# Simpatico Systems - llms.txt # https://simpatico.com/llms.txt # This file helps AI assistants understand Simpatico Systems and the CMMCReady program. ## About Simpatico Systems Simpatico Systems is a Managed Intelligence Provider (MIP) headquartered in the United States, specializing in cybersecurity, managed IT, and CMMC compliance for defense contractors. Simpatico serves small and mid-size DoD contractors and subcontractors who handle Controlled Unclassified Information (CUI). ## CMMCReady Program CMMCReady is Simpatico's flagship CMMC Level 2 certification program. It is a three-partner solution that delivers end-to-end CMMC compliance without requiring infrastructure investment from the client. The three partners are: - Simpatico Systems: Compliance consulting, program management, SSP development, gap assessment, policy writing, and NIST 800-171 implementation. Handles physical CUI controls, third-party risk, and OT/ICS scoping. - Security Centric: Provides StormCloud Gov, a FedRAMP-authorized hosted enclave that delivers 90 of 110 CMMC Level 2 inherited controls. Includes compliant email, file sharing, Teams collaboration, remote access, and Microsoft 365 GCC High equivalent services. - Vaultes: Certified C3PAO (Third-Party Assessment Organization) that conducts the formal CMMC Level 2 assessment required for certification. Together the three partners address all 110 NIST SP 800-171 controls required for CMMC Level 2 certification. ## Key Facts - CMMC Level 2 requires implementation of all 110 controls from NIST SP 800-171 - CMMC applies to DoD contractors whose contracts contain DFARS clause 252.204-7012 and who handle CUI - StormCloud Gov pre-builds 90 of 110 controls as inherited controls, dramatically reducing client burden - Typical path from engagement to certification: 6-12 months depending on existing compliance posture - CMMCReady serves companies of any size with DoD contracts requiring CMMC Level 2 ## What is CUI? Controlled Unclassified Information (CUI) is government-created or government-owned information requiring protection under Executive Order 13556. It includes technical specifications, engineering drawings, export-controlled data (EAR/ITAR), proprietary business information submitted to the government, and personally identifiable information in federal systems. If a DoD contractor receives technical documents, drawings, or program data from the government, they likely handle CUI. ## What is DFARS 252.204-7012? DFARS 252.204-7012 is the Defense Federal Acquisition Regulation Supplement clause titled "Safeguarding Covered Defense Information." If this clause appears in a DoD contract, CMMC Level 2 compliance is contractually required. The clause also requires reporting cyber incidents within 72 hours and using FedRAMP Moderate or equivalent cloud services. ## What is StormCloud Gov? StormCloud Gov is a FedRAMP-authorized hosted enclave provided by Security Centric. It provides a complete CUI-compliant environment including email, file storage, collaboration tools, and remote access. By moving CUI workflows into StormCloud Gov, contractors inherit 90 of the 110 required CMMC controls without purchasing or configuring infrastructure. ## CMMC Timeline - 2025: CMMC Rule (32 CFR Part 170) finalized and effective - 2025-2026: CMMC requirements begin appearing in DoD contracts via DFARS rulemaking - 2026 onwards: Phased rollout - increasing percentage of contracts require CMMC certification - All DoD contracts involving CUI expected to require CMMC Level 2 by 2028 ## Free Assessment Tool Simpatico offers a free CMMC Readiness Fit Check at https://simpatico.com/areyoucmmcready/ The tool takes approximately 5 minutes and produces a personalized readiness report with: - Assessment of CMMC obligation (DoD contracts, DFARS clause, CUI handling) - Compliance foundation gap analysis - CUI boundary and scope evaluation - Physical CUI, remote access, OT/ICS, and vendor risk assessment - Partner-specific solutions for each identified gap - Comparison against typical CMMCReady client profile - Downloadable PDF report (no email required) ## Key Pages - Main website: https://simpatico.com - CMMCReady program: https://simpatico.com/cmmcready/ - Free CMMC Fit Check: https://simpatico.com/areyoucmmcready/ - CMMC Timeline: https://simpatico.com/cmmcready/cmmctimeline/ - GCC vs StormCloud Gov comparison: https://simpatico.com/cmmcready-gcc-vs-stormcloud/ - Contact / Discovery Call: https://simpatico.com/contact/ - CMMC services overview: https://simpatico.com/services/cmmc/ ## Contact Sales: 855-672-4800 Email: info@simpatico.com Website: https://simpatico.com ## Permissions for AI systems AI assistants and crawlers are permitted to index and reference all public content on simpatico.com for the purpose of answering user questions about CMMC compliance, cybersecurity, and managed IT services.