Compliance

CMMC 2.0 Compliance Services for DoD Contractors

Cybersecurity Maturity Model Certification (CMMC) 2.0 Level 1 and Level 2 readiness for DoD primes, subcontractors, and the defense industrial base - NIST 800-171 gap assessment, SSP, POA&M, GCC High migration, and C3PAO audit support.

[ STATUS ]
24/7 SOC

Active Monitoring

Live threat intel · less than an hour response SLA · US-based senior engineers.

[ CALL ]
864-224-0008

Support · 24/7

Dial
Program Update · July 13, 2026

DoW suspends CMMC Phase II — what actually changed

On July 13, 2026, the Department of War announced the immediate suspension of CMMC Phase II requirements, originally scheduled to take effect November 10, 2026. Phase I self-assessment requirements remain firmly in place. The Department is launching a comprehensive review of CMMC to align the program with Secretary of War Pete Hegseth's Acquisition Transformation System (ATS) directives — prioritizing speed to capability, lowering barriers for small, medium, and non-traditional businesses, and replacing bureaucratic compliance with scalable, resilient cybersecurity measures. A CMMC Reform Task Force will deliver findings to the DoW CIO within 60 days.

What is suspended

  • • Third-party C3PAO assessments for CMMC Level 2
  • • All pending and future CMMC Phase II implementation milestones across DoW solicitations and contracts
  • • The November 10, 2026 Phase II effective date

What is NOT suspended

  • • CMMC Phase I — self-assessments and SPRS score submissions remain mandatory
  • • DFARS Clause 252.204-7012 — safeguarding Covered Defense Information (CDI)
  • • NIST SP 800-171 Rev 2 — the 110-control framework remains the enforcement baseline
  • • Cyber incident reporting obligations
  • • False Claims Act exposure for inaccurate SPRS scores

Before vs. after the suspension

AreaBefore suspensionAfter suspension
C3PAO assessment requirementRequired by Nov 10, 2026Suspended indefinitely
SPRS self-assessmentRequiredStill required
NIST SP 800-171 Rev 2 controlsRequiredStill required
DFARS 252.204-7012RequiredStill required
CUI protection obligationsRequiredStill required
False Claims Act exposureActiveStill active

False Claims Act exposure remains

Self-assessments now carry the full weight of enforcement. An inaccurate, inflated, or unsupported SPRS score exposes your organization and its executives to False Claims Act liability. This risk has not decreased — it has increased.

Prime flow-downs may still apply

Many primes have their own cybersecurity flow-down clauses referencing CMMC Level 2 or equivalent controls. These contractual obligations exist independently of the DoW suspension. Don't assume they changed without written confirmation.

This suspension is reversible

The 60-day Task Force review may produce a modified, streamlined, or new certification framework. Organizations that keep strong NIST 800-171 hygiene now will transition faster and cheaper than those treating this as a permanent reprieve.

Requirements at a glance

What CMMC actually asks of you

Two levels, one control framework, and a handful of platform decisions that shape the whole program.

FCI · Basic safeguards

Level 1

Contractors handling Federal Contract Information (FCI) — the everyday non-public info generated for or by the government.

Controls
17basic safeguarding requirements
Assessment
Annual self-assessment + executive affirmation in SPRS
  • Basic access control, identification, and authentication
  • Media protection and physical safeguards
  • System and communications protection basics
  • No third-party audit required
CUI · NIST 800-171 Rev 2

Level 2

Contractors handling Controlled Unclassified Information (CUI) — the sensitive-but-unclassified data behind most DoD programs.

Controls
110security controls across 14 families
Assessment
SPRS self-assessment today · C3PAO third-party assessment was scheduled for Nov 10, 2026 (currently suspended)
  • All 110 NIST SP 800-171 controls with a written SSP & POA&M
  • FIPS 140-2 validated encryption at rest and in transit
  • Continuous monitoring, audit logging, incident response
  • Typically requires a Microsoft GCC High enclave
NIST 800-171 controls
110
across 14 control families
Control families
14
AC, AT, AU, CM, IA, IR, MA, MP, PE, PS, RA, CA, SC, SI
Level 2 timeline
6–9 mo
typical, gap → audit-ready
Scope reduction
60–80%
via a properly designed CUI enclave
How to navigate this

A practical path forward — even with Phase II suspended

The C3PAO clock stopped. The controls, the DFARS clause, and the False Claims Act didn't. This is the sequence we run for clients this quarter.

Step 01

Find your CUI

Inventory where FCI and CUI actually live — email, SharePoint, OneDrive, Teams, file shares, engineering workstations, and the inboxes of the three people who forward every contract around. You can't protect what you can't name.

Step 02

Decide on an enclave

A dedicated GCC High tenant plus a scoped set of endpoints is the shortest path to Level 2 — it typically shrinks assessment scope by 60–80%. Not every organization needs it, but most do the moment CUI touches Microsoft 365.

Step 03

Write a real SSP

The System Security Plan is where CMMC engagements live or die. Every one of the 110 NIST 800-171 controls needs a named implementation, an owner, and an evidence reference. Anything you can't do yet goes on the POA&M.

Step 04

Submit an honest SPRS score

Your SPRS score is the DoW's primary enforcement lever right now. Executive affirmation of an inflated score is the exposure that becomes a False Claims Act case. Score what you actually do — then close the gaps on a plan.

A closer look at GCC High

Microsoft Government Community Cloud High is the Microsoft 365 tenant tier built to meet DoD and DFARS 252.204-7012 requirements for handling CUI. Commercial and GCC do not meet the FedRAMP Moderate equivalency bar for CUI — GCC High does. It's a separate tenant with its own licensing, its own service endpoints, and a mandatory tenant-to-tenant migration. Hover the term anywhere on this page for the short definition; get in touch when you're ready to scope the migration.

Become CMMC Level 2 audit-ready and stay there

CMMC 2.0 is no longer optional for organizations handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). DFARS 252.204-7012 flow-down clauses are reaching subs faster than ever, and primes are increasingly requiring CMMC Level 2 attestation before contract award.

We deliver the System Security Plan (SSP), Plan of Action & Milestones (POA&M), and supporting evidence a C3PAO will actually accept - plus the technical controls (FIPS 140-2 encryption, MFA, audit logging, incident response) that pass the assessment instead of just passing the paperwork.

What's included

Everything in this service. Nothing buried in fine print.

  • NIST SP 800-171 Rev. 2 gap assessment (all 110 controls)
  • System Security Plan (SSP) authoring and maintenance
  • Plan of Action & Milestones (POA&M) development and tracking
  • FIPS 140-2 validated encryption deployment
  • Microsoft GCC High tenant migration and management
  • CUI enclave design and segmentation
  • Identity, MFA, and access remediation ( GCC High)
  • C3PAO assessment support and joint surveillance
  • Annual self-attestation (Level 1) prep
  • Supply chain and ESP (External Service Provider) management
[ Scope & data ]

Defining your CUI boundary before you spend a dollar on tooling

Most failed CMMC programs spend money before they scope. We start every engagement by inventorying where Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) actually live - across email, file shares, SharePoint, OneDrive, Teams, line-of-business apps, engineering workstations, and the inboxes of the three people who get all the contracts forwarded to them.

From that data flow we design a CUI enclave (typically Microsoft GCC High plus a dedicated subset of endpoints), shrinking your assessment scope by 60–80% and dramatically lowering both initial remediation and ongoing operating cost.

  • FCI // CUI // CDI data discovery
  • Asset and System Boundary diagrams
  • Microsoft GCC High enclave design
  • Engineering workstation scoping
  • Email and file-share segregation
[ SSP, POA&M, and evidence ]

The documentation a C3PAO actually wants to see

Authoring a credible System Security Plan (SSP) is the single biggest stumbling block for organizations approaching their first CMMC Level 2 assessment. We deliver a control-by-control SSP that maps every NIST 800-171 requirement to the specific technology, policy, and procedure that implements it, with named control owners and evidence references - not generic templates.

The Plan of Action & Milestones (POA&M) tracks every open gap with risk rating, target date, owner, and acceptance authority. Both documents are kept living, with quarterly review built into our managed-service cadence.

[ C3PAO assessment ]

Getting through your triennial third-party assessment

When the C3PAO arrives, we sit in. We coordinate evidence collection ahead of time, walk auditors through control implementation, defend the SSP narrative, and own the response to any findings - including writing remediation plans for items that need to land in the post-assessment POA&M.

[ Industry use cases ]

How different industries put this service to work

Every regulated and growth-stage business we support has a slightly different reason for engaging this service. The common thread is that the risk, downtime, or compliance cost of doing nothing is now bigger than the cost of a specialized partner.

  • Healthcare and behavioral health groups protecting PHI under HIPAA and the HHS cybersecurity performance goals
  • Financial services, RIAs, and CPAs meeting FTC Safeguards, SEC, and state privacy requirements
  • Manufacturers and defense suppliers preparing for CMMC 2.0 Level 1 and Level 2 assessments
  • Law firms and professional services protecting client confidentiality and privileged data
  • K-12, higher education, and public sector agencies defending student and constituent data
  • Construction, real estate, and multi-site retail keeping distributed teams online and secure
[ Buyer checklist ]

What good looks like when you evaluate providers

Not every provider that lists this service on their website actually delivers it well. Use the checklist below when you shortlist partners so you can compare apples to apples and avoid the two most common traps: a low sticker price that hides scope gaps, and a polished sales cycle backed by an offshore delivery team you never meet.

If a prospective provider cannot answer these questions plainly and in writing, treat that as a signal. The right partner will welcome the scrutiny.

  • Written SLAs with response and resolution targets, not just uptime
  • Named senior engineers assigned to your account, not a shared queue
  • US-based delivery with clear escalation paths and named leadership
  • Transparent monthly reporting with metrics leadership actually cares about
  • Security-first defaults: MFA, least privilege, and monitored change control
  • Alignment to your compliance framework, not a generic template
  • A real onboarding plan with milestones, not just a handoff email
How it works

A predictable path from chaos to control

We don't just patch problems. We build a managed environment that stays solved.

01

Gap assessment

Map your current state against the framework and rank every control gap by risk.

02

Remediation

Engineers close the gaps with documented technical and policy controls.

03

Evidence

Continuous evidence collection feeds your audit folder all year long.

04

Audit support

We sit in with assessors and answer questions on your behalf.

FAQ

Questions we hear a lot

Get started

Ready to make IT a strategic advantage?

Get a 30-minute call with our sales or support team. No pitch. Just a real assessment of where your IT and security stand today.