Defense

Imprimis serves organizations that operate at the intersection of innovation, national security, and public trust. Our Department of Defense clients span a wide range of government and military sectors -- each with unique missions, but all united by mandated requirements for robust cybersecurity compliance.

Defense Contractors

The Defense Industrial Base (DIB) includes contractors of all sizes, from those submitting their first SBIR proposal to very large enterprises managing classified, mission-critical contracts with complex supply chains. As of 2025, DoD contractors face strict cybersecurity requirements under Cybersecurity Maturity Model Certification (CMMC) 2.0, codified in 32 CFR and implemented through 48 CFR. This covers any company handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), mandating compliance with specific security standards.

CMMC 2.0 Consists of 3 Levels

    • Level 1: Annual self-assessments for basic safeguarding of FCI (15 controls under FAR 52.204-21)
  •  
    • Level 2: Compliance with 110 controls from NIST SP 800-171 for CUI, requiring self-assessments or third-party assessments depending on contract sensitivity
  •  
    • Level 3: Applies to highly sensitive CUI, adds NIST SP 800-172 controls, with government-led assessments.

Contractors must also comply with DFARS 252.204-7012 and 252.204-7020, which require assessment of NIST SP 800-171 implementation and submission of scores to the Supplier Performance Risk System (SPRS). These requirements extend to subcontractors and the supply chain. Non-compliance may disqualify companies from future contracts or even cause them to lose their current ones.

Imprimis Support for Defense Contractors

    • Support for CMMC Levels 1 and 2, and NIST 800-171/172 assessments
  •  
    • Remediation activities and sustainment support
     
    • SPRS score optimization
     
    • Required documentation for compliance
    •  
    • Readiness for CMMC/NIST final assessments and ongoing sustainment

 

By Using the Imprimis i2ACT Assessment and Compliance Tool, and leveraging our 15+ years of experience in navigating the complexities of CMMC and NIST you will be able to achieve CMMC Compliance with precision and speed... allowing you to spend time focusing on delivering mission-critical capabilities for your customers with confidence.

The Imprimis i2ACT™ Assessment and Compliance Platform streamlines assessments, documentation, artifact management and reporting to help you begin the compliance planning process with confidence.

 

 

 

 


No matter your size or sector, we meet you where you are and take you where you need to be.