When Construction Companies Need CMMC Compliance
A construction company may need CMMC compliance when it performs work for the Department of Defense, supports a defense contractor or handles contract information that is subject to federal cybersecurity requirements.
Not every contractor needs the same compliance level. The correct requirement depends on:
- The contracts the company pursues
- The type of federal information it receives
- Whether the company is a prime contractor or subcontractor
- The cybersecurity clauses included in the contract
- The systems and employees that access regulated information
A construction company should begin evaluating its obligations 6–12 months before a required certification, customer deadline or contract award. Waiting until a bid is due can create unnecessary costs, rushed technology decisions and lost business opportunities.
This guide uses a six-part framework to help construction leaders determine whether CMMC applies, identify the systems in scope and prepare a practical compliance roadmap.
The Six-Part CMMC Readiness Framework
- Review contracts and customer requirements.
- Identify the information the company receives or creates.
- Define the employees, devices and systems in scope.
- Compare current security controls with required practices.
- Remediate technical and documentation gaps.
- Prepare evidence and maintain ongoing compliance.
CMMC is not simply an IT project. It affects contracts, policies, employee behavior, vendors, cloud systems and the way regulated information moves through the company.
Construction companies preparing for federal cybersecurity requirements can review 911 IT's CMMC compliance services.
What Is CMMC?
CMMC stands for Cybersecurity Maturity Model Certification. It is a Department of Defense program designed to verify that contractors and subcontractors protect certain federal contract information appropriately.
CMMC requirements may apply to organizations that handle:
- Federal Contract Information
- Controlled Unclassified Information
- Technical drawings
- Project specifications
- Facility information
- Security-related documents
- Contract deliverables
- Other information identified by the contract
The contract, solicitation and customer requirements determine whether CMMC or related cybersecurity obligations apply.
CMMC Is Broader Than Cybersecurity Software
Installing antivirus and multi-factor authentication does not complete a compliance program. A construction company may also need:
- Written security policies
- Defined employee responsibilities
- Access-control procedures
- Device and software inventories
- Incident response procedures
- Security training
- Risk assessments
- System documentation
- Evidence that controls are operating
- Ongoing monitoring and review
A compliant environment should connect technical safeguards with documented business processes.
Step 1: Review Contracts and Customer Requirements
The first step is determining whether the company's contracts, solicitations or customer agreements include cybersecurity requirements.
Documents to Review
- Prime contracts
- Subcontracts
- Requests for proposal
- Requests for quotation
- Purchase orders
- Flow-down requirements
- Customer cybersecurity questionnaires
- Representations and certifications
- Data-handling instructions
Questions to Ask
- Does the contract reference CMMC?
- Does it include DFARS cybersecurity clauses?
- Will the company receive Federal Contract Information?
- Will the company receive Controlled Unclassified Information?
- Are requirements flowing down from a prime contractor?
- Is a specific CMMC level identified?
- Is an assessment or certification required before award?
- What deadline applies?
- Which subcontractors must meet the same requirements?
- Who inside the company owns the contract review?
Do not assume CMMC is irrelevant because the company is not contracting directly with the federal government. Requirements may flow from a prime contractor to subcontractors, suppliers and service providers.
Build a Contract Requirements Register
Create a simple register containing:
- Customer or agency
- Contract number
- Cybersecurity clauses
- Information type
- Required CMMC level
- Assessment deadline
- Internal owner
- Subcontractor obligations
This prevents compliance obligations from remaining buried inside contract documents that only one employee has reviewed.
Step 2: Identify the Information the Company Handles
CMMC scope begins with information. The company needs to know what regulated information it receives, creates, stores, processes and transmits.
Federal Contract Information
Federal Contract Information generally involves information provided by or generated for the government under a contract that is not intended for public release.
Construction-related examples may include:
- Contract schedules
- Project correspondence
- Nonpublic specifications
- Internal deliverables
- Government-provided project information
Controlled Unclassified Information
Controlled Unclassified Information is not classified information, but it still requires protection under applicable laws, regulations or government policies.
Examples in a construction environment may include:
- Facility drawings
- Security system details
- Infrastructure information
- Technical specifications
- Site access procedures
- Controlled project documentation
- Other information marked or identified as controlled
The company should not decide whether information is regulated based only on file names or assumptions. Contract requirements, data markings and customer guidance should be reviewed carefully.
Create a Data Flow Map
For each regulated information type, document:
- Who sends it to the company?
- How is it received?
- Where is it stored?
- Which employees can access it?
- Which applications process it?
- How is it shared with subcontractors?
- How is it archived or deleted?
A data flow map helps the company define the compliance boundary and find uncontrolled copies.
Step 3: Define the CMMC Scope
CMMC scope includes the people, processes, devices, applications and service providers that handle regulated information or protect the systems that do.
Potentially In-Scope Employees
- Project managers
- Estimators
- Executives
- Accounting personnel
- Contract administrators
- Field supervisors
- IT administrators
- Employees who support government projects
Potentially In-Scope Devices
- Office computers
- Field laptops
- Tablets
- Smartphones
- Servers
- Portable drives
- Printers and scanners
- Jobsite networking equipment
Potentially In-Scope Applications
- Microsoft 365
- SharePoint
- OneDrive
- Microsoft Teams
- Procore
- Bluebeam
- Accounting platforms
- File servers
- Email security platforms
- Backup systems
- Remote support tools
Potentially In-Scope Vendors
- Managed IT providers
- Cloud service providers
- Software vendors
- Backup providers
- Subcontractors
- Document-management vendors
- Security monitoring providers
A vendor may become part of the compliance discussion when it stores, processes, transmits or can administratively access regulated information.
Three Common Scoping Approaches
| Approach | Description | Advantages | Challenges |
|---|---|---|---|
| Enterprise-wide scope | Most or all company systems meet the required standard | Simple user experience and fewer boundaries | Higher cost and broader implementation effort |
| Dedicated secure environment | Regulated information is limited to selected users and systems | Smaller compliance boundary | Requires strong separation and employee discipline |
| Specialized cloud enclave | Regulated work occurs in a separate controlled platform | May reduce local infrastructure requirements | Requires workflow changes and careful vendor evaluation |
The best approach balances security, usability, cost and the number of employees who need access.
Step 4: Assess Current Security Controls
After defining scope, the company should compare its current practices with the applicable requirements.
Access Control
Review whether the company:
- Uses individual user accounts
- Limits access based on job responsibilities
- Removes former employee access promptly
- Restricts administrator privileges
- Controls remote access
- Reviews user permissions regularly
Identification and Authentication
Review:
- Multi-factor authentication
- Password requirements
- Administrative accounts
- Service accounts
- Account lockout settings
- Cloud sign-in monitoring
Device and System Protection
Review:
- Endpoint detection and response
- Security patching
- Device encryption
- Mobile device management
- Application controls
- Supported operating systems
- Vulnerability management
Email and Cloud Security
Review:
- Email filtering
- Impersonation protection
- External forwarding controls
- Microsoft 365 administrator roles
- Third-party application permissions
- Cloud security logging
- Data-sharing settings
Network Security
Review:
- Business-grade firewalls
- Network separation
- Secure wireless access
- Jobsite connectivity
- Remote administration
- Configuration backups
- Monitoring and alerting
Backup and Recovery
Review:
- Microsoft 365 backup
- Server and application backup
- Protected or immutable backup copies
- Backup monitoring
- Recovery testing
- Incident recovery procedures
Policies and Procedures
Review whether documented policies exist for:
- Access control
- Acceptable use
- Incident response
- Employee onboarding and offboarding
- Media handling
- Remote work
- Mobile devices
- Risk assessments
- Security training
- Vendor management
Written policies should describe what the company actually does. Copying generic templates without implementing the stated procedures creates risk during an assessment.
Step 5: Build a Remediation Plan
A gap assessment will usually identify technical, procedural and documentation improvements. Rank them by risk, dependency and deadline.
Use a Three-Tier Priority Model
- Critical: Gaps that create immediate security, contractual or assessment risk.
- Important: Items to complete during the next 30–90 days.
- Strategic: Longer-term improvements requiring budgeting, migration or process redesign.
Common Critical Gaps
- Multi-factor authentication is not required.
- Regulated information is stored in uncontrolled locations.
- Former employees retain access.
- Unsupported computers are in use.
- Administrative accounts are shared.
- Backups are not tested or protected.
- No incident response process exists.
- Required security clauses have not been reviewed.
Common Important Gaps
- Policies do not match actual procedures.
- Device inventory is incomplete.
- Permissions have not been reviewed.
- Security awareness training is inconsistent.
- Jobsite devices are not centrally managed.
- Vendor access is not documented.
- Cloud application permissions are excessive.
Common Strategic Improvements
- Moving regulated data into a dedicated environment
- Replacing legacy applications
- Segmenting networks
- Deploying centralized logging
- Improving security monitoring
- Redesigning subcontractor workflows
- Creating a formal governance program
Remediation Plan Template
| Finding | Risk | Recommended Action | Owner | Target Date |
|---|---|---|---|---|
| Multi-factor authentication missing | Critical | Require it for all in-scope accounts | IT provider | Within 30 days |
| Regulated files stored on unmanaged laptops | Critical | Move files to an approved protected environment | Operations and IT | Within 30 days |
| Device inventory incomplete | Important | Build and validate a central inventory | IT provider | Within 60 days |
| Incident response plan untested | Important | Run a tabletop exercise | Leadership and IT | Within 90 days |
| Legacy file server requires replacement | Strategic | Migrate to a compliant platform | Leadership and IT | Within 6–12 months |
Step 6: Prepare Documentation and Evidence
CMMC readiness requires evidence that security controls exist and are operating. A written policy alone may not demonstrate implementation.
Examples of Evidence
- System configuration screenshots
- Device inventory reports
- User access lists
- Multi-factor authentication reports
- Training completion records
- Incident response exercise records
- Backup restoration results
- Vulnerability scan reports
- Patch compliance reports
- Security meeting records
- Vendor agreements
- Risk assessment documents
System Security Plan
A System Security Plan describes the environment, information flows, systems, responsibilities and implementation of security controls.
It may include:
- Company and environment overview
- Network and system diagrams
- Data flow descriptions
- In-scope users and devices
- Security control implementation
- External service providers
- Known limitations
- Supporting policies and procedures
Plan of Action and Milestones
A Plan of Action and Milestones documents unresolved gaps, required actions, ownership and target completion dates.
The company should verify which gaps can be managed through a remediation plan and which must be completed before an assessment or contract deadline.
Evidence Should Be Current
Evidence should represent the current environment. Old screenshots, former employee lists and outdated diagrams may not demonstrate that controls are operating today.
CMMC Responsibilities Across the Company
Compliance should not belong only to the IT provider. Multiple departments have important responsibilities.
| Role | Typical Responsibilities |
|---|---|
| Executive leadership | Approve budget, risk decisions and accountability |
| Contracts or legal | Review clauses, flow-downs and customer obligations |
| Operations | Define project workflows and employee access |
| Human resources | Support onboarding, offboarding and training records |
| IT provider | Implement, monitor and document technical controls |
| Employees | Follow policies and report security concerns |
| Subcontractors | Meet applicable contractual and data-handling requirements |
Assign one internal leader to coordinate the program, even when an outside IT or compliance provider performs much of the technical work.
How CMMC Affects Microsoft 365
Microsoft 365 may hold email, documents, project communications and identity information. Its role in the compliance environment should be evaluated carefully.
Microsoft 365 Controls to Review
- License and cloud environment suitability
- Multi-factor authentication
- Conditional access policies
- Administrative roles
- External sharing
- Email forwarding
- Device access
- Security logging
- Retention and backup
- Third-party application access
Do Not Assume Every Microsoft 365 Configuration Is Equivalent
Different Microsoft cloud services, licensing plans and configurations may support different compliance needs. The company should confirm that its chosen environment aligns with contract and information requirements.
Limit Regulated Information to Approved Locations
Employees should know whether controlled information may be stored in:
- Exchange Online
- SharePoint
- OneDrive
- Microsoft Teams
- Local laptops
- Personal devices
- Other cloud applications
Unclear rules lead to uncontrolled copies and unnecessary scope.
How CMMC Affects Procore and Construction Applications
Construction applications may store drawings, RFIs, submittals, photos, schedules and project correspondence. The company should determine whether any of that content is regulated.
Questions to Ask About Procore or Similar Platforms
- Will regulated information be stored in the platform?
- Which employees and subcontractors will access it?
- Which security and compliance documentation does the vendor provide?
- How are permissions managed?
- How are accounts removed?
- How is information exported?
- How are audit records retained?
- Can access be limited to approved devices or users?
The software vendor, construction company and IT provider may each have different responsibilities. Those responsibilities should be documented.
Separate Regulated and Nonregulated Work When Appropriate
A contractor may decide to keep regulated government projects in a dedicated environment while using its normal platforms for commercial work.
This approach may reduce scope, but employees need clear instructions and technical restrictions to prevent files from crossing between environments.
How CMMC Affects Jobsite Technology
Jobsite laptops, tablets, networks and printers may become part of the compliance boundary when employees access regulated information from the field.
Jobsite Security Requirements to Review
- Company-owned and managed devices
- Full-device encryption
- Multi-factor authentication
- Endpoint security
- Secure wireless networks
- Separate guest access
- Remote lock and wipe capabilities
- Restricted local storage
- Lost-device reporting
- Physical protection of printed materials
Personal Devices
Allowing personal phones, tablets or computers to access regulated information may increase compliance scope and risk. A company may choose to prohibit personal device access or limit it through controlled applications and policies.
Printed Information
Compliance is not limited to electronic files. The company should determine how printed drawings, specifications and project documents are:
- Stored
- Transported
- Accessed
- Copied
- Disposed of
How CMMC Affects Subcontractors and Vendors
Prime contractors may need to flow requirements down to subcontractors that receive or handle regulated information.
Subcontractor Management Questions
- Which subcontractors receive regulated information?
- What contractual requirements apply to them?
- How is their access approved?
- Which systems do they use?
- How is access removed after the project?
- What evidence must they provide?
- Who monitors compliance?
Managed Service Provider Access
An MSP may have administrative access to devices, accounts, security tools and backups. The construction company should understand:
- Which MSP employees have access
- How privileged accounts are protected
- How support sessions are logged
- Which tools the MSP uses
- How incidents are reported
- Which contractual responsibilities the MSP accepts
911 IT offers co-managed IT services for companies that want to keep internal IT responsibilities while adding security, monitoring and compliance support.
How Long Does CMMC Preparation Take?
A construction company should generally allow 6–12 months for a structured CMMC readiness program. A smaller, well-managed environment may require less time, while a complex or poorly documented environment may require longer.
Factors That Affect the Timeline
- Current cybersecurity maturity
- Number of employees and devices
- Number of offices and jobsites
- Amount of regulated information
- Legacy systems
- Cloud platform suitability
- Quality of documentation
- Employee training needs
- Vendor and subcontractor dependencies
- Budget approval timelines
Example Preparation Timeline
| Phase | Typical Activities | Example Duration |
|---|---|---|
| Discovery | Review contracts, data and scope | 2–4 weeks |
| Gap assessment | Evaluate controls and documentation | 2–6 weeks |
| Remediation planning | Prioritize projects and approve budget | 2–4 weeks |
| Implementation | Deploy controls and improve processes | 2–8 months |
| Evidence preparation | Collect documentation and validate controls | 1–2 months |
| Final readiness review | Test the environment before assessment | 2–4 weeks |
These ranges are planning examples. Actual timelines depend on the required level, assessment path and condition of the current environment.
How Much Does CMMC Compliance Cost?
CMMC preparation costs vary based on company size, required controls, technology changes, consulting needs and assessment requirements.
Budget categories may include:
- Readiness or gap assessment
- Compliance consulting
- Microsoft licensing
- Cybersecurity tools
- Device replacement
- Network upgrades
- Cloud migration
- Policy development
- Employee training
- Evidence collection
- Third-party assessment
- Ongoing monitoring
Three Common Cost Scenarios
| Current Environment | Typical Situation | Likely Cost Impact |
|---|---|---|
| Mature and well documented | Modern devices, strong security and limited scope | Lower remediation cost |
| Partially prepared | Some controls exist, but documentation and consistency are weak | Moderate remediation cost |
| Legacy and broadly scoped | Old systems, shared accounts and uncontrolled information | Higher remediation cost |
A smaller compliance boundary can sometimes reduce cost, but it must be technically and operationally realistic. An environment that employees constantly bypass will not create reliable compliance.
Ask for a Phased Budget
A practical proposal should separate:
- Assessment costs: Discovery, gap analysis and planning.
- Remediation costs: Technology, policies, projects and training.
- Certification costs: External assessment activities when required.
- Ongoing costs: Monitoring, licensing, reporting and annual reviews.
Managed IT for a construction company with 25–50 employees may commonly range from approximately $100–$275 per user per month. Formal compliance consulting, cloud migrations, documentation and external assessments may be priced separately.
Common CMMC Mistakes Construction Companies Make
1. Waiting Until a Bid Deadline
Compliance projects may require months of technology, policy and workflow changes.
2. Assuming CMMC Applies Only to Prime Contractors
Requirements may flow down to subcontractors that receive regulated information.
3. Treating CMMC as an IT-Only Project
Contracts, operations, human resources, leadership and employees all have responsibilities.
4. Buying Tools Before Defining Scope
The company may overspend or select technology that does not fit the required environment.
5. Using Generic Policy Templates
Policies should match the company's actual systems, employees and procedures.
6. Allowing Regulated Data Everywhere
Uncontrolled copies on laptops, email, personal devices and cloud applications increase scope.
7. Ignoring Jobsite Devices
Field laptops, tablets, printers and networks may be part of the compliance boundary.
8. Forgetting Subcontractor Access
Subcontractors may create contractual and technical compliance obligations.
9. Failing to Collect Evidence
A company may operate a control without retaining enough evidence to demonstrate it.
10. Treating Certification as the Finish Line
Compliance requires ongoing monitoring, training, access reviews and documentation updates.
CMMC Readiness Checklist for Construction Companies
Contracts and Scope
- Cybersecurity clauses have been reviewed.
- Required CMMC obligations are documented.
- Federal information types have been identified.
- Data flows are mapped.
- In-scope users, systems and vendors are defined.
Identity and Access
- Every user has an individual account.
- Multi-factor authentication is enabled.
- Administrator access is restricted.
- Former employee access is removed promptly.
- User permissions are reviewed regularly.
Devices and Networks
- All in-scope devices are inventoried.
- Devices are encrypted.
- Endpoint security is active.
- Security updates are managed.
- Office and jobsite networks are secured.
Data Protection
- Regulated information is stored only in approved systems.
- External sharing is controlled.
- Backups are protected and tested.
- Personal device use is restricted or managed.
- Printed information has handling procedures.
Policies and Evidence
- Security policies reflect actual practices.
- Employee training is documented.
- Incident response procedures are tested.
- Risk assessments are current.
- Evidence is organized and maintained.
A 90-Day CMMC Readiness Plan
Days 1–30: Determine Requirements and Scope
- Review contracts and flow-down clauses.
- Identify regulated information.
- Map information flows.
- List users, devices and applications.
- Select the initial scoping approach.
Days 31–60: Complete the Gap Assessment
- Review identity and access controls.
- Inspect device and network security.
- Review Microsoft 365 and cloud services.
- Evaluate policies and employee procedures.
- Identify missing documentation and evidence.
Days 61–90: Begin Critical Remediation
- Enable multi-factor authentication.
- Remove former employee accounts.
- Secure regulated data locations.
- Encrypt and manage in-scope devices.
- Create a prioritized remediation roadmap.
After the first 90 days, continue with longer-term projects, documentation, testing and assessment preparation.
Questions to Ask a CMMC Consultant or IT Provider
- How many CMMC readiness projects have you supported?
- Do you understand construction project workflows?
- Will you review our contracts and data flows?
- Can you help us define a smaller, practical scope?
- Which Microsoft 365 environments do you support?
- How will Procore, Bluebeam and other applications be evaluated?
- Can you secure office and jobsite devices?
- Will you help write and implement policies?
- Can you build our System Security Plan?
- How will evidence be collected and organized?
- Can you help remediate technical gaps?
- Do you provide ongoing monitoring after readiness?
- Which services are included in the quoted fee?
- Which assessment or certification costs are separate?
- How will you protect our sensitive compliance documentation?
Frequently Asked Questions
Does every construction company need CMMC?
No. CMMC generally becomes relevant when a company pursues or performs work involving Department of Defense contracts or receives applicable requirements through a prime contractor or subcontract.
Can CMMC requirements flow down to subcontractors?
Yes. Prime contractors may be required to flow cybersecurity obligations to subcontractors that receive or handle regulated information.
How do I know which CMMC level applies?
Review the solicitation, contract clauses, information type and customer requirements. Legal, contracts and compliance professionals should help confirm the applicable obligation.
How long does CMMC preparation take?
Many companies should plan for approximately 6–12 months. The actual timeline depends on scope, existing security, documentation and required technology changes.
Can we limit CMMC to a small group of employees?
Possibly. A dedicated environment or enclave may reduce scope when regulated information can be separated effectively from normal business systems.
Does Microsoft 365 support CMMC compliance?
Microsoft services can support many security and compliance requirements, but the correct cloud environment, licensing and configuration depend on the contract and information handled.
Can regulated information be stored in Procore?
The company should evaluate the information type, contract requirements, vendor capabilities, access controls and documentation before using any construction platform for regulated information.
Do personal phones and tablets affect CMMC scope?
They may. Personal devices that access, store or transmit regulated information can create additional scope and risk. Many companies restrict that access.
Is a cybersecurity assessment the same as a CMMC assessment?
No. A general cybersecurity assessment identifies broad risks. A CMMC assessment evaluates compliance with specific requirements and evidence expectations.
What happens after certification or assessment?
The company must continue operating security controls, maintaining evidence, training employees, reviewing access and updating documentation as systems and contracts change.
Why Construction Companies Work With 911 IT
911 IT helps construction companies evaluate federal cybersecurity requirements, define practical compliance boundaries and implement the technical controls needed to protect regulated information.
Construction clients receive access to:
- CMMC readiness assessments
- Scope and data-flow analysis
- Microsoft 365 security planning
- Endpoint and mobile device management
- Office and jobsite network security
- Policy and documentation support
- Backup and recovery planning
- Employee security training
- Ongoing monitoring and reporting
- 24/7 IT support
Companies that need broader technology management can also review 911 IT's managed IT services and cybersecurity services.
“They are experienced and they take time to know our setup. This allows them to resolve our issues fast.”
Clay, Owner, Construction
To review contract requirements, identify regulated information and build a practical CMMC roadmap, schedule a discovery call. You can also contact 911 IT for additional information.
