CMMC Level 1 & 2 · NIST SP 800-171 · DFARS 252.204-7012

One Call Scopes Your Program. One Day Later, An Engineer Is Working It.

Bring the DFARS clause, the prime's questionnaire, or your SPRS number. On the call we confirm which level applies and where the boundary should sit. By the next business day a named engineer owns the file, and by the end of the first week the evidence an assessor will eventually read is already collecting. A certificate takes a C3PAO and a calendar. The engineering waits for neither, and neither did DFARS 252.204-7012: NIST SP 800-171 is already in your contracts, suspension or no suspension.

Level confirmed on the call Named engineer within one day Assessor liaison to the finding letter
GUARDIENT® · CMMC Level 2 Coverage
Access Control (AC)
88%
Identification & Auth (IA)
92%
Incident Response (IR)
75%
Risk Assessment (RA)
83%
System & Comm Protection (SC)
79%
110 Controls
Level 2 Certification

83 of 110 NIST 800-171 controls addressed automatically through GUARDIENT® platform activity. The rest, we build with you.

Start a Readiness Consultation →
// Background

CMMC 2.0: The Defense Department's Mandatory Cybersecurity Standard

CMMC stands for Cybersecurity Maturity Model Certification, the DoD's framework for ensuring that all defense contractors protect sensitive federal information.

CMMC applies to every company in the Defense Industrial Base (DIB) that handles Controlled Unclassified Information (CUI) or Federal Contract Information (FCI). If your contract involves either type of data, CMMC compliance is not optional.

Where the program stands today: the CMMC Final Rule took effect in December 2024, and Phase I began flowing into solicitations in November 2025. On July 13, 2026, the Department of War suspended Phase II pending a Reform Task Force review. Phase I remains fully in effect: Level 1 and Level 2 self-assessments, DFARS 252.204-7012, NIST SP 800-171 compliance, SPRS score postings, and annual affirmations all continue without interruption. During the pause, new solicitations may designate only Level 1 (Self) or Level 2 (Self); third-party C3PAO and government-led assessment designations are on hold until the phased rollout resumes.

The stakes are straightforward: your existing obligations never paused. DFARS 252.204-7012 and NIST 800-171 are already in your contracts, self-assessment requirements are live, and defense primes are asking subcontractors where they stand today. The 110 controls you implement now are the same 110 controls a C3PAO will assess when Phase II resumes.

300,000+
DIB companies required to comply with CMMC across the defense supply chain
110
NIST 800-171 controls required for CMMC Level 2 certification
Phase I
In effect now: self-assessments, SPRS scores, and annual affirmations (Phase II suspended July 2026, pending review)
// DFARS 252.204-7012 · 7019 · 7020 · 7021

Four Clauses Carry CMMC Into a Contract. Three Are Already in Force.

CMMC is not a new set of controls. It is a verification layer on requirements the Department has flowed down through the Defense Federal Acquisition Regulation Supplement since 2017. If a contract you hold today contains 7012, NIST SP 800-171 already applies to you, suspension or no suspension.

These are the four clauses we read with you on the first call, in the order they usually show up.

7012

DFARS 252.204-7012

Safeguarding covered defense information. Requires NIST SP 800-171 on every system that stores, processes, or transmits CUI, cyber incident reporting to the Department within 72 hours of discovery, and flow-down to every subcontractor that handles the data.

7019

DFARS 252.204-7019

Notice of NIST SP 800-171 assessment requirements. A Basic (self) assessment score no more than three years old must be posted in the Supplier Performance Risk System (SPRS) before a contract can be awarded.

7020

DFARS 252.204-7020

NIST SP 800-171 assessment requirements. Gives the Department the right to conduct Medium and High assessments of your implementation and carries the SPRS requirement down to subcontractors.

7021

DFARS 252.204-7021

The CMMC clause itself. Requires the CMMC level named in the solicitation to be held at award and maintained through performance. The C3PAO assessment requirement it would have carried in Phase II is what the July 2026 suspension removed from active solicitations.

// Framework

Three Levels. One Standard for the Defense Supply Chain.

CMMC 2.0 organizes cybersecurity requirements across three tiers, each matched to the sensitivity of the information handled and the risk profile of the program.

Level 1. Foundational

Basic Cyber Hygiene

Annual self-assessment · FCI only
15
security requirements
  • Basic cyber hygiene practices
  • Annual self-assessment with annual affirmation
  • Applies to companies handling only Federal Contract Information
  • No third-party assessment required
Level 2. Advanced Most Relevant

Advanced Cyber Practices

Self or C3PAO assessment · CUI programs
110
NIST 800-171 controls required
  • Full NIST SP 800-171 control implementation
  • Two tracks: Level 2 (Self) annually, or Level 2 (C3PAO) triennially for designated programs
  • Only Level 2 (Self) may be designated while Phase II is suspended; C3PAO designations resume with the phased rollout
  • System Security Plan (SSP) and POA&M required
  • SPRS score submission and annual affirmation required
This is where most defense contractors operate, and where USX Cyber specializes.
Level 3. Expert

Higher-Level Cyber Practices

Government-led assessment · Priority CUI programs
110+
practices including NIST 800-172
  • 110 NIST 800-171 practices plus NIST 800-172 enhancements
  • Government-led assessment (DIBCAC)
  • Applies to the highest-priority CUI programs
  • Reserved for critical defense program contractors
// Platform Coverage

GUARDIENT® Was Built for CMMC. Not Retrofitted to It.

Most compliance platforms were designed for IT ops and adapted to meet compliance requirements. GUARDIENT® was purpose-built around the NIST 800-171 control families from day one, meaning coverage is native, not bolted on.

When you operate inside GUARDIENT®, evidence builds automatically. Your C3PAO won't need to wait for you to pull screenshots.

01

Automated Control Evidence

Every platform action auto-generates evidence mapped to NIST 800-171 control families. No manual screenshots, no spreadsheet evidence collection.

02

Continuous Compliance Monitoring

Your CMMC posture is tracked in real time inside Compliance Command. You know your gap count before the assessor does.

03

Incident Response Coverage

Reactor SOAR handles IR documentation, containment logs, and after-action evidence automatically, covering the full IR control domain.

04

Access Control & Identity Management

Sentry XDR enforces and logs access control policies across your environment, covering AC and IA control families end-to-end.

05

Audit-Ready Output

When your C3PAO arrives, your evidence package is already built. GUARDIENT® exports a complete SPRS scoring package and control-by-control evidence map.

// Control Responsibility Matrix · NIST SP 800-171

110 Requirements, Each Assigned Before the Assessor Asks.

Our Control Responsibility Matrix assigns each of the 110 NIST SP 800-171 requirements one of four handling models, from fully covered by GUARDIENT® to guided consulting in your environment. Hover a family or a legend entry to see how the work splits.

Entirely Covered 18 Fully handled end to end, no client action required.
Technical 29 Delivered through USX Cyber's technical stack and tooling.
Documentation 15 Supported via policies, procedures, and documentation.
Consulting 48 Guided together, depends on client environment and choices.
47 requirements delivered by the platform and stack 110 requirements across 14 families
AC Access Control 22
AT Awareness and Training 3
AU Audit and Accountability 9
CM Configuration Management 9
IA Identification and Authentication 11
IR Incident Response 3
MA Maintenance 6
MP Media Protection 9
PS Personnel Security 2
PE Physical Protection 6
RA Risk Assessment 3
CA Security Assessment 4
SC System and Communications Protection 16
SI System and Information Integrity 7

The pattern tells the story. Audit and Accountability sits almost entirely on our side: eight of its nine requirements are covered end to end with no client action. System and Information Integrity is delivered wholly through the technical stack, and Awareness and Training is carried by our documentation and training program. At the other end, Personnel Security is guided consulting, because only you can run a background check or walk someone out, and consulting-heavy families like Media Protection and Physical Protection depend on how your facility and media actually work. Wherever a requirement is guided, we supply the template, the calendar reminder, and the engineer who checks the result, and the platform holds the proof once it exists.

The Path to CertificationFrom gap assessment to C3PAO certification, the five-phase process
// The Path to Certification

From Gap Assessment to C3PAO Certification. We Own the Process.

USX Cyber manages every phase of your CMMC journey, from the first gap assessment through the final C3PAO report, following the same Delivery Framework we apply to every program: scope and boundary engineering first, so your assessed environment is no larger than it has to be. You don't need to coordinate multiple vendors or piece together your own path.

1

Gap Assessment

We run a full NIST 800-171 gap assessment against your environment. You get a SPRS score and a prioritized remediation plan within 2 weeks. No surprises, just a clear picture of where you stand and what it takes to get certified.

Deliverable: SPRS score + prioritized remediation plan
2

Onboard to GUARDIENT®

Your environment connects to the platform. Automated coverage kicks in immediately, typically closing 75%+ of gaps within 30 days. Evidence collection starts from day one.

Typical result: 75%+ of gaps closed within 30 days
3

Remediation Sprint

Our advisory team works through remaining gaps: policy documentation, missing controls, configuration hardening, and System Security Plan (SSP) completion. Every finding gets an owner and a deadline.

Deliverable: Complete SSP + remediated control set
4

Pre-Assessment Readiness Review

Internal mock assessment using the official CMMC assessment guide. We identify and close any remaining findings before the C3PAO arrives. This is the step that separates first-attempt passes from costly reassessments.

Deliverable: Readiness report + closed finding list
5

C3PAO Assessment

We coordinate the official assessment with a qualified C3PAO. Most GUARDIENT® clients pass on the first attempt. Your evidence package is pre-assembled and your team is briefed, no last-minute scrambles.

Result: CMMC Level 2 certification
// Engagement Options

Two Ways to Engage. One Path to Certification.

Whether you're starting from scratch or already midway through your CMMC journey, we have an engagement model that fits your timeline and budget.

CMMC Readiness Package

Get Assessment-Ready

Everything you need to walk into a C3PAO assessment with confidence
  • Gap assessment against NIST 800-171 with full SPRS scoring
  • GUARDIENT® platform onboarding and automated coverage
  • System Security Plan (SSP) and required policy documentation
  • Remediation advisory through all remaining control gaps
  • Pre-assessment readiness review and mock assessment
Contact us for a quote based on your environment size and starting posture, most readiness engagements are scoped within one working session.
CMMC Full Certification Bundle Most Complete

Certification and Beyond

From gap to certified, and continuously compliant afterward
  • Everything in the CMMC Readiness Package
  • C3PAO coordination and official assessment support
  • On-site or remote assessment presence from USX Cyber advisors
  • Post-certification continuous monitoring inside GUARDIENT®
  • Annual evidence refresh for triennial recertification readiness
  • Control drift alerts and remediation advisory year-round
Contact us for a quote, pricing based on organization size, environment complexity, and current posture.
// Common Questions

CMMC 2.0. What You Need to Know

Which CMMC level applies to my company?

Read the clause. If your contracts carry FAR 52.204-21 and you hold only Federal Contract Information, Level 1 applies: 15 requirements and an annual self-assessment. If they carry DFARS 252.204-7012 and you receive, create, or store Controlled Unclassified Information, Level 2 applies: all 110 requirements of NIST SP 800-171. Level 3 is invoked by the Department for named programs, not chosen by the contractor. Send us the clause, we'll confirm the level on the first call.

Do I need CMMC if I'm a subcontractor?

If you handle CUI or FCI, yes. CMMC flows down through the prime contractor to all subcontractors handling covered data. Your prime will require proof of certification before awarding you work. Being a sub does not create an exemption; it creates a deadline set by whoever sits above you in the supply chain.

How long does it take to get CMMC Level 2 certified?

With GUARDIENT®, most clients are assessment-ready within 60–90 days of onboarding. Timelines vary based on organization size, the number of systems in scope, and your starting posture. Organizations with significant existing gaps or large, complex environments may take longer. The gap assessment we run in week one gives you a clear timeline estimate.

Is CMMC paused? What does the Phase II suspension mean?

On July 13, 2026, the Department of War suspended CMMC Phase II pending a Reform Task Force review, so new solicitations may currently designate only Level 1 (Self) or Level 2 (Self), third-party C3PAO and government-led designations are on hold. What did not pause: Phase I self-assessments, DFARS 252.204-7012, NIST SP 800-171 compliance, SPRS score postings, and annual affirmations. Contractors who use this window to close gaps and build evidence will be first in line when third-party assessments resume.

What is a C3PAO and do I need one?

A C3PAO (Certified Third-Party Assessment Organization) is a Cyber AB-authorized company that conducts official CMMC Level 2 (C3PAO) assessments. Under the phased rollout, many CUI-handling contractors will need a C3PAO assessment once Phase II resumes; while Phase II is suspended, only self-assessment designations may appear in new solicitations. The controls are identical either way, so readiness work transfers one-for-one. USX Cyber coordinates the C3PAO engagement as part of our Full Certification Bundle and can recommend qualified assessors aligned with your timeline.

What happens if I fail the assessment?

You have the opportunity to remediate and reassess. USX Cyber stays with you through the process, our pre-assessment readiness review is specifically designed to prevent first-attempt failures by surfacing and closing findings before the official assessor arrives. If a finding does emerge during the assessment, we help you document the remediation path and get back in front of the C3PAO as quickly as possible.

Can GUARDIENT® replace my existing security tools?

For most small-to-mid sized defense contractors, yes. GUARDIENT® provides XDR, SIEM, SOAR, and GRC in one unified platform, replacing the need for separate EDR, log management, incident response, and compliance tools. This consolidation also reduces your attack surface and simplifies the scope of your CMMC assessment environment.

// Get Started

Ready to Start Your CMMC Journey?

Whether you're just discovering the requirement or facing a contract deadline, USX Cyber will meet you where you are. Book a call with our CMMC team and we'll walk you through your current posture, your timeline, and exactly what it takes to certify.

Start a CMMC Readiness Consultation