Where CMMC stands, September 2026

The Department of Defense paused third-party CMMC certification in July 2026 while it reviews the program. The requirements underneath it did not pause: contracts that carry DFARS 252.204-7012 still require NIST SP 800-171, and self-assessment scores and annual affirmations in SPRS still apply.

Is this you?

  • A prime or contracting officer has asked for your CMMC level or SPRS score.
  • You handle Controlled Unclassified Information (CUI) or Federal Contract Information (FCI).
  • Your SPRS score was entered once and has not been revisited since.
  • You have policies, but not the evidence that shows they are followed.

What you get

  • Scoping: where CUI and FCI live, and which systems, people and providers are in scope
  • A gap assessment against all 110 NIST SP 800-171 requirements
  • A System Security Plan (SSP) and a Plan of Action and Milestones (POA&M)
  • Policies and procedures written for your environment, not copied from a template
  • An accurate SPRS score and the evidence behind it
  • Preparation for a self-assessment or a third-party (C3PAO) assessment

How it works

  1. Step 1: Scope

    Find where CUI and FCI live and draw the assessment boundary.

  2. Step 2: Assess

    Test every requirement against how your environment actually runs.

  3. Step 3: Remediate

    Close gaps in priority order, writing the documentation as we go.

  4. Step 4: Prove

    Assemble the SSP, POA&M and evidence, and walk you through the assessment.

Every step follows Cyber BAMCIS, our planning method.

Related work

  • Technology company

    CMMC policies across seven control families

    Identification and authentication, system and communications protection, audit, system integrity, media protection, risk assessment and security assessment policies, written to CMMC requirements.

  • Global connectivity provider

    CMMC gap assessment, expanded to SOC 2

    A CMMC gap assessment across five global locations and a Google Cloud, AWS and Google Workspace estate, expanded to add SOC 2 Type 2 readiness.

Questions

Is CMMC still required while certification is paused?

The pause applies to third-party certification. Contracts with DFARS 252.204-7012 still require the 110 requirements of NIST SP 800-171, and SPRS scores and affirmations still have to be accurate. Readiness work done now counts whenever certification resumes.

Which CMMC level do we need?

It depends on the information you handle and the clauses in your contracts. Federal Contract Information alone generally means Level 1. Controlled Unclassified Information generally means Level 2, which maps to NIST SP 800-171. We will help you read the clauses and scope it correctly.

How long does readiness take?

It depends on your starting point. The gap assessment answers that question with a prioritized plan and a realistic timeline for everything still open.

Can you help once we are compliant?

Yes. Controls drift as people, systems and providers change. We can stay on through a virtual CISO engagement to keep your evidence current and your affirmations defensible.

Other services

Tell us what’s driving the deadline

One short call is enough to know whether we’re the right fit and what the work would take.