Managed IT and Managed Security · Leesburg, VA

Government Contractors

IT Support and Managed Security for Government Contractors, From a Team That Knows CMMC.

We understand security and regulated businesses. Defense contractors, subcontractors and federal suppliers protect Controlled Unclassified Information (CUI) and Federal Contract Information (FCI). We run the IT and security around it, and our Compliance Division delivers the CMMC work.

Manufacturers, engineering firms, construction companies, technology providers and professional services that work for the Department of Defense and federal agencies.

Which CMMC level applies to a government contractorA decision diagram. Your contract decides what you handle. Federal Contract Information leads to CMMC Level 1, the 15 requirements of FAR 52.204-21. Controlled Unclassified Information leads to CMMC Level 2, the 110 requirements of NIST SP 800-171.Your contractHandles FCIFederal Contract InformationHandles CUIControlled Unclassified InfoCMMCLevel 115 requirementsFAR 52.204-21CMMCLevel 2110 requirementsNIST SP 800-171

What a Government Contractor Needs From an MSP

Why Does My MSP Need CMMC Experience?

Because your MSP is inside your assessment. An MSP that runs your security tools holds Security Protection Data, so the services it provides fall inside your CMMC scope, and your System Security Plan (SSP) has to describe who does what between you and them. An MSP that does not know NIST SP 800-171 can leave you with controls nobody owns.

We have done this work. Iron Lift, a construction company, reached a CMMC Level 2 self-assessment with 110 of 110 controls met, standing as verified 2026-09-15, with the compliance work delivered by our Compliance Division.

Watch the Iron Lift Video Case Study

How Do You Handle NIST SP 800-171 and CUI?

NIST SP 800-171 is the 110 security requirements behind CMMC Level 2. Most of them are things your IT has to do every day: access control, multi-factor authentication, audit logging, patching, malware protection, incident response, media protection. We run those controls, and keep the evidence that they ran.

Level 1 is the 15 requirements of FAR 52.204-21, for FCI. Level 2 is for CUI, and your contract decides how it is assessed. DFARS 252.204-7012 and NIST SP 800-171 remain the baseline either way.

Level 1 Versus Level 2 · CMMC Level 2 Requirements

Do We Need a CUI Enclave or Microsoft GCC High?

Often not the whole company. A CUI enclave puts CUI in a defined part of the environment, such as Microsoft GCC High with Azure Virtual Desktop, so most of the business stays out of scope. Our Compliance Division designs the enclave and documents it; we run the IT and security around it.

Microsoft GCC High addresses where CUI is stored and processed. It does not on its own satisfy the 14 control families, which is why the people running your systems matter as much as the tenant they sit in.

CUI Enclave Design

Will You Get Us Ready for a C3PAO Assessment?

Where your contract calls for a C3PAO assessment, readiness is the work: controls in place, evidence collected, the SSP and POA&M current. Our Compliance Division runs the gap assessment, the SSP and the program, and we keep the controls running between assessments. Neither of us is an Authorized C3PAO, which means we can fix what we find.

What a C3PAO Assessment Looks Like · Your SPRS Score

Do You Provide MDR and SOC Monitoring?

Yes. Our managed detection and response watches logs across your cloud, network and endpoints 24/7 from a security operations center, with incident response behind it. Monitoring, audit logging and incident response all appear in NIST SP 800-171, so this is where security operations and compliance meet.

Managed Security Monitoring

Can You Support Us On-Site in Northern Virginia?

Yes. We are based in Leesburg, Virginia, and work on-site across Northern Virginia, including Ashburn, Leesburg and the rest of Loudoun County. Support is remote first, and someone comes to the floor when the work needs it.

CMMC in Loudoun County

What Does It Cost?

Managed IT and security are a fixed monthly cost scoped to your environment, given on the call. Our Compliance Division publishes its CMMC prices on its own site, including the gap assessment and CMMC In A Container.

Published CMMC Gap Assessment Price · CMMC In A Container

How We Cover It

6 SERVICES

Managed IT and Help Desk

Fixed monthly cost, unlimited remote support, patching and backups.

Microsoft 365 and Email Security

Tenant administration, MFA and email protection; GCC High design through our Compliance Division.

MFA and EDR

Multi-factor authentication and endpoint detection and response on every device.

MDR and 24/7 SOC

Logs across cloud, network and endpoints watched around the clock.

Vulnerability Scanning and Testing

Scheduled scanning, penetration testing and a retest of every fix.

Virtual CISO

Security leadership, governance and incident response planning.

Compliance

CMMC Is Delivered by Our Compliance Division, Capital Cyber Compliance.

The CMMC Level 2 gap assessment, the System Security Plan, POA&M development, CUI enclave design, a fractional CISO and the managed program are the work of Capital Cyber Compliance. We run the IT and security those controls depend on. One company, so the documentation and the systems do not drift apart.

CMMC Level 2 Gap Assessment · CMMC and CUI Services · CMMC Case Studies

On the Record

CASE STUDY

Iron Lift

A construction company that needed CMMC to stay competitive for government work, with no cybersecurity or compliance team in-house.

CMMC Level 2 · self-assessment · verified 2026-09-15

Frequently Asked Questions

6 QUESTIONS
Are you a CMMC certified MSP or a C3PAO?

We are not an Authorized C3PAO and we do not certify anyone. Only an authorized C3PAO can certify a contractor, and only the Department of Defense accepts a score. We run the IT and security, and our Compliance Division prepares you for the assessment.

What is the difference between FCI and CUI?

Federal Contract Information is non-public information provided by or generated for the government under a contract, protected at CMMC Level 1 by the 15 requirements of FAR 52.204-21. Controlled Unclassified Information is a marked category that requires the 110 requirements of NIST SP 800-171 at Level 2.

Do we have to move the whole company to GCC High?

Usually not. A CUI enclave keeps CUI in a defined part of the environment so most of the business stays out of scope. Our Compliance Division designs it with you.

Is the CMMC Phase 2 deadline still November 2026?

No. On 2026-07-13 the Department of War paused the CMMC rollout and suspended Phase 2 implementation pending a review. Level 1 and Level 2 self-assessments, SPRS and DFARS 252.204-7012 with NIST SP 800-171 remain in effect. Our Compliance Division tracks the current status.

Do you have references?

Yes. Iron Lift's president describes the work in the video case study on this site, and our Compliance Division publishes its CMMC case studies on its own site.

Do you work with contractors outside Virginia?

Yes. Iron Lift is in Massachusetts. Support is remote first; on-site work is in Northern Virginia.

Services for This Industry

Managed IT and Help Desk

Unlimited remote support, monitoring and maintenance at a fixed monthly cost.

Managed Security Monitoring (MDR and SOC)

Round the clock monitoring, detection and response from a security operations center.

Microsoft 365 and Email Security

Microsoft 365 set up, secured and run, with email protection against phishing and spoofing.

Vulnerability Assessment and Penetration Testing

Find the weaknesses before an attacker does, then retest every fix.

Virtual CISO (vCISO)

Senior security leadership, a roadmap and governance, without a full-time hire.

Talk Through Your Contracts and Your IT.

Pick a time. Tell us what you handle, FCI or CUI, and who runs your IT today.

Looking for CMMC? Our Compliance Division, Capital Cyber Compliance, delivers it.

Book a 30-Minute Call