Cloud & InfrastructureAugust 13, 202610 min readBy Steve Song

Your DoD Subcontract Renewal Now Depends on CMMC — Is Your Company's AWS Setup Ready? (Northern Virginia Guide, 2026)

Part of:Website Cost & Decision Framework

Around Annandale, Centreville, and Chantilly, Virginia — a corridor with one of the largest concentrations of Korean-American-owned IT staffing, systems integration, and professional services firms in the country — a specific business model has quietly powered a lot of family wealth: win a subcontract under a large defense prime or federal systems integrator, place skilled engineers or provide a service, and renew year after year on the strength of good work and a good relationship. That model still works. What has changed underneath it is that 'good work' is no longer sufficient by itself. Every prime contractor is now required to flow down cybersecurity requirements to its subcontractors, and a growing number of them are actually checking — which means a subcontractor's own IT setup, not just its people, has become part of what gets evaluated at renewal time.

What changed: CMMC is no longer a large-prime problem

The Cybersecurity Maturity Model Certification (CMMC) program exists because the DoD found, repeatedly, that sensitive information was leaking through the weakest link in a long subcontractor chain, not through the prime itself. The fix was to push the requirement down: any company handling Federal Contract Information needs baseline safeguards (CMMC Level 1, self-assessed), and any company handling Controlled Unclassified Information needs a more rigorous set of controls aligned to NIST SP 800-171 (CMMC Level 2, often requiring third-party assessment). For a small Korean-American subcontractor, the practical effect shows up quietly — a prime's annual vendor questionnaire suddenly asks for a System Security Plan you do not have, or a new task order requires an attestation your current setup cannot support. Nobody tells you the subcontract did not renew because of this. It just does not renew, and the reason sits buried in a compliance review you were never part of.

What we typically find when we look at a subcontractor's actual setup

Common gaps between what CMMC/NIST SP 800-171 requires and how a growing subcontractor is actually running today:

  • No documented System Security Plan (SSP) or Plan of Action & Milestones (POA&M) — the two documents every assessment starts with, often nonexistent because nobody was ever asked for them before.
  • CUI mixed with everything else — contract deliverables, emails, and general company files sitting in the same shared drive or inbox as data that actually requires controlled handling.
  • No multi-factor authentication enforced company-wide, or MFA on some systems but not the ones actually touching contract data.
  • Access that outlives the assignment — an engineer rotated off a contract eight months ago whose access to that contract's shared resources was never revoked.
  • No real incident response plan — if a laptop is lost or a phishing email is clicked, there is no documented, rehearsed process, which is itself a specific control assessors check for.

What a CMMC-ready AWS architecture actually includes

This is not about buying a certification — no vendor, including us, sells you a CMMC certificate. What a properly designed AWS environment does is put the technical controls in place that a System Security Plan documents and a Certified Third-Party Assessor Organization (C3PAO) verifies, for Level 2 engagements that require it.

Concrete pieces of a compliance-aligned AWS setup, and the control each one supports:

  • Data classification and boundary design — CUI, FCI, and unrestricted company data are identified and separated first, before any infrastructure decision, since this determines whether GovCloud is actually required or commercial AWS with proper controls is sufficient.
  • AWS GovCloud (US) for CUI workloads — meets the FedRAMP Moderate-equivalent baseline and data residency requirements DFARS 252.204-7012 calls for when CUI is genuinely in scope.
  • IAM with mandatory MFA and least-privilege access — every user's access is scoped to exactly what their current contract role requires, reviewed on a schedule, and revoked immediately when a role or assignment ends.
  • Encryption at rest and in transit (KMS-managed keys) — a specific, checkable control under NIST SP 800-171, not a general best practice left to chance.
  • CloudTrail logging and centralized monitoring — an auditable record of who accessed what and when, which is both a required control and what makes an incident response plan actually executable instead of theoretical.
  • Documented System Security Plan and POA&M — the AWS architecture is only half the requirement; the written documentation describing it, kept current, is what an assessor actually reviews first.

Why this needs a partner fluent in both the compliance language and yours

CMMC and NIST SP 800-171 work is dense enough that most subcontractors reasonably bring in outside help — the question is whether that help can also explain, in Korean when needed, why a specific control matters to a business owner who did not build a career in federal compliance. A large compliance-only consultancy will hand you a control matrix and a bill; what a small Korean-American-owned firm in Annandale or Centreville often actually needs is someone who can sit down, explain in plain terms what CUI means for the specific contract you are on, and build the AWS environment and documentation together rather than handing over a report and disappearing. We treat this the same way we treat every engagement — one point of contact, in Korean or English, from the initial data-classification conversation through ongoing monitoring, reachable on KakaoTalk.

How an engagement actually runs

We start with a data-classification and gap assessment — walking through your actual contracts to determine what data you handle (FCI, CUI, or neither), then mapping your current environment against NIST SP 800-171 to identify what is already in place versus missing. From there we design the architecture around your actual scope rather than defaulting to the most expensive option, and remediate in phases: access control and MFA first, since those close the highest-risk gaps fastest and require no data migration, then encryption and logging, then GovCloud migration for CUI workloads if your classification work shows it is required, finishing with the System Security Plan and POA&M documentation an assessor will actually read. Your team keeps working throughout — this is staged remediation, not a weekend cutover. Once in place, monitoring, access review, and documentation updates continue as an ongoing service, since CMMC compliance is an annual affirmation, not a one-time project.

FAQFrequently asked questions
  • Does a small Korean-American IT staffing or subcontracting company really need CMMC compliance, or is that only for large defense primes?

    Size does not exempt you — CMMC (Cybersecurity Maturity Model Certification) applies anywhere in the DoD supply chain that a contract clause flows down to, and prime contractors are now required to pass that requirement on to every subcontractor and sub-subcontractor who touches Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), regardless of company size. A five-person Korean-American IT staffing firm placing engineers on a DoD help-desk contract, or a small firm doing systems integration work as a second-tier sub, is just as in scope as a thousand-person prime. The level required (Level 1 self-assessment for FCI-only, Level 2 for CUI, often requiring third-party certification) depends on what data you actually handle — but 'we're too small to matter' is exactly the assumption that gets a subcontract non-renewed when the prime's own audit asks for your certification and you do not have one.

  • Do we need AWS GovCloud specifically, or can we use regular commercial AWS?

    It depends on what you actually store, not on being a government contractor in general. Federal Contract Information alone can often be secured on commercial AWS with the right controls — encryption, access logging, network segmentation. Controlled Unclassified Information is the trigger for AWS GovCloud (US): DFARS 252.204-7012 requires CUI to be stored and processed in an environment that meets FedRAMP Moderate equivalent controls, with data residency and personnel-screening requirements commercial AWS regions do not meet. In practice this means the first real question in any engagement is a data-classification exercise — what you actually handle, contract by contract — before anyone recommends GovCloud, standard AWS, or a hybrid, because moving everything to GovCloud by default when most of your workload is FCI or unrestricted data means paying more for infrastructure you do not need.

  • How long does it take, and how much does it cost, to get a small subcontracting company CMMC-ready?

    For a small subcontractor doing a gap assessment against NIST SP 800-171 and remediating what is found, a realistic timeline runs two to six months depending on how far your current setup is from compliant — a company already on a reasonably modern cloud setup with basic access controls closes gaps faster than one still running on local servers and shared logins. Cost has two separate parts: the assessment and remediation engagement itself (a one-time or phased project), and your ongoing AWS usage, which for a small subcontractor's workload is typically a modest monthly cost scaled to usage, not a large fixed infrastructure bill. Weigh that against the alternative, which is not a fine — it is simply not being eligible for subcontract renewal or new task orders once a prime's own compliance review catches up with yours, which for a company whose revenue depends on DoD subcontracts is a harder cost to absorb than the remediation itself.

Written by

Steve SongFounder — ZOE LUMOS

Builds bilingual websites and runs local SEO and Google Ads for Korean-American businesses from Fort Lee, NJ.

About Steve
Next chapter

Ready for a website that earns its keep?

ZOE LUMOS is a Korean-American digital marketing agency in Fort Lee, NJ, specializing in bilingual websites, local SEO, and Google Ads.

← Back to Blog