MSSP, Governance, Risk and Compliance, SOC, Compliance Management

C3’s Bill Wootton: “Most MSPs don’t recognize what CMMC requires”

CMMC has made cybersecurity a much more everyday part of running a defense contractor environment. The systems have to be set up and secured the right way, and the documentation has to reflect what is actually happening in practice.

That pulls a lot of things into the same conversation, from managed IT and security operations to compliance, assessments, data sovereignty and staffing. For MSPs and MSSPs, the challenge is making sure all of those pieces stay connected as they support the customer.

C3 Integrated Solutions has built its model around bringing them together. The company works with organizations in the defense industrial base, combining managed IT, managed security, and compliance around the same customer environment.

Bill Wootton, co-founder and chief growth officer at C3 Integrated Solutions, said one of the biggest challenges is that MSPs may underestimate how much CMMC affects the way managed services themselves have to be delivered.

“What most MSPs don't recognize is how much of their processes need to not only be supportive of the client, but map to the compliance requirements as well,” Wootton said. That means configuration, monitoring, security operations and documentation all have to stay aligned with what the customer says it is doing.

Generalist MSPs often struggle with CMMC

Wootton said the company starts with a prescriptive reference architecture that guides how customer environments are built, managed, monitored and documented.

“For us, it starts with a foundation in the reference architecture that we deploy to our clients,” Wootton said.

Under CMMC, the documentation needs to reflect what is actually happening in the customer’s environment. The controls described on paper need to be supported by how systems are configured, monitored and managed in practice.

That is also where NIST 800-171 comes into the picture. The requirements touch everything from how the environment is scoped and configured to how controls are managed and documented over time. The tools are only one piece of it. How those tools are operated, and what evidence they produce, becomes part of the compliance process.

For MSPs used to managing commercial IT environments, that can require a different approach. Monitoring, security operations and compliance work become closely connected because the day-to-day work of managing the environment can ultimately help show whether the customer is doing what its documentation says it is doing.

C3 Command and Catalyst split the work differently

C3 has built two primary offerings around that model, Command and Catalyst.

Command is designed for organizations that want to outsource most of the technical and compliance work. C3 provides the reference architecture, tooling, Microsoft environment, managed IT services, security monitoring, and compliance documentation.

Wootton said many customers come to C3 specifically because they want to hand off as much of that work as possible.

“Many clients come to us and want to outsource as much as possible of this challenge with CMMC,” he said.

Under Command, C3 said it can support more than 80% of the 320 CMMC assessment objectives. Requirements involving areas such as physical security and background checks remain with the customer.

Catalyst is more collaborative and uses the same underlying architecture, management and monitoring model but allows customers to work with another consultant on documentation and compliance management.

“Command does everything,” Wootton said. “Catalyst is more of a collaborative solution with other industry partners.”

That gives customers two ways to work with C3, depending on how much of the CMMC process they want to hand off and whether they already have a consultant involved.

Why C3 sought its own CMMC Level 2 certification

Service providers supporting defense contractors can also become part of the assessment conversation. Wootton said the final CMMC rule does not require every service provider to hold its own CMMC certification. But when a third party is handling customer systems or data, assessors may still look at how that provider operates.

C3 has completed its own CMMC Level 2 assessment. Wootton said having that certification can reduce some of the uncertainty for customers when an assessor starts examining third-party providers.

“When you have the CMMC level 2 certification, generally the assessor stops asking questions,” Wootton said.

Assessors still have discretion to look further if they choose, he said. The certification does not necessarily remove the service provider from scrutiny, but it can reduce another area of risk for the customer.

A defense-focused SOC comes with different requirements

Those same CMMC requirements also shape how C3 runs its SOC.

Data sovereignty is a big part of that. Many of C3’s customers need their data to stay in the United States and be accessed only by U.S. persons, which directly affects where the SOC operates and who can handle customer information.

“First and foremost, completely US-based,” Wootton said.

The other piece is making sure the SOC is doing what the customer’s compliance documentation says it is doing. During a CMMC assessment, assessors look at the System Security Plan and compare it with what is actually happening in the environment. That means monitoring, configuration changes and security controls all have to line up with what has been documented.

“The documentation says six, are you doing six?” Wootton said. “And that's the critical piece for that tie-in to the documentation.”

For MSSPs supporting defense contractors, that makes compliance part of the everyday security operation. The SOC, the environment and the documentation all have to stay in sync.

The recent CMMC pause has not stopped customer work

The Pentagon’s recent pause on the expansion of Phase 2 assessments has raised another question for defense contractors and their service providers: whether organizations will slow down CMMC work while the program is under review.

Wootton said that has not been the reaction C3 is seeing from most customers.

“Most of our clients and even a lot of our clients in this pre-sale cycle have come back and said, we understand this needs to happen,” he said. “It's the right thing to do. We wanna move forward.”

He also pointed to continued references to NIST 800-171 Revision 2 in Defense Department communications, which he sees as an indication that the underlying security requirements remain part of the direction for the defense industrial base.

What happens with the assessment process itself could still change. The immediate issue for MSPs is that defense contractors still have security requirements to address, regardless of how the assessment timeline changes.

C3 is building its own SOC talent pipeline

That operational focus also extends to staffing. C3 runs a SOC Analyst Internship Program that started at Ingalls Information Security, a Louisiana-based company that merged with C3 in 2023.

Cyrus Robinson, SVP of Security Operations at C3, said the program grew out of his experience trying to build a cybersecurity career in Louisiana, where there were few opportunities to gain practical security experience.

Robinson said the gap isn't interest - it's access to real experience. “There is no shortage of people interested in cybersecurity; the shortage is in candidates who have been given the chance to develop practical experience,” Robinson said.

Interns work with the same tools, processes, investigations and workflows they would encounter in a full-time SOC role. That gives them experience working through security issues in a production environment while also giving C3 a pool of entry-level candidates who already understand its operations.

Robinson said technical knowledge alone is not enough. Analysts also have to gather evidence, determine what happened, assess risk, document their reasoning and communicate with customers.

“We have also found that strong SOC analysts come from many backgrounds, and qualities like communication, curiosity, resilience, empathy and composure under pressure can be just as important as technical knowledge,” he said.

"Crawl, Walk, Run” model

The program follows what C3 calls a “Crawl, Walk, Run” model. Interns begin by shadowing Tier 1 analysts. They then move into reverse shadowing, where they perform the work with guidance. Eventually, they receive their own client assignments with appropriate supervision.

“We do not view interns as inexpensive labor or place them into operational situations without appropriate support; the objective is development through meaningful work, mentorship, feedback and increasing responsibility,” Robinson said.

There is also a benefit for experienced analysts. Having to explain how they investigate an event, why they make certain decisions and how they reach a conclusion forces them to be more deliberate about their own processes.

C3 is now extending the model beyond traditional student internships. Robinson said the company recently started a cohort through the DoW SkillBridge program for active-duty military members preparing to transition into the commercial workforce.

The company is also working with universities, industry mentors, guest speakers and DEF CON communities and has shared parts of its internship model with other organizations in Louisiana.

“Some interns will build long-term careers at C3, while others may take what they learned into another SOC, government service or another part of the cybersecurity industry, and we consider both outcomes successful,” Robinson said.

For MSSPs, the program gets at a workforce problem that hiring alone does not solve. Analysts need technical skills, but they also need experience making decisions in live customer environments.

AI is being used with a human in the loop

C3 is also looking at where AI and automation can take some of the repetitive work out of security operations while keeping analysts involved in the decisions that require judgment.

“AI is used to supplement the practices and the skills and the processes that we have today,” Wootton said.

For C3, that means using AI within existing SOC workflows rather than handing the work over entirely. “It's always critical that we keep a human in the loop as part of that process,” Wootton said.

When alerts need to be investigated before they reach the customer, this become important. Wootton said the goal is to understand what happened and determine what actually matters rather than simply passing more alerts downstream. AI can help analysts get through that work, but people still have to make the judgment calls and communicate the findings clearly.

That also connects back to C3’s focus on developing SOC talent. As more routine work becomes automated, analysts still need the experience and judgment to investigate incidents, make decisions and explain those decisions to customers.

For C3, those pieces all feed into the larger challenge of serving the defense industrial base, where security operations, compliance requirements and the people managing them have to stay aligned.

“The market to protect our defense industrial base is just getting started,” Wootton said.


Suparna Chawla Bhasin

Suparna is the Senior Managing Editor for CyberRisk Alliance’s Channel Brands, including MSSP Alert and ChannelE2E. She manages content development, sharpens editorial workflows, and ensures storytelling is tightly aligned with audience needs. With a background in technology, media, and education, she combines strategic insight with creative execution.

You can skip this ad in 5 seconds