Compliance

CMMC 2.0: What Maryland
Contractors Need to Know

Published by RTS Team • 12 min read

If your business holds DoD contracts, CMMC compliance isn't optional. With assessments ramping up, contractors near Fort Meade need to act now.

The Three CMMC Levels

Level 1 — Foundational: 17 practices. Self-assessment. For Federal Contract Information (FCI).
Level 2 — Advanced: 110 practices (NIST 800-171). Third-party assessment for CUI.
Level 3 — Expert: 110+ practices. Government-led assessment for sensitive programs.

Why Maryland Contractors Should Act Now

Maryland has one of the highest concentrations of defense contractors nationally. As CMMC requirements flow through supply chains, even small subcontractors will need certification.

Your 90-Day Action Plan

Days 1-30: Assess

Determine your required CMMC level. Conduct a gap assessment. Identify where CUI exists in your environment.

Days 31-60: Plan

Develop your System Security Plan. Create a Plan of Action & Milestones. Budget for remediation and assessment.

Days 61-90: Act

Implement highest-priority items. Deploy MFA, encryption, and logging. Train employees on CUI handling.

How RTS Can Help

Our CEO holds the CCP credential and we've helped Maryland contractors navigate from assessment to certification. Schedule a free CMMC readiness conversation →

Need CMMC Guidance?

CCP-certified team helping Maryland contractors navigate compliance.