CMMC compliance and readiness advisory.

Lightbridge Cloud is an independent CMMC compliance readiness advisor for defense contractors preparing for the Cybersecurity Maturity Model Certification. We guide CMMC 2.0 scoping, NIST 800-171 gap assessment, and C3PAO assessment preparation across Levels 1, 2, and 3, without acting as a certifying body or a vendor reseller.

Lightbridge Cloud explains the three CMMC 2.0 levels.

CMMC 2.0 organizes requirements into three levels, each tied to the sensitivity of the information a contract involves. Lightbridge Cloud helps defense contractors determine which level applies to a given contract and what evidence each one demands.

Level 1: Foundational

Applies to contractors handling Federal Contract Information (FCI). Built on a set of basic safeguarding practices aligned with FAR 52.204-21. Verified through annual self-assessment and affirmation under the current CMMC 2.0 model.

Level 2: Advanced

Applies to contractors handling Controlled Unclassified Information (CUI). Maps to the 110 security requirements of NIST SP 800-171. Many Level 2 contracts require a third-party assessment by an authorized C3PAO, while some are permitted self-assessment depending on the contract.

Level 3: Expert

Applies to the highest-priority programs and the most sensitive CUI. Adds requirements drawn from NIST SP 800-172 on top of the Level 2 baseline. Assessed by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), per the published model.

Lightbridge Cloud aligns CMMC Level 2 to NIST 800-171.

CMMC Level 2 is built directly on the 110 security requirements of NIST SP 800-171, the standard for protecting Controlled Unclassified Information in nonfederal systems. Lightbridge Cloud assesses your environment against each requirement and its assessment objectives, then translates the gaps into a remediation plan that an authorized C3PAO can verify.

This work connects to the broader regulatory picture. For the contractual safeguarding and incident-reporting obligations, see our guide to DFARS and NIST 800-171. To understand what counts as protected data in the first place, see our explainer on Controlled Unclassified Information. Clause specifics evolve, so confirm them against acquisition.gov and the NIST publication itself.

The Lightbridge Cloud CMMC readiness path.

Lightbridge Cloud runs CMMC readiness as a structured program, from scoping through the maintenance cadence that keeps a posture defensible between assessment cycles. We prepare contractors for assessment; we do not perform the certifying assessment.

Scoping and CUI Identification

Lightbridge Cloud maps your information flows to determine where FCI and CUI live, who touches them, and which systems fall inside the assessment boundary. Accurate scoping reduces the control footprint before any remediation begins.

Gap Assessment Against NIST 800-171

We assess your environment against the 110 NIST SP 800-171 requirements that underpin CMMC Level 2, documenting each as met, partially met, or not met, with evidence references aligned to assessment objectives.

System Security Plan and POA&M

Lightbridge Cloud helps you author a System Security Plan (SSP) and a Plan of Action and Milestones (POA&M) that withstand external scrutiny. These artifacts are the backbone of any defensible CMMC posture.

Remediation and Architecture

We design the enclave, identity, logging, and encryption architecture that closes gaps, including FIPS-validated cryptography and access controls. Vendor selection stays vendor-neutral and fit-driven.

Assessment Readiness

Lightbridge Cloud runs a mock assessment against the published assessment objectives so you enter a C3PAO engagement with evidence organized and findings already closed. We are an independent readiness advisor, not the certifying body.

Continuous Compliance

CMMC posture decays without maintenance. We establish the monitoring, evidence collection, and annual affirmation cadence that keeps your environment ready between assessment cycles.

Lightbridge Cloud delivers independent, vendor-neutral CMMC advisory.

Lightbridge Cloud accepts no vendor kickbacks and carries no reseller quotas. CMMC tooling, enclave platform, and security-stack recommendations are driven by control coverage and fit, not by commission. Where a defense contractor relies on a managed cloud platform such as AWS GovCloud or Microsoft Azure Government, we advise on configuration and control mapping without an obligation to favor any single offering.

CMMC scope often reaches finance, project, and ERP systems where Controlled Unclassified Information flows, and defense contractors face separate accounting-system expectations under DCAA oversight. For that accounting-system angle, Lightbridge ERP maintains a guide to DCAA-compliant accounting.

Lightbridge Cloud separates CMMC from FedRAMP.

CMMC governs how defense contractors protect federal information on their own systems. FedRAMP authorizes cloud service offerings sold to United States federal agencies. The two programs are frequently confused because both draw on NIST control families, but they have different authorities, scopes, and assessment paths. If your organization sells a cloud service to agencies rather than performing on defense contracts, see our FedRAMP readiness advisory.

Certifications and compliance.

ISO 27001 Certification in progress
SOC 2 Type II Certification in progress
ISO 42001 Certification in progress

Frequently asked questions.

What is CMMC and who needs it?

CMMC, the Cybersecurity Maturity Model Certification, is the United States Department of Defense framework for verifying that defense contractors and subcontractors protect sensitive federal information. Organizations in the Defense Industrial Base that handle Federal Contract Information or Controlled Unclassified Information generally fall in scope. Specific applicability flows from your contract clauses, so confirm requirements against the official DoD CIO and acquisition.gov sources.

How many levels does CMMC 2.0 have?

CMMC 2.0 defines three levels. Level 1 (Foundational) covers basic safeguarding of Federal Contract Information. Level 2 (Advanced) aligns to the 110 security requirements of NIST SP 800-171 and protects Controlled Unclassified Information. Level 3 (Expert) adds requirements drawn from NIST SP 800-172 for the most sensitive programs. The applicable level is set by the contract.

What is a C3PAO and does Lightbridge Cloud certify CMMC?

A C3PAO is a CMMC Third-Party Assessment Organization authorized to conduct CMMC Level 2 certification assessments. Lightbridge Cloud is an independent readiness advisor and does not issue CMMC certifications. Only an authorized C3PAO, or DIBCAC for Level 3, performs the certifying assessment. We prepare your organization so that assessment goes smoothly, and we stay vendor-neutral throughout.

How does CMMC relate to NIST 800-171 and DFARS?

CMMC Level 2 is built on the 110 security requirements in NIST SP 800-171. DFARS clause 252.204-7012 has long required contractors handling Controlled Unclassified Information to implement those safeguards and report incidents, and related DFARS clauses govern assessment scoring and CMMC. See our DFARS and NIST 800-171 guide at /guides/dfars-nist-800-171, and verify clause specifics against acquisition.gov.

How long does CMMC Level 2 readiness take?

Timelines vary with the size of your environment, the maturity of existing controls, and the scope of Controlled Unclassified Information you handle. Many organizations spend several months on scoping, remediation, and documentation before they are ready for a C3PAO assessment. Lightbridge Cloud begins with a gap assessment so the effort is sized to evidence, not guesswork.

What is the difference between CMMC readiness and FedRAMP?

CMMC governs how defense contractors protect federal information on their own systems. FedRAMP authorizes cloud service offerings sold to United States federal agencies. They are distinct programs with different scopes and authorities, though both draw on NIST control families. If you sell a cloud service to agencies, see our FedRAMP readiness page at /services/fedramp-readiness.

Does CMMC affect my accounting and ERP systems?

It can. If Controlled Unclassified Information flows through finance, project, or ERP systems, those systems may fall inside your assessment boundary. Defense contractors also face separate accounting-system expectations under DCAA oversight. For the accounting-system angle, Lightbridge ERP maintains a DCAA-compliant accounting guide at https://lightbridgeerp.com/guides/dcaa-compliant-accounting.

How does Lightbridge Cloud stay vendor-neutral on CMMC?

Lightbridge Cloud accepts no vendor kickbacks and carries no reseller quotas, so tooling and platform recommendations are driven by fit and control coverage, not commission. We advise on readiness across cloud platforms and security tools without an obligation to steer you toward any single vendor.

This page is general guidance, not legal, audit, or accounting advice. CMMC, DFARS, NIST, and related requirements change. Verify specifics against the official sources, including acquisition.gov, the DoD CIO and OUSD(A&S), NIST, the NARA CUI Registry, DCSA, and, for export controls such as ITAR and EAR, DDTC and BIS.

AWS, GovCloud, Microsoft, Azure, Deltek, Costpoint, and Unanet are trademarks of their respective owners. Lightbridge Cloud is independent and is not affiliated with, endorsed by, or a partner-tier reseller of these vendors.

Start your CMMC readiness assessment.

We scope your environment, assess it against NIST 800-171, and deliver a remediation roadmap that prepares you for a C3PAO assessment.