
Not automatically. The programs share the NIST SP 800-171 lineage, but there is no mutual recognition. PSPC may accept a valid CMMC certification case by case at Level 1, after confirming the assessment covers the required scope.
Level 1 has been in select contracts since summer 2026, and it's required at contract award. PSPC plans to put Level 2 into select contracts from spring 2027.
A lot of Level 1 work you can do yourself. Start with CPCSC, explained, the free book, the policy builder, and the CPCSC templates and checklists.
For organizations early in the process, an architecture review and gap assessment is usually the right first engagement. For organizations close to assessment, the focus is on closing the highest-impact gaps and aligning documentation to the actual technical state.
Yes. I develop System Security Plan and Plan of Action and Milestones documentation that describes the environment accurately and identifies open gaps. The aim is an environment that holds up technically, not paper-only compliance.
Architecture review, gap assessment, remediation oversight, and SSP and POA&M development are discrete engagements. Each is scoped on a call, and a written quote comes before any work starts.
Architecture review, gap assessment, remediation oversight, and SSP/POA&M development are all available as discrete engagements. The earliest point of engagement is also the highest-impact point.
Related work: a defence supplier taken to CMMC and NIST SP 800-171 readiness.
Delivered remotely, or through the DHD, a remote access device shipped to site.
Two tools run by default to help me understand how the site is used. You can turn either off at any time. Cloudflare's server-side analytics is always on and never sees your identity.