Sandra M.
Protecting Controlled Unclassified Information (CUI) is critical to supporting government missions and maintaining trust with federal customers. CUI may include sensitive operational, technical, or contractual information that, while not classified, still requires safeguarding against unauthorized access or disclosure. As cybersecurity requirements across the Defense Industrial Base (DIB) continue to evolve, organizations supporting Department of War (DoW) are under increasing pressure to demonstrate that CUI is being properly protected across their environments and operations. The Cybersecurity Maturity Model Certification (CMMC) framework was established to help validate that contractors are implementing and maintaining the security controls necessary to safeguard sensitive government information.
Recognizing the importance of staying aligned with evolving DoW cybersecurity requirements, ActioNet prioritized completing its CMMC Level 2 assessment through a C3PAO before the Summer. This milestone represents months of collaboration, coordination, and dedication across IT Operations, Security, Contracts, Human Resources, Program Management, and Leadership to ensure that processes aligned with both operational workflows and CMMC expectations. The following roadmap provides a high-level overview of the key phases involved in progressing from a CMMC Level 2 self-assessment to formal C3PAO certification readiness and assessment completion.

Unlike self-assessments, formal third-party assessments conducted by a C3PAO require organizations to demonstrate that security controls are not only documented but are also operating effectively in practice. Assessors review technical configurations, policies and procedures, audit logs, and supporting artifacts while conducting interviews and walkthroughs to validate that documented processes align with actual operational practices.
A major focus of the effort centered around the implementation and maturation of ActioNet’s High Security CUI enclave. The environment was designed to support the secure handling of CUI through identity and access management, Conditional Access policies, Intune-managed devices, and separation between the Commercial and High Security environments. Then, the most time-intensive aspect of the CMMC readiness effort was preparing for the formal C3PAO assessment. This involved collecting and organizing a significant volume of assessment evidence, including screenshots, audit logs, policies, procedures, technical configurations, and other supporting artifacts. Teams worked to map evidence to specific assessment objectives, update and validate the System Security Plan (SSP), prepare stakeholders for interviews, and verify that documented processes aligned with actual operational practices.
One of the biggest lessons learned throughout the CMMC readiness effort was the level of detail and evidence required to support each assessment objective. Preparing for the assessment involved much more than simply referencing policies or existing documentation. Each assessment objective had to be specifically addressed within the SSP. The effort also highlighted the complexity of documenting shared responsibility areas within the High Security environment, including understanding which security controls were inherited, which were the responsibility of ActioNet, and how those controls aligned with applicable CMMC requirements.
The assessment process also reinforced that CMMC readiness is much more than a technical exercise. Assessors evaluate whether implemented controls and supporting evidence consistently align across the environment. In many cases, a single artifact or control implementation could lead to additional questions or reveal dependencies impacting other controls. While the effort was at times daunting, it ultimately strengthened organizational processes, improved coordination across teams, and enhanced ActioNet’s overall cybersecurity governance and assessment readiness posture moving forward.




