One path to compliant: measure your posture with the self-assessment software — free at CMMC Level 1 — then close the gaps and prove readiness with senior-led consulting from a Lead Certified CMMC Assessor.
Phase 1 CMMC self-assessment requirements are in DoD solicitations today, and DFARS 252.204-7012 has required NIST 800-171 for years. The July 2026 suspension of Phase 2 paused third-party assessments — not the security obligations, and not the liability for overstating compliance. Understanding your level is the first step.
17 practices aligned to basic safeguarding of Federal Contract Information (FCI). Annual self-assessment.
110 practices aligned to NIST 800-171. Handles Controlled Unclassified Information. Verified today by self-assessment and select government-led assessments; the C3PAO mandate is suspended pending DoD review.
All 110 NIST 800-171 controls plus 24 enhanced requirements from NIST 800-172. Government-led assessments for the most sensitive programs.
Software built by an assessor for defense contractors: self-assess and track your compliance posture before a formal assessment. Level 1 is free in your browser; the licensed desktop app unlocks Level 2.
A browser-based walkthrough of the CMMC Level 1 practices — free, with everything stored locally in your browser and no account required. The browser version is Level 1 only: the Level 2 assessment — all 110 controls across 14 NIST SP 800-171 R2 families, your running SPRS score, and a compliance summary — lives in the licensed desktop app.
The full Level 2 assessment is exclusive to the desktop app for Linux, macOS, and Windows — licensed, fully offline, with your data stored entirely on your own machine. Every subscription starts with a 14-day free trial. Curious what's inside? See the full feature set.
Get the Desktop App Linux · macOS · WindowsThe software shows you where you stand; these engagements get you the rest of the way. From NIST 800-171 gap analysis to mock assessments — end-to-end readiness support, led by a Lead Certified CMMC Assessor.
Pre-assessment evaluations led by a Lead Certified CMMC Assessor, measuring your practices against CMMC Level 1 and Level 2 requirements — so you can face a government-led review, a C3PAO assessment, or your own SPRS attestation with no surprises.
Learn more →Thorough review of your current security posture against NIST 800-171 controls, with a prioritized remediation roadmap before your formal assessment.
Learn more →Design and implementation guidance for Zero Trust architectures aligned to DoD and NIST frameworks — on-prem, Azure, or hybrid environments.
Development of System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), and all supporting policies required for CMMC compliance.
Learn more →Hardening of cloud infrastructure to meet CMMC and FedRAMP alignment requirements, including SIEM integration, VLAN segmentation, and MDM policy.
Custom cybersecurity training programs and tabletop exercises designed for defense contractor teams navigating CMMC requirements for the first time.
DoD suspended the CMMC Phase 2 requirements — originally set to take effect November 10, 2026 — along with pending implementation milestones, while a task force reviews the program.
Phase 1 self-assessments, DFARS 252.204-7012, and NIST SP 800-171 — now enforced through self-assessments and select government-led assessments. An inflated SPRS score still carries False Claims Act exposure.
The CMMC Reform Task Force reports on the program's future within 60 days. Requirements can return — reshaped — on short notice; contractors who keep implementing won't be starting over.
The certification pause is not a security pause: your contracts still require NIST 800-171, and the government is still checking. Read the plain-English breakdown of the suspension.
Quick answers to the questions defense contractors ask most about CMMC 2.0, NIST 800-171, and the assessment process.
Yes. On July 13, 2026 the DoD suspended the CMMC Phase 2 requirements — the third-party assessment rollout originally set for November 10, 2026 — pending a 60-day program review. Phase 1 self-assessment requirements remain firmly in place, DFARS 252.204-7012 still requires NIST SP 800-171, and the department is enforcing it through self-assessments and select government-led assessments in the interim. Read the full breakdown of what changed.
CMMC 2.0 (Cybersecurity Maturity Model Certification) is the Department of Defense's framework for verifying that contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Phase 1 self-assessment requirements are appearing in new DoD solicitations now; the Phase 2 third-party assessment rollout was suspended in July 2026 pending a program review. Companies in the defense supply chain — primes and subcontractors alike — still need to meet the CMMC level specified in their contracts.
Level 1 covers 17 basic safeguarding practices for FCI and allows annual self-assessment. Level 2 requires all 110 NIST SP 800-171 controls for handling CUI. The planned triennial C3PAO assessment requirement for most CUI contracts was suspended in July 2026 — in the interim, Level 2 is verified through self-assessment and select government-led assessments.
Most small and mid-sized contractors need 6 to 18 months to reach Level 2 readiness, depending on their starting posture. A gap analysis early in the process gives you a realistic timeline and a prioritized remediation roadmap.
Your SPRS (Supplier Performance Risk System) score reflects your self-assessed implementation of NIST SP 800-171, ranging from -203 to a perfect 110. DoD contracting officers can view it, and an accurate score is required under DFARS 252.204-7019/7020.
No — official Level 2 certification assessments are conducted by authorized C3PAOs. GetCMMC provides consulting, gap analysis, remediation support, and mock assessments led by a Lead Certified CMMC Assessor so you walk into your C3PAO assessment fully prepared.
Conflict-of-interest rules prohibit a C3PAO from conducting your certification assessment if it helped you prepare for it — so prepping with a C3PAO takes that firm off your list of potential assessors. GetCMMC is readiness-only: assessor-grade preparation from a Lead Certified CMMC Assessor, with every C3PAO still available to conduct your official assessment.
A clear, senior-led path from where you stand today to facing any assessment — government-led, C3PAO, or your annual self-attestation — prepared, led personally at every step by a Lead Certified CMMC Assessor.
A short conversation about your contracts, the CMMC level you need, your timeline, and your current security posture — so we both know whether it's a fit before any commitment.
A thorough review of your environment against all 110 NIST SP 800-171 controls, delivered as a prioritized findings report and your current SPRS score.
We work the plan together — System Security Plan (SSP), POA&M, technical hardening, and the supporting policies CMMC requires — closing gaps in priority order.
An assessor-led dry run against the official criteria, so you face your formal assessment with no surprises and the evidence to back every control.
Whether you're starting from scratch or preparing for a formal assessment, let's talk through where you stand and what it takes to get compliant. Every inquiry starts with a free 30-minute consultation — no obligation.
Pick a time that works for you — no back-and-forth email.
Thanks for reaching out. Neal will be in touch within 1–2 business days.