CMMC Compliance & NIST 800-171 for Defense Contractors

If your business holds DoD contracts (or wants to), CMMC is no longer optional, and your competitors are getting ready. Ghosxt prepares small defense contractors and subcontractors on the Central Coast for CMMC and NIST SP 800-171, led by an engineer with DoD infrastructure experience who has lived inside these exact controls. Not a generic checklist from a vendor who has never handled CUI: readiness built by someone who has.

Built by an engineer with DoD infrastructure experience: not a checklist from someone who has never touched CUI.

Microsoft 365 GCC High for small defense contractors

Ghosxt is a Salinas, CA managed IT provider run by owner and sole engineer Ulises Paiz. For small defense contractors and subcontractors handling controlled unclassified information (CUI), we set up and harden Microsoft 365 GCC High: the government community cloud environment built for CUI, configured with Intune for device management, Defender for Business for threat protection, and Conditional Access for access policies. See pricing for our published rates; GCC High onboarding is scoped and quoted separately from our standard Microsoft 365 default scope.

We do not write your System Security Plan (SSP), Plan of Action and Milestones (POA&M), or other CMMC documentation, and we do not perform your official CMMC assessment. The compliance assessment itself is arranged through a third-party assessor.

What CMMC is, and who it's for

The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense's framework for verifying that contractors protect the information they are trusted with. It builds on NIST SP 800-171 and applies to the entire defense industrial base: not just the primes, but the machine shops, engineering firms, manufacturers, and service providers in their supply chains. If your contracts carry DFARS 252.204-7012, or a prime has started asking about your security posture, this affects you. The program itself is run by the DoD CIO's CMMC office.

The hard truth for small businesses is that CUI does not care how small you are. A two-person subcontractor that handles controlled drawings is in scope, and being out of compliance increasingly means losing the contract to someone who is in compliance.

Why an engineer with DoD infrastructure experience is different here

Most IT shops approaching CMMC are learning it from a binder. Ghosxt is run by a DoD-cleared engineer with prior DoD and federal contractor infrastructure experience, which is why the GCC High environment we build survives real scrutiny: the difference between a paper SSP that describes controls nobody actually configured, and a tenant that actually enforces them.

It also means realism. We design the smallest defensible scope, implement what the controls actually require, and tell you plainly what is and is not done: the same discipline expected inside a real accreditation boundary.

How we get you CMMC-ready

A scoped, practical path from wherever you are now to assessment-ready, without securing your entire company to a level only your CUI needs.

GCC High Setup & Hardening

Microsoft 365 GCC High tenant setup and hardening: Intune for device management, Defender for Business for threat protection, and Conditional Access for access policies, configured to what your contracts require.

Environment Scoping

We help you understand where CUI lives in your environment so your GCC High configuration matches your actual scope, instead of guessing.

Third-Party Assessment

Your CMMC assessment or NIST 800-171 self-assessment is arranged through a third-party assessor. We do not write your SSP or POA&M, and we do not perform or certify the assessment ourselves.

Access & Device Controls

Conditional Access policies, MFA, and Intune-managed devices configured inside your GCC High tenant, hardened by an engineer with prior DoD and federal contractor infrastructure experience.

Threat Protection

Defender for Business deployed and tuned across your GCC High tenant, so the environment your assessor reviews is actually monitored, not just configured on paper.

Ongoing Compliance

CMMC is not one-and-done. Continuous monitoring, patching, and evidence collection keep you assessment-ready year over year, folded into managed IT so it is maintained, not left to drift.

Find out exactly what CMMC will take for your business

Book a free assessment. We will help you understand which level your contracts reference, then build and harden the Microsoft 365 GCC High environment that level requires. Gaps against the full control set are assessed through the third-party assessor, and we will explain a realistic path to readiness in plain language, whether or not you hire us.

Book your free assessment

We build the environment, not the paperwork

The fastest way to fail a CMMC assessment is documentation that does not match reality: an SSP that claims controls you never implemented, or a POA&M that has not moved in a year. We do not write your SSP or POA&M. What we build is the Microsoft 365 GCC High environment, hardened with Intune, Defender for Business, and Conditional Access, that those documents are meant to describe, so when your third-party assessor asks how something works, the answer is actually deployed and true. That is also how we approach C-TPAT and every other framework: controls first, deployed and verifiable.

GCC High readiness pairs naturally with our cybersecurity and manufacturing and engineering IT work, since most defense subs on the Central Coast are exactly those kinds of shops.

CMMC & NIST 800-171 FAQs

Who actually needs CMMC?
Any business in the defense supply chain that handles federal contract information (FCI) or controlled unclassified information (CUI), whether prime contractors or, increasingly, their subcontractors. If your DoD contracts include DFARS clause 252.204-7012, CMMC is coming for you. Level 1 covers FCI; Level 2 covers CUI and maps to the 110 controls of NIST SP 800-171.
What's the difference between CMMC Level 1 and Level 2?
Level 1 is 17 basic safeguarding practices for FCI, met with an annual self-assessment. Level 2 is the full 110 controls of NIST 800-171 for CUI, and for most contracts requires a third-party (C3PAO) assessment every three years. We determine which applies to your contracts before doing anything else, so you are not over- or under-building.
We're just a subcontractor: do we still need it?
Very likely yes. Primes are required to flow CMMC requirements down to subcontractors who touch FCI or CUI. Many small subs are now being told by their prime that they need to show compliance to keep the work. Getting ahead of that is how you keep contracts instead of losing them to a compliant competitor.
Can you get us a SPRS score and write our SSP and POA&M?
No. We do not write your System Security Plan (SSP) or Plan of Action and Milestones (POA&M), and we do not calculate or submit your SPRS score. What we do is set up and harden the Microsoft 365 GCC High environment those documents describe, with Intune, Defender for Business, and Conditional Access, and arrange your compliance assessment through a third-party assessor.
Do you set up Microsoft 365 GCC High?
Yes. We set up and harden Microsoft 365 GCC High for small defense contractors and subcontractors: Intune for device management, Defender for Business for threat protection, and Conditional Access for access policies, configured to what your contracts require.
Who performs our CMMC assessment?
Not us. Ghosxt does not perform your official CMMC assessment and does not author your SSP, POA&M, or other compliance documentation. Your assessment is arranged through a third-party assessor, and we build and harden the Microsoft 365 GCC High environment that assessment evaluates.
Do you perform the official CMMC assessment?
No. The formal Level 2 certification is performed by an accredited C3PAO, and a credible provider should not both prepare you and certify you. We set up and harden the Microsoft 365 GCC High environment being assessed; the assessment itself is arranged through a third-party assessor.
How long does CMMC readiness take?
It depends on your starting point and scope, but a focused small-business effort is typically a few months. What Ghosxt builds and hardens is the Microsoft 365 GCC High environment scoped to your CUI, rather than securing your entire environment to the same level.
Who will I actually talk to?
Ulises Paiz, the owner, directly. There is no tier-1 queue and no offshore call center: the engineer who knows your environment answers the phone, and critical incidents carry our 4-hour notification commitment.

Protect your defense contracts before the deadline does

Book a free CMMC assessment, or call (831) 204-0501. The earlier you start, the cheaper and calmer readiness is, and the less likely a compliance gap costs you a contract.

Book your free assessment Send a Message
Call (831) 204-0501 Book free assessment