Virga Security / Services / Policy, Compliance & Governance
Service 04 · Policy, Compliance & Governance

The standards and evidence that make your program defensible.

A security program that only lives in someone's head isn't a program — it's a liability. We build the policies, procedures, and documentation that make yours auditable, defensible, and ready for any regulator or board, including our signature CMMC 2.0 and CUI physical readiness work below.

Why not write it in-house, or hire a generalist compliance firm?

Policies written by the people they govern rarely survive an outside audit, and most compliance consultants have never assessed a physical security control in the field. Virga's governance work is built on real federal audit experience — the kind regulators and primes actually recognize.

What This Covers

Governance that survives contact with an auditor.

Policy documents that sit in a drive nobody opens don't help you in a review. We build governance your organization actually runs on.

01

Policies & Procedures

Written to match how your organization actually operates, not copied from a template that assumes a facility you don't have.

02

System Security Plans

SSP control narratives that map directly to the requirements your environment answers to — drafted, not just outlined.

03

Standards Mapping

Identifying which frameworks actually apply — NIST 800-53, NIST 800-171, RMF, CISA guidance, sector-specific rules — and reconciling the conflicts between them.

04

Audit & Regulatory Readiness

Documentation built to hold up under a real review, not just to look complete in a binder.

05

Governance Structure

Roles, accountability, and review cadence — who owns the program, and how it stays current as your environment changes.

06

Board & Regulator Reporting

Findings and posture translated into language a board, prime contractor, or contracting officer can act on.

Audit Readiness, Proven Under Real Inspection

Governance built where the audits are highest-stakes.

Signature Program

CMMC 2.0 & CUI Physical Readiness Assessment.

Thirty-one of the 110 weighted points in a CMMC Level 2 self-assessment depend on physical security — and twenty-six of them cannot be placed on a POA&M. In most organizations that scope gets assessed by someone whose expertise is networks.

The Exposure — CMMC Level 2 Scoring Methodology, 32 CFR § 170.24

Where the points actually sit.

A Level 2 self-assessment starts at 110 and subtracts a weighted value for every requirement not fully implemented. The resulting score goes to SPRS, where contracting officers check it before award. Here is the portion that lives in your building rather than on your network — and which of it can be deferred.

PracticeRequirementPointsPOA&M?
Physical Protection family
PE.L2-3.10.1Limit physical access to systems, equipment, and operating environments5No
PE.L2-3.10.2Protect and monitor the facility and its support infrastructure5No
PE.L2-3.10.3Escort visitors and monitor visitor activity1Yes
PE.L2-3.10.4Maintain audit logs of physical access1Yes
PE.L2-3.10.5Control and manage physical access devices1Yes
PE.L2-3.10.6Safeguard CUI at alternate work sites1Yes
Requirements that cannot be met without physical evidence
MA.L2-3.7.6Supervise maintenance personnel without required access authorization1Yes
MP.L2-3.8.1Protect system media containing CUI — paper and digital3No
MP.L2-3.8.2Limit access to CUI on media to authorized users3No
MP.L2-3.8.3Sanitize or destroy media before disposal or reuse5No
PS.L2-3.9.2Protect CUI during and after terminations and transfers5No
Total points in the physical domain31
Of which cannot be placed on a POA&M26

Why the POA&M column is the important one

To achieve a Conditional Level 2 status, 32 CFR § 170.21 requires that no security requirement on your POA&M carries a point value greater than 1 — the only exception being encryption that is employed but not FIPS-validated.

Every 3-point and 5-point requirement above therefore has to be fully implemented, with final evidence, at the time of assessment. There is no remediate-later pathway for any of them. And under § 170.24, a POA&M is not a substitute for a completed requirement in any case — a requirement not implemented is assessed NOT MET whether or not it appears on one.

Scored against NIST SP 800-171 Revision 2 — the revision incorporated by reference in 32 CFR Part 170 for CMMC Level 2, and the revision the Department confirmed it is enforcing during the current pause in Phase 1. Revision 3 is included in every report as forward-looking design guidance, not as a scoring basis — so you do not rebuild your program around requirements that are not yet assessed.

Why this can't be a self-assessment by internal IT — or a generic compliance vendor

Most internal security teams and compliance consultants are built around network controls. The physical evidence behind these eleven requirements — badge logs, media destruction records, boundary construction — falls outside their usual scope entirely. This work sits at the intersection of federal physical-security standards and NIST SP 800-171A assessment methodology, the same combination DoD and DHS facilities are held to — not a generalist audit.

If You Handle FCI — CMMC Level 1

At Level 1 there is no POA&M at all.

Level 1 covers Federal Contract Information and consists of the fifteen basic safeguarding requirements at FAR 52.204-21(b)(1). Three of the fifteen are physical or media requirements, carrying twelve assessment objectives between them.

PE.L1-b.1.viii

Limit Physical Access

4 objectives · NIST 3.10.1

Authorized individuals identified; physical access to systems, equipment, and operating environments limited to them.

PE.L1-b.1.ix

Manage Visitors & Access

6 objectives · NIST 3.10.3–.5

Visitors escorted and monitored; audit logs of physical access maintained; access devices identified, controlled, and managed.

MP.L1-b.1.vii

Media Disposal

2 objectives · NIST 3.8.3

Media containing FCI sanitized or destroyed before disposal, and sanitized before release for reuse.

Level 1 is pass or fail, in its entirety

Under 32 CFR § 170.24(c)(1), all Level 1 requirements must be fully implemented to be considered MET, no POA&M is permitted, and results are scored MET or NOT MET in their entirety. A single assessment objective scored NOT MET fails the whole requirement.

In practice that means a key inventory nobody maintains, or a visitor log that records arrival but not escort or areas accessed, is enough to fail the self-assessment — and without a current status in SPRS, you are not eligible for award.

Why an outside physical-security specialist, not an internal check

Level 1 is graded MET or NOT MET in its entirety — a single missed objective fails the whole requirement, and grading your own visitor log or key inventory is exactly the blind spot an independent assessor exists to catch. Virga brings the same physical-security assessment discipline used at federal facilities, from someone with no stake in telling you what you want to hear.

How We Work

We look for what a document review can't see.

Our on-site review goes past the policy binder — into the physical evidence, the access records, and the areas your CUI actually touches. The result is scored against every requirement and delivered as a single evidence package, not a memo.

VIRGA SECURITY · REPORT CMMC 2.0 / CUI Physical Readiness SCORE 5 3 1 INCLUDED IN YOUR PACKAGE Findings & POA&M SSP Narratives Scored Register Annotated Floor Plan
What You Receive

An evidence package, not a memo.

Executive Summary

Posture, point exposure, and recommended sequence, written for a decision-maker.

Scored Assessment Register

Every requirement with its CMMC practice ID, status, point value, and POA&M eligibility.

Findings & POA&M

Recommendations tied to each requirement, with every POA&M-ineligible item flagged must-close-before-assessment.

SSP Control Narratives

Drafted language for the physical sections of your System Security Plan.

Annotated Floor Plan

Zones, boundaries, enforcement points, and gaps, marked on your own drawing.

A Direct Walkthrough

Findings explained in plain language, with your questions answered on the spot, not weeks later.

Engagements

Four ways to start.

Physical Readiness Scan
Remote · 3–5 days

Document review and a guided virtual walkthrough. Scored gap register, your five most material findings, and a remediation cost band.

Level 1 Assessment
On site · half to one day

All twelve assessment objectives across the three physical and media requirements, per NIST SP 800-171A methods. Objective-by-objective determination with an evidence index.

Level 2 Assessment
On site · 2–3 weeks

One to two days on site, then full analysis and reporting. Delivers the complete evidence package including the annotated floor plan and SSP narratives. Additional sites available.

Program Build & Design
Design · 4–14 weeks

Turns findings into an operating program: policies, procedures, registers, zone and boundary design, vendor-neutral specifications, and a closeout evidence package.

Sources

Every figure here is checkable.

Point values and Level 1 scoring32 CFR § 170.24, CMMC Scoring Methodology.
POA&M eligibility32 CFR § 170.21, Plan of Action and Milestones requirements.
Level 1 requirementsFAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems, and the CMMC Assessment Guide – Level 1.
Level 2 requirementsNIST SP 800-171 Rev 2, with assessment objectives from NIST SP 800-171A.
Underlying contractual obligationDFARS 252.204-7012.
Current program statusDoD CIO CMMC program page. CMMC Phase II was suspended on 13 July 2026; Phase I self-assessment requirements remain in force, and the Department has stated it will enforce compliance with NIST SP 800-171 Rev 2 through self-assessments and select government-led assessments during the review.

Readiness assessment services only. Virga Security does not certify compliance, is not a CMMC Third-Party Assessment Organization, does not perform assessments under any authorized assessment program, and does not guarantee any score or contract outcome.

Know your physical score before SPRS does.

Start with a Physical Readiness Scan, or go straight to a full Level 1 or Level 2 assessment.