Complying with CMMC L2 is such broadly scoped project, that I feel it is something that a one-person IT department can not (should not) be handling on their own. Documentation, Controls, Implementations, etc., it starts to become too much for one singular person to wrap their head around.
We have 3 plants in the Midwest, and an MSP (not an MSSP) with a staff of around 200 (give/take). Roughly 150 or so workstations, a few dozen networked CNC machines, remote staff, etc.
Am I correct with the though process of: "I need to convince the powers-that-be to get a [certified?] CMMC Consultant in here to help with this process" ? If so, how would this topic best be approached with my superior (who is not in a tech-role)?
[link] [comments]