
CMMC readiness
Assessment-ready. Not assessed by us. By design.
Our consultants hold the Certified CMMC Professional credential. We prepare you for the assessment; a C3PAO conducts it. Keeping those roles separate is how the program is meant to work, and it is how you get an honest result rather than a graded exam marked by the tutor.
What changed on July 13, 2026, and what didn't
Last updated: September 2026
- Changed
- The Department suspended CMMC Phase 2, which would have required third-party (C3PAO) Level 2 certification in new solicitations from November 10, 2026. Later phases are paused with it while a Reform Task Force reviews the program.
- Didn't change
- DFARS 252.204-7012 and NIST SP 800-171 obligations. Phase 1 self-assessments, SPRS scores, and the annual senior-official affirmation. Prime flow-downs in your existing contracts. And the exposure that comes with an SPRS score you can't back with evidence.
- What that means for you
- A pause in verification is not a pause in liability. The contractors who use this window to close their POA&Ms and build real evidence will move fastest when the requirement returns, in whatever form it takes.
01 — How we work
Five stages, in order, every time.
- 01
Scope
- 02
Assess
- 03
Remediate
- 04
Rehearse
- 05
Sustain
Who this is for
Small and mid-size defense contractors and subcontractors handling FCI or CUI, especially teams without a full-time compliance function. If you're a prime looking to raise the readiness of your supply chain, we can work across your subcontractors too.
Where the large firms fit
Firms like Coalfire and Deloitte do excellent work at enterprise scale. Most of the DIB isn't enterprise scale. We give you a senior practitioner who translates the controls into a plan your team can actually execute, at a cost that fits a company your size.
Talk through your scope.
Tell us what you handle, where it lives, and who touches it. That conversation costs nothing and usually shortens the engagement.
Email us