Federal & defense · US Department of War (DoD)
Cybersecurity Maturity Model Certification 2.0
Phase 1 self-assessments, DFARS 7012 and SPRS scores are in force today. A paused Phase 2 is not a pardon.
Who it applies to
The businesses that carry CMMC 2.0, and the pages written for them.
Each industry page names the regulation, the obligation and the clock, tells the story of an owner in that trade, and shows what we protect for them.
Which packages satisfy it
CMMC Level 2 Gap Readiness Package
Defense manufacturers, engineering and design firms, and IT and service suppliers of 10 to 300 people handling CUI
CMMC Self-Assessment and SPRS Score Calculation
Suppliers who need a current, defensible SPRS score now and a clear path toward Level 2 later
Mock Audit Package: SOC 2, HIPAA or CMMC
Organizations within 90 days of a SOC 2 audit, an OCR inquiry or a C3PAO assessment, and any leadership team that wants to know before it counts
What it asks for
In plain English, what CMMC 2.0 expects you to have in place.
- CUI scopingWhere Controlled Unclassified Information lives, moves and can be contained, so the assessment covers what matters and nothing more.
- 110 requirements from NIST SP 800-171Each one met or on a plan, with objective-level evidence, across the fourteen control families.
- A System Security PlanThe document an assessor reads first. It describes your environment and how every requirement is satisfied.
- A POA&M with eligible items onlyOpen items are allowed only where the rule permits, with owners and closure dates.
- A defensible SPRS scoreCalculated with the DoD methodology and backed by a worksheet you can hand to a prime.
- A 72-hour incident procedureDFARS 252.204-7012 reporting to DIBNet, rehearsed, with logs that show what left and what did not.
A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. We help interpret the requirements, scope what applies, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify.
CMMC in more detail: the certification path · what drives the cost · the 12-item checklist · what the C3PAO assessment looks like · the enclave question
Questions we get about CMMC 2.0
Do you certify CMMC 2.0 compliance?
Where do we start with CMMC 2.0?
We also need other frameworks. Do we do CMMC 2.0 separately?
Also in federal & defense: NIST 800-171 · CJIS 6.0 · every framework by industry
Next step
Thirty minutes, an engineer, a written scope for CMMC 2.0.
Book the demo and see how one control set carries CMMC 2.0 and everything else you owe. Or leave your details and an engineer replies within one business day.