Defense Contractor Compliance

CMMC COMPLIANCE FOR DEFENSE CONTRACTORS

CMMC Phase 2 certification milestones are paused, but your contract obligations are not: DFARS 252.204-7012, SPRS scoring and Phase 1 self-assessments remain in force. Petronella Technology Group, Inc. prepares you, from gap assessment to a self-assessment score you can defend, or to a C3PAO assessment when your contract calls for one.

CMMC Registered Provider Org|BBB A+ Since 2003|30+ Years Experience
Why Now

Phase 2 Is Paused. Your Obligations Are Not.

On July 13, 2026 the Department of War suspended CMMC Phase 2 (memorandum 26-P-1023) while a CMMC Reform Task Force reviews the program. The requirements already in your contracts still apply.

DFARS 252.204-7012 Still Applies

Where you handle Controlled Unclassified Information, your contracts require NIST SP 800-171 controls and cyber incident reporting.

Supply Chain Flow-Down

Prime contractors flow these requirements down and ask subcontractors for their SPRS score. Your position in the defense supply chain depends on a score you can defend.

Know Which Assessment Applies

Level 1 is a self-assessment of the 15 FAR 52.204-21 requirements. Level 2 covers the 110 NIST SP 800-171 requirements and is either a self-assessment or a C3PAO certification assessment, depending on your contract.

Competitive Advantage

Getting ready during the pause positions your firm as a preferred supplier, with a defensible score and documentation already in place.

Our Services

How We Prepare You for CMMC

Assessment and Planning

  • CMMC gap assessment with SPRS scoring
  • CUI boundary scoping and enclave design
  • Remediation roadmap and budget planning

Implementation and Assessment Preparation

  • Technical control deployment and hardening
  • SSP, POA&M, and policy documentation
  • Mock assessment and C3PAO preparation
FAQ

CMMC FAQs

What is CMMC?

The Cybersecurity Maturity Model Certification (32 CFR Part 170) is the Department of War program that sets how defense contractors show they protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Phase 1 self-assessments are in force; Phase 2 certification milestones were suspended on July 13, 2026 pending a CMMC Reform Task Force review.

Who needs CMMC?

Any organization in the defense supply chain that handles FCI or CUI under a DoD contract needs to meet the CMMC level that contract specifies: Level 1 (15 FAR 52.204-21 requirements) for FCI, Level 2 (110 NIST SP 800-171 requirements) for CUI.

How long does CMMC preparation take?

It depends on your scope: how many systems, people and locations touch contract data, and how many controls already operate. The steps are a scoping call, a gap assessment with an SPRS score, remediation, documentation, and then a self-assessment or, if your contract requires one, a C3PAO assessment scheduled on the assessor's calendar. Documentation is the fast part: ComplianceArmor® generates the Level 1 self-assessment package in minutes and the Level 2 documentation in days.

What does CMMC cost?

Cost varies by organization size and maturity. Contact us for a scoping estimate.

Get Started

Do Not Wait. Start Your CMMC Journey Today.

The pause is the cheapest time to get an SPRS score you can defend. Talk with a CMMC-RP about your scope and your score.