CMMC COMPLIANCE FOR DEFENSE CONTRACTORS
CMMC Phase 2 certification milestones are paused, but your contract obligations are not: DFARS 252.204-7012, SPRS scoring and Phase 1 self-assessments remain in force. Petronella Technology Group, Inc. prepares you, from gap assessment to a self-assessment score you can defend, or to a C3PAO assessment when your contract calls for one.
Phase 2 Is Paused. Your Obligations Are Not.
On July 13, 2026 the Department of War suspended CMMC Phase 2 (memorandum 26-P-1023) while a CMMC Reform Task Force reviews the program. The requirements already in your contracts still apply.
DFARS 252.204-7012 Still Applies
Where you handle Controlled Unclassified Information, your contracts require NIST SP 800-171 controls and cyber incident reporting.
Supply Chain Flow-Down
Prime contractors flow these requirements down and ask subcontractors for their SPRS score. Your position in the defense supply chain depends on a score you can defend.
Know Which Assessment Applies
Level 1 is a self-assessment of the 15 FAR 52.204-21 requirements. Level 2 covers the 110 NIST SP 800-171 requirements and is either a self-assessment or a C3PAO certification assessment, depending on your contract.
Competitive Advantage
Getting ready during the pause positions your firm as a preferred supplier, with a defensible score and documentation already in place.
How We Prepare You for CMMC
Assessment and Planning
- CMMC gap assessment with SPRS scoring
- CUI boundary scoping and enclave design
- Remediation roadmap and budget planning
Implementation and Assessment Preparation
- Technical control deployment and hardening
- SSP, POA&M, and policy documentation
- Mock assessment and C3PAO preparation
Explore More
CMMC FAQs
What is CMMC?
The Cybersecurity Maturity Model Certification (32 CFR Part 170) is the Department of War program that sets how defense contractors show they protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Phase 1 self-assessments are in force; Phase 2 certification milestones were suspended on July 13, 2026 pending a CMMC Reform Task Force review.
Who needs CMMC?
Any organization in the defense supply chain that handles FCI or CUI under a DoD contract needs to meet the CMMC level that contract specifies: Level 1 (15 FAR 52.204-21 requirements) for FCI, Level 2 (110 NIST SP 800-171 requirements) for CUI.
How long does CMMC preparation take?
It depends on your scope: how many systems, people and locations touch contract data, and how many controls already operate. The steps are a scoping call, a gap assessment with an SPRS score, remediation, documentation, and then a self-assessment or, if your contract requires one, a C3PAO assessment scheduled on the assessor's calendar. Documentation is the fast part: ComplianceArmor® generates the Level 1 self-assessment package in minutes and the Level 2 documentation in days.
What does CMMC cost?
Cost varies by organization size and maturity. Contact us for a scoping estimate.
Do Not Wait. Start Your CMMC Journey Today.
The pause is the cheapest time to get an SPRS score you can defend. Talk with a CMMC-RP about your scope and your score.