Tier 3: Compliance Starter
Best For: Defense contractors who handle Controlled Unclassified Information (CUI) and must achieve CMMC Level 2.
This is our comprehensive compliance partnership. We manage all CMMC Level 1 requirements and collaboratively implement the 110 controls for CMMC Level 2, guided by your leadership.
Key Features:
Everything in Tier 2, plus:
- Full CMMC Level 1 Management: We manage all 15 controls, including the self-assessment and evidence gathering.
- Included Mobility: Mobile Device Management (MDM) included.
CMMC Level 2 Technical Implementation:
- Collaborative implementation of all 110 NIST 800-171 controls.
- Includes advanced system hardening, FIPS-validated encryption, and implementation of Zero Trust principles.
Formal GRC & Audit Program:
- Annual Formal Risk Assessment (RA)
- Development of all required Security Policies & Procedures
- Collaborative SSP & POAM Management, Umbra provides the management platform
- Technical Audit Support & Evidence Collection
