CMMC Level 2 Managed IT Checklist for Defense Contractors
By Tom Hermstad · HD Tech

What managed IT services does a defense contractor need to meet CMMC 2.0 Level 2 requirements in Orange County?
If you're a defense contractor in Orange County — Irvine, Anaheim, Fullerton — CMMC Level 2 isn't a bureaucratic checkbox. Failing that assessment means losing contract eligibility, and with it, the revenue your team depends on. That assessment is built around 110 active security controls drawn from NIST SP 800-171 Rev. 2. Managed IT is the operational layer that keeps those controls running, documented, and defensible every day — before the assessor walks in and after the contract is signed.
It's not if your environment gets scrutinized. It's when. The contractors who survive that scrutiny are the ones who prepared before the solicitation landed.
Why Orange County Defense Contractors Can't Wait on CMMC 2.0
The CMMC 2.0 proposed rule (32 CFR Part 170) was published December 26, 2023 in the Federal Register and is being phased into contracts on a rolling basis — check the Federal Register for current phase dates.
According to the Department of Defense CIO, Level 2 protections apply to any contractor or subcontractor that handles CUI (Controlled Unclassified Information) — the sensitive technical data that flows through Southern California's aerospace and defense supply chain every day.
That means you, even if you're a subcontractor further down the chain. The protections flow down.
Here's the part most contractors miss. CMMC Level 2 readiness isn't just a compliance requirement. It's a competitive weapon. The contractor who walks into a solicitation already certified doesn't just meet the bar — he owns the bid. Primes have to source from someone. Make it easy for them to choose you.
Compliance tied to uptime and documented controls is how a smaller Orange County manufacturer competes against a much larger prime. That's not theoretical — we've watched it happen.
Three misconceptions keep Orange County manufacturers and suppliers from acting in time:
- "CMMC is only for prime contractors." The DoD is explicit: CMMC requirements flow down to subcontractors handling FCI (Federal Contract Information) or CUI. If you touch the data, you're in scope.
- "Level 2 is a one-time audit." It's not. Level 2 requires ongoing control operation and periodic affirmations. You don't pass once and forget it.
- "We can bolt this on before the next solicitation." Readiness work needs to start before contract language appears. By the time you see CMMC clauses in a solicitation, the window to prepare is already closing.
The pattern we see most often: a contractor heard "CMMC is coming" at an industry event, nodded, and went back to running the business. Then a solicitation landed with CMMC language — and they were already significantly behind before they even started.
Don't let that be you.
You survived ransomware once. CMMC is the next test. Preparation is the only answer that works both times.
If you want the full compliance picture first, read our CMMC compliance guide for defense contractors. Then come back here for the operational checklist.
The Managed IT Checklist: Mapped to CMMC Level 2 Practice Families
CMMC Level 2 requires 110 practices aligned to the 14 control families defined in NIST SP 800-171 Rev. 2. Managed IT services are the operational engine behind the vast majority of them.
Here's how the Lifeguard Loop™ — Monitor → Detect → Respond → Recover — maps directly to what you need running before your assessment.
Monitor: Lock Down Access and Configuration
These controls live in CMMC's Access Control, Configuration Management, and System & Communications Protection families.
We sat across from a Fullerton aerospace sub last year who had a solid team, good intentions, and zero visibility into which devices were actually touching their CUI environment. They couldn't list them.
That's where we start with every new client — because that's where breaches start. The clarity those first few weeks deliver changes everything. They go from "we think we're covered" to "we know exactly what's in our environment and who can touch it."
What your managed IT provider must be doing:
- Asset inventory — current and complete. Every endpoint, server, and network device in your CUI environment must be catalogued. If you can't list it, you can't protect it.
- Least-privilege access enforcement. Users get only the permissions their role requires. Admin rights are tightly controlled and audited.
The 2020 SolarWinds supply-chain compromise showed exactly what happens when vendor pathways go unwatched. Attackers moved through trusted software update channels undetected — because no one was watching the vendor layer.
- Patch management on a defined schedule. Unpatched systems are the most common entry point for attackers. Critical patches deploy promptly, and every deployment is documented.
- Secure configuration baselines. We harden every system to a defined standard — CIS benchmarks are the common reference — and track every deviation. No exceptions, no undocumented drift.
- Vendor and third-party access controls. Every outside vendor connecting to your environment needs documented access — scoped, time-limited, and reviewed.
📋 GCC High Note: If you're handling CUI in Microsoft 365, you likely need GCC High — a government-specific version of Microsoft 365 built to meet federal data-handling requirements — not the commercial tier. See our breakdown of GCC High vs. commercial Microsoft 365 for defense contractors before assuming your current licensing covers you.
Handing a contractor a clean, current asset inventory for the first time — watching them realize they finally know exactly what's in their environment — that's the foundation everything else is built on.
Detect: See Everything, Miss Nothing
These controls map to CMMC's Audit & Accountability, Risk Assessment, and System & Information Integrity families.
Here's where the game changes for you.
Logs are only useful if someone is actually reading them. We've walked into environments where years of log data were sitting in storage, untouched, while an attacker had been present for an extended period. That's not a detection program — that's a digital filing cabinet.
When real detection goes live for the first time, the reaction is always the same: "We had no idea how much was happening in our own environment." That's exactly the point.
Within days, you're seeing failed login attempts, unusual file access, and configuration changes you didn't know were happening. That visibility turns compliance from a paperwork exercise into an actual defense.
What your managed IT provider must be doing:
- Centralized log collection and retention. CMMC requires audit logging across systems — logins, privilege use, configuration changes, file access. Your provider protects those logs from tampering and retains them per your SSP (System Security Plan — the master document describing your environment and how each control is implemented).
- SIEM monitoring (Security Information and Event Management — a centralized platform that correlates log data and flags anomalies in real time). Without it, your logs are storage, not intelligence.
- Vulnerability scanning on a regular cadence. Authenticated scans of your environment, documented results, and a remediation plan tied to risk ranking.
- Integrity monitoring. Alerts when critical system files or configurations change unexpectedly. This catches both external intrusions and insider mistakes before they become incidents.
- Periodic documented risk assessments. CMMC Level 2 requires documented risk assessments per NIST SP 800-171 RA controls. Your managed IT provider should produce this — not just help you fill out a form.
This is also where AI is changing the equation.
We onboarded a defense sub in Anaheim last year that had SIEM in place but no AI-assisted analysis behind it. Their team was manually reviewing alerts — a great many each day — and triaging by gut feel. Threats were getting buried.
When we layered in AI-driven behavioral analysis, they went from drowning in noise to acting on what actually mattered. Real threats surfaced in minutes, not hours.
For a smaller contractor competing against a large prime with a full security team, that's how you level the playing field. AI-accelerated detection gives you enterprise-grade visibility without the enterprise headcount.
At HD Tech, we're actively deploying these tools inside CMMC-scoped environments. Faster detection means shorter exposure windows. Shorter exposure windows mean fewer incidents to explain to an assessor.
If you want to understand how AI tools accelerate detection inside a compliant environment, our post on how defense contractors can use AI in a CMMC-compliant environment covers the guardrails.
Respond: Have a Plan Before You Need One
These controls map to CMMC's Incident Response and Security Assessment families.
We've seen contractors with solid technology and zero documentation. When something goes wrong, they can't prove what happened, who responded, or what they contained. That gap has ended careers and contracts.
What your managed IT provider must be doing:
- A documented Incident Response (IR) plan — tested, not just filed. CMMC Level 2 requires you to have a plan, to train to it, and to update it after incidents or exercises.
- Clear escalation paths. Who gets called in the middle of the night? Who has authority to isolate systems? Who contacts the DoD if CUI is involved? Every answer must be written down before the incident.
- Evidence preservation capability. When something happens, logs and forensic images need to be captured and preserved. Your MSP should know how to do this without destroying the chain of custody.
- Containment and communication protocols. Speed matters, but so does discipline. Uncoordinated responses often cause more data exposure than the attack itself.
Here's what a real incident response drill looks like: everyone knows their role, the escalation chain is clear, and when the call comes in, no one is improvising. That confidence shows up in how your people carry themselves going into a solicitation — and assessors notice it.
For a broader look at the compliance mistakes that trip up contractors at this stage, read the biggest cybersecurity compliance mistakes defense contractors make.
Recover: Prove You Can Come Back
Backup and recovery controls are operationally critical for business continuity. They support CMMC's broader goal of protecting CUI integrity over time.
Most contractors think they have a recovery plan. What they actually have is a backup that's never been tested and an RTO they made up on the spot.
We sat with an Irvine defense sub some time ago — solid company, good people — and asked them to show us their last restore test. Silence. When the assessor asks for that documentation, silence is a very expensive answer.
What your managed IT provider must be doing:
- Tested, documented backups. Backup existence isn't the same as backup readiness. Your MSP should run regular restore tests and document the results.
- RTOs and RPOs defined. RTO (Recovery Time Objective) = how fast you need to be back online. RPO (Recovery Point Objective) = how much data loss is acceptable. If you don't have written answers, you don't have a recovery plan.
- Air-gapped or immutable backup copies. Ransomware routinely targets connected backup systems. At least one copy needs to be out of reach.
- Disaster Recovery (DR) testing on a schedule. A plan that's never been tested is a guess, not a plan.
You may have gaps here. That's not failure — it's a starting point. The contractors who reach assessment-ready aren't the ones who had a perfect starting point. They're the ones who looked at the gap list, rolled up their sleeves, and kept moving forward one control at a time.
Keep Paddling. This work compounds. Every gap you close today is one less exposure an assessor finds tomorrow.
What "Evidence-Ready" Actually Means
CMMC readiness requires evidence, not intent. Your managed IT provider needs to produce:
- A current SSP (System Security Plan) documenting your environment and how each control is implemented
- A POA&M (Plan of Action & Milestones — your punch list of gaps and deadlines for closing them)
- Audit logs retained and protected per your SSP
- Patch and vulnerability scan records
- Incident response test documentation
- Periodic affirmation records
If your current MSP can't hand you this documentation on request, you are not assessment-ready — regardless of what they've told you.
Trust, yet verify. Don't wait for the solicitation to find out where you actually stand.
Call your MSP today and ask two questions directly: "Can you produce our SSP and POA&M right now?" and "Can you show me recent patch and scan documentation?"
If you get hesitation, a vague promise, or a blank stare — that's your answer. A provider doing the job has this ready. One who isn't will talk around it. The answer to those two questions will tell you more about your real CMMC posture than any sales conversation ever will.
Why a Generalist MSP Won't Get You Across the Finish Line
A generalist IT provider — or your nephew who's great with computers — can keep your email running, push patches, and show up when the server goes down. That's real value, and I'm not dismissing it.
But CMMC Level 2 asks for something fundamentally different.
An assessor doesn't want to know that your systems were up last quarter. They want a defensible System Security Plan that maps every one of the 110 controls to a specific technical implementation in your environment.
They want an evidence trail — log records, scan results, incident response test documentation, access control reviews — that they can walk through control by control.
They want a POA&M that shows you identified your gaps, dated them, and closed them on a documented schedule.
A general MSP produces day-to-day uptime. CMMC demands a documented security program. Those are different products, and confusing one for the other is the most expensive mistake we see Orange County contractors make.
By the time they realize the gap, the solicitation is already on the table.
Here's what the turnaround actually looks like. An Irvine defense subcontractor came to us in documentation disaster — no SSP, no centralized logging, inconsistent patching across their CUI environment.
In time, they had a complete SSP, a working SIEM, a tested IR plan, and a POA&M with every gap dated and tracked. They went into their next solicitation assessment-ready — and won the contract renewal.
That transformation is what the Lifeguard Loop™ is built for. It's not just a security framework. It's an evidence factory. Every monitoring log, every detection alert, every response action, and every recovery test becomes a document your assessor can verify.
We show our work. We expect you to check it.
Frequently Asked Questions
Size doesn't protect you. If you touch CUI, you're in scope — full stop.
We've seen it firsthand. An Anaheim sub told us they were "too far down the chain to matter." They were wrong. A prime asked for their CMMC status before renewing the contract. They didn't have an answer.
The Department of Defense is explicit: requirements flow down to any contractor or subcontractor handling FCI or CUI. Know your data. Know your scope. Don't assume your way out of a contract requirement.
110 controls — and every one must be operating, not just documented.
We've reviewed environments where contractors had great policies on paper and nothing running underneath them. Beautiful binders. Empty controls. That won't pass.
CMMC Level 2 pulls directly from NIST SP 800-171 Rev. 2 across 14 control families — Access Control, Incident Response, Configuration Management, Audit & Accountability, and ten more. Managed IT is the engine that keeps the majority of those controls running day to day.
Both paths require the same 110 controls — self-assessment doesn't mean fewer.
Some contracts mandate a third-party assessment by a DoD-authorized firm; which applies depends on the solicitation. Here's the real risk: you attest that controls are operating, an audit follows, and they weren't actually running.
That's not just a compliance gap. That's a False Claims Act exposure. Don't sign what you can't prove. We've seen this trip up contractors who assumed self-assessment was the easy path. It isn't.
Longer than most contractors expect — and the ones who underestimate the timeline pay for it:
- No SSP means starting documentation from scratch before a single control can be verified.
- No centralized logging means building detection infrastructure before you can prove control operation.
- Inconsistent patching means a remediation backlog that takes real time to clear.
- Start now — before the clause shows up. Waiting until a solicitation appears is too late. We've watched contractors assume they could get ready in a few weeks. They couldn't.
Ask two questions right now — and listen carefully to the answers:
- "Can you produce our SSP, POA&M, and audit log evidence today?" Hesitation is your answer.
- "Can you show me proof of a prior CMMC engagement?" A general MSP handles day-to-day IT. CMMC readiness requires a provider who understands NIST SP 800-171, can scope CUI environments, and produces documentation an assessor can verify.
We've had this conversation with contractors who assumed their long-term IT provider had it covered. They didn't. Trust, yet verify — before the solicitation forces the issue.
Orange County's defense supply chain is a target — not because you're large, but because you're connected to programs that matter. Miss a CMMC clause and your next bid goes in the trash. That's not a hypothetical — that's the conversation we've had with contractors who thought they had more time.
The Lifeguard Loop™ keeps your CMMC controls running, documented, and defensible every day — not just during audit season. No jargon. No guesswork. This is exactly the work we show up fired up to do every single day — because getting you to that assessment table ready, confident, and documented is what protecting your business actually looks like.
Don't be a casualty — be exceptional.
Book your free Cyber Preparation Assessment. You'll walk away with a written gap list mapped to CMMC's 110 controls, a snapshot of where each control stands today, and a clear starting point — no commitment, no jargon, no surprises.

Tom Hermstad
President & CMO, HD Tech
Tom Hermstad has led HD Tech since 1995, building one of Southern California's most trusted managed IT and cybersecurity firms. He specializes in helping Orange County businesses eliminate IT headaches and stay ahead of evolving cyber threats — in plain English.
