CMMC readiness
Get your NIST SP 800-171 controls, documentation and evidence in order, so a contract requirement never turns into a lost contract.
Where CMMC stands, September 2026
The Department of Defense paused third-party CMMC certification in July 2026 while it reviews the program. The requirements underneath it did not pause: contracts that carry DFARS 252.204-7012 still require NIST SP 800-171, and self-assessment scores and annual affirmations in SPRS still apply.
Is this you?
- A prime or contracting officer has asked for your CMMC level or SPRS score.
- You handle Controlled Unclassified Information (CUI) or Federal Contract Information (FCI).
- Your SPRS score was entered once and has not been revisited since.
- You have policies, but not the evidence that shows they are followed.
What you get
- Scoping: where CUI and FCI live, and which systems, people and providers are in scope
- A gap assessment against all 110 NIST SP 800-171 requirements
- A System Security Plan (SSP) and a Plan of Action and Milestones (POA&M)
- Policies and procedures written for your environment, not copied from a template
- An accurate SPRS score and the evidence behind it
- Preparation for a self-assessment or a third-party (C3PAO) assessment
How it works
-
Step 1: Scope
Find where CUI and FCI live and draw the assessment boundary.
-
Step 2: Assess
Test every requirement against how your environment actually runs.
-
Step 3: Remediate
Close gaps in priority order, writing the documentation as we go.
-
Step 4: Prove
Assemble the SSP, POA&M and evidence, and walk you through the assessment.
Every step follows Cyber BAMCIS, our planning method.
Related work
-
Technology company
CMMC policies across seven control families
Identification and authentication, system and communications protection, audit, system integrity, media protection, risk assessment and security assessment policies, written to CMMC requirements.
-
Global connectivity provider
CMMC gap assessment, expanded to SOC 2
A CMMC gap assessment across five global locations and a Google Cloud, AWS and Google Workspace estate, expanded to add SOC 2 Type 2 readiness.
Questions
Is CMMC still required while certification is paused?
The pause applies to third-party certification. Contracts with DFARS 252.204-7012 still require the 110 requirements of NIST SP 800-171, and SPRS scores and affirmations still have to be accurate. Readiness work done now counts whenever certification resumes.
Which CMMC level do we need?
It depends on the information you handle and the clauses in your contracts. Federal Contract Information alone generally means Level 1. Controlled Unclassified Information generally means Level 2, which maps to NIST SP 800-171. We will help you read the clauses and scope it correctly.
How long does readiness take?
It depends on your starting point. The gap assessment answers that question with a prioritized plan and a realistic timeline for everything still open.
Can you help once we are compliant?
Yes. Controls drift as people, systems and providers change. We can stay on through a virtual CISO engagement to keep your evidence current and your affirmations defensible.
Other services
-
Assessments and SOC 2
A customer wants your SOC 2 report before they sign.
Explore Assessments & SOC 2 -
Virtual CISO
You need a CISO, not a full-time hire.
Explore Virtual CISO -
Zero Trust and cloud
Your network outgrew its perimeter.
Explore Zero Trust & cloud security
Tell us what’s driving the deadline
One short call is enough to know whether we’re the right fit and what the work would take.