Three hours later, Mara called Tom back into her office.

Priya didn’t flinch. She shared her screen.

Priya pulled up a second document: a 32-page Globalscape CMMC SSP Mapping Guide .

Mara Chen, CISO of Defense Kinetic Solutions , stared at the clock on her laptop. 11:47 PM. Her third cup of cold brew sat beside a stack of printed SSPs (System Security Plans). In six weeks, her company would face its first Joint Surveillance Voluntary Assessment (JSVA) for CMMC Level 2.

Mara nodded. That was the baseline.

“But,” Priya continued, zooming into a flowchart, “CMMC cares about auditable events (AU.L2-3.3.1). Your current legacy version logs who sends a file, but not what specific system patch level they were on when they sent it , and it definitely doesn’t integrate with your SIEM in real time.”