ScopeHunter

ScopeHunter · FAQ

Compliance & security, answered plainly

Straight answers on CMMC 2.0, SOC 2, and ISO 27001 — what applies to you, what you actually have to do, and where automation stops.

Do I need CMMC 2.0 if I don't handle CUI?

CMMC applies to U.S. Department of Defense contractors that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). FCI generally puts you at Level 1; CUI puts you at Level 2. If you handle neither, CMMC does not apply to you — but many organizations still adopt NIST SP 800-171, the standard underneath CMMC Level 2, as a security baseline. Note that third-party assessment is currently suspended while the underlying 800-171 obligations continue to apply; see below.

Are CMMC third-party (C3PAO) assessments happening right now?

No. The Department of Defense has suspended CMMC Phase II third-party assessment requirements, which removes the immediate need to engage a Certified Third-Party Assessment Organization (C3PAO). Status as of August 2026 — a suspension is a pause, not a repeal, so confirm the current position before you plan around it.

What has not changed is the part that binds you. The suspension targets third-party auditing only. Phase I self-assessment requirements remain fully active and legally binding, NIST SP 800-171 is still a contractual requirement under DFARS 252.204-7012, and your SPRS score is still a figure you submit to the government.

So the freeze changes who checks, not what is required — and it moves the checking onto you. An assessor is also a second pair of eyes: a company being assessed has someone to catch an overstatement before it becomes a false claim. A self-attesting company does not, and the officer who signs carries that under the False Claims Act. Fewer external checks concentrate the exposure rather than reducing it.

CMMC self-assessment vs a C3PAO assessment?

Level 1 and a subset of Level 2 allow an annual self-assessment. Level 2 for CUI is written to require a third-party assessment by an authorized C3PAO every three years — though see above: those assessments are currently suspended. A tool can track your posture and gather evidence, but a certificate is awarded only after a C3PAO assesses your system against your System Security Plan (SSP). No software issues one, and anything that implies otherwise is selling you something.

SOC 2 vs CMMC 2.0 vs ISO 27001 — which do I need?

SOC 2 is a commercial trust attestation issued by a CPA firm, common when selling to enterprises. CMMC 2.0 is for U.S. DoD contracting and is based on NIST SP 800-171. ISO/IEC 27001 is an internationally recognized certification for an information security management system. The three overlap heavily on controls, so a single control implementation can satisfy requirements across all of them — which is how ScopeHunter maps one piece of evidence to multiple frameworks at once.

Can CMMC / NIST 800-171 host hardening be automated?

The OS-enforceable subset — account lockdown, logging, firewall posture, cryptography, patching — can be automated with configuration management such as Salt. That covers the technical half of NIST 800-171. Procedural and documentary requirements can't be enforced by a script, so automation gets you a hardened baseline and the evidence behind it, never the attestation itself. We write about automating CMMC 2.0 hardening and dogfooding it on our own box.

What is a POA&M?

A Plan of Action and Milestones (POA&M) is the tracked list of control gaps, the plan to close each, the owner, and the target date. CMMC requires a POA&M when controls aren't yet fully met, with closure expected inside a defined window.

What is FOCI in defense contracting?

FOCI stands for Foreign Ownership, Control, or Influence — the U.S. government's concern about whether a foreign entity could influence a contractor in a way that risks protected information. Affected contractors may need to disclose ownership and put mitigation measures in place.

How do I track compliance SLAs and control-review cadences?

Obligations like "review access every quarter" or "scan monthly" need due-date tracking. ScopeHunter derives SLA status from your evidence — the last time a control was met or an automated check passed — and flags each obligation as on-track, due soon, or overdue per system, with no manual check-offs.

Does ScopeHunter store my CUI or FCI?

No. ScopeHunter tracks compliance metadata — control status, evidence pointers, policies, and SLAs — not your regulated data. It's an issuer, not a vault: you keep secrets and CUI/FCI in your own systems, and ScopeHunter never asks you to upload them.

Get started on ScopeHunter → Preview the compliance workspace

See also: automating CMMC 2.0 hardening · default-credential scanner · feature status · security policy · privacy policy.

ScopeHunter is built and operated by L-IT Technical Solutions, a Texas IT consultancy — the same people who run the CMMC automation described here against their own production infrastructure.