CMMC Level 2 Readiness for Thomson Reuters Special Services

Get a Quote
The Project

Overview

Thomson Reuters Special Services (TRSS), founded in 2008 and headquartered in McLean, Virginia, delivers data, analytics, and mission support to national security and law enforcement customers. That mission puts Controlled Unclassified Information in scope and CMMC Level 2 on the contract path. TRSS engaged BD Emerson to define the CUI boundary, build a compliant enclave, author the System Security Plan, and organize the evidence a certified assessor examines. The program carried TRSS from scoping to assessment-ready, validated along the way by an independent pre-assessment.
Partnership

BD Emerson x 

Thomson Reuters Special Services

Challenge

CMMC Level 2 requires an organization to implement the 110 security requirements of NIST SP 800-171 and prove it to a certified third-party assessor, a C3PAO. For TRSS, the practical question was scope. Running every corporate system through a CMMC assessment would have multiplied cost and drag without improving the protection of Controlled Unclassified Information. TRSS needed a defined boundary where CUI lives, an environment built to hold it, and documentation that maps each of the 320 assessment objectives to something an assessor can verify.

Solution

BD Emerson scoped the CUI boundary first, then built the environment to match it: an Azure Government enclave engineered for the 800-171 control set, so the assessment surface is the enclave rather than the entire company. With the boundary fixed, the team authored the System Security Plan control by control, using the Paramify platform to structure the SSP and correcting default control statements where they drifted from the assessment objectives. Gaps went onto a Plan of Action and Milestones with owners and dates, and evidence was collected against each objective as controls came online. An independent firm ran a pre-assessment against the draft SSP, which confirmed the approach and sharpened the remaining items.

BD Emerson is not a C3PAO, and does not need to be. The certification assessment belongs to an independent assessor, which is exactly why the engagement was built around what that assessor will test.

Conclusion

TRSS now holds an assessment-ready CMMC Level 2 posture: a defensible CUI boundary, an Azure Government enclave built for the control set, a complete SSP, a managed POA&M, and evidence organized by assessment objective. When the C3PAO arrives, the work is already in the shape the assessment demands.

Industry
National Security Data & Analytics
Location
McLean, Virginia, USA
Company size
201-500
Founded
2008
Certificates

Our accreditations

At BD Emerson, we believe that our team's extensive certifications not only set us apart but also ensure that we provide the highest level of service to our clients.