A security program that only lives in someone's head isn't a program — it's a liability. We build the policies, procedures, and documentation that make yours auditable, defensible, and ready for any regulator or board, including our signature CMMC 2.0 and CUI physical readiness work below.
Policies written by the people they govern rarely survive an outside audit, and most compliance consultants have never assessed a physical security control in the field. Virga's governance work is built on real federal audit experience — the kind regulators and primes actually recognize.
Policy documents that sit in a drive nobody opens don't help you in a review. We build governance your organization actually runs on.
Written to match how your organization actually operates, not copied from a template that assumes a facility you don't have.
SSP control narratives that map directly to the requirements your environment answers to — drafted, not just outlined.
Identifying which frameworks actually apply — NIST 800-53, NIST 800-171, RMF, CISA guidance, sector-specific rules — and reconciling the conflicts between them.
Documentation built to hold up under a real review, not just to look complete in a binder.
Roles, accountability, and review cadence — who owns the program, and how it stays current as your environment changes.
Findings and posture translated into language a board, prime contractor, or contracting officer can act on.
Thirty-one of the 110 weighted points in a CMMC Level 2 self-assessment depend on physical security — and twenty-six of them cannot be placed on a POA&M. In most organizations that scope gets assessed by someone whose expertise is networks.
A Level 2 self-assessment starts at 110 and subtracts a weighted value for every requirement not fully implemented. The resulting score goes to SPRS, where contracting officers check it before award. Here is the portion that lives in your building rather than on your network — and which of it can be deferred.
| Practice | Requirement | Points | POA&M? |
|---|---|---|---|
| Physical Protection family | |||
| PE.L2-3.10.1 | Limit physical access to systems, equipment, and operating environments | 5 | No |
| PE.L2-3.10.2 | Protect and monitor the facility and its support infrastructure | 5 | No |
| PE.L2-3.10.3 | Escort visitors and monitor visitor activity | 1 | Yes |
| PE.L2-3.10.4 | Maintain audit logs of physical access | 1 | Yes |
| PE.L2-3.10.5 | Control and manage physical access devices | 1 | Yes |
| PE.L2-3.10.6 | Safeguard CUI at alternate work sites | 1 | Yes |
| Requirements that cannot be met without physical evidence | |||
| MA.L2-3.7.6 | Supervise maintenance personnel without required access authorization | 1 | Yes |
| MP.L2-3.8.1 | Protect system media containing CUI — paper and digital | 3 | No |
| MP.L2-3.8.2 | Limit access to CUI on media to authorized users | 3 | No |
| MP.L2-3.8.3 | Sanitize or destroy media before disposal or reuse | 5 | No |
| PS.L2-3.9.2 | Protect CUI during and after terminations and transfers | 5 | No |
| Total points in the physical domain | 31 | ||
| Of which cannot be placed on a POA&M | 26 | ||
To achieve a Conditional Level 2 status, 32 CFR § 170.21 requires that no security requirement on your POA&M carries a point value greater than 1 — the only exception being encryption that is employed but not FIPS-validated.
Every 3-point and 5-point requirement above therefore has to be fully implemented, with final evidence, at the time of assessment. There is no remediate-later pathway for any of them. And under § 170.24, a POA&M is not a substitute for a completed requirement in any case — a requirement not implemented is assessed NOT MET whether or not it appears on one.
Scored against NIST SP 800-171 Revision 2 — the revision incorporated by reference in 32 CFR Part 170 for CMMC Level 2, and the revision the Department confirmed it is enforcing during the current pause in Phase 1. Revision 3 is included in every report as forward-looking design guidance, not as a scoring basis — so you do not rebuild your program around requirements that are not yet assessed.
Most internal security teams and compliance consultants are built around network controls. The physical evidence behind these eleven requirements — badge logs, media destruction records, boundary construction — falls outside their usual scope entirely. This work sits at the intersection of federal physical-security standards and NIST SP 800-171A assessment methodology, the same combination DoD and DHS facilities are held to — not a generalist audit.
Level 1 covers Federal Contract Information and consists of the fifteen basic safeguarding requirements at FAR 52.204-21(b)(1). Three of the fifteen are physical or media requirements, carrying twelve assessment objectives between them.
4 objectives · NIST 3.10.1
Authorized individuals identified; physical access to systems, equipment, and operating environments limited to them.
6 objectives · NIST 3.10.3–.5
Visitors escorted and monitored; audit logs of physical access maintained; access devices identified, controlled, and managed.
2 objectives · NIST 3.8.3
Media containing FCI sanitized or destroyed before disposal, and sanitized before release for reuse.
Under 32 CFR § 170.24(c)(1), all Level 1 requirements must be fully implemented to be considered MET, no POA&M is permitted, and results are scored MET or NOT MET in their entirety. A single assessment objective scored NOT MET fails the whole requirement.
In practice that means a key inventory nobody maintains, or a visitor log that records arrival but not escort or areas accessed, is enough to fail the self-assessment — and without a current status in SPRS, you are not eligible for award.
Level 1 is graded MET or NOT MET in its entirety — a single missed objective fails the whole requirement, and grading your own visitor log or key inventory is exactly the blind spot an independent assessor exists to catch. Virga brings the same physical-security assessment discipline used at federal facilities, from someone with no stake in telling you what you want to hear.
Our on-site review goes past the policy binder — into the physical evidence, the access records, and the areas your CUI actually touches. The result is scored against every requirement and delivered as a single evidence package, not a memo.
Posture, point exposure, and recommended sequence, written for a decision-maker.
Every requirement with its CMMC practice ID, status, point value, and POA&M eligibility.
Recommendations tied to each requirement, with every POA&M-ineligible item flagged must-close-before-assessment.
Drafted language for the physical sections of your System Security Plan.
Zones, boundaries, enforcement points, and gaps, marked on your own drawing.
Findings explained in plain language, with your questions answered on the spot, not weeks later.
Document review and a guided virtual walkthrough. Scored gap register, your five most material findings, and a remediation cost band.
All twelve assessment objectives across the three physical and media requirements, per NIST SP 800-171A methods. Objective-by-objective determination with an evidence index.
One to two days on site, then full analysis and reporting. Delivers the complete evidence package including the annotated floor plan and SSP narratives. Additional sites available.
Turns findings into an operating program: policies, procedures, registers, zone and boundary design, vendor-neutral specifications, and a closeout evidence package.
Point values and Level 1 scoring — 32 CFR § 170.24, CMMC Scoring Methodology.
POA&M eligibility — 32 CFR § 170.21, Plan of Action and Milestones requirements.
Level 1 requirements — FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems, and the CMMC Assessment Guide – Level 1.
Level 2 requirements — NIST SP 800-171 Rev 2, with assessment objectives from NIST SP 800-171A.
Underlying contractual obligation — DFARS 252.204-7012.
Current program status — DoD CIO CMMC program page. CMMC Phase II was suspended on 13 July 2026; Phase I self-assessment requirements remain in force, and the Department has stated it will enforce compliance with NIST SP 800-171 Rev 2 through self-assessments and select government-led assessments during the review.
Readiness assessment services only. Virga Security does not certify compliance, is not a CMMC Third-Party Assessment Organization, does not perform assessments under any authorized assessment program, and does not guarantee any score or contract outcome.
Start with a Physical Readiness Scan, or go straight to a full Level 1 or Level 2 assessment.