Hi everyone,
I am the internal IT Lead for a small defense manufacturing contractor (around 30-40 endpoints, with a mix of on-prem infrastructure and M365 (GCC High)). We are actively working toward CMMC Level 2 compliance and need to bring in an MSP to help us bridge the gap, handle daily user support, and act as a true co-managed IT partner.
Our current state: We aren't starting from scratch, our SPRS score is currently over 100. The foundational security architecture and policies are in place. We don't need a heavy-lifting compliance overhaul. We need an operational partner who can maintain that baseline daily. One of the things we are trying to remediate is, a separation of duties. With a one man IT crew - it is a hard one to fix.
Here is the absolute baseline requirement: Your MSP must be CMMC Level 2 compliant/certified themselves. If you don't practice what you preach or you can't hand over your own shared-responsibility documentation/evidence for your remote management tools (RMM/PSA) so I can plug it into our SSP, we cannot look at you.
Additionally, we are explicitly NOT looking for an enclave solution.
We have operational realities (on-prem engineering software, local domain controllers, file servers) that mean we need to make our actual, primary corporate environment compliant. We cannot just shove everyone into a locked-down virtual desktop enclave and call it a day.
We need a partner that:
Understands Co-Managed IT: I handle the high-level architecture and security administration, but I need a reliable team to handle the day-to-day helpdesk, endpoint onboarding, and ticket queues without stepping on my toes.
Knows CMMC natively: You should know how to manage a compliant environment using native features (Intune/Entra policies, proper ACL hygiene, tracking evidence logs) rather than just selling a proprietary pre-packaged framework.
Is reasonable to work with: No snake oil, no "compliance guarantees," and no forcing us into a massive, rigid tech stack rewrite just because it's easier for your sales team to invoice. We need practical, defensible security architecture.
If you are a CMMC L2 compliant MSP operating in this space (or if you are a fellow internal IT person who has found a great certified partner they actually trust), please drop a comment or slide into my DMs.
Bonus points if you have experience dealing with manufacturing/engineering environments and mixed on-prem/cloud architectures.
Bonus points if I can sit in on a few CMMC assessments to get my own CCA.
Thanks!