Service
Policies, controls & evidence
A security program you can repeat and prove
Compliance readiness
Readiness for CMMC Level 1 and Level 2 against FAR 52.204-21 and NIST SP 800-171 Rev 2, with support for self-assessments and for a certification assessment by an authorized C3PAO if you need one.
CMMC Program (32 CFR Part 170); Level 2 uses NIST SP 800-171 Rev 2
Program rule effective December 16, 2024; acquisition rule effective November 10, 2025
As of 2026-09-26, CMMC Level 2 is defined by NIST SP 800-171 Rev 2 (32 CFR 170.14(c)(3)), and DFARS 252.204-7012 applies NIST SP 800-171 to covered contractor information systems. For the program's current implementation, read the dated program update on this page.
CMMC program update — September 26, 2026: CMMC implementation remains paused in Phase 1 following the suspension of Phase II on July 13, 2026. Phase I self-assessment requirements remain in force. During the suspension, procurement requirements may designate CMMC Level 1 (Self) or Level 2 (Self), but not Level 2 (C3PAO) or Level 3 (DIBCAC).
Check the DoW CIO CMMC page and your contract language before relying on this page.
CMMC, the Cybersecurity Maturity Model Certification program, is a Department of Defense program that verifies how contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
Level 1 covers the 15 requirements in FAR 52.204-21 and is self-assessed every year. Level 2 covers the 110 requirements of NIST SP 800-171 Rev 2 and is either self-assessed or assessed by an authorized C3PAO, every three years. Level 3 adds 24 requirements from NIST SP 800-172 and is assessed by DCMA DIBCAC.
Results are entered in SPRS, and your organization's own senior Affirming Official makes the required affirmations.
CMMC Level 2 uses NIST SP 800-171 Revision 2. The program rule says the Level 2 security requirements “are identical to the requirements in NIST SP 800-171 R2” (32 CFR 170.14(c)(3)), and the DoW CIO describes Level 2 as the 110 security requirements in that revision.
NIST published Revision 3 in May 2024 and withdrew Revision 2 on May 14, 2024. Both facts hold at once: Revision 2 is withdrawn by NIST and is still the CMMC Level 2 baseline, because the CMMC rule incorporates Revision 2 by reference.
For CMMC planning, map your controls and evidence to Revision 2. If you also track Revision 3, keep the two mappings separate so an assessment against one isn't confused with the other, and check your contract language for the revision it names.
Sources: eCFR: 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program; DoW CIO: About CMMC; NIST SP 800-171 Rev. 2 (withdrawn by NIST on May 14, 2024; still the CMMC Level 2 baseline); NIST SP 800-171 Rev. 3 (May 2024)
Read the full guide: CMMC Level 2 and NIST SP 800-171: readiness basics
Federal Contract Information (FCI) is information, not intended for public release, that is provided by or generated for the government under a contract to develop or deliver a product or service. It excludes information the government makes public and simple transactional information, such as what's needed to process payments (FAR 52.204-21).
FAR 52.204-21 sets 15 basic safeguarding requirements for contractor information systems that process, store, or transmit FCI, and CMMC Level 1 consists of exactly those 15 requirements (32 CFR 170.14(c)(2)).
Controlled Unclassified Information (CUI) is unclassified information that requires safeguarding or dissemination controls under law, federal regulation, or government-wide policy. The National Archives administers the CUI program, which Executive Order 13556 established. For covered contractor information systems that aren't operated on the government's behalf, DFARS 252.204-7012 applies the security requirements of NIST SP 800-171, which is where CMMC Level 2 comes in.
Sources: FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems; eCFR: 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program; National Archives: Controlled Unclassified Information (CUI) program; DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
A system security plan (SSP) describes a system's boundaries, its environments of operation, how each security requirement is implemented, and its relationships with or connections to other systems. NIST SP 800-171 Revision 2 requires contractors to develop, document, and periodically update one (requirement 3.12.4). A DFARS Basic Assessment is based on the contractor's review of its system security plans (DFARS 252.204-7020).
A plan of action and milestones (POA&M) describes how unimplemented security requirements will be met and how planned mitigations will be carried out (requirement 3.12.2).
The CMMC rule limits POA&Ms (32 CFR 170.21). A Level 1 self-assessment never permits one. At Level 2, a POA&M can support only a conditional status, only for requirements worth one point in the CMMC scoring method (with one narrow exception for encryption), and never for the system security plan requirement itself. It must be closed out within 180 days of the conditional status date, or the conditional status expires.
Sources: NIST SP 800-171 Rev. 2 (withdrawn by NIST on May 14, 2024; still the CMMC Level 2 baseline); DFARS 252.204-7020, NIST SP 800-171 DoD Assessment Requirements; eCFR: 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program
The Supplier Performance Risk System (SPRS) is where NIST SP 800-171 assessment scores are posted and where CMMC affirmations are entered. Under the CMMC rule, an Affirming Official from each organization, prime or subcontractor, affirms continuing compliance after every assessment, including a POA&M closeout, and annually after that (32 CFR 170.22).
Four DFARS clauses tie NIST SP 800-171 and CMMC to defense contracts:
Sources: DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting; DFARS 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements; DFARS 252.204-7020, NIST SP 800-171 DoD Assessment Requirements; SPRS: NIST SP 800-171 assessments; eCFR: 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program
Read the full guide: CMMC Level 2 and NIST SP 800-171: readiness basics
Readiness work prepares you. The formal outcome below comes only from the organization the program authorizes.
Security Inspect isn't a managed SOC, an MDR provider, or a round-the-clock emergency-response provider. We don't offer ASV scanning, PCI forensic investigations, or P2PE, SSF, PIN, or 3DS assessments, and we don't perform CMMC certification assessments or HITRUST assessments.
CMMC Level 1 and Level 2 readiness — preparation for self-assessment or a certification assessment by an authorized C3PAO.
Under 32 CFR 170.8(b)(17)(ii)(G), members of the CMMC ecosystem may not take part in the Level 2 certification assessment process for an organization they served as a consultant to prepare for any CMMC assessment within three years. The rule reaches C3PAOs, their assessors, and CMMC professionals.
When a program requires a formal assessment, audit, or certification, it's performed by an independent, authorized assessor. We keep advisory work and formal assessment apart: a practitioner never assesses controls they designed, developed, or implemented.
Every engagement begins with a written scope and proposal.
Check which CMMC level and assessment type your solicitation or contract calls for, and read the dated program update on this page.
Identify the systems, people, facilities, and providers that handle FCI or CUI.
Compare your practices and evidence with FAR 52.204-21 or NIST SP 800-171 Rev 2.
Build or update your system security plan and POA&M, and agree on a remediation plan. Level 1 doesn't permit POA&Ms.
Get ready for your self-assessment and SPRS entry, or for a C3PAO certification assessment that you arrange directly.
From $6,000
Typical scoped range: $6,000 to $12,000
One-time project
From $15,000
Typical scoped range: $15,000 to $40,000
One-time project
Non-binding. Final pricing follows a written scope and proposal.
Pricing depends on environment size, complexity, testing depth, locations, applications, accounts, user roles, compliance objectives, and delivery timeline. Every engagement begins with a written scope and proposal. Taxes, travel, remediation, third-party audit or certification fees, licensing, and emergency work are separate. Readiness services do not include independent certification, attestation, legal advice, or a guarantee of passing.
Only if your contract or solicitation calls for Level 2 (C3PAO), or a customer asks for one. Each CMMC requirement names a level and an assessment type: Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), or Level 3 (DIBCAC). Which of these the Department includes in solicitations has changed over time, so read the dated program update on this page, the DoW CIO CMMC page, and your contract language before you plan.
No. Where DFARS 252.204-7012 is in your contract, it applies NIST SP 800-171 to covered contractor information systems whether or not the contract also names a CMMC level. DFARS 252.204-7019 separately calls for a current NIST SP 800-171 assessment, with summary level scores posted in SPRS. CMMC Level 2 is defined by NIST SP 800-171 Rev 2, not Rev 3, even though NIST has published Rev 3.
Not for a Level 2 certification assessment within three years. 32 CFR 170.8(b)(17)(ii)(G) bars CMMC ecosystem members from the Level 2 certification assessment process for an organization they served as a consultant to prepare for any CMMC assessment within the previous three years. It applies to C3PAOs, their assessors, and CMMC professionals.
The CMMC Assessor and Instructor Certification Organization (CAICO) certifies individuals such as CCPs and CCAs, and ISACA has held that role since December 17, 2025. C3PAOs certify organizations at Level 2; they don't certify people. The Cyber AB remains the Accreditation Body that authorizes C3PAOs.
Your organization does. Results go into SPRS, and your own senior Affirming Official makes the affirmation. An outside adviser can help you prepare the assessment and its evidence, but can't make the affirmation on your behalf.
Information on this website is general and educational. It isn't legal advice, and it doesn't create a client relationship.
Tell us what’s driving the work and who’s asking for it, and we’ll help you judge where you stand and whether readiness support makes sense.