CMMC advisory · Defense Industrial Base

Know exactly what CMMC Level 2 will take.

Built in — not bolted on.

We help defense contractors figure out whether CMMC applies, what level you actually need, and the shortest practical path to get there — scoped to the contracts you hold, not a stack of tools and licenses you may never use. The Department paused the November 2026 Phase 2 deadline for a 60-day review — Phase 1 self-assessment and your DFARS safeguarding obligations haven’t moved. We’ll show you what it means for your shop and where to start.

Independent. We prep you, never assess you.
Built for small shops. Owner‑operators with no internal IT.
Led by a Cyber AB RPA. Registered Practitioner Advanced.
CMMC update · July 2026

Phase 2 is paused. Your obligations aren’t.

On July 13, 2026, the Department of Defense suspended the November 10, 2026 transition to CMMC Phase 2 — the milestone that would have made third‑party Level 2 certification a standard contract requirement — and opened a 60‑day review of the program. This is not a cancellation of CMMC.

Phase 1 self‑assessment requirements are still in force. NIST SP 800‑171 Rev 2 is still the standard the Department expects you to meet, enforced through self‑assessment and select government‑led reviews. Your DFARS 252.204‑7012 obligation to safeguard covered defense information hasn’t moved. The goal was never the certificate — it’s keeping contract information out of the hands of people who want it. That goal hasn’t changed.


Paused
Nov 10, 2026 Phase 2 transition and mandatory third‑party Level 2 certification

Still in effect
Phase 1 self‑assessment, NIST SP 800‑171 Rev 2, and DFARS 252.204‑7012 safeguarding

If you were racing toward a November certification deadline, you now have room to build your program right instead of rushing it. This is exactly where a Registered Practitioner earns their keep: reading what changed, scoping what still applies to you, and making sure the self‑assessment score you submit to SPRS is one you can defend if the government asks. We’re watching the 60‑day review and will update this page as the rules take shape.

Is this you?

If any of these sound familiar, you’re in the right place.

  • A customer or prime told us we need CMMC
  • We handle CUI and aren’t sure what that obligates
  • We don’t know whether we’re Level 1 or Level 2
  • We’re already ISO 27001 certified and want to reuse that work
  • We have policies or an SSP but don’t know if they’d pass
  • We’re not sure whether GCC High applies to us
  • We need to be certified inside 12 months
  • We’ve started CMMC already and feel stuck
Check one or more and we’ll map the fastest, lowest‑cost path from where you actually are.

The model

Five steps. One clean path to certified.

You start where your maturity puts you and move at the depth you choose. We own four of them. The fifth, the assessment itself, goes to an independent C3PAO we don’t profit from. That separation is what keeps your certification clean.

01 / Assess

Scope & Gap Assessment

We map your CUI, find every gap against the controls, and hand you a prioritized POA&M.
Scoped pricing

02 / Remediate

Advisory subscription

We design the fixes and write the policies. Your team or an MSP partner does the hands-on build, at a pace you can sustain.
Monthly

03 / Prep

Assessment Readiness

We rehearse the audit so you present evidence the way assessors expect to see it.
Scoped pricing

04 / Certify

Independent C3PAO

We refer you to an independent assessor from our list. No fee to us for the handoff.
Independent

05 / Sustain

Sustainment plan

Annual affirmations, SPRS upkeep, POA&M tracking, and triennial reassessment prep.
Monthly

Where are you today?

Find your starting line.

Match where you actually are to the right first move. Wherever you start, the path ends the same way — an independent C3PAO assessment we take no fee from.

You’re new to CMMC and not sure it even applies to you
Free 30‑minute fit call
Pin your level & scope · no cost
Book it →
You know you need Level 2, but nothing’s documented yet
L2 Scope & Gap Assessment
Starting at $7,500
Start here →
You’ve got some policies in place and you’re mid‑build
Advisory subscription
Starting at $1,200/mo · pick your level of help
Compare plans →
You’ve built your controls and written an SSP
Assessment Readiness & Coaching
Starting at $6,500 · rehearse the audit
Get ready →
You’re already certified and need to stay that way
Sustainment plan
Starting at $850/mo · affirmations, SPRS, reassessment
Stay compliant →
Start here

Scope & Gap Assessment

Scoped pricing, fast turnaround, and the deliverables are yours to keep whether or not you continue with us. It’s the honest first step: you can’t fix what you haven’t measured.

What you walk away with

  • CUI / FCI scope and data‑flow map
  • Asset and system inventory within scope
  • Gap register against the relevant controls (15 for Level 1, 110 for Level 2)
  • Draft POA&M with a prioritized remediation order
  • Written plan recommendation and a rough timeline
We credit 50% of the assessment fee toward your first two months if you subscribe within 30 days.

Already built to NIST 800-171, ISO 27001, or SOC 2? The assessment maps what carries over, so you only build what’s missing.

starting at $2,500
L1 Readiness Snapshot
FCI · 15 requirements
starting at $7,500
L2 Scope & Gap Assessment
110 requirements
Remediation subscription

Pick the level of help that fits.

Your gap assessment tells us where you stand. From there, the right plan comes down to how much you want us in the work and how much your team can carry.

Priced in advisory sessions per month. A session is a focused 90‑minute working block on a named deliverable (policy review, control walkthrough, evidence review), plus async Q&A between sessions.
Guided
Starting at $1,200 / month
2 sessions/mo · 2 business‑day replies
  • Policy & template library
  • Monthly progress check‑in
  • You keep your POA&M; we direct the work
  • Best for a team with time to do the work

Book a fit call
or subscribe directly →

Most chosen

Partnered
Starting at $2,800 / month
4 sessions/mo · 1 business‑day replies
  • Everything in Guided
  • POA&M tracked with you
  • Monthly roadmap + quarterly report
  • Partner referrals coordinated
  • Best for most small contractors

Book a fit call
or subscribe directly →

Managed
Starting at $5,500 / month
8 sessions/mo · next business‑day replies
  • Everything in Partnered
  • We co‑maintain your SSP and POA&M
  • MSP partner work managed end‑to‑end
  • Priority scheduling + bundled coaching
  • Best for owner‑operators with no IT staff

Book a fit call
or subscribe directly →

Annual billing: pay 10 months, get 12.
Assessment readiness

Technically compliant isn’t the same as ready to be assessed.

Plenty of contractors build the controls and then walk into the C3PAO engagement unsure how an assessment runs or how to present what they’ve done. How you present can decide a pass as much as what you built. We rehearse it with you first.

starting at $6,500
Assessment Readiness & Coaching
starting at $2,500
Evidence & Interview Mini‑Review
Why we’re different

We don’t sell you tools. We tell you which ones you actually need.

Most CMMC help starts with a product to sell — a license bundle, a managed‑security contract, an enclave you may not need. We start somewhere cheaper for you: what your contracts actually require. From there we scope only the controls and technology that get you certified, and the technical build goes to your own IT team or an MSP partner. You spend less, finish sooner, and walk into the assessment with nothing bolted on for show.


Lower cost
Build only what the contract requires

Faster to assessment
No detours through tools you don’t need

Less disruption
Your stack, changed as little as possible
How the work divides

You’re hiring strategists, not an IT department.

We help your team decide exactly what to build and document. The technical heavy lifting: firewalls, MDM, enclaves, SIEM and SOC, stays with your own IT team or your MSP/MSSP. If you need it, we can match you to the right partner for your environment and we’ll help with managing the tech stack to meet your needs while complying with the requirements of the Standard.

We take no money from assessors.

We prepare you, then hand you to an independent C3PAO we don’t profit from. You choose from a short list of independent assessors. That separation isn’t a nicety; under the Code of Professional Conduct it’s what keeps your certification defensible.

Talk to us

Stage 05 · Already certified

Sustainment plan

Certification isn’t the finish line. Keep your affirmations, SPRS entries, POA&M, and reassessment prep current without thinking about it.

starting at $850 / mo

Stay compliant

Not sure where you stand? Start with a free 30‑minute fit call.

We’ll figure out your level, your timeline, and the right first step. No pressure to subscribe.

Book your free fit call

SECTION 07 / FAQ

Questions, answered

CMMC facts and how we work — verified, no fluff.

CMMC basics

What is CMMC, and does it apply to me?
The Cybersecurity Maturity Model Certification is the Defense Department’s program for verifying that contractors protect federal contract information (FCI) and controlled unclassified information (CUI). If you’re in the defense supply chain and touch either — prime or sub — it applies to you.
What are the CMMC levels?
Three. Level 1 covers 15 basic requirements for FCI, with an annual self-assessment. Level 2 covers all 110 NIST SP 800-171 (Rev 2) requirements for CUI. Level 3 adds requirements from NIST SP 800-172 for the highest-priority programs. Most DIB contractors handling CUI are aiming at Level 2.
Did the July 2026 announcement cancel CMMC?
No. On July 13, 2026, the Department suspended the November 10, 2026 transition to Phase 2 — the milestone that would have made Level 2 third-party certification a standard contract requirement — and opened a 60-day review. Phase 1 self-assessment stays in place, NIST SP 800-171 Rev 2 enforcement continues through self-assessment and select government-led reviews, and DFARS 252.204-7012 safeguarding obligations haven’t changed. We’re tracking the review and will update this page as details firm up.
When do I actually need to be ready?
The rule that puts CMMC into contracts took effect November 10, 2025, so requirements are already appearing in new solicitations. The Department has since paused the November 10, 2026 Phase 2 transition for a 60-day reform review, so that date is no longer a hard trigger for third-party certification. Phase 1 self-assessment is required now, and if a contract you’re pursuing lists certification as a requirement, confirm current status with the contracting office rather than assuming the old timeline still applies.
Level 2 specifics

What does a Level 2 assessment involve?
An accredited C3PAO evaluates your environment against all 110 requirements, broken into 320 assessment objectives across 14 domains. Certification lasts three years, with an annual affirmation in between.
Can I self-assess for Level 2?
Some Level 2 contracts allow self-assessment; those involving prioritized acquisitions and critical information require a C3PAO. Assume you’ll need third-party certification unless a specific contract says otherwise.
What if I’m not at 100% by assessment day?
You can earn a Conditional status by scoring at least 80% and putting the remaining items on a POA&M — but those items must be closed and verified within 180 days to reach Final status. A handful of requirements can’t be deferred at all.
Isn’t CMMC moving to NIST 800-171 Rev 3?
Assessments today are still against Rev 2. DoD has said it will transition to Rev 3 through future rulemaking, so it’s not the current standard — but it’s worth building your program in a way that won’t break when it changes.
How we work

What does Comply-By-Design actually do?
We prepare you for assessment: scoping, gap analysis, remediation guidance, evidence and interview coaching. We get you ready to pass — we don’t run the certification assessment itself.
You mention independence. What does that mean?
We take zero fees from C3PAO assessors, and no assessor pays us for referrals. That keeps our advice pointed at your outcome, not a relationship. It’s the core of how we operate — it’s published, not just promised.
Can you guarantee I’ll pass?
No one honestly can, and anyone advising you can’t also assess you. What we can do is get your scope, controls, and evidence in the shape assessors expect, so there are no surprises on assessment day.
Getting started

Where do I start?
Most clients begin with the L2 Scope & Gap Assessment (starting at $7,500) — a scoped front door that maps where you stand against all 110 requirements. Half of it credits toward a subscription if you continue.
What are the ongoing tiers?
After the entry assessment, three subscriptions match your pace: Guided (starting at $1,200/mo), Partnered (starting at $2,800/mo), and Managed (starting at $5,500/mo). Once you’re certified, Sustainment (starting at $850/mo) keeps you audit-ready between cycles.