A Practical CMMC Guide for Engineering Firms
An engineering firm may need CMMC compliance when it performs work for the U.S. Department of Defense, supports a prime contractor, participates in the defense supply chain, or stores, processes, or transmits Federal Contract Information or Controlled Unclassified Information.
For a firm with 25 to 50 employees, preparing for CMMC can take approximately 6 to 18 months and may require an initial investment ranging from $25,000 to more than $150,000. The actual cost depends on the required CMMC level, number of users and devices, current cybersecurity maturity, documentation quality, Microsoft licensing, enclave design, remediation needs, and whether an independent assessment is required.
CMMC should not be treated as a paperwork exercise. Engineering firms must implement security controls, document how those controls operate, retain evidence, train employees, monitor the environment, and correct deficiencies before an assessment or contract deadline.
This guide presents a seven-step framework for determining whether CMMC applies, identifying the required level, estimating costs, and building a realistic compliance roadmap.
The Seven-Step CMMC Readiness Framework
- Determine whether regulated government information enters the firm.
- Identify the contracts and clauses that create obligations.
- Confirm the required CMMC level.
- Define the systems, users, and locations inside the assessment scope.
- Compare the current environment with the required controls.
- Remediate technical, administrative, and documentation gaps.
- Collect evidence and prepare for assessment or affirmation.
Completing these steps in order helps prevent two costly mistakes: building controls that are not required and underestimating obligations that already apply.
1. Does CMMC Apply to Your Engineering Firm?
CMMC may apply when an engineering firm works directly for the Department of Defense or serves as a subcontractor, consultant, designer, manufacturer, or service provider within the defense industrial base.
Potential indicators include:
- A contract or subcontract contains DFARS cybersecurity clauses.
- The firm receives drawings, specifications, technical data, or project information marked as controlled.
- A prime contractor sends cybersecurity questionnaires or flow-down requirements.
- The firm must submit or maintain a cybersecurity assessment score.
- Employees access a government or prime-contractor system containing regulated information.
- The firm supports military facilities, weapons systems, aerospace projects, defense manufacturing, or related infrastructure.
- A request for proposal identifies a future CMMC requirement.
The presence of government work alone does not automatically establish the required level. The firm must determine what information it receives, where that information is stored, who can access it, and which contractual clauses apply.
Federal Contract Information
Federal Contract Information, commonly abbreviated as FCI, is information provided by or generated for the government under a contract that is not intended for public release. It generally requires basic safeguarding.
Controlled Unclassified Information
Controlled Unclassified Information, commonly abbreviated as CUI, is sensitive government information that requires protection even though it is not classified.
Engineering examples may include:
- Technical drawings
- Design specifications
- Facility information
- Research and engineering data
- Manufacturing details
- Testing information
- Controlled technical information
- Project correspondence containing regulated details
The contract owner, legal counsel, contracting officer, or prime contractor should help confirm whether information is FCI or CUI. The IT provider should then help determine where that information moves through the technical environment.
2. Which Contract Requirements Should Be Reviewed?
Before purchasing security tools, collect the firm's contracts, subcontracts, requests for proposal, supplier requirements, and cybersecurity questionnaires.
Review for references to:
- CMMC
- DFARS
- NIST SP 800-171
- Controlled Unclassified Information
- Federal Contract Information
- Cyber incident reporting
- System security plans
- Supplier-performance risk systems
- Flow-down requirements
- Data-location or citizenship restrictions
Contractual obligations may flow from a prime contractor to an engineering subcontractor. A firm should not assume that requirements apply only when it contracts directly with the federal government.
Create a Contract Requirements Register
A simple register can include:
| Field | Information to Record |
|---|---|
| Contract or Project | Name, number, client, and prime contractor |
| Information Type | FCI, CUI, public, proprietary, or undetermined |
| Required Standard | CMMC level, NIST controls, DFARS clause, or client requirement |
| Systems Used | Email, file storage, CAD platform, cloud service, workstation, or portal |
| Responsible Owner | Executive, project manager, compliance lead, or contract owner |
| Deadline | Proposal, award, renewal, assessment, or remediation date |
This register gives leadership a single location for understanding which projects create security obligations.
3. Which CMMC Level Does an Engineering Firm Need?
The required CMMC level depends primarily on the information handled and the contract requirement.
CMMC Level 1
Level 1 focuses on basic safeguarding of Federal Contract Information. It is intended for organizations that handle FCI but not CUI.
Typical areas include:
- Limiting system access to authorized users
- Controlling physical access
- Protecting communications
- Identifying and correcting system flaws
- Using appropriate malware protection
- Managing media and information disposal
CMMC Level 2
Level 2 applies to organizations that handle Controlled Unclassified Information. It is aligned with the security requirements of NIST SP 800-171 and is substantially more demanding than Level 1.
Level 2 includes requirements involving:
- Access control
- Awareness and training
- Audit and accountability
- Configuration management
- Identification and authentication
- Incident response
- Maintenance
- Media protection
- Personnel security
- Physical protection
- Risk assessment
- Security assessment
- System and communications protection
- System and information integrity
Depending on the contract and type of information, a Level 2 organization may need either a self-assessment or an assessment by an authorized third-party organization.
CMMC Level 3
Level 3 is intended for organizations supporting the most sensitive programs and facing advanced persistent threats. Most small and midsize engineering firms will not require Level 3 unless the contract specifically identifies it.
Do Not Choose the Level Independently
The required level should be confirmed through contractual language and qualified legal or compliance guidance. An IT provider can evaluate technical readiness but should not unilaterally determine the firm's legal obligations.
911 IT provides CMMC compliance services to help organizations identify technical gaps, implement security controls, document systems, and prepare for required assessments.
4. What Systems Are Included in CMMC Scope?
Scope is one of the most important cost and complexity factors. A firm that allows CUI to move through every email account, workstation, server, mobile device, cloud platform, and office may create a much larger assessment boundary than necessary.
Systems Commonly Included in Scope
- Workstations used to access CUI
- File servers or cloud storage containing CUI
- Email accounts that send or receive CUI
- Identity and authentication systems
- Firewalls, switches, and remote-access systems
- Security monitoring and logging platforms
- Backup and recovery systems
- CAD, BIM, document-management, or collaboration platforms
- Administrative systems used to manage in-scope devices
- Facilities where regulated information is accessed
Specialized Assets and Supporting Systems
Some systems may not directly store CUI but still protect or manage the regulated environment. Examples include:
- Endpoint management platforms
- Security-information and event-management tools
- Password managers
- Remote monitoring systems
- Backup-management portals
- Ticketing systems containing technical details
- Administrative workstations
Using a CUI Enclave
A CUI enclave is a deliberately limited environment used to process, store, and transmit regulated information. Instead of bringing every employee and system into scope, the firm may restrict CUI to a smaller group of approved users, devices, applications, and storage locations.
An enclave may reduce assessment scope, but it also requires clear boundaries and disciplined workflows.
A practical enclave may include:
- Dedicated user accounts
- Approved managed workstations
- Restricted cloud storage
- Controlled email or secure file transfer
- Multi-factor authentication
- Centralized logging
- Restricted printing and removable media
- Documented data-entry and data-exit procedures
An enclave fails when employees routinely copy regulated information into normal email, personal storage, unauthorized CAD platforms, or general company file shares.
5. What Does a CMMC Gap Assessment Review?
A gap assessment compares the firm's current policies, technical controls, practices, and evidence with the applicable requirements.
A complete review should cover five categories.
People
- Who has access to FCI or CUI?
- Are roles and responsibilities documented?
- Do employees receive security and CUI-handling training?
- Are background-screening or personnel-security procedures required?
- Are onboarding, role changes, and offboarding documented?
Processes
- How is access requested, approved, reviewed, and removed?
- How are incidents reported and investigated?
- How are changes approved and documented?
- How are backups tested?
- How are vulnerabilities identified and remediated?
- How is regulated information marked, shared, retained, and destroyed?
Technology
- Multi-factor authentication
- Endpoint detection and response
- Disk and communication encryption
- Secure configuration
- Patch management
- Centralized logging
- Access restrictions
- Network segmentation
- Backup protection
- Mobile-device controls
Documentation
- System Security Plan
- Policies and procedures
- Network and data-flow diagrams
- Asset inventory
- User and role lists
- Risk assessments
- Incident-response plan
- Configuration standards
- Training records
- Plans of Action and Milestones
Evidence
- Configuration screenshots
- System reports
- Tickets and approval records
- Logs
- Training completion records
- Meeting notes
- Restore-test results
- Access reviews
- Incident exercises
- Policy acknowledgments
A control should not be marked complete simply because a policy says it exists. The firm must be able to show that the practice is implemented and operating consistently.
6. How Much Does CMMC Compliance Cost?
CMMC costs vary widely. A 25–50 employee engineering firm may spend between $25,000 and $150,000 or more on initial readiness, remediation, documentation, licensing, and assessment preparation.
A firm with strong existing security, a small enclave, current documentation, and limited remediation may fall near the lower end. A firm that allows CUI across the entire company, uses outdated systems, lacks centralized management, or requires major cloud and network changes may spend substantially more.
Common Initial Cost Categories
| Category | Illustrative Planning Range |
|---|---|
| Readiness or Gap Assessment | $5,000–$25,000 |
| Policies, SSP, and Documentation | $7,500–$35,000 |
| Security Remediation | $10,000–$75,000+ |
| Cloud or Enclave Implementation | $10,000–$100,000+ |
| Training and Exercises | $1,000–$10,000 |
| Assessment Preparation | $5,000–$25,000 |
| Independent Assessment | Varies by scope and assessor |
These ranges are directional and should not be treated as a quote. Costs depend on scope, contract requirements, number of locations, technology, documentation quality, assessment type, and remediation complexity.
Common Recurring Costs
- Managed cybersecurity services
- Microsoft or other cloud licensing
- Endpoint detection and response
- Security monitoring and log retention
- Backup and disaster recovery
- Vulnerability scanning
- Security awareness training
- Policy reviews and risk assessments
- Incident-response exercises
- Ongoing evidence collection
- Annual affirmations or periodic assessments
Why Scope Has Such a Large Effect on Cost
Assume a 40-person engineering firm has only eight employees who need CUI access. Placing all 40 employees, every workstation, every cloud application, and the entire office network inside the controlled environment may create unnecessary licensing, documentation, monitoring, and assessment work.
A well-designed enclave might limit the controlled environment to:
- Eight named users
- Eight managed workstations
- A restricted storage platform
- A limited group of administrative systems
- Defined network and security services
The enclave still requires careful implementation, but reducing the number of in-scope assets can make compliance more manageable.
7. What Documentation Is Required?
Documentation demonstrates that the firm understands its environment and has repeatable security practices.
System Security Plan
The System Security Plan, often called the SSP, explains:
- The systems included in scope
- Where regulated information is stored and transmitted
- How each security requirement is implemented
- Which technologies and service providers are involved
- Who is responsible for each control
- Which controls are shared or inherited
- Which deficiencies remain
The SSP should describe the actual environment. Generic language copied from a template can create contradictions during an assessment.
Plans of Action and Milestones
A Plan of Action and Milestones, commonly called a POA&M, records deficiencies, corrective actions, responsible owners, deadlines, and completion status.
A useful entry includes:
- The affected requirement
- Description of the deficiency
- Business and security risk
- Required remediation
- Responsible owner
- Budget
- Target completion date
- Evidence required to close the item
Not every deficiency can remain open during an assessment. The firm should understand which requirements must be fully satisfied and which limited exceptions may be permitted.
Policies and Procedures
Common documents include:
- Access-control policy
- Acceptable-use policy
- Incident-response plan
- Configuration-management policy
- Media-protection policy
- Personnel-security procedures
- Physical-security procedures
- Risk-management policy
- Backup and recovery procedures
- Change-management procedures
- CUI-handling procedures
- Vendor and service-provider management
Policies define expectations. Procedures explain how employees and administrators perform the required activity.
Technical Controls Engineering Firms Commonly Need
Multi-Factor Authentication
Multi-factor authentication should protect remote access, cloud systems, administrative functions, and in-scope accounts where required.
The firm should document:
- Which accounts require multi-factor authentication
- Which authentication methods are approved
- How enrollment is verified
- How lost or replaced devices are handled
- How service and emergency accounts are controlled
Managed Endpoints
In-scope workstations should be centrally managed and configured. Typical controls include:
- Approved operating-system versions
- Endpoint detection and response
- Disk encryption
- Patch management
- Restricted administrative privileges
- Automatic screen locking
- Logging
- Secure configuration standards
- USB and removable-media controls
Centralized Logging
The firm may need to collect and review activity from:
- Identity systems
- Workstations
- Servers
- Firewalls
- Cloud platforms
- Remote-access systems
- Security tools
- File-storage systems
Logs must be retained, protected, and reviewed according to documented procedures. Collecting logs without monitoring or response does not satisfy the operational purpose.
Encryption
Encryption may be required for regulated information at rest and in transit.
Review:
- Workstation disk encryption
- Server and cloud-storage encryption
- Email and file-transfer methods
- Remote-access encryption
- Backup encryption
- Portable media
- Encryption-key management
Backup and Recovery
Backup systems should protect regulated data while preventing unauthorized access.
The program should define:
- Which systems are backed up
- Backup frequency
- Retention
- Encryption
- Administrative access
- Isolation or immutability
- Restore testing
- Incident recovery priorities
911 IT's business continuity services help organizations design protected backups, recovery procedures, and testing programs for critical systems and regulated information.
How CMMC Affects AutoCAD, Revit, and Engineering Workflows
CMMC requirements can affect how engineers receive, store, modify, print, share, and archive technical files.
CAD and BIM Storage
Regulated project files should remain in approved storage with controlled access, encryption, logging, backup, and documented retention.
Employees should not place CUI in:
- Personal cloud-storage accounts
- Unapproved file-sharing platforms
- Unmanaged home computers
- Personal email
- Unencrypted removable drives
- Unapproved project-management applications
External References and Linked Models
A project may include external references, linked Revit models, point clouds, templates, images, reports, and specifications. The entire project workflow should be evaluated rather than only the primary drawing or model.
Printing and Plotting
Printed regulated information may require:
- Controlled printers and plotters
- Restricted output locations
- Prompt collection
- Secure storage
- Approved destruction
- Physical-access controls
Remote Engineering Work
Remote access should use approved devices, secure authentication, encrypted connections, managed storage, and documented procedures.
Employees should understand whether they may:
- Download files locally
- Print at home
- Use personal monitors or peripherals
- Access files from mobile devices
- Work from public locations
- Transfer information to project partners
A 12-Month CMMC Implementation Roadmap
| Timeframe | Primary Actions |
|---|---|
| Months 1–2 | Review contracts, identify FCI and CUI, appoint an executive owner, and begin an asset and data-flow inventory |
| Months 3–4 | Confirm required level, define scope, perform a gap assessment, and create the remediation budget |
| Months 5–7 | Implement identity, endpoint, network, logging, encryption, backup, and access-control improvements |
| Months 8–9 | Complete policies, procedures, diagrams, the SSP, and required training |
| Months 10–11 | Collect evidence, conduct access reviews, test incident response and recovery, and close high-priority POA&M items |
| Month 12 | Perform a readiness review, correct remaining deficiencies, and prepare for assessment or affirmation |
Some firms can move faster. Others may need 18 months or longer when major infrastructure changes, contract uncertainty, cloud migration, or extensive documentation work is required.
Who Should Be Involved in the CMMC Project?
CMMC is not solely an IT responsibility. A successful project usually includes:
- Executive sponsor: Provides authority, budget, and accountability.
- Contract owner: Interprets project and customer requirements.
- Compliance lead: Coordinates documentation, evidence, and remediation.
- IT or managed service provider: Implements and operates technical controls.
- Human resources: Supports personnel security, training, and offboarding.
- Facilities representative: Addresses physical access and protected work areas.
- Legal counsel: Advises on contracts, reporting, and legal obligations.
- Department leaders: Confirm that security procedures work within engineering operations.
Assign an owner to every control and remediation item. Tasks without a named owner and deadline tend to remain incomplete.
Common CMMC Mistakes Engineering Firms Make
Waiting for a Contract Deadline
Building a compliant environment can take months. Waiting until a proposal or renewal deadline may force rushed decisions, increase costs, and put eligibility at risk.
Assuming the IT Provider Handles Everything
The IT provider can implement and manage technical controls, but leadership remains responsible for contracts, policies, employee behavior, physical security, risk acceptance, and organizational affirmations.
Buying Tools Before Defining Scope
Purchasing security products without understanding the required level and assessment boundary can create unnecessary cost or leave critical gaps.
Copying a Generic System Security Plan
An SSP must match the actual environment. Assessors may compare written statements with configurations, interviews, tickets, and evidence.
Allowing CUI Everywhere
Uncontrolled movement of regulated information can bring more users, devices, cloud services, and office systems into scope.
Ignoring Service Providers
Managed IT companies, cloud platforms, backup providers, security vendors, and other external services may affect compliance. Responsibilities should be documented and contracts reviewed.
Marking Controls Complete Without Evidence
A configuration screenshot from one day may not prove that a process operates consistently. Evidence should demonstrate implementation over time.
Treating Compliance as a One-Time Project
Systems, employees, applications, contracts, and threats change. Compliance requires ongoing monitoring, training, documentation updates, access reviews, testing, and improvement.
CMMC Readiness Checklist for Engineering Firms
- Contracts and subcontracts have been reviewed for cybersecurity clauses.
- The firm knows whether it receives FCI, CUI, or both.
- The required CMMC level has been confirmed.
- An executive sponsor and compliance owner are assigned.
- In-scope users, devices, systems, applications, and facilities are documented.
- Data-flow diagrams show how regulated information enters, moves through, and leaves the firm.
- A formal gap assessment has been completed.
- Multi-factor authentication protects required systems and accounts.
- In-scope endpoints are centrally managed, encrypted, patched, and monitored.
- Administrative privileges are restricted and reviewed.
- Logs are collected, retained, reviewed, and protected.
- Backups are encrypted, isolated, monitored, and tested.
- External sharing and file-transfer methods are controlled.
- Employees receive role-appropriate security and CUI training.
- An incident-response plan has been tested.
- The SSP accurately reflects the current environment.
- POA&M items have owners, budgets, and completion dates.
- Evidence is collected continuously rather than immediately before an assessment.
- Cloud and managed service providers have been reviewed.
- The firm has completed an independent readiness review.
Every “no” or “not sure” response identifies a potential compliance or contract risk.
How to Reduce CMMC Cost Without Weakening Security
Cost reduction should focus on controlling scope, standardizing systems, and avoiding duplicate tools rather than removing required protections.
Practical strategies include:
- Limit CUI access to employees who genuinely need it.
- Use a clearly defined enclave when appropriate.
- Standardize approved workstations and configurations.
- Consolidate overlapping cybersecurity products.
- Use cloud platforms that support required security capabilities.
- Maintain one accurate asset inventory.
- Automate evidence collection where practical.
- Integrate CMMC tasks into normal IT operations.
- Address high-impact scope decisions before purchasing licenses.
- Build documentation from actual procedures rather than generic templates.
A lower-cost solution that does not satisfy the required controls, protect engineering data, or produce assessment evidence is not a savings.
What Engineering Clients Say About 911 IT
“911 IT's services allow us to focus on our core business by effectively and safely managing security for our cloud-based services, such as Microsoft Office 365, Atlassian, GitLab, NextCloud, and more. They thoroughly research options before responding and work with us to implement the right solutions.”
— Scott, Engineering
“911 IT was professional, responsive, and easy to work with from start to finish. I'd highly recommend them to anyone looking for reliable and knowledgeable IT support.”
— Jorge, Engineering
Engineering compliance projects require both responsive technical support and careful research. More customer experiences are available on the 911 IT client testimonials page.
Frequently Asked Questions
Does every engineering firm need CMMC compliance?
No. CMMC generally applies when contract requirements involve Federal Contract Information, Controlled Unclassified Information, or participation in the Department of Defense supply chain. Review the firm's contracts and data before determining applicability.
Does CMMC apply to subcontractors?
It can. Cybersecurity requirements may flow from a prime contractor to subcontractors and suppliers. Review the subcontract and any referenced clauses or security requirements.
How long does CMMC compliance take?
A 25–50 employee engineering firm may need 6 to 18 months. Firms with current security controls, limited scope, and strong documentation may move faster. Major infrastructure, cloud, policy, or remediation projects can extend the timeline.
How much does CMMC Level 2 cost?
Initial readiness and remediation for a small or midsize engineering firm may range from approximately $25,000 to more than $150,000. Assessment fees, recurring licensing, managed security, cloud services, and ongoing compliance work may be additional.
Can Microsoft 365 support CMMC compliance?
Microsoft cloud services can support many security requirements when the correct environment, licensing, configuration, monitoring, and procedures are used. A standard Microsoft 365 subscription is not automatically a compliant solution.
Can CUI be sent by email?
Only through an approved email or secure-transfer method that satisfies applicable security and contractual requirements. The firm should document the approved process and train employees not to use personal or unauthorized accounts.
Can employees work with CUI from home?
Remote work may be permitted when approved devices, secure authentication, controlled storage, physical safeguards, and documented procedures are in place. The firm's contract and policies should define the allowed workflow.
Does an engineering firm need a CUI enclave?
Not always. An enclave can reduce scope when only a subset of employees and systems require access. The design must prevent regulated information from spreading into uncontrolled systems.
What is an SSP?
A System Security Plan describes the regulated environment, system boundaries, responsibilities, and how applicable security requirements are implemented.
What is a POA&M?
A Plan of Action and Milestones documents a security deficiency, the required corrective action, responsible owner, completion date, and evidence needed for closure.
Can an MSP make a company CMMC compliant?
An MSP can implement, monitor, document, and support many technical controls. The engineering firm remains responsible for contracts, governance, employee practices, physical safeguards, organizational procedures, and compliance representations.
What happens after the firm passes an assessment?
The firm must continue operating its controls, collecting evidence, monitoring security, updating documentation, training employees, reviewing access, and correcting new deficiencies. Compliance must be maintained as systems and contracts change.
Build a CMMC Roadmap for Your Engineering Firm
CMMC readiness begins with understanding the contract and controlling where regulated information enters the business. The strongest approach combines a carefully defined scope, documented procedures, implemented cybersecurity controls, employee training, continuous evidence, and executive accountability.
911 IT has served businesses in the Salt Lake City area since 2004 and helps engineering firms implement cybersecurity, Microsoft cloud services, managed IT support, backup and recovery, documentation, and CMMC readiness programs.
To identify your likely CMMC scope, evaluate current security gaps, and create a phased compliance budget, review 911 IT's CMMC compliance services or schedule a discovery call with 911 IT.
