CMMC Compliance
For the Defense Industrial Base

Delivered by a cybersecurity firm, not a compliance shop.
Led by a former CMMC instructor and assessor.
Gap Assessment. Remediation. SSP. Mock Assessment. Certification.
CMMC basics

What is CMMC?

The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense program that verifies contractors actually protect the Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) they handle. It turns long-standing DFARS safeguarding obligations into a verified condition of contract award.
CMMC applies to primes and subcontractors alike, all the way down the supply chain. If your organization touches FCI or CUI, your CMMC status now decides whether you can bid, win, and keep DoD work.
CMMC in 2026

Where the program stands today

Phase 1 is in effect

Since November 10, 2025, new DoD solicitations involving FCI or CUI can require a Level 1 or Level 2 self-assessment, posted in SPRS, as a condition of award. The DoD can also require a third-party Level 2 certification on specific contracts.

Phase 2 is on hold

Phase 2, which would have made third-party Level 2 certification the norm on applicable contracts starting November 10, 2026, was suspended on July 13, 2026 pending a program review. No new date has been announced.

What has not changed

DFARS 252.204-7012 and the 110 NIST SP 800-171 requirements still apply to every contract that involves CUI, along with SPRS scoring, annual affirmations, and incident reporting.

The pause changes the deadline, not the requirement. Contractors who keep preparing will be ready the day certification returns.

Why it matters

Your CMMC status is now part of every bid

Contract eligibility

Stay in the running for the awards you depend on

Contracting officers check your SPRS status before award. The right level, posted and current, keeps you eligible.

Supply chain position

Be the subcontractor primes want to keep

Primes flow CMMC requirements down and are already screening suppliers. Being ready makes you the safe choice.

Legal exposure

Sign your affirmation with confidence

A senior official affirms compliance in SPRS. A program that holds up under scrutiny protects you from False Claims Act risk.

Real protection

Protect the information you were trusted with

The work behind CMMC hardens access, monitoring, and incident response against the adversaries targeting the defense supply chain.
CMMC levels

Three levels. Most contractors need Level 2

Your level is set by the information you handle, and it is written into the contract. We confirm the level you actually need before you spend a dollar on controls you do not.
Level 1: Foundational

Basic safeguarding for FCI

15 requirements from FAR 52.204-21. Annual self-assessment and affirmation.
Level 2: Advanced

The level most contractors need

All 110 NIST SP 800-171 requirements for CUI. Assessed every three years with annual affirmation.
Level 3: Expert

For the highest-priority programs

Level 2 certification plus 24 selected NIST SP 800-172 requirements, assessed by the government (DIBCAC).
Our CMMC background

Built on real CMMC experience, not consulting theory

We know what an assessor looks for, because we have been the assessor.

InfoGuard’s CMMC practice is led by a former C3PAO assessor and CMMC instructor who has trained CMMC instructors, assessors, and DoD contractors, and who was selected to help shape the CMMC framework itself.

Assessor perspective

We prepare you against the same assessment objectives and evidence standards a C3PAO will apply, so nothing in the real assessment comes as a surprise.

Cybersecurity at our core

We understand the architecture, identity, cloud, and network decisions behind each requirement, not just the documentation that describes them.

Hands-on senior leadership

Senior practitioners work alongside your team from gap assessment through certification, not a junior analyst running a checklist.

One effort, multiple frameworks

Much of the NIST SP 800-171 work behind CMMC carries over to SOC 2, ISO 27001, and FedRAMP, so adding a framework later costs far less.

Your compliance investment should deliver more than checklists and documentation.
It should improve your cybersecurity as well.

How we help

From gap assessment to certification, and beyond

01

Discovery & Gap Assessment

We assess your environment against all 110 NIST SP 800-171 requirements using the NIST SP 800-171A assessment procedures, and give you an honest SPRS score to start from.
02

Scope & CUI Boundary

We map where CUI actually flows and design the boundary around it, often with an enclave, so you are not paying to certify systems that never needed to be in scope.
03

Build & Remediation

We implement the technical, operational, and governance controls your plan calls for, along with the tooling and evidence trail to support them.
04

SSP & POA&M

We build the System Security Plan and Plan of Action & Milestones, the core documents your assessor evaluates you against, written to match how your environment really works.
05

Mock Assessment

A full practice assessment using the same evidence reviews, interviews, and testing a C3PAO uses confirms you are ready before the official assessment is scheduled.
06

Certification & Sustain

We connect you with a trusted C3PAO partner, stay engaged through the assessment, then keep your controls, SSP, and annual affirmation current.
FAQ

CMMC questions, answered

Assessment and certification

A C3PAO (CMMC Third-Party Assessment Organization) is a Cyber-AB accredited firm authorized to perform official CMMC Level 2 certification assessments. For separation of duty, we focus on readiness, remediation, and assessment support, and when you are ready for certification we connect you with a trusted C3PAO partner and stay involved through the assessment.
Conflict-of-interest rules require your C3PAO to be independent of any organization that helped build your controls. Splitting the two roles is not a limitation. It is what keeps your certification valid.
A mock assessment is a practice run through the same evidence reviews and interviews a C3PAO will use, done before the real assessment. It is the most reliable way to catch a gap while it is still inexpensive to fix.
A Level 2 certification or self-assessment is valid for three years, with an annual affirmation in between. Level 1 is self-assessed and affirmed every year. We build continuous monitoring into our engagements so the affirmation is never a scramble.
Incomplete or inaccurate System Security Plans are the most common failure point, not missing technical controls. A mock assessment before the real one is the most reliable way to catch this while it is still cheap to fix.

Scope, timing, and cost

The suspension paused the rollout of mandatory third-party certification, not the underlying requirements. DFARS 252.204-7012, NIST SP 800-171, SPRS scoring, and annual affirmations still apply, and Level 2 readiness typically takes months. Waiting usually means a compressed, more expensive project later.
NIST SP 800-171 is the set of 110 security requirements for protecting CUI. CMMC is the DoD program that verifies contractors have actually implemented them. In short, NIST SP 800-171 defines what to do, and CMMC Level 2 verifies you did it.
Possibly, yes. If you handle Federal Contract Information but not CUI, you likely fall under Level 1, which still requires an annual self-assessment. Not handling CUI does not automatically mean CMMC does not apply to you.
It depends on your SSP maturity and CUI footprint, but most Level 2 engagements run several months from initial gap assessment to assessment-ready. We give you a realistic timeline once we have scoped your environment.
Cost depends on your current security maturity, CUI footprint, and how much remediation your systems need. There is no flat fee. We provide a firm quote after an initial gap assessment.
Yes. CMMC applies down through the supply chain, and smaller subcontractors often have the fewest in-house resources to prepare. That is exactly where InfoGuard helps most.
Cybersecurity first

A checkbox compliance provider won't cut it

You need real cybersecurity expertise to protect CUI against the adversaries targeting the defense supply chain, and to pass an assessment built to find the gaps.
InfoGuard is a cybersecurity firm first. Explore our cybersecurity services →
Next step

Tell us where you stand

Tell us what you’re trying to accomplish. We’ll reply with next steps, whether that’s a gap assessment, a mock assessment, or a straight introduction to a C3PAO partner.