Know exactly what CMMC Level 2 will take.
Built in — not bolted on.
We help defense contractors figure out whether CMMC applies, what level you actually need, and the shortest practical path to get there — scoped to the contracts you hold, not a stack of tools and licenses you may never use. The Department paused the November 2026 Phase 2 deadline for a 60-day review — Phase 1 self-assessment and your DFARS safeguarding obligations haven’t moved. We’ll show you what it means for your shop and where to start.
Built for small shops. Owner‑operators with no internal IT.
Led by a Cyber AB RPA. Registered Practitioner Advanced.
Phase 2 is paused. Your obligations aren’t.
On July 13, 2026, the Department of Defense suspended the November 10, 2026 transition to CMMC Phase 2 — the milestone that would have made third‑party Level 2 certification a standard contract requirement — and opened a 60‑day review of the program. This is not a cancellation of CMMC.
Phase 1 self‑assessment requirements are still in force. NIST SP 800‑171 Rev 2 is still the standard the Department expects you to meet, enforced through self‑assessment and select government‑led reviews. Your DFARS 252.204‑7012 obligation to safeguard covered defense information hasn’t moved. The goal was never the certificate — it’s keeping contract information out of the hands of people who want it. That goal hasn’t changed.
Paused
Nov 10, 2026 Phase 2 transition and mandatory third‑party Level 2 certification
Still in effect
Phase 1 self‑assessment, NIST SP 800‑171 Rev 2, and DFARS 252.204‑7012 safeguarding
If you were racing toward a November certification deadline, you now have room to build your program right instead of rushing it. This is exactly where a Registered Practitioner earns their keep: reading what changed, scoping what still applies to you, and making sure the self‑assessment score you submit to SPRS is one you can defend if the government asks. We’re watching the 60‑day review and will update this page as the rules take shape.
If any of these sound familiar, you’re in the right place.
- A customer or prime told us we need CMMC
- We handle CUI and aren’t sure what that obligates
- We don’t know whether we’re Level 1 or Level 2
- We’re already ISO 27001 certified and want to reuse that work
- We have policies or an SSP but don’t know if they’d pass
- We’re not sure whether GCC High applies to us
- We need to be certified inside 12 months
- We’ve started CMMC already and feel stuck
Five steps. One clean path to certified.
You start where your maturity puts you and move at the depth you choose. We own four of them. The fifth, the assessment itself, goes to an independent C3PAO we don’t profit from. That separation is what keeps your certification clean.
Scope & Gap Assessment
We map your CUI, find every gap against the controls, and hand you a prioritized POA&M.
Scoped pricing
Advisory subscription
We design the fixes and write the policies. Your team or an MSP partner does the hands-on build, at a pace you can sustain.
Monthly
Assessment Readiness
We rehearse the audit so you present evidence the way assessors expect to see it.
Scoped pricing
Independent C3PAO
We refer you to an independent assessor from our list. No fee to us for the handoff.
Independent
Sustainment plan
Annual affirmations, SPRS upkeep, POA&M tracking, and triennial reassessment prep.
Monthly
Find your starting line.
Match where you actually are to the right first move. Wherever you start, the path ends the same way — an independent C3PAO assessment we take no fee from.
Scope & Gap Assessment
Scoped pricing, fast turnaround, and the deliverables are yours to keep whether or not you continue with us. It’s the honest first step: you can’t fix what you haven’t measured.
What you walk away with
- CUI / FCI scope and data‑flow map
- Asset and system inventory within scope
- Gap register against the relevant controls (15 for Level 1, 110 for Level 2)
- Draft POA&M with a prioritized remediation order
- Written plan recommendation and a rough timeline
Already built to NIST 800-171, ISO 27001, or SOC 2? The assessment maps what carries over, so you only build what’s missing.
FCI · 15 requirements
110 requirements
Pick the level of help that fits.
Your gap assessment tells us where you stand. From there, the right plan comes down to how much you want us in the work and how much your team can carry.
- Policy & template library
- Monthly progress check‑in
- You keep your POA&M; we direct the work
- Best for a team with time to do the work
- Everything in Guided
- POA&M tracked with you
- Monthly roadmap + quarterly report
- Partner referrals coordinated
- Best for most small contractors
- Everything in Partnered
- We co‑maintain your SSP and POA&M
- MSP partner work managed end‑to‑end
- Priority scheduling + bundled coaching
- Best for owner‑operators with no IT staff
Technically compliant isn’t the same as ready to be assessed.
Plenty of contractors build the controls and then walk into the C3PAO engagement unsure how an assessment runs or how to present what they’ve done. How you present can decide a pass as much as what you built. We rehearse it with you first.
We don’t sell you tools. We tell you which ones you actually need.
Most CMMC help starts with a product to sell — a license bundle, a managed‑security contract, an enclave you may not need. We start somewhere cheaper for you: what your contracts actually require. From there we scope only the controls and technology that get you certified, and the technical build goes to your own IT team or an MSP partner. You spend less, finish sooner, and walk into the assessment with nothing bolted on for show.
Lower cost
Build only what the contract requires
Faster to assessment
No detours through tools you don’t need
Less disruption
Your stack, changed as little as possible
You’re hiring strategists, not an IT department.
We help your team decide exactly what to build and document. The technical heavy lifting: firewalls, MDM, enclaves, SIEM and SOC, stays with your own IT team or your MSP/MSSP. If you need it, we can match you to the right partner for your environment and we’ll help with managing the tech stack to meet your needs while complying with the requirements of the Standard.
We take no money from assessors.
We prepare you, then hand you to an independent C3PAO we don’t profit from. You choose from a short list of independent assessors. That separation isn’t a nicety; under the Code of Professional Conduct it’s what keeps your certification defensible.
Sustainment plan
Certification isn’t the finish line. Keep your affirmations, SPRS entries, POA&M, and reassessment prep current without thinking about it.
Not sure where you stand? Start with a free 30‑minute fit call.
We’ll figure out your level, your timeline, and the right first step. No pressure to subscribe.
Questions, answered
CMMC facts and how we work — verified, no fluff.