CMMC Program Status / C3PAO Selection

C3PAO Selection Guide
for DoD Contractors (2026)

CMMC Phase 2 was suspended by the Department of War on July 13, 2026 (memo 26-P-1023), so the third-party certification phase-in that had been scheduled for November 10, 2026 is not proceeding while a CMMC Reform Task Force completes its review. There is no certification clock in front of you right now. The certificate still comes from a C3PAO whenever Level 2 assessment requirements return, the ecosystem is small, and the backlog is real. This is the vendor-neutral guide Petronella Technology Group built to help DoD contractors choose the right C3PAO partner without losing 12 months to the wrong call.

Cyber AB RPO #1449 / CMMC-RP Team / Founded 2002 / Raleigh, NC
Definition

A C3PAO (CMMC Third-Party Assessment Organization) is an organization authorized by the Cyber AB to conduct CMMC Level 2 assessments of DoD contractors. On July 13, 2026 the Department of War suspended CMMC Phase 2 (memo 26-P-1023), so third-party certification requirements are not being phased into new solicitations while a CMMC Reform Task Force completes a 60-day review. DFARS 252.204-7012 safeguarding and CMMC Phase 1 self-assessment requirements are unaffected and still apply. Choosing the right C3PAO partner still matters because the ecosystem is small, assessor capacity is constrained (contractors commonly report waiting 6 to 9 months for a slot), assessor quality varies, and findings that exceed POAM tolerance force a re-engagement that can blow contract timelines.

110 NIST SP 800-171 Requirements at Level 2
80,000+ DoD Contractors Estimated in Scope
6-9 mo Scheduling Wait Contractors Commonly Report
2026-07-13 CMMC Phase 2 Suspended
Why It Matters

Why C3PAO Selection Matters in 2026

With Phase 2 suspended there is no certification clock to race, which makes this the calm window to do the diligence. The CMMC ecosystem is small, capacity is the binding constraint, and the wrong C3PAO partner can stall a contract for a full quarter or longer.

For 24 years Petronella Technology Group has worked with DoD subcontractors across the Mid-Atlantic, and the conversation through 2026 sounds the same on every call: a prime contractor has flowed CMMC Level 2 down through the supply chain, the program manager still wants assurance the sub can protect CUI, and the sub is trying to work out what the July 2026 suspension of Phase 2 actually changed. Selection of the C3PAO is the single most external-dependent decision in a Level 2 program. Implementation is internal, evidence is internal, even mock assessment is internal, but the certificate that a contracting officer wants to see comes only from a C3PAO. Pick the wrong partner and the schedule slips.

The factors that shape a C3PAO decision in 2026:

  • Phase 2 is suspended, so there is no certification clock right now. The Department of War suspended CMMC Phase 2 on July 13, 2026 (memo 26-P-1023). Phase 2 had been scheduled to start on November 10, 2026 and would have begun placing Level 2 assessment requirements into selected solicitations. A CMMC Reform Task Force is running a 60-day review with a public request for information, and the stated aim is to reduce certification burden rather than lower the cybersecurity baseline. DFARS 252.204-7012 and Phase 1 self-assessment requirements are unaffected. Running the C3PAO diligence without a deadline on your back is the low-stress version of this work.
  • The C3PAO ecosystem is small. The organizations fully authorized to conduct CMMC Level 2 assessments number in the dozens, against a population estimated above 80,000 defense contractors and subcontractors that may need certification at full enforcement. The count changes month to month, so treat the Cyber AB directory as the current number rather than any figure quoted in a guide. The math is not favorable to last-minute scheduling.
  • The Cyber AB DoD IG audit surfaced concerns. An Industrial Cyber report on the DoD IG audit documented gaps in the C3PAO authorization process, including authorizations issued without verified quality control leads in some cases. Translation: not every C3PAO is operating at the same maturity.
  • Evidence demands vary widely between firms. Certified CMMC Assessors (CCAs) talking informally describe wildly different evidence requests for the same NIST 800-171 control. Some C3PAOs will accept a screenshot and a policy reference; others insist on raw configuration export plus a workflow walk-through. Picking a methodology that does not match your evidence library is a slow-motion fail.
  • Assessor capacity is the bottleneck, not contractor readiness. Ready contractors are calling C3PAOs and being told the next available slot is 6 to 9 months out, sometimes longer for niche industry verticals. That is a scheduling problem you do not solve by working harder on remediation.

None of this means CMMC Level 2 is impossible. It means selecting the C3PAO is no longer an afterthought. It is a strategic decision that should happen during gap analysis, not after remediation is "done."

Process

What Does a C3PAO Actually Do?

The CMMC Level 2 assessment is a defined, multi-stage process. Here is what the C3PAO owns end-to-end.

STAGE 01

Pre-Engagement Scoping

System Security Plan review, scope agreement, definition of the assessment boundary, identification of in-scope assets and information flows.

STAGE 02

Evidence Review

Control-by-control review of the 110 NIST SP 800-171 requirements that make up CMMC Level 2. Evidence is documented, examined, and tested. Level 3 is not C3PAO work: its 24 additional NIST SP 800-172 requirements (134 in total) are assessed by the government through DIBCAC, with a Final Level 2 certification from a C3PAO as a prerequisite (32 CFR 170.18). Level 3 contract designations are currently suspended.

STAGE 03

On-Site or Remote Assessment

Workforce interviews, evidence walk-throughs, observation of operations, configuration sampling, and any technical testing the C3PAO methodology requires.

STAGE 04

Findings + POAM

Assessment findings are documented. Where gaps exist, the contractor builds a Plan of Action and Milestones (POAM) to remediate within allowed parameters.

STAGE 05

Cyber AB Submission

Final assessment report is submitted to the Cyber AB for review. Quality assurance review at this layer is one place where the IG audit found inconsistency.

STAGE 06

Certificate Issuance

Upon a passing assessment and Cyber AB review, the contractor receives a CMMC Level 2 certificate valid for three years. The clock starts again at year three.

Critical Distinction

Pre-Assessment vs Assessment: Why You Need Both an RPO and a C3PAO

This is the single most-misunderstood aspect of the CMMC ecosystem. Two separate organizations. Two separate roles. By Cyber AB design.

Activity RPO (Registered Provider Organization) C3PAO (Third-Party Assessment Org)
Gap analysis Yes - core RPO function No - conflict of interest
Control implementation Yes - hands-on remediation No - cannot remediate then assess
Policy and procedure authoring Yes - SSP, POAM, supporting docs No
Mock assessment / dry run Yes - simulates the C3PAO experience No - that is what the formal assessment is
Formal CMMC L2 assessment No - not authorized to certify Yes - the only path to certification
Certificate issuance No Yes - via Cyber AB submission
Post-assessment POAM remediation Yes - close gaps No - a different C3PAO would re-assess

Petronella Technology Group is a Cyber AB Registered Provider Organization (RPO) #1449, verified at cyberab.org/Member/RPO-1449-Petronella-Cybersecurity-And-Digital-Forensics. We are not a C3PAO. We do not certify. The CMMC ecosystem is intentionally separated this way, and that separation is in the contractor's favor: the firm that helped you implement controls has a meaningful incentive to score them generously, so the assessor must come from a different organization. If a vendor offers to do both your remediation and your formal assessment, that is a red flag. The Cyber AB does not authorize that arrangement.

What that means in practice for a Level 2 contractor: you will engage two different organizations. An RPO (or in-house team plus consultancy) handles months 1 through 12, including gap analysis, policy authoring, technical remediation, evidence buildout, and a mock assessment. A C3PAO handles the formal assessment in months 13 through 22. Petronella Technology Group plays the RPO role end-to-end, and we coordinate with the C3PAO our client selects, but we do not certify, and we never claim that authority.

Selection Framework

How to Choose a C3PAO

A vendor-neutral checklist, built from the patterns Petronella has observed across more than two decades of helping DoD subcontractors navigate compliance assessments.

Red Flags to Avoid

  • Claims of "flexibility" on evidence requirements. The standards are the standards. NIST 800-171 controls are defined. A C3PAO that promises to lower the bar is offering something the Cyber AB will eventually catch.
  • Promises of "fast" assessments. A proper Level 2 assessment runs three to six weeks of active engagement, depending on scope. "Two-week assessment" usually means evidence corners are being cut.
  • No CCA on staff with verifiable assessor ID. Every formal assessment must be led by a Certified CMMC Assessor. Ask for the assessor name and Cyber AB ID. Verify it.
  • Vague or "all-inclusive" pricing. A reputable C3PAO will scope based on enclave size, evidence volume, and contract complexity. "Flat rate, all-in" usually means scope creep is coming.
  • No commitment to specific timeline windows. "We will get to you when we can" with no delivery date is a sign of a backlogged C3PAO that has not built operational discipline.
  • No public references from completed assessments. A C3PAO with a year of experience should be able to name three contractors who have agreed to be referenced.
  • Recent disciplinary action from the Cyber AB. The Cyber AB publishes notices on suspended or revoked C3PAO authorizations. Check it.
  • No documented quality assurance process. The DoD IG audit specifically flagged inconsistent QA. Ask: who reviews the lead CCA findings before submission? If the answer is "the lead CCA," walk.

Green Flags to Look For

  • CCAs with verifiable Cyber AB profiles. Named, listed, identifiable. Recently re-credentialed if the original cert is older.
  • Defined methodology and sample evidence requests pre-engagement. Before contract signature, the C3PAO can show you what an evidence request package looks like for a control you both pick.
  • Transparent pricing. Many C3PAOs publish typical engagement bands rather than holding every number back until after a scoping call. Ask for the band, and ask which variables move it: enclave size, evidence volume, number of sites, and travel. A firm that will put that in writing before contract signature is a green flag.
  • Public client testimonials with names and companies. Not "a satisfied client in the aerospace industry," but actual contractor names with permission to be cited.
  • Clean Cyber AB record. No suspensions. No public corrective action notices. Active in good standing.
  • Documented quality assurance process. Peer review of findings before submission, an internal QA lead reviewing every assessment, and a documented escalation path for disputed findings.
  • Industry vertical experience. A C3PAO that has assessed contractors in your vertical (aerospace, shipbuilding, electronics manufacturing, software, engineering services) brings pattern recognition you do not have to teach them.
  • Insurance and liability coverage. Errors and omissions coverage that names the C3PAO authorization. Worth asking, worth getting in writing.
Diligence

Questions to Ask Every C3PAO Before Signing

Take this list to every C3PAO meeting. Document the answers. Compare side by side.

  1. How many CMMC Level 2 assessments has your firm completed to a final certificate?
  2. Who specifically will be the lead Certified CMMC Assessor on our engagement, and what is their Cyber AB ID?
  3. What is your typical assessment-to-certificate timeline, measured from the kickoff meeting?
  4. What happens if we have a finding? What is your remediation re-review process and is it included or extra?
  5. Will you provide references from three completed assessments in the past 12 months that we can call?
  6. What is your insurance and liability coverage if your assessment is later disputed by the Cyber AB or DoD?
  7. What is your evidence request methodology? Can we see a sample evidence package for one control before we sign?
  8. What is your internal quality assurance process before findings are submitted to the Cyber AB?
  9. Have you completed an assessment in our industry vertical? If so, can we speak to that contractor?
  10. What is the soonest you can begin our assessment, and what does the schedule look like through certificate?
  11. If our scope expands during assessment, how do you handle change orders?
  12. What is your policy on scope and Federal Contract Information (FCI) versus Controlled Unclassified Information (CUI) boundary disputes?
Ecosystem

The Current C3PAO Ecosystem

A grounded picture of supply, geography, and how to research for yourself.

Honest framing first: this section does not list "best" or "worst" C3PAOs by name. We have not assessed every C3PAO in the ecosystem, no public comparative data set exists, and any ranking would be editorial speculation. Instead, here is what we know about the ecosystem, with sources.

Authorization counts. The population of fully authorized Level 2 C3PAOs is measured in dozens, not thousands, and it moves month to month as the Cyber AB authorizes additional firms. Any number printed in a guide like this one goes stale, so pull the live count from the Cyber AB directory before you plan around it. What has held steady is the direction: new authorizations have come slower than growth in contractor demand, so capacity remains constrained.

Geography. The C3PAO population is concentrated in the Mid-Atlantic and DC area, with smaller clusters in the Southeast (including North Carolina), the Midwest (Michigan, Ohio), and a handful in the Mountain West and Pacific Coast. Remote assessments are now standard practice, so geographic proximity is a logistics-and-budget consideration, not a capability constraint.

The official directory. The Cyber AB maintains the official directory of authorized C3PAOs at cyberab.org. This is the only authoritative source. Vendor lists from CMMC consultants, blog posts ranking "top 10 C3PAOs," and industry conference promotions are secondary at best.

How to research a specific C3PAO. Start with the Cyber AB directory entry, which lists authorization status and any public corrective action. Pull the firm LinkedIn and look at the assessor team individual profiles. Search the firm name plus "Cyber AB" plus "suspension" or "revoke" to surface any disciplinary history. Ask the firm directly for three reference contractors, and call them. Then run the twelve diligence questions listed above through every candidate and compare the written answers side by side.

What we will not publish. A list of "top C3PAOs" without testing each one. A claim that one C3PAO is faster than another based on hearsay. Any framing that treats C3PAO selection as a procurement-only decision, because it is not. The C3PAO becomes part of your supply chain for three years per certification cycle.

Realistic Timeline

Sequencing Your CMMC Level 2 Program

A realistic 18-to-24 month timeline for a Level 2 contractor today, including the 6-to-9 month C3PAO scheduling window most planning misses.

MONTHS 1-2

Pre-Assessment / Gap Analysis

RPO work. Petronella Technology Group, RPO #1449, evaluates current control state against NIST 800-171, documents gaps, and produces an SSP and gap remediation plan.

MONTHS 3-9

Remediation

Control implementation, evidence buildout, policy authoring, technical hardening, vendor coordination. The longest phase, and the phase where most "we are 80% there" projects discover the last 20% is the hardest.

MONTHS 10-12

Mock Assessment

RPO-led dry run that simulates the C3PAO experience. Findings get rolled into final remediation. This is where Petronella often finds three to five gaps the team thought they had closed.

MONTHS 13-15

C3PAO Selection + Scheduling

Diligence on three to five candidate C3PAOs, references, contract negotiation. The 6-to-9 month wait many contractors discover too late starts ticking here.

MONTHS 16-22

Formal C3PAO Assessment

Pre-engagement scoping, evidence review, on-site or remote assessment, findings, POAM, Cyber AB submission, certificate issuance. Three years of validity from issuance.

YEAR 3

Re-Certification

CMMC Level 2 certificates are valid for three years. Re-assessment cycle begins six months before expiration to avoid lapse, and that is the time to evaluate whether to stay with the same C3PAO.

The total of 18 to 24 months is why Petronella Technology Group recommends starting readiness work now rather than waiting for the CMMC Reform Task Force to report. The suspension removed a phase-in schedule, not the length of the work: gap analysis, remediation, evidence buildout, and mock assessment take the same time whenever you start them, and evidence has to accumulate over months rather than be produced on demand. Contractors who use this window to measure and remediate are ready for whatever the review produces, and their NIST SP 800-171 posture is already what primes and contracting officers ask about today.

This sequencing also makes the RPO and C3PAO separation impossible to ignore. The C3PAO cannot do remediation, so a separate RPO (or in-house compliance team plus consultancy) has to own months 1 through 12. There is no "single vendor" path. Assessor independence and conflict-of-interest management are conditions of C3PAO authorization under the CMMC program rule (32 CFR 170) and the Cyber AB Code of Professional Conduct, so a combined-role arrangement is not something to plan a program around. Ask any candidate C3PAO to state its conflict-of-interest position in writing.

Engagement Model

How Petronella Technology Group Partners With C3PAOs

Independent. Vendor-neutral. RPO-only. Here is the engagement archetype for clients selecting a C3PAO with our coordination.

Petronella Technology Group is a Cyber AB RPO #1449. We are not a C3PAO. We are not authorized to certify, and we will never represent that we are. What we do is the work on the contractor side of the line: gap analysis, remediation, evidence buildout, mock assessment, advisor coordination during the formal assessment, and post-assessment POAM closure. The assessment result belongs to the C3PAO and to the Cyber AB review that follows it. We do not control that determination and we do not predict it. Selection of the C3PAO is a client decision; we structure the diligence so the decision is informed.

Engagement archetype

  • Months 1-2: Gap analysis and SSP authoring. We document current state against all 110 NIST 800-171 controls, produce or update the System Security Plan, build the initial Plan of Action and Milestones, and scope the assessment boundary. This phase is RPO work in our hands.
  • Months 3-9: Remediation execution. We coordinate technical implementation, policy authoring, vendor changes, training, and evidence collection. We do not subcontract this to the eventual C3PAO. That separation is by design.
  • Months 10-12: Mock assessment. Petronella runs a dry-run assessment that mirrors the methodology our clients can expect from a C3PAO. Findings produce a final round of pre-assessment hardening.
  • Months 13-15: C3PAO selection coordination. We do not certify. We help our clients identify three to five C3PAO candidates whose methodology and stack alignment matches the client environment. We take notes during diligence calls. We do not steer business to any particular C3PAO and we receive no commission from any C3PAO.
  • Months 16-22: Assessment advisor. Where the C3PAO permits, Petronella attends the formal assessment in advisor or observer capacity. We do not interfere with assessor judgment. We help the client interpret evidence requests and surface relevant documentation in real time.
  • Post-assessment: POAM remediation. If the assessment produces findings inside the allowed POAM band, Petronella owns the closure work. If the assessment produces findings outside POAM tolerance, we own the remediation work and the evidence rebuild that prepare the contractor for re-assessment. Whether a re-assessment succeeds is the C3PAO determination, not ours.

What we deliberately do not do: certify, recommend "the best" C3PAO, accept C3PAO referral commission, or push a client toward a specific assessor. The independence is in the client favor. It is also a Cyber AB requirement.

Lessons From the Field

Common C3PAO Selection Mistakes

Patterns Petronella Technology Group has watched derail otherwise-prepared contractors. Avoid all six.

MISTAKE 01

Picking the Cheapest C3PAO Without Checking CCA Credentials

A low-bid C3PAO may not have a CCA on staff with the experience required for your scope. The fee saved becomes a 12-month delay when the assessment fails review.

MISTAKE 02

Picking the Fastest C3PAO Without Confirming Methodology

"We can have you assessed in two weeks" usually means the assessor is skipping evidence rigor. Cyber AB QA review can reject those findings, and you start over.

MISTAKE 03

Not Asking for References

Reference calls take 30 minutes and surface the patterns no marketing page will. Skipping them is the most-preventable mistake in this entire process.

MISTAKE 04

Not Understanding the RPO / C3PAO Separation

One firm cannot both remediate your environment and assess it. Independence and conflict-of-interest management are conditions of C3PAO authorization under 32 CFR 170 and the Cyber AB Code of Professional Conduct. Budget and schedule for two organizations from the start.

MISTAKE 05

Selecting Too Late

A 6-to-9 month wait for a slot is normal in 2026. Contractors who start C3PAO selection after remediation is "done" lose a quarter or more to scheduling alone.

MISTAKE 06

Treating It as Procurement, Not Strategy

The C3PAO becomes part of your supply chain for three years per certificate. This is not a quote-three-vendors-and-pick-the-low-bid decision. It is a strategic partnership selection.

Why Petronella

Why Petronella Technology Group

Real credentials, no marketing fluff, no fabricated stats, no outsourced assessor relationships.

  • Cyber AB Registered Provider Organization (RPO) #1449. Verified at cyberab.org/Member/RPO-1449-Petronella-Cybersecurity-And-Digital-Forensics. The Cyber AB authorization is what makes us eligible to do the prep work the C3PAO will later assess.
  • CMMC-RP Certified team. Craig Petronella, Blake Rea, Justin Summers, and Jonathan Wood all hold CMMC-RP certification. Craig also holds CCNA, CWNE, and Digital Forensics Examiner (DFE) #604180.
  • BBB A+ accredited since 2003. Twenty-plus years of clean accreditation in a small business with skin in the game.
  • Founded 2002. Twenty-four years serving DoD subcontractors and other regulated SMBs across the Mid-Atlantic and beyond.
  • Raleigh, NC. Headquartered at 5540 Centerview Drive, Suite 200, Raleigh, NC 27606.
  • (919) 348-4912. Direct line. Penny, our AI assistant, books a free 15-minute call with Craig or Blake when you call during off hours. Real humans for the second call.

What you will not see on this page: a "100% pass rate" claim, a list of "satisfied clients" we cannot name, fictional case studies, fabricated testimonials, or a promise of a specific timeline that depends on a C3PAO we do not control. The Cyber AB ecosystem is honest by design, and we operate the same way. We are independent, we recommend C3PAOs based on fit, and we tell our clients what we do not know.

What we will not do: certify, accept C3PAO referral commission, or push a client toward one specific assessor. The integrity of the engagement is the engagement.

FAQ

C3PAO Selection FAQ

The questions Petronella Technology Group hears most often during CMMC Level 2 program kickoffs.

What is a C3PAO?

A C3PAO (CMMC Third-Party Assessment Organization) is an organization authorized by the Cyber AB to conduct formal CMMC Level 2 assessments of DoD contractors. The C3PAO performs the assessment, documents findings, submits the final report to the Cyber AB, and is the only entity that can issue a CMMC Level 2 certificate. The authorized C3PAO population is small, measured in dozens, and changes month to month; the Cyber AB directory at cyberab.org carries the current count. Note that CMMC Level 3 is not C3PAO work: Level 3 is assessed by the government through DIBCAC and requires a Final Level 2 certification first (32 CFR 170.18).

How is a C3PAO different from an RPO?

An RPO (Registered Provider Organization, like Petronella Technology Group, RPO #1449) does the preparation work: gap analysis, control implementation, policy authoring, evidence buildout, and mock assessment. A C3PAO does the formal assessment that produces the certificate. The Cyber AB intentionally separates the two roles because a single firm doing both would have an obvious conflict of interest. The same firm cannot remediate and then assess.

Do I need both an RPO and a C3PAO?

For most contractors targeting CMMC Level 2, yes. The RPO (or in-house compliance team plus consultancy) handles the 12 to 14 months of preparation. The C3PAO handles the 6 to 9 months of formal assessment and certification. They are different organizations with different authorizations. A small contractor with a strong in-house team can sometimes self-prepare, but the volume of NIST 800-171 evidence required for Level 2 typically benefits from RPO engagement.

How long does a CMMC Level 2 assessment take?

From C3PAO kickoff to certificate, plan on 6 to 9 months for a typical Level 2 contractor. This includes pre-engagement scoping (2 to 4 weeks), evidence review and on-site or remote assessment (3 to 6 weeks of active engagement), findings and POAM (2 to 4 weeks), and Cyber AB submission and review (4 to 12 weeks). Add 6 to 9 months of pre-assessment scheduling wait time on top of that, depending on C3PAO backlog.

What is the C3PAO assessor backlog like in 2026?

Backlog is real and varies by C3PAO. As of mid-2026, contractors calling for the first time are commonly quoted 6 to 9 month waits before the assessment can begin. Some C3PAOs with niche industry expertise quote 12 months or longer. The math is straightforward: a few dozen authorized firms against a population estimated above 80,000 defense contractors at full CMMC enforcement creates a capacity-constrained ecosystem. The July 2026 suspension of Phase 2 has taken near-term pressure off assessor calendars, which is a reason to finish selection diligence now rather than when demand returns.

Can my C3PAO also help with remediation?

No. The Cyber AB does not authorize combined remediation-and-assessment engagements with a single firm. A C3PAO that helps you implement controls and then assesses those same controls has a conflict of interest. If a vendor offers to do both, that is a red flag. The Cyber AB framework intentionally separates RPO work (remediation) from C3PAO work (assessment). For Petronella Technology Group, this is why we are RPO-only and never C3PAO. We do the prep. A separate C3PAO does the assessment.

Where can I find the official list of C3PAOs?

The Cyber AB maintains the official directory of authorized C3PAOs at cyberab.org. This is the only authoritative source. Vendor lists, industry blog "top 10" rankings, and conference promotional material are secondary at best. Always verify a C3PAO authorization status directly with the Cyber AB before signing.

What happens if I fail the C3PAO assessment?

It depends on the nature of the findings. Minor gaps inside the allowed Plan of Action and Milestones (POAM) tolerance can be remediated post-assessment without re-engagement; the C3PAO confirms closure and the certificate issues. Major gaps that exceed POAM tolerance trigger a re-assessment, which under Cyber AB rules typically requires re-engagement (often with a different C3PAO to preserve independence) and can add 6 to 12 months to your timeline. This is why mock assessment under an experienced RPO matters: the goal is to surface the gaps before the C3PAO does.

Ready to Plan Your CMMC Level 2 Program?

Petronella Technology Group, Cyber AB RPO #1449, helps DoD subcontractors plan readiness, run remediation, conduct mock assessments, and select the right C3PAO partner. Independent, vendor-neutral, no commission relationships.

Penny, our AI assistant, books a free 15-minute call with Craig or Blake to discuss your CMMC L2 readiness and your C3PAO selection.