CMMC Compliance in Salt Lake City
NIST 800-171 is the standard the Department of War enforces today, and the obligation to protect controlled defense information has not changed. BlueKey IT helps Salt Lake City defense contractors and suppliers reach NIST 800-171 and CMMC Level 2 readiness, delivered locally from our West Valley City office. When you are ready to certify, we coordinate an independent C3PAO to come to you.
Where things stand today: The Department of War enforces cybersecurity compliance against the NIST SP 800-171 standard right now, through self-assessments and select government-led assessments. The third-party CMMC certification mechanism is being reviewed and refined, but the underlying requirement has not gone anywhere: every defense contractor and subcontractor remains obligated to protect covered defense information under DFARS clause 252.204-7012. Getting your 800-171 house in order is the move that holds up no matter how the certification program evolves.
Why Utah Contractors Need CMMC
Utah's defense industry runs on Hill Air Force Base. As the home of the Ogden Air Logistics Complex, Hill sustains the F-35, the Minuteman III ground-based missile system, and a vast aircraft maintenance mission, and it anchors a supplier base that spreads down the Wasatch Front. Northrop Grumman's ground-based strategic deterrent work, along with machine shops, composites manufacturers, and engineering firms across the valley, ties thousands of Utah jobs to contracts that carry cybersecurity obligations.
Those obligations are not advisory. If your company handles Federal Contract Information or Controlled Unclassified Information, protecting it to the NIST 800-171 standard is a current contractual requirement, enforced through self-assessment and government-led review. Primes flow these requirements down to subcontractors, and a supplier's demonstrated security posture increasingly shapes who stays on an approved vendor list.
BlueKey IT gets Salt Lake City contractors ready. We work from our West Valley City office to scope your environment, close NIST 800-171 gaps, build the documentation assessors actually ask for, and prepare you for third-party assessment. When you are ready to certify, we coordinate an independent C3PAO assessor to come to you, so the readiness work and the certification stay properly separated the way the program requires.
How the Standard Is Enforced Today
- The baselineNIST SP 800-171
The 110 security requirements that define how contractors must protect Controlled Unclassified Information. This is the standard, and it is stable regardless of how the certification program is packaged around it.
- Enforced nowSelf-assessment and DFARS 252.204-7012
Contractors self-assess against 800-171, post scores to SPRS, and remain contractually obligated to safeguard covered defense information. Select government-led assessments verify it. This is live today.
- Under reviewThird-party CMMC certification
The mechanism for independent C3PAO certification is being reviewed and refined to reduce burden on small and mid-sized businesses. The security baseline stays; the packaging is what is in motion.
- The constantProtecting CUI never lapses
Whatever the certification program becomes, the obligation to actually protect controlled information does not pause. Readiness built on 800-171 holds its value through any version of the program.
Which CMMC Level Applies to You?
-
Level 1
Self-assessment, annualFor companies handling Federal Contract Information only. Covers 15 basic safeguarding requirements from FAR 52.204-21, with an annual self-assessment and affirmation.
-
Level 2
Where most CUI holders landBuilt on all 110 security requirements of NIST SP 800-171. Depending on the contract, met by self-assessment or by a certification assessment from a C3PAO covering all 110 controls.
-
Level 3
Highest sensitivityFor programs involving the most sensitive information. Adds requirements from NIST SP 800-172 on top of Level 2, assessed by the government (DIBCAC).
Most Salt Lake City suppliers we talk to land at Level 2. The practical question is not which level exists but which one your specific contract, option, or subcontract flow-down actually names, and that is where a conversation with someone who knows the standard saves months.
How BlueKey IT Gets You There
CMMC readiness fails most often for two reasons: companies scope too broadly, pulling their entire network into the assessment when only a fraction of it touches CUI, and they treat documentation as an afterthought when it is precisely what an assessor evaluates. We work the problem in the opposite order.
Our CMMC Services in Salt Lake City
From first conversation through assessment day.
-
NIST 800-171 Gap Assessment
A formal, in-depth gap assessment is part of our CMMC offering. We evaluate your environment against all 110 NIST SP 800-171 requirements, produce your SPRS score, and hand you a prioritized remediation plan that shows exactly what stands between where you are and where your contract requires you to be. It is the deep, structured baseline the rest of the work builds on.
-
CUI Scoping & Enclave Architecture
Scope drives cost. We identify which systems actually touch CUI and design a separated, hardened enclave that keeps controlled information out of the rest of your network. A tight enclave shrinks what an assessor reviews, which shortens the project and lowers what you spend getting through it.
-
System Security Plan & POA&M
Your SSP is the document an assessor reads first. We build it to describe your environment accurately, control by control, alongside a Plan of Action and Milestones that shows credible progress on anything not yet closed. Documentation that matches reality is what separates a clean assessment from a painful one.
-
Assessment Prep & C3PAO Coordination
We run you through the assessment before the assessor does: evidence collection, control-by-control walkthrough, interview prep for your team, and remediation of anything that would not hold up. When you are ready, we coordinate an independent C3PAO to come out and certify you, then support the continuous compliance obligations that follow.
Why a Local Salt Lake City Partner Matters for CMMC
CMMC work is not a remote checklist exercise. Scoping conversations happen best on site, seeing which systems touch controlled information and which do not. Enclave design depends on how your operation actually runs. Our West Valley City office puts engineers on site across the valley, close to the Hill Air Force Base supplier corridor, throughout the readiness project rather than only on assessment day.
BlueKey IT combines the resources of a national operation, seven offices, 200+ business clients, and 5,500+ monitored endpoints, with a Salt Lake City team that knows the local supplier base. CMMC readiness sits inside the same managed IT and cybersecurity practice that keeps your business running day to day. That matters more than it sounds: the controls that pass an assessment only stay passed if someone maintains them, and protecting controlled information is an ongoing obligation, not a one-time event.
Start With a Conversation, Not a Commitment
The best first step is a free 30-minute strategy call with someone who knows the standard. We talk through what your contracts actually require, where your environment likely stands, and what a realistic path looks like. If a formal, in-depth gap assessment is the right next step, that is part of our CMMC offering and we will scope it to your environment. No pressure, and no charge to have the conversation.
What a full engagement costs and how long it takes depends almost entirely on scope: how much CUI you handle, how many systems touch it, and how far your current environment sits from the 110 controls. A tightly scoped enclave for a small shop is a fundamentally different project from bringing an entire manufacturing network into compliance. The strategy call is where we figure out which one you are looking at.
CMMC FAQ - Salt Lake City
Is CMMC still required, or did it go away?The obligation to protect controlled defense information has not gone away. The Department of War enforces the NIST SP 800-171 standard today through self-assessments and select government-led assessments, and DFARS clause 252.204-7012 still binds every defense contractor and subcontractor. The third-party certification mechanism is being reviewed to reduce burden on smaller businesses, but the underlying security requirement is live now.
Should I wait until the certification program is finalized?Waiting does not help, because the thing you would be waiting on, meeting NIST 800-171, is exactly what is enforced today and what any future version of the program will still require. Readiness commonly takes many months of real work. Companies that get their 800-171 house in order now are positioned no matter how the certification packaging changes.
What CMMC level does my Salt Lake City company need?Companies handling only Federal Contract Information typically need Level 1. Companies handling Controlled Unclassified Information generally need Level 2, which covers all 110 NIST SP 800-171 requirements. Level 3 applies to the most sensitive programs. The authoritative answer comes from your specific solicitation or contract flow-down, and confirming it is something we cover on the strategy call.
Do you certify us yourselves?No, and no one should offer to do both. Certification assessments must be performed by an independent C3PAO, and that separation is how the program is designed to work. What we do is get you ready: scoping, remediation, documentation, and evidence collection. When you are ready, we coordinate a C3PAO assessor to come out and perform the certification assessment.
We are a subcontractor, not a prime. Does this apply to us?Frequently, yes. These requirements flow down from primes to subcontractors when the subcontract involves FCI or CUI. Many Utah suppliers first hear about it from a Northrop Grumman email or a Hill AFB program office rather than a solicitation. If a prime has told you that you need to meet 800-171 or CMMC, that is a real requirement worth talking through.
What is included in the gap assessment?The gap assessment is a formal part of our CMMC offering. We review your environment against all 110 NIST SP 800-171 requirements, identify which systems handle CUI, calculate your SPRS score, and deliver a prioritized remediation roadmap with scope and timeline. We will talk through whether it is the right step for you on the free strategy call first.
Start With a Free 30-Minute Strategy Call
NIST 800-171 is enforced today, and readiness takes real time to do properly. The useful first move is a short conversation with someone who knows the standard, to understand where you stand and what a realistic path looks like for your business. No obligation, and no charge for the call.
Free 30-Minute CMMC Strategy Callor call (480) 291-8440









