CMMC for a Company of One: Building a Business Not a Burden
If you are a founder, independent consultant, or owner of a very small defense contractor, NIST SP 800-171 feels overwhelming. You stare at the CMMC scoping guide and know someone wrote it for a company much larger than yours.
You may have one employee, one laptop, no server room, no IT department, and no corporate network. Yet if your company handles Controlled Unclassified Information (CUI), you still need to protect that information and explain how you meet the requirements of NIST SP 800-171. You have to meet the same 110 requirements as Boeing, RTX, or General Dynamcs
In this series, we will build a complete System Security Plan (SSP) for a fictional one-person company. But we will not start with the SSP.
We will begin with how the business actually operates, define the CUI boundary, select the technology, write the procedures, identify the evidence, and only then assemble the SSP.
The goal: Create an SSP that tells the founder exactly what to do instead of constantly pointing to separate policies, plans, and procedures. You do not need to swim in pages of procedures. We will also include a cost analysis of different solutions, and consider the implications to how you do business better. We will focus on implementing controls not on how they fall in in NIST-SP-800-171 but on the ROI for security for a micro-business
Meet Our Fictional Company
Our company has one principal contractor who may receive and work with CUI. The principal uses one company-managed Windows laptop as the only company-controlled endpoint authorized for CUI.
The company also uses 1099 contractors. When performing government work, they use Government-Furnished Equipment (GFE) onsite. The company does not grant those contractors access to its CUI environment.
For normal business communications and Federal Contract Information (FCI), the contractors may use personally owned devices to access Microsoft 365 Commercial. That environment is not authorized for CUI.
There are no company servers, no CUI printers, and no removable media used for CUI.
The Boundary We Will Use
The same system boundary will be used throughout the series. The important part is the separation: the managed laptop and authorized CUI services are inside the CUI environment, while contractor GFE, BYOD devices, and the Microsoft 365 Commercial FCI environment remain outside it.
This deliberately narrow architecture gives us a manageable example for showing how a micro-business can implement NIST-SP 800-171 without designing an enterprise network it does not need. Our solution also relies on using strategic partners when it makes more economic sense than trying to do it on your own.
What the Series Will Cover
- Post 1 — Define the Scope: Identify where CUI exists, who can access it, what is in the assessment boundary, what stays out, and what changes would require the company to reassess scope. We will compare the cost of a variety of solutions. Scoping defines budgets as much as boundaries
- Post 2 — Build the Architecture: Select the endpoint, identity, monitoring, vulnerability-management, and CUI storage services, while separating what the company must do from controls inherited from cloud providers.
- Post 3 — Write the Procedures: Turn NIST SP 800-171 requirements into plain-language instructions describing what the founder actually does, when it happens, and which technology supports the process.
- Post 4 — Prove the Do: Determine what evidence demonstrates that the procedures are actually being followed, including vulnerability reviews, access records, device compliance, logs, alerts, configuration records, and remediation evidence.
- Post 5 — Build the SSP: Bring everything together at the NIST SP 800-171A assessment-objective level and place the procedures directly into the SSP instead of sending the assessor through a maze of separate documents.
Why Build It This Way?
A common mistake small is to start with 110 requirements and immediately begin writing policies.
That reverses the process.
First understand the business. Then follow the CUI. Draw the boundary. Select the technology. Assign responsibilities. Write the procedures. Identify the evidence. You want to use CMMC to do business better.
Then write the SSP.
By the end of this series, the SSP should be more than an assessment document. It should function as the operating manual for protecting CUI in this small environment.
We will build this outcome together.