CMMC Registered Practitioner (RPA) advisoryCyber AB RPA
CMMC readiness with a scoped enclave — not a firm-wide freeze
Navigating CMMC for the Defense Industrial Base starts with honest scoping. Staff who handle Controlled Unclassified Information work inside a dedicated enclave; the rest of the practice stays on the ordinary stack. We design it, remediate it, and sit with you through readiness — as an RP/RPA, not a slide shop.
Registered Practitioner advisory for the Defense Industrial Base
CMMC is a unified standard designed to protect contractors handling sensitive federal data. Manage IT NY helps you scope a dedicated enclave for Controlled Unclassified Information, close NIST 800-171 gaps, and prepare assessment evidence — without turning the entire firm into a compliance freeze.
We provide guidance, gap analysis, and remediation support as a Cyber AB Registered Practitioner Advanced firm. Formal certification remains the domain of authorized C3PAOs — our job is to maximize your readiness with honest assessments and controls you can operate.
Navigating CMMC compliance for the Defense Industrial Base
Select a program stage to review requirements, focus areas, mandates, and assessment expectations — in the same order as our Registered Practitioner advisory outline.
The Cybersecurity Maturity Model Certification (CMMC) is a unified standard designed to protect the Defense Industrial Base (DIB) from evolving cyber threats. It ensures that contractors handling sensitive federal data have the maturity to safeguard it against unauthorized disclosure. By verifying the implementation of specific cybersecurity practices, CMMC builds a resilient supply chain for the Department of War.
To safeguard the nations digital infrastructure by detecting, preventing, and responding to cyber threats.
To create a secure, resilient, and trusted digital environment for individuals, and government institutions.
Foundational Safeguarding & FAR 52.204-21
Level 1 is the baseline for all DoD contractors. It covers 6 domains with 17 specific practices:
- Access Control (AC): 4 practices (e.g., limiting system access to authorized users).
- Identification & Authentication (IA): 2 practices (e.g., verifying user identities).
- Media Protection (MP): 1 practice (e.g., sanitizing media before disposal).
- Physical Protection (PE): 4 practices (e.g., limiting physical access to systems).
- System & Communication Protection (SC): 2 practices (e.g., monitoring boundary communications).
- System & Information Integrity (SI): 4 practices (e.g., flaw remediation and malware protection).
Protecting Federal Contract Information (FCI).
Codified in FAR 52.204-21, which mandates the basic safeguarding of contractor information systems.
Requires an annual self-assessment and formal affirmation in the Supplier Performance Risk System (SPRS).
CMMC Level 2: Advanced Data Protection
Implementing 110 security practices to safeguard sensitive Controlled Unclassified Information.
Compliance is driven by DFARS 252.204-7012 requiring adequate information security.
Strictly adhering to the 14 families of federal security requirements.
High-priority contracts require independent verification by an authorized C3PAO auditor.
Maintaining capabilities to detect, analyze, and report cyber security incidents.
Developing documented procedures that govern organizational access and data handling.
Scoping & Boundary Definition
We identify all people, technology, and facilities that process, store, or transmit FCI and CUI.
Defining a clear "Security Domain" allows us to isolate sensitive data, reducing the audit footprint and overall compliance costs.
Identifying External Service Providers (ESPs) and Cloud Service Providers (CSPs) to ensure their FedRAMP or CMMC equivalence.
Gap Analysis & Readiness Review
We perform a deep-dive technical and administrative audit of your current environment against the 110 NIST controls.
- NIST 800-171 Control Audit
- SPRS Score Calculation
- Remediation Roadmap Development
As an RP, I provide a detailed readiness report that highlights "Red/Yellow/Green" status for every required practice.
- NIST 800-171 Control Audit
- SPRS Score Calculation
- Remediation Roadmap Development
We calculate your current summary score to ensure accurate reporting to the Department of War.
- NIST 800-171 Control Audit
- SPRS Score Calculation
- Remediation Roadmap Development
SSP & POA&M Development
We author the mandatory 200+ page document detailing how your organization meets every CMMC requirement.
For CMMC Level 2, we document a prioritized list of remediation tasks for eligible controls that are not yet fully implemented. While the Department of War allows these specific items to be resolved within a 180-day window for final certification, it is critical to note that high-impact "critical" controls are not eligible for a POA&M and must be fully met at the time of assessment.
CMMC Level 1 requires 100% compliance at the time of assessment; POA&Ms are not permitted for L1.
Technical Remediation & Implementation
Closing the gaps identified in the analysis through technical configuration and security deployments.
Implementing robust MFA, Zero Trust architecture, and encrypted communication tunnels (VPN/IPsec).
Configuring the centralized logging and auditing systems required to detect and report cyber incidents to the Department of War.
Continuous Monitoring & Annual Affirmation
CMMC is not a "one-and-done" audit; we implement the governance required to maintain your security posture.
We facilitate the yearly requirement for a senior company official to affirm continuous compliance in SPRS.
Keeping your SSP, network diagrams, and policy sets updated as your business grows and federal regulations evolve.
Where CMMC programs stall
Four readiness friction points we clear first
Registered Practitioner advisory turns unscoped CUI, thin SPRS scores, missing SSP evidence, and one-and-done myths into a scoped, operable plan.
CUI everywhere
Most contractors discover Controlled Unclassified Information lives in more mailboxes, shares, and SaaS apps than the last slide claimed — and a firm-wide freeze is the expensive default.
110 practices, thin evidence
CMMC Level 2 expects 110 security practices aligned to NIST 800-171. Without a current-state audit and SPRS score, you cannot tell red from green before a C3PAO arrives.
SSP and POA&M still blank
Assessors expect a living System Security Plan and a prioritized Plan of Action & Milestones. Critical controls cannot hide behind a 180-day promise.
One-and-done audit myth
CMMC is not a certificate you hang and forget. Annual affirmation in SPRS and continuous monitoring are part of staying in the supply chain.
What our RPA advisory covers
Readiness support inside the CMMC ecosystem
Gap analysis, SSP and POA&M authorship, enclave scoping, Zero Trust remediation, and continuous monitoring — delivered under the Cyber AB Code of Professional Conduct.
RP / RPA advisory
Cyber AB registered practitioner
Steve Greenberg is a CMMC Registered Practitioner Advanced, trained and registered with The Cyber AB to provide specialized consulting and readiness support — integrity and technical accuracy first.
Gap analysis & SPRS
Current-state against 110 controls
Deep-dive technical and administrative audit, red/yellow/green readiness reporting, and an accurate SPRS summary score for DoD reporting.
SSP & POA&M
Assessment-ready documentation
We author the System Security Plan and a prioritized Plan of Action & Milestones for eligible Level 2 gaps — with clear notes on controls that cannot wait.
Enclave scoping
Isolate CUI without freezing the firm
A dedicated environment for the people and systems that touch CUI — identity, devices, and logging that match the assessment you are walking toward.
Technical remediation
MFA, Zero Trust, and logging
Close gaps with access controls, encrypted paths, and centralized audit logging required to detect and report cybersecurity incidents.
Continuous monitoring
Annual affirmation support
Governance to maintain posture year-round, facilitate SPRS affirmations, and keep SSP, diagrams, and policies current as regulations evolve.
Ethics, scope, and answers leaders ask first
Consulting versus assessment, CoPC integrity, POA&M limits, and what an Enclave Box actually means for your firm.
A CMMC enclave is a smaller, dedicated environment for Controlled Unclassified Information. Staff who need CUI work there; the rest of the practice stays on the ordinary stack. “Enclave box” here means approach — identity, network, and process walls — not a gadget on a price list.
No. As a Registered Practitioner, Manage IT NY provides guidance, gap analysis, and remediation support. Formal CMMC certification assessments are the exclusive domain of authorized C3PAOs. We cannot consult for an organization and then participate in its formal certification assessment.
We adhere to the Cyber AB Code of Professional Conduct: honest assessments without exaggeration, rigorous protection of CUI and FCI encountered during consulting, and immediate disclosure of potential conflicts of interest to the client and The Cyber AB.
DoD allows certain eligible items to be resolved within a 180-day window for final certification, but high-impact critical controls are not eligible for a POA&M and must be fully met at the time of assessment. Level 1 requires 100% compliance at assessment; POA&Ms are not permitted for L1.
That is the point of an enclave: the people and systems that touch CUI, not every mailbox in the firm. If your contract requires more, we will say that early — shrinking the scope is often the first honest step.
CMMC without freezing the whole firm
Scope first, then prove the controls
Defense contractors need Level 2 maturity for Controlled Unclassified Information — driven by DFARS 252.204-7012 and NIST 800-171 — without putting every intern workstation under the same control set. We turn that pressure into a scoped enclave and assessment-ready evidence.
Unscoped CUI and thin readiness
Enclave design plus RP readiness
CMMC certification is determined solely by an independent C3PAO and DoD authorities. Manage IT NY provides RP/RPA consulting and readiness support; we do not perform formal certification assessments.
Advisory themes for defense contractors
DIB program navigation, DFARS and NIST alignment, assessment prep, and incident-ready logging — browse by theme.
Navigating CMMC for the Defense Industrial Base
CMMC verifies that contractors handling sensitive federal data have the maturity to safeguard it. We translate program language into a scoped plan your operations team can execute — Level 1 foundational safeguarding through Level 2 advanced CUI protection.
Readiness assessmentDFARS 252.204-7012 and NIST 800-171 alignment
Level 2 compliance is driven by DFARS requirements for adequate information security and the 14 families of NIST 800-171. We map your environment to those practices and close gaps with controls you can operate day to day.
System hardeningReady for self-assessment or C3PAO review
Level 1 requires annual self-assessment and SPRS affirmation. High-priority Level 2 contracts need independent verification by an authorized C3PAO. We prepare evidence, SSP, and remediation status so you walk in with facts.
Schedule a one-on-one with an RPA consultantDetect, analyze, and report
Level 2 expects incident response capability and enforceable security policies. We configure centralized logging and Zero Trust access so you can detect, analyze, and report cybersecurity incidents as required.
EDR / MDR1 / 4


