Platform

HexaCore, The unified resilience core HexaSOC, AI agentic SOC & MDR HexaInt, Cyber & dark-web intelligence HexaOT, OT & ICS security HexaComply, Compliance & TPRM HexaAI, AI security & governance HexaCustody, Digital content custody HexaStrike, Agentic offensive security HexaMatrix, ATT&CK coverage & mapping HexaView, Multi-tenant customer portal

Solutions

Managed Detection & Response, 24/7 AI-agentic detection & response Co-Managed SOC, Your team and ours, one operation Detection Engineering, Coverage you can measure Incident Response Retainer, A hand on the wheel before you need it Penetration Testing, See your estate the way attackers do Red & Purple Teaming, Offence that hardens your defence Continuous Security Validation, Validate continuously, not annually Cyber Crisis Tabletop & War-Gaming, Rehearse the bad day Continuous Threat Exposure Management, From a list of vulns to a plan Cyber Risk Quantification, Risk as a number the board can use Managed Threat Intelligence, Signal, not noise Digital Risk & Brand Protection, Protect your name where you cannot see Managed OT & IoT Monitoring, Security for systems that cannot go down OT/ICS Assessment, Know your OT before an attacker does Compliance as a Service, Gap assessment to certification Third-Party & Supply-Chain Risk Management, Risk does not stop at your perimeter Virtual CISO & Governance Advisory, Executive security leadership, on tap AI Security & Governance, Govern the AI you are adopting Managed Content Custody, Custody for your crown jewels

Industries

Maritime, Fleets, ports and shore-side IT Media & Entertainment, Pre-release content and production Casino & Gaming, Platform integrity and player trust Financial Services, DORA, resilience and fraud Critical National Infrastructure, Converged IT and OT estates Manufacturing, Plants, PLCs and supply chain Healthcare, Clinical systems and patient data Pharmaceutical & Life Sciences, Research IP, GxP and data integrity Energy & Utilities, Generation, grid and SCADA Government, Sovereign data and assurance

Partners

Partner programme, Refer, resell or white-label Cyber Dockside AI, Maritime, exclusive partner TeamLogic IT, US channel partner Walking Comet, Australia, casino & gaming Copla, GRC technology partner Nexovern, Runtime AI sensor partner

Learning

Learning Hub: explainers, guides and briefings

Company

About HexaShield Contact Book a meeting Client Login Book a demo
Explainer

CMMC 2.0 and the defence supply chain

What the levels mean, how it relates to NIST SP 800-171, and why the assessment is the easy part.

Updated August 2026 · 6 minute read

What it is for

The Cybersecurity Maturity Model Certification programme exists because self-attestation across a very large supply chain did not produce reliable protection of sensitive but unclassified information.

It applies to organisations in the US defence industrial base that handle federal contract information or controlled unclassified information, which reaches a long way past prime contractors.

The relationship to NIST SP 800-171

The important thing to understand is that CMMC is largely an assurance wrapper around an existing control set. The technical requirements come from NIST SP 800-171.

That is good news if you have done 800-171 work already: the control implementation transfers. What CMMC adds is the requirement to demonstrate it to someone else, to a defined standard, on a defined cadence.

The levels

The levels differ principally in how assurance is obtained rather than in inventing new controls at each step. Lower levels rely on self-assessment against a basic set; the middle level introduces assessment by an accredited third party against the 800-171 control set; the highest introduces government-led assessment for the most sensitive programmes.

Which level applies is driven by the information you handle under a given contract, which means a single organisation can face different levels for different work.

Why the assessment is the easy part

Organisations that struggle rarely fail on the controls. They fail on scope and evidence.

Scope, because controlled unclassified information has usually spread further than anyone documented: into engineering file shares, onto supplier portals, into email. Narrowing and enforcing an enclave is most of the work.

Evidence, because the assessment asks for demonstration over time rather than a snapshot. If your evidence is assembled for the assessment, it describes the week of the assessment.

If you also serve non-defence customers

Most manufacturers do, and each large customer arrives with its own security schedule. The efficient approach is one control set mapped to many obligations rather than a separate programme per customer.

CMMC in particular is a fast-moving programme; current status and applicability are verified for your entities during onboarding.

FAQ

Questions, answered

We are a subcontractor. Does CMMC reach us?
It can. The obligation follows the information rather than the tier. If you handle federal contract information or controlled unclassified information under a contract, requirements can flow down to you regardless of how far from the prime you sit.
Does ISO 27001 cover it?
No, though it helps. An ISO 27001 ISMS gives you governance, risk treatment and much of the evidence machinery, but CMMC assesses a specific control set against specific information types. The overlap is substantial; the mapping is not automatic.

Want this applied to your estate?

Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.