Close up of server stack.
CMMC Expertise

CMMC Compliance Made Simple

CMMC Solutions for All DoD Contractors

Whether you need third party assistance to prepare for your CMMC Audit, full managed IT services from a CMMC-knowledgable MSP/MSSP, or simply looking to lock in your CMMC Level 1 self-assessment, Stratus Services is here to help.

We are prepared to handle your CMMC needs and ensure you are ready to crush your audit and maintain your compliance in the meantime.

CMMC Level 1 Compliance

CMMC Level 1 is the entry-level certification aimed at protecting Federal Contract Information (FCI) for DoD contractors. It focuses on basic cyber hygiene and implementing foundational cybersecurity practices.

Close up of a server stack with open ports

CMMC Level 1 Assessments

For orgs that encounter FCI

We help small and medium-sized businesses achieve CMMC Level 1 compliance, ensuring your organization meets the Department of Defense’s baseline cybersecurity requirements.

  • Review your current cybersecurity practices against the 17 required Level 1 controls.
  • Provide guidance and coaching to implement any necessary changes.
  • Prepare your self-assessment and help you confidently attest to compliance.
  • Support ongoing cyber hygiene to maintain readiness for future audits or higher CMMC levels.
Close up of a server stack with switches.

CMMC Level 1 Advantage Enclave

For orgs with Level 2 on their horizon

Built in FedRAMP-authorized cloud environments, this solution ensures basic cyber hygiene to meet all Level 1 cybersecurity requirements today, while laying the foundation for Level 2 compliance in the future.

  • Turnkey virtual enclave meeting all Level 1 controls.
  • Secure cloud infrastructure hosted in FedRAMP-authorized environments for scalability.
  • Simplified management and guidance from Stratus Services to maintain ongoing compliance.
  • Future-ready design that makes transitioning to Level 2 seamless when your business requires it.

CMMC Level 2 Compliance Packages Customized for Your Business

Before you can achieve CMMC compliance, the most important step is deciding how you'll get there. Whether you're building a secure environment from the ground up or integrating compliance into your existing operations, your approach determines everything—from cost and complexity to timeline and long-term success.

Regardless of approach Stratus Services is your full time partner in CMMC compliance. Our CMMC focused managed services are designed to take you from the ground floor to a CMMC Level 2 certification and ongoing compliance afterwards. Each of the packages below include CMMC-compliance managed services billed on a per user basis.

An enclave is often the right choice for companies who's business is only partially DoD based, as well as for companies who are looking to achieve compliance quickly.

Aegis & Vanguard Enclave Packages

Stratus Services' CMMC-ready Aegis & Vanguard Enclaves provide turn key solutions for companies seeking to obtain CMMC certification quickly; fully managed enclaves preconfigured to meet the technical requirements for CMMC, along with all the policy, procedure, and paperwork required to meet the non technical ones.

Stratus Services follows a shared responsibility model where no control is fully on the customer. Depending on the approach as many as 85% of the controls are squarely the responsibility of Stratus Services, with the rest being a shared responsibility Stratus will help you implement.

The Aegis & Vanguard Enclave packages includes policies and procedures which Stratus Services compliance proffesionals will help tailor to your organization and on going consulting up to, during, and after an assessment.

Basic diagram of a cloud infrastructure.

Aegis Package

CMMC-Enabled Virtual Enclave

Our Aegis Enclave is a cloud native virtual enclave built to meet all technical controls required for CMMC.

  • Faster
  • Easily scalable security that grows with your business
  • Cloud Native
  • Supports a hybrid workforce–accessible from anywhere
  • 85/15 Shared Responsibility Model
Graphical representation of a firewall system protecting a data center

Vanguard Package

CMMC-Enabled Physical Enclave

Our Vanguard Enclave is for organizations with on-prem requirements and that use physical CUI.

  • Required for printing, removable media, physical CUI
  • Repurpose existing equipment
  • Simplified user experience
  • More cost effective for certain workloads
  • 80/20 Shared Responsibility Model

Network of virtualized apps that look like blocks.

Atlas Package (All-In CMMC-Enabled Enclave + Managed IT Services)

Companies whose business practices don't align with the restrictions of an enclave usually need to take the 'all-in' approach to CMMC compliance. This involves bringing all users and existing IT infrastructure into compliance.

Stratus Services cut it's teeth on these types of projects and developed the the Atlas model for CMMC compliant managed services. Due to the complexities and nuances of an all-in approach, Stratus Services will work with you to tailor our solution to fit your needs. Shared responsibility follows an 80/20 breakdown but will vary slightly depending on your needs.

Compliance Services

CMMC-Enabled Virtual Enclave

The following compliance services are included in each of the packages listed above.

  • Policies & Procedures
  • System Security Plan (SSP)
  • Evidence Gathering
  • Assessment Participation
  • Ongoing Compliance
  • Risk Assessments
  • Incident Management
  • Change Management
  • Plan of Action and Milestones (PoAM)
  • Annual Self Assessment
  • Ad hoc Consulting
  • Tabletop Exercises

Technical Services

CMMC-Enabled Physical Enclave

The following technical services are included in each of the packages listed above.

  • Managed SIEM
  • Antivirus/Endpoint Protection
  • Vulnerability Scans
  • Vulnerability Remediation
  • Identity Management
  • Network/Firewall Management
  • Backups
  • Incident Response
  • InTune Device Management
  • Secure Device Configurations
  • Role Based Access Control
  • Helpdesk support

Virtual CISO (vCISO) Services

Stratus’ Virtual CISO (vCISO) support provides ongoing compliance support to your organization. Stratus Services will manage and oversee all aspects of your CMMC compliance program. Stratus Services will provide policies, procedures, and ad hoc consulting to you and your local IT provider on adherence to CMMC requirements. As a standalone vCISO, Stratus Services will not be responsible for any technical administration and will not have administrative access to configure the enclave. Details of which controls Stratus Services is responsible for will be documented in a Shared Responsibility Matrix and during a C3PAO assessment Stratus Services will bear responsibility for their status. This vCISO add-on is included in our Atlas package.

About Image

vCISO Service Offerings

Documentation: System Security Plan | User Agreements | Access Control Policy | Vulnerability & Patch Management | Audit Management Policy & Procedure | Systems Communication Policy | Change Management Policy | Configuration Management Policy | Risk Assessment Policy | User Agreements
Assessment Services: Assessment Preparation | Evidence Gathering | Assessment Participation
Security & Compliance Monitoring Services: POA&M Tracking | Incident Tracking | Vulnerability Tracking | Risk Assessment | Security Awareness Training
CMMC Program Support & Advisory Services: CMMC Progress Check ins – Weekly | Change Management Meetings – Monthly | Ad hoc consulting – 5 hours monthly | Annual Self-Assessment/Attestation | Security Control Monitoring

Request a Consultation

Don't wait. Reach out and secure your data today!

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Decorative image of accounting devices.

Frequently Asked Questions: CMMC Assessments

The following are some of the most common questions we receive from current and potential clients.

Are you a Cyber AB Registered Provider Organization (RPO)?

Yes, we have been a certified Cyber AB Registered Provider Organization (RPO) since 2022 and renew annually, as required. Feel free to review our certification.

Do you have staff who are certified Registered Practitioners (RPs)?

Yes. As of 2025 Stratus employees three Registered Practitioners (RPs), two Registered Practitioner Advanced (RPAs), and one CMMC Certified Professional (CCP). Feel free to review our certification.

Do you have experience with clients in my specific industry or with similar data types?

Stratus has experience implementing and maintaining CMMC compliance across many sectors that support the DIB, such as construction, engineering, manufacturing, and more. We are proud have successfully guided a large, local engineering firm to pass their CMMC Level 2 Certification Assessment this year (2025), one of the first nationally!
Additionally, as an IT consulting organization, we also have extensive experience with other compliance-forward organizations such as finance, mortgage & title, and medical offices.  

Can you help determine the appropriate CMMC level for my business and contracts?

Yes. We offer scoping services to help assist you in figuring out what CMMC level will be required based on your specific needs. This is a core tenant of proper CMMC planning. For more information, we recommend this blog post on the topic: CMMC Level 2 Scoping: Understanding Asset Categories for Compliance

Will you help create or revise policies and procedures as part of compliance prep?

Yes, we offer a comprehensive CMMC implementation package that includes the creation of new policies and revision of existing policies.

Can you assist with System Security Plans (SSPs) and Plans of Action & Milestones (POAMs)?

Yes, for those pursuing CMMC Level 2 compliance, SSPs are included for alignment with CA.L2-3.12.4. While SSPs are not required for Level 1 compliance, arrangements can be made for an SSP if this is requested. POA&Ms will be developed as needed to address any identified deficiencies.

Can you collaborate with our IT or MSP teams, or do you provide hands-on technical support?

Yes. While we are a fully staffed Managed Service Provider and can provide these services as added support to CMMC Compliance contracts, we are more than willing to work with internal or existing third-party MSP teams to implement a CMMC-compliant environment.

How do you ensure that we maintain compliance post-certification?

We offer services to ensure continued compliance with CMMC requirements that support your yearly self-assessments and/or triennial third-party assessments.

When will CMMC be required for DoD contracts?

As of August 2025, the DoD’s planned rollout of CMMC compliance will be tiered in three different phases. Level 1 requirements will be enforced on contracts when the 48 CFR final rule is released, which is expected to happen by October 2025 earliest, and February 2026 at latest. Level 2 requirements will be enforced a year after the Level 1 rollout. Level 3 requirements will be enforced a year after the Level 2 rollout. HOWEVER, once the 48 CFR final rule is in place, program managers can require higher levels of CMMC before the enforcement date set in place by the DoD.