What is CMMC and who needs to comply?
CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense's framework for verifying that contractors protect Federal Contract Information and Controlled Unclassified Information. If your company holds or pursues DoD contracts that involve FCI or CUI, CMMC requirements apply to you — including small subcontractors in the Defense Industrial Base.
What is the difference between CMMC Level 1 and Level 2?
Level 1 covers 17 basic safeguarding practices for Federal Contract Information and allows annual self-assessment. Level 2 aligns with the 110 controls of NIST SP 800-171 for protecting Controlled Unclassified Information and, for most contracts, requires a third-party (C3PAO) assessment.
What does a vCISO actually do?
A virtual CISO gives you executive-level security leadership without a full-time hire: risk assessments, security roadmaps, policy development, NIST 800-171 alignment, SSP and POA&M ownership, vendor review, and audit preparation — scaled to a fraction of the cost of a salaried CISO.
What is an SSP and a POA&M?
The System Security Plan (SSP) documents how your environment implements each NIST 800-171 control. The Plan of Action & Milestones (POA&M) tracks the controls you haven't fully met and how you'll close them. Both are foundational evidence for CMMC assessment and SPRS scoring.
Where does O Williams Consulting work with clients?
We serve Maryland, Washington DC, and Virginia in person — including residential technology services for DMV homeowners — and work with defense contractors and growing businesses remotely nationwide.