Bring the DFARS clause, the prime's questionnaire, or your SPRS number. On the call we confirm which level applies and where the boundary should sit. By the next business day a named engineer owns the file, and by the end of the first week the evidence an assessor will eventually read is already collecting. A certificate takes a C3PAO and a calendar. The engineering waits for neither, and neither did DFARS 252.204-7012: NIST SP 800-171 is already in your contracts, suspension or no suspension.
CMMC stands for Cybersecurity Maturity Model Certification, the DoD's framework for ensuring that all defense contractors protect sensitive federal information.
CMMC applies to every company in the Defense Industrial Base (DIB) that handles Controlled Unclassified Information (CUI) or Federal Contract Information (FCI). If your contract involves either type of data, CMMC compliance is not optional.
Where the program stands today: the CMMC Final Rule took effect in December 2024, and Phase I began flowing into solicitations in November 2025. On July 13, 2026, the Department of War suspended Phase II pending a Reform Task Force review. Phase I remains fully in effect: Level 1 and Level 2 self-assessments, DFARS 252.204-7012, NIST SP 800-171 compliance, SPRS score postings, and annual affirmations all continue without interruption. During the pause, new solicitations may designate only Level 1 (Self) or Level 2 (Self); third-party C3PAO and government-led assessment designations are on hold until the phased rollout resumes.
The stakes are straightforward: your existing obligations never paused. DFARS 252.204-7012 and NIST 800-171 are already in your contracts, self-assessment requirements are live, and defense primes are asking subcontractors where they stand today. The 110 controls you implement now are the same 110 controls a C3PAO will assess when Phase II resumes.
CMMC is not a new set of controls. It is a verification layer on requirements the Department has flowed down through the Defense Federal Acquisition Regulation Supplement since 2017. If a contract you hold today contains 7012, NIST SP 800-171 already applies to you, suspension or no suspension.
These are the four clauses we read with you on the first call, in the order they usually show up.
Safeguarding covered defense information. Requires NIST SP 800-171 on every system that stores, processes, or transmits CUI, cyber incident reporting to the Department within 72 hours of discovery, and flow-down to every subcontractor that handles the data.
Notice of NIST SP 800-171 assessment requirements. A Basic (self) assessment score no more than three years old must be posted in the Supplier Performance Risk System (SPRS) before a contract can be awarded.
NIST SP 800-171 assessment requirements. Gives the Department the right to conduct Medium and High assessments of your implementation and carries the SPRS requirement down to subcontractors.
The CMMC clause itself. Requires the CMMC level named in the solicitation to be held at award and maintained through performance. The C3PAO assessment requirement it would have carried in Phase II is what the July 2026 suspension removed from active solicitations.
CMMC 2.0 organizes cybersecurity requirements across three tiers, each matched to the sensitivity of the information handled and the risk profile of the program.
Most compliance platforms were designed for IT ops and adapted to meet compliance requirements. GUARDIENT® was purpose-built around the NIST 800-171 control families from day one, meaning coverage is native, not bolted on.
When you operate inside GUARDIENT®, evidence builds automatically. Your C3PAO won't need to wait for you to pull screenshots.
Every platform action auto-generates evidence mapped to NIST 800-171 control families. No manual screenshots, no spreadsheet evidence collection.
Your CMMC posture is tracked in real time inside Compliance Command. You know your gap count before the assessor does.
Reactor SOAR handles IR documentation, containment logs, and after-action evidence automatically, covering the full IR control domain.
Sentry XDR enforces and logs access control policies across your environment, covering AC and IA control families end-to-end.
When your C3PAO arrives, your evidence package is already built. GUARDIENT® exports a complete SPRS scoring package and control-by-control evidence map.
Our Control Responsibility Matrix assigns each of the 110 NIST SP 800-171 requirements one of four handling models, from fully covered by GUARDIENT® to guided consulting in your environment. Hover a family or a legend entry to see how the work splits.
The pattern tells the story. Audit and Accountability sits almost entirely on our side: eight of its nine requirements are covered end to end with no client action. System and Information Integrity is delivered wholly through the technical stack, and Awareness and Training is carried by our documentation and training program. At the other end, Personnel Security is guided consulting, because only you can run a background check or walk someone out, and consulting-heavy families like Media Protection and Physical Protection depend on how your facility and media actually work. Wherever a requirement is guided, we supply the template, the calendar reminder, and the engineer who checks the result, and the platform holds the proof once it exists.
USX Cyber manages every phase of your CMMC journey, from the first gap assessment through the final C3PAO report, following the same Delivery Framework we apply to every program: scope and boundary engineering first, so your assessed environment is no larger than it has to be. You don't need to coordinate multiple vendors or piece together your own path.
We run a full NIST 800-171 gap assessment against your environment. You get a SPRS score and a prioritized remediation plan within 2 weeks. No surprises, just a clear picture of where you stand and what it takes to get certified.
Deliverable: SPRS score + prioritized remediation planYour environment connects to the platform. Automated coverage kicks in immediately, typically closing 75%+ of gaps within 30 days. Evidence collection starts from day one.
Typical result: 75%+ of gaps closed within 30 daysOur advisory team works through remaining gaps: policy documentation, missing controls, configuration hardening, and System Security Plan (SSP) completion. Every finding gets an owner and a deadline.
Deliverable: Complete SSP + remediated control setInternal mock assessment using the official CMMC assessment guide. We identify and close any remaining findings before the C3PAO arrives. This is the step that separates first-attempt passes from costly reassessments.
Deliverable: Readiness report + closed finding listWe coordinate the official assessment with a qualified C3PAO. Most GUARDIENT® clients pass on the first attempt. Your evidence package is pre-assembled and your team is briefed, no last-minute scrambles.
Result: CMMC Level 2 certificationWhether you're starting from scratch or already midway through your CMMC journey, we have an engagement model that fits your timeline and budget.
Read the clause. If your contracts carry FAR 52.204-21 and you hold only Federal Contract Information, Level 1 applies: 15 requirements and an annual self-assessment. If they carry DFARS 252.204-7012 and you receive, create, or store Controlled Unclassified Information, Level 2 applies: all 110 requirements of NIST SP 800-171. Level 3 is invoked by the Department for named programs, not chosen by the contractor. Send us the clause, we'll confirm the level on the first call.
If you handle CUI or FCI, yes. CMMC flows down through the prime contractor to all subcontractors handling covered data. Your prime will require proof of certification before awarding you work. Being a sub does not create an exemption; it creates a deadline set by whoever sits above you in the supply chain.
With GUARDIENT®, most clients are assessment-ready within 60–90 days of onboarding. Timelines vary based on organization size, the number of systems in scope, and your starting posture. Organizations with significant existing gaps or large, complex environments may take longer. The gap assessment we run in week one gives you a clear timeline estimate.
On July 13, 2026, the Department of War suspended CMMC Phase II pending a Reform Task Force review, so new solicitations may currently designate only Level 1 (Self) or Level 2 (Self), third-party C3PAO and government-led designations are on hold. What did not pause: Phase I self-assessments, DFARS 252.204-7012, NIST SP 800-171 compliance, SPRS score postings, and annual affirmations. Contractors who use this window to close gaps and build evidence will be first in line when third-party assessments resume.
A C3PAO (Certified Third-Party Assessment Organization) is a Cyber AB-authorized company that conducts official CMMC Level 2 (C3PAO) assessments. Under the phased rollout, many CUI-handling contractors will need a C3PAO assessment once Phase II resumes; while Phase II is suspended, only self-assessment designations may appear in new solicitations. The controls are identical either way, so readiness work transfers one-for-one. USX Cyber coordinates the C3PAO engagement as part of our Full Certification Bundle and can recommend qualified assessors aligned with your timeline.
You have the opportunity to remediate and reassess. USX Cyber stays with you through the process, our pre-assessment readiness review is specifically designed to prevent first-attempt failures by surfacing and closing findings before the official assessor arrives. If a finding does emerge during the assessment, we help you document the remediation path and get back in front of the C3PAO as quickly as possible.
For most small-to-mid sized defense contractors, yes. GUARDIENT® provides XDR, SIEM, SOAR, and GRC in one unified platform, replacing the need for separate EDR, log management, incident response, and compliance tools. This consolidation also reduces your attack surface and simplifies the scope of your CMMC assessment environment.
Whether you're just discovering the requirement or facing a contract deadline, USX Cyber will meet you where you are. Book a call with our CMMC team and we'll walk you through your current posture, your timeline, and exactly what it takes to certify.
Start a CMMC Readiness Consultation