Phase 1 in force

Straight answers to CMMC questions

The questions defense contractors actually ask us, answered without the consultant fog.

Is CMMC still happening after the Phase 2 suspension?

Yes. DoD suspended Phase 2 (third-party certification rollout) on July 13, 2026 while it reviews the program. Phase 1 remains fully in force: Level 1 and Level 2 self-assessments in new solicitations, SPRS scores, and annual affirmations. NIST SP 800-171 obligations under DFARS 252.204-7012 never paused.

My prime says I need CMMC — what do they actually mean?

Usually one of three things: they want your SPRS score on file, they need you to self-assess at Level 1 or 2 under a flow-down, or they are getting ahead of future certification requirements. We help you find out exactly which, then meet it — nothing more, nothing less.

Do I need Level 1 or Level 2?

Level 1 if you only handle Federal Contract Information (basic contract data). Level 2 if you receive Controlled Unclassified Information — controlled drawings, specs, and technical data. Most companies making DoD parts or assemblies handle CUI and need Level 2.

Are my part drawings CUI?

If a prime sends you controlled technical data — drawings marked with distribution statements, export-control markings, or CUI banners — yes. Even unmarked technical data can qualify. This determination drives your whole scope, so we make it carefully during intake.

What is a SPRS score and who can see it?

The Supplier Performance Risk System score is your NIST SP 800-171 self-assessment result, from -203 to 110, posted to a DoD system. Contracting officers and your primes can check it. A missing or stale score is a red flag that costs suppliers work.

How long does it take to get to Level 2?

Typically 3–9 months depending on starting point, company size, and how much CUI scoping we can tighten with an enclave. The site walk and gap snapshot in week one give you a real timeline, not a guess.

What does CMMC compliance cost a small shop?

It depends on gap size and scope. An enclave approach often cuts cost dramatically by shrinking what has to comply. We publish honest cost breakdowns on the blog, and your gap snapshot comes with a fixed work plan — no open-ended billing surprises.

Does my legacy production equipment need antivirus?

Machines in scope need protection appropriate to what they are. Legacy controllers that cannot run modern tools are handled with segmentation, restricted access, and compensating controls — documented properly in your SSP. Nobody is installing an agent on your 1998 controller.

Can I keep using regular Microsoft 365?

For Level 1, generally yes. For Level 2 with CUI, it depends on your data and contracts — some organizations need GCC High, many can architect around commercial M365 plus an enclave. We assess before anyone pays for a migration they may not need.

What happens if I affirm compliance and I am wrong?

Annual affirmations are certifications to the government. Inaccurate ones carry False Claims Act exposure, and enforcement on cybersecurity representations is active. This is why we collect evidence continuously — every affirmation you sign should be supportable on demand.

Do you certify us?

No — and be wary of anyone who says they can. When third-party assessment applies, it is done by an independent authorized assessor. We do everything before and after: implement, prepare, maintain, and support.

What is included in ongoing servicing?

Monitoring across endpoints, identity, and network; drift and incident alerts; patch and firmware cadence; evidence collection; annual self-assessment and affirmation prep; and a support desk with SLAs — all visible in your portal.

We already have an IT guy — how do you work with him?

Great — he gets a portal login too. We handle the compliance layer and heavy lifting; he keeps doing what he does, with our monitoring and documentation behind him. Most shop IT folks are relieved, not threatened.

What is a site walk and why do you start with one?

A physical walkthrough of your facility: every workstation, server, controller, network device, and door lock. Compliance built on an inaccurate inventory fails assessments and audits. We start from what is actually in your environment.

Didn't find yours? Ask us directly