/ RPO #1449 / Cyber AB Registered / Raleigh, NC

CMMC Readiness Assessment

CMMC compliance reinvented for speed. Level 1 in minutes. Level 2 documentation in days. Powered by ComplianceArmor®.

A CMMC readiness assessment gives you three things you cannot get any other way: your true SPRS self-score, a graded gap list across all 110 NIST SP 800-171 requirements, and a costed plan to close them. Run by a fully credentialed CMMC-RP team in Raleigh, North Carolina for Levels 1, 2, and 3.

Free, and there is no obligation. Twenty minutes on the phone, then a fixed-scope quote within two business days. Or call (919) 348-4912.

Read those numbers precisely, because we state them precisely. They describe documentation: the System Security Plan, policies, procedures, POA&M, and SPRS score that ComplianceArmor® generates from a guided assessment. Full Level 1 self-attestation still runs about two to three weeks once registration, signatures, and provisioning happen on your side, and Level 2 certification runs on a Certified Third Party Assessment Organization's calendar, which no consultant controls.

Not ready to talk yet? Download the free CMMC scoping worksheet instead.

  • Confirm the level your contracts require
  • Sketch your CUI enclave
  • Get a defensible SPRS number
  • Fixed quote in 2 business days

Cyber AB RPO #1449/Every practitioner CMMC-RP/In business since 2002

#1449 Cyber AB RPO Registered Provider Organization
100% Team CMMC-RP Every practitioner credentialed
L1+L2+L3 All CMMC Levels Self, Third-Party, Government
110 Controls Scored NIST SP 800-171 gap analysis
2002 Established BBB A+ since 2003
Program status / Updated August 2026

CMMC Phase 2 is suspended, and that is the reason to move now. On July 13, 2026 the Department of War issued memorandum 26-P-1023 suspending CMMC Phase 2, which had been scheduled to begin November 10, 2026, and placing pending implementation milestones in abeyance. A CMMC Reform Task Force is running a 60-day top-to-bottom review and is collecting industry input through a public request for information.

What did not change: DFARS 252.204-7012, DFARS 252.204-7019, DFARS 252.204-7020, and the Phase 1 self-assessment requirements all remain in force. You are still contractually required to implement NIST SP 800-171 and to keep a current, defensible self-assessment score posted in the Supplier Performance Risk System. The Department stated plainly that it is reducing certification-related burdens, not lowering the underlying cybersecurity baseline.

What that means for you: the deadline pressure is off, the legal obligation is not. This is a preparation window, and it is the least expensive one you will get. Getting measured and remediated while there is no clock is far cheaper and calmer than scrambling once the Task Force reports and requirements resume.

Powered by ComplianceArmor®

CMMC compliance, reinvented for speed.

ComplianceArmor® is the proprietary, USPTO-registered compliance platform built by Petronella Technology Group, Inc. From a guided assessment it generates the assessor-ready System Security Plan, policy set, procedures, POA&M, and SPRS score. At Level 1 it produces the documentation package in minutes, covering all 15 FAR 52.204-21 requirements. For Level 2 and NIST SP 800-171 it produces the documentation package and SPRS self-assessment in days for clients onboarded onto our encrypted enclave and managed detection stack.

The honest boundary: a fast document set is not a fast certificate. Full Level 1 self-attestation still takes roughly two to three weeks end to end, and Level 2 certification is performed by a Certified Third Party Assessment Organization on its own calendar. Petronella Technology Group, Inc. is a Registered Provider Organization, so we prepare and we consult; we do not assess, certify, or promise an outcome. Book a free scoping consultation and watch the platform run against your own environment.

Petronella Technology Group back cover advertisement in National Defense Magazine: CMMC compliance reinvented for speed
As seen on the back cover of National Defense Magazine

The Short Version

  • A readiness assessment is a diagnosis, not a certification. It tells you exactly where you stand against NIST SP 800-171 before you spend a dollar on remediation or book a C3PAO.
  • You walk away with five concrete artifacts: a scoped CUI boundary, a 110-control gap analysis, your real SPRS self-score, a prioritized POA&M, and a path-to-assessment roadmap.
  • Petronella Technology Group covers all three CMMC levels - Level 1 self-assessment, Level 2 third-party, and Level 3 government-led - as Cyber AB Registered Provider Organization #1449.
  • Typical timeline: powered by ComplianceArmor®, a Level 1 documentation package is generated in minutes and the Level 2 / NIST SP 800-171 documentation package and SPRS self-assessment that take most firms months land in days. Most single-enclave readiness assessments wrap in about two weeks. Full Level 1 self-attestation still takes two to three weeks end to end, and technical remediation, evidence maturity, and C3PAO scheduling scale with enclave size and starting score.
  • Pricing is custom and scope-first. Scope depends on enclave size, CUI flow, asset count, and your current SPRS posture. Start with a free scoping consultation and the CMMC scoping worksheet.
  • The Phase 2 suspension is a preparation window, not a reprieve. DFARS 252.204-7012, -7019, and -7020 were never suspended, so the underlying NIST SP 800-171 obligation and the SPRS posting duty are still live while the pressure is off.

That is the whole pitch. If it fits your situation, the next step is a free twenty-minute scoping call with a CMMC-RP, ending in a fixed-scope quote within two business days. The rest of this page is the detail behind it.

Book my free scoping call
Section 01 / What You Get

What a CMMC Readiness Assessment Actually Is

A CMMC readiness assessment is a structured, evidence-based diagnosis of where your organization stands against the controls a C3PAO or government assessor will measure you against. It is the first move every serious defense contractor makes - because you cannot fix, budget for, or schedule what you have not measured.

Think of it as the difference between guessing your weight and stepping on a scale. Many contractors believe they are "mostly compliant" because they run modern endpoint protection and multifactor authentication. A readiness assessment turns that feeling into a number: your actual Supplier Performance Risk System (SPRS) self-score, calculated honestly against all 110 NIST SP 800-171 controls. For most organizations that have never done this formally, the first honest score is lower than expected, and frequently negative. That is normal, and it is far better to learn it now than in front of a Certified Third Party Assessment Organization. We hold ourselves to the same standard: in June 2026, Petronella Technology Group scored a perfect 110 on its own CMMC Level 2 self-assessment of its own environment, with an empty POA&M. If you want the full picture before you start, request the free CMMC book by Craig Petronella and read it in an evening.

The assessment is also a scoping exercise. Before any control is graded, a CMMC-RP from Petronella Technology Group works with your team to draw the boundary of where Controlled Unclassified Information (CUI) actually lives - the file servers, the Microsoft 365 tenant, the laptops, the removable media, and the cloud services that touch it. A tightly scoped CUI enclave is the single biggest lever on cost and timeline, because the 110 controls only have to apply inside that boundary, not across your entire enterprise network.

The five deliverables you leave with

  • Scoped CUI boundary. A diagram and asset inventory of every system that processes, stores, or transmits Controlled Unclassified Information, with the enclave boundary drawn explicitly.
  • NIST SP 800-171 gap analysis. All 110 controls assessed for current state - met, partially met, or not met - with the supporting observation for each finding.
  • SPRS self-score. A defensible score posted or ready to post to the Supplier Performance Risk System, with the point-by-point calculation worksheet behind it.
  • Prioritized POA&M. A Plan of Action and Milestones that ranks every gap by risk and effort so you remediate the highest-impact items first.
  • Path-to-assessment roadmap. A sequenced plan with target dates connecting today's score to certification readiness.

Why a readiness assessment comes first

  • It prices the project accurately. Remediation quotes built on a guess are wrong. A scored gap list lets us build a fixed-scope plan instead of an open-ended retainer.
  • It protects your SPRS posture. Posting an inflated self-score creates False Claims Act exposure. The assessment produces a number you can defend.
  • It sequences the spend. Not every gap costs the same to close. The POA&M lets you spend remediation dollars on the controls that move your score the most.
  • It de-risks the C3PAO. A mock-graded environment means no surprises in the room that determines whether you keep your contracts.
  • It is the prerequisite for everything else. The CMMC compliance program, the System Security Plan, and the certification itself all build on the assessment baseline.

It covers all three CMMC levels

The readiness assessment is scaled to the level your contracts require. Petronella consults at Level 1, Level 2, and Level 3, and the assessment determines which applies before scoring begins. The level cards below summarize the differences, and the section on DFARS clauses shows you how to read your own contracts to confirm which level you owe.

Level 01

Foundational

15 requirements · FCI only · Self-assessed

For contractors that handle only Federal Contract Information (FCI), not CUI. Built on the 15 basic safeguarding requirements drawn from FAR 52.204-21.

  • Annual self-assessment
  • Senior official affirmation
  • Light SSP and basic policies
CMMC assessment detail →
Level 02

Advanced

110 practices · CUI handling · C3PAO-assessed

Required when CUI is processed, stored, or transmitted. Aligns to NIST SP 800-171. Most CUI-flowing contracts require Level 2 with a triennial third-party assessment.

  • Triennial C3PAO assessment
  • Full SSP, POA&M, policy library
  • SPRS score posted
CMMC compliance pillar →
Level 03

Expert

110+24 practices · APT-targeted · Gov-assessed

For the most sensitive programs where Advanced Persistent Threats are a credible risk. Overlays NIST SP 800-172 on top of 800-171, assessed by the government (DIBCAC).

  • Government-led assessment
  • Enhanced security requirements
  • Threat hunting and deception controls
Talk to a CMMC consultant →
Section 02 / Why Now

The Certification Clock Is Paused. Your DFARS Obligations Are Not

This is the cheapest, calmest preparation window the defense industrial base has had. The certification mandate is in abeyance, the underlying contractual duty to implement NIST SP 800-171 is not, and the clauses that create that duty are already sitting in your active agreements. A readiness assessment turns an ambiguous moment into a measured plan.

Here is the honest picture. On July 13, 2026 the Department of War suspended CMMC Phase 2 through memorandum 26-P-1023, put pending and future CMMC implementation milestones in abeyance, and stood up a CMMC Reform Task Force to run a 60-day top-to-bottom review informed by a public request for information. Contracting activities were directed to reconsider CMMC Level 2 and Level 3 requirements in active solicitations. The Department was equally clear about the other half: it is reducing certification-related burdens, not lowering the cybersecurity baseline, and it said the action does not eliminate the requirement for companies to protect federal data.

So the correct read is not "CMMC went away." It is "the audit was postponed and the homework was not." DFARS 252.204-7012 still contractually requires you to implement NIST SP 800-171 and to report cyber incidents. DFARS 252.204-7019 still requires a current self-assessment score in the Supplier Performance Risk System, and an inflated score still carries False Claims Act exposure whether or not a certification assessment is scheduled. Primes still send security questionnaires, still ask for your SPRS number, and still make award decisions with it in hand.

That combination is what makes a readiness assessment worth doing right now rather than later. Remediation is a function of engineering time, procurement cycles, and how deep the hole is. Those things do not compress just because a deadline reappears. Organizations that use this window to get measured, fix the expensive gaps on a normal budget cycle, and post a number they can defend will be ready whenever the Task Force reports. Organizations that wait will be buying the same work later, under time pressure, in a market where every other contractor wants the same practitioners and the same C3PAO calendar slots.

Start by pulling every active and pipeline agreement and reading the four DFARS clauses below. Each one signals a different piece of your CMMC scope, and together they tell you what level your contracts point toward and what you must have posted in SPRS today.

DFARS 252.204-7012 · still in force

Safeguarding and incident reporting

Mandates safeguarding of Covered Defense Information (which includes CUI) and rapid reporting of cyber incidents. It was not suspended. The presence of this clause is the strongest single signal that a Level 2 scope of work applies to you, and it is the live legal hook regardless of certification timing.

DFARS 252.204-7019 · still in force

SPRS score required

Requires you to post a current NIST SP 800-171 self-assessment score in the Supplier Performance Risk System. It was not suspended. A readiness assessment produces the defensible score this clause demands, with the calculation worksheet behind it.

DFARS 252.204-7020 · still in force

Government access and flow-down

Requires you to grant the government access to verify your NIST SP 800-171 implementation and to flow these requirements down to your own subcontractors. It was not suspended. This is the mechanism that pushes obligations through the supply chain to small subcontractors.

DFARS 252.204-7021 · in abeyance

The CMMC certification clause

This is the clause that names a required CMMC level and certification cadence, and it is the one affected by the July 2026 suspension. Contracting activities were directed to reconsider Level 2 and Level 3 CMMC requirements in solicitations while the Reform Task Force completes its review. Read it as postponed, not repealed, and note that it sits on top of the three clauses above rather than replacing them.

The cost of waiting did not disappear with the suspension, it just changed shape. Contractors who treat the pause as permission to stop discover later that their gaps were structural rather than clerical, that a prime's security questionnaire arrived anyway, or that they left an indefensible number posted in SPRS for another year. A readiness assessment is the inexpensive, fast first step that removes all three problems. It gives you a measured starting point, a number you can stand behind, and the runway to remediate on a normal budget cycle instead of an emergency one. For a deeper breakdown of what drives engagement cost, see the CMMC cost breakdown, and to understand the scoring math, see how the CMMC self-score is calculated.

Stop guessing your SPRS number. A free, no-obligation scoping call sizes the work and gives you a fixed-scope quote within two business days. You keep the worksheet either way.

Book my free scoping call
The Platform / ComplianceArmor®

Why the Documentation Takes Days Instead of Months

Speed on a compliance project usually means one of two things: somebody cut corners, or somebody removed work from the critical path. ComplianceArmor® is the second kind. Here is exactly how it works, what it produces, and where it stops, stated plainly enough that you can check us on it.

The mechanism: we run the same stack we deploy for you

Most CMMC documentation projects are slow for a structural reason, not a clerical one. Every one of the 110 NIST SP 800-171 requirements has to be satisfied by something real in your environment, and if each control is engineered from scratch inside a general-purpose business network, the writing cannot start until the engineering finishes. So the System Security Plan waits on the architecture, the procedures wait on the plan, and the calendar stretches into quarters.

Petronella Technology Group, Inc. inverts that order by standardizing the environment first. Clients operate inside an encrypted enclave with managed detection behind it: extended detection and response on the endpoints, a security information and event management pipeline collecting and correlating the logs, and a security operations center watching the output. Those platforms carry the bulk of the technical control burden as a deployed baseline rather than as a bespoke build. Encryption of CUI in transit and at rest, boundary protection, audit log creation and retention, session controls, malicious code protection, and continuous monitoring are already implemented and already producing artifacts on day one of the engagement.

ComplianceArmor® then generates the documentation layer on top of that known baseline. Because the platform knows what the enclave and the managed detection stack implement, the guided assessment only has to resolve what is genuinely specific to you: your CUI boundary, your people and roles, your physical sites, your subcontractor flow-down, and your organizational processes. That is a much smaller set of unknowns, and it is why the writing collapses from months to days. This is not a shortcut around the requirements. It is the requirements being satisfied by a stack that was built to satisfy them, then documented by software instead of by hand.

We are the first customer of our own product. In June 2026 Petronella Technology Group, Inc. put its own environment through this exact process and produced its complete Level 2 self-assessment package in hours rather than months, landing at 110 of 110 in SPRS with an empty POA&M. That is the same method described on this page, run on ourselves before we ran it on anyone else.

What ComplianceArmor® actually generates

The artifacts it produces

  • System Security Plan. The assessor-ready SSP, written to the control set and mapped to your scoped boundary rather than to a generic template.
  • Policy set. The governing policies each control family expects, in the vocabulary an assessor is trained to read.
  • Procedures. The operational documents that show a control is not just stated but performed, with owners named.
  • POA&M. A dated Plan of Action and Milestones for everything not yet closed, ranked so remediation dollars go to the highest-weight items first.
  • SPRS score. The point-by-point NIST SP 800-171 calculation and the resulting score, with the worksheet behind it so the number is defensible under questioning.

The frameworks it covers

  • CMMC Levels 1, 2, and 3. The 15 FAR 52.204-21 requirements at Level 1, the 110 NIST SP 800-171 requirements at Level 2, and the 110 plus 24 NIST SP 800-172 enhanced requirements at Level 3.
  • NIST SP 800-171 and NIST SP 800-53. The defense baseline and the broader federal control catalog.
  • NIST CSF 2.0. For the board-level and enterprise risk view that sits above the control set.
  • SOC 2, PCI DSS, HIPAA, and FTC Safeguards. The commercial and sector frameworks most defense suppliers carry alongside CMMC, generated from the same assessment rather than from a second project.

The caveat we put in writing: documentation speed is not evidence maturity

This is the part most vendors leave off the slide, so we will lead with it. An assessor does not only want to read that a control exists. The assessor wants to see it operating and producing evidence over time. Training records need people who have actually taken the training. Incident response needs a tabletop exercise that actually happened, with the after-action notes to prove it. Audit review needs a log of reviews performed on a stated cadence, not a policy asserting that reviews will occur. Vulnerability management needs a run of scans and closed findings, not a single scan from last Tuesday.

So a client-side operating window remains, and no platform removes it. What ComplianceArmor® removes is the documentation bottleneck that used to sit in front of that window and consume the calendar before the clock on evidence could even start. In practice that means you begin generating real operating evidence in week one instead of month four, which is the actual reason the total timeline shortens. Saying this out loud is a differentiator rather than a weakness. Any firm that tells you a document generator alone makes you assessment-ready is describing a finding waiting to happen, and the same firm is usually the one that will not tell you which controls still need a maturity window.

Where the platform stops and the practitioner starts

Petronella Technology Group, Inc. is a Cyber AB Registered Provider Organization, RPO #1449, staffed by CMMC Registered Practitioners. We provide consulting. We do not assess, we do not certify, and we do not guarantee a certification result, because the outcome belongs to a Certified Third Party Assessment Organization at Level 2 and to the government at Level 3. Every ComplianceArmor® package is reviewed by a CMMC-RP before it leaves our hands, which is the point: software speed with a credentialed human accountable for what the document says. For the mechanics of how the score itself is computed, see the CMMC self-score breakdown, and for the full platform detail see ComplianceArmor®.

Want to see it run against your environment? The scoping call is free, takes about twenty minutes, and ends with a fixed-scope quote within two business days.

Book my free scoping call
Section 03 / The Engagement

How Petronella Runs a Readiness Assessment

The assessment is a focused engagement measured in days, not months: ComplianceArmor® automates the documentation-heavy work while a CMMC-RP runs the interviews and evidence review. It feeds directly into remediation and, eventually, certification readiness. Here is the phase structure and the artifacts each phase produces.

PHASE 01 Day 1

Scoping & Discovery

A kickoff workshop with your executive sponsor, IT lead, and compliance owner to identify which contracts impose CMMC and where CUI lives today.

  • DFARS clause inventory
  • CUI footprint sketch
  • Enclave boundary candidates
  • Signed assessment scope
PHASE 02 Week 1

Gap Analysis

A control-by-control assessment against NIST SP 800-171, combining asset discovery, evidence review, and interview-based control walkthroughs.

  • Asset inventory and CUI flow map
  • 110-control current-state matrix
  • Evidence gaps documented
  • Findings observations recorded
PHASE 03 Week 2

SPRS Scoring

Translation of the gap analysis into a defensible SPRS self-score with the supporting calculation, ready to post under DFARS 252.204-7019.

  • 110-control point calculation
  • Defensible SPRS self-score
  • Calculation worksheet
  • Submission guidance
PHASE 04 Week 2

Roadmap Handoff

A working session that delivers the prioritized POA&M and the path-to-assessment roadmap, with a fixed-scope quote for the remediation phase.

  • Prioritized POA&M
  • Path-to-assessment roadmap
  • Remediation scope and quote
  • C3PAO timing guidance
No.
Deliverable
What you get
01
Scoped CUI Boundary
A diagram and inventory of every system that touches CUI, with the enclave boundary drawn explicitly
02
110-Control Gap Analysis
Every NIST SP 800-171 control graded met, partial, or not met with a supporting observation
03
SPRS Self-Score
A defensible score with the point calculation worksheet behind it, ready for SPRS
04
Prioritized POA&M
A ranked Plan of Action and Milestones ordered by risk and remediation effort
05
Path-to-Assessment Roadmap
A sequenced plan with target dates connecting today's score to certification readiness

Ready to put a number on your readiness? Twenty minutes with a CMMC-RP, no cost, no commitment, and a fixed-scope quote within two business days.

Book my free scoping call

What separates a Petronella assessment from a template-driven checklist is that the same firm that scores you can also remediate the gaps and operate the controls afterward through our CMMC compliance services. The findings are written by a CMMC-RP who understands not just the language of NIST SP 800-171 but the engineering required to satisfy a control under interview - multifactor authentication scope, FIPS-validated cryptography, audit logging coverage, and configuration baselines. For a side-by-side look at the consulting role versus the assessor role, see our CMMC consultant overview, and for the control-to-control crosswalk see the CMMC to NIST mapping.

Section 04 / Why Petronella

Why a Credentialed RPO and Not a Generic IT Firm

Anyone can call themselves a CMMC expert. The Cyber AB Marketplace is the only authoritative list of firms credentialed to prepare contractors for assessment. Petronella Technology Group is listed there as Registered Provider Organization #1449.

#1449 RPO

Cyber AB Registered Provider Organization

An RPO is a company authorized by the Cyber AB, the official accreditation body of the CMMC ecosystem, to provide readiness, consulting, and advisory services to organizations preparing for CMMC. RPOs sign a code of professional conduct and their practitioners individually hold the CMMC-RP credential. You can verify any consultant at the official Cyber AB marketplace.

One outcome, stated plainly. Petronella Technology Group, Inc. prepared a defense industrial base client for a Certified Third Party Assessment Organization certification assessment at CMMC Level 2, and that client certified on the first attempt. We will not tell you that guarantees your result, because no consultant controls an assessor's findings and nobody can promise you a certification. We will tell you that the preparation work that produced it is the same work described on this page.

Real credentials, verifiable on the record

Every practitioner on the Petronella compliance team holds the CMMC-RP (Registered Practitioner) designation - not just the principal. Craig Petronella, the firm's founder, holds CMMC-RP alongside CCNA, CWNE, Digital Forensic Examiner (DFE) #604180, and is MIT-Certified in AI and Blockchain.

The forensic background is not decoration. A CMMC readiness assessment leans on audit logging, incident response, and evidence preservation that mirror the chain-of-custody discipline used in digital forensics. A practitioner who has actually collected an evidentiary disk image writes a sharper Incident Response Plan and a more honest gap finding than one who has only read about it. When an assessor asks how you would preserve logs after a suspected compromise, that answer comes from real casework, not a template.

Petronella Technology Group has operated as a North Carolina IT and security firm since 2002, with a BBB A+ rating since 2003, headquartered at 5540 Centerview Dr., Suite 200, Raleigh, NC 27606. That two-decade operating history matters during an assessment, because organizational maturity is itself a signal assessors weigh. Firms that stood up a CMMC division in the last eighteen months to chase the contract dollar work from a thinner bench than one that has been engineering, defending, and forensically investigating networks for more than twenty years.

AI plus compliance, built for the NC defense corridor

Petronella pairs CMMC readiness with a private AI security practice, which is increasingly relevant as contractors adopt AI tooling inside CUI environments and need that adoption mapped to controls rather than bolted on. The firm focuses on the North Carolina defense corridor - the contractors and engineering firms serving Fort Liberty (Fort Bragg), Seymour Johnson Air Force Base, Camp Lejeune, and the engineering and research community across the Research Triangle Park. Local presence means scoping workshops can be run on-site, and it means the team understands the specific contract types and CUI profiles common to the region.

What changes when your readiness partner is a real RPO

  • Cyber AB listed and verifiable. Your procurement and contracts teams can pull the listing as an objective credential.
  • Code of professional conduct. Constrains what the firm can claim about your readiness in proposals and to your primes.
  • Curriculum-aligned vocabulary. The gap analysis, POA&M, and SPRS language match what assessors are trained to read.
  • A clean referral path to C3PAOs. RPOs work alongside Certified Third Party Assessment Organizations constantly and know which assessors fit your contract type, geography, and CUI profile.
Section 05 / Engagement Framing

Framed by Timeline, Scoped by Your Environment

CMMC engagement cost is custom because no two CUI environments are alike. Rather than publish a number that would be wrong for your situation, Petronella scopes first and quotes a fixed price. What we can tell you up front is how the work is paced.

How the work is paced

  • Readiness assessment - about two weeks. Scoping, the 110-control gap analysis, your SPRS self-score, and the prioritized POA&M and roadmap - with ComplianceArmor® doing the documentation-heavy lifting in days, not months.
  • Remediation - paced by your gaps, not paperwork. ComplianceArmor® generates the System Security Plan, policy library, and POA&M updates in days. Technical control buildout is scoped to your enclave size and starting score.
  • Full path to assessment - faster than you have been told. Level 1 self-attestation can complete in as little as two to three weeks end to end. For Level 2, certification readiness is paced by technical remediation and C3PAO scheduling, not document production - and includes a mock C3PAO walkthrough and evidence package staging.

What drives the scope and quote

  • Enclave size. A narrowly scoped CUI boundary is the biggest lever on cost - the 110 controls only apply inside it.
  • CUI flow complexity. How CUI moves between on-premises systems, Microsoft 365, and cloud services.
  • Asset and user count. The number of endpoints, servers, tenants, and people who touch CUI.
  • Starting SPRS posture. A deeper hole takes longer to climb out of than a near-ready environment.
  • Target level. Level 1 is lightest; Level 3 overlays NIST SP 800-172 and is heaviest.

The fastest way to a real number is a free scoping consultation. Twenty minutes with a CMMC-RP walking your DFARS clauses and CUI footprint typically gives us enough to size a fixed-scope quote within two business days. Come prepared by downloading the CMMC scoping worksheet, which captures your in-scope assets, users, and data flows before the call so the conversation is faster and more accurate. To browse the full compliance practice, see the compliance services overview.

Section 06 / Straight Answers

The Six Reasons People Hesitate, Answered Honestly

These are the objections that come up on almost every scoping call. We would rather you read the honest answer here than spend a call on it.

"CMMC Phase 2 is suspended. Why would I spend money now?"

Because the suspension moved the audit, not the work. DFARS 252.204-7012 still obligates you to implement NIST SP 800-171, DFARS 252.204-7019 still obligates you to keep a current SPRS score posted, and the Department of War said in the same breath that it is reducing certification burden rather than lowering the security baseline. Remediation takes engineering time and procurement cycles that do not compress on demand. Doing it now, without a clock, is the cheapest version of this project you will ever be offered.

"We already have an IT provider."

Good, and you will probably keep them. A readiness assessment is a measurement exercise, not a rip-and-replace pitch. Most general IT providers are excellent at uptime and terrible at evidence, because NIST SP 800-171 grades documented, demonstrable control implementation rather than whether a tool is installed. We routinely hand the gap list and POA&M to an incumbent provider and let them close what they are equipped to close.

"We are too small for this to be worth it."

Small is normal here. Flow-down under DFARS 252.204-7020 pushes the same handling obligation to a five-person machine shop that it pushes to a prime. We frequently work with firms in the 5 to 50 employee range that have a single CUI enclave, and small scope is an advantage: the 110 requirements only apply inside the boundary you draw, so a tight enclave is the single biggest lever on your total cost.

"Is this a sales trap for a big remediation contract?"

The scoping call is free and produces a fixed-scope quote you are free to take elsewhere. The assessment itself is a paid, standalone deliverable: you own the CUI boundary diagram, the graded gap list, the SPRS calculation worksheet, and the POA&M whether or not you ever hire us again. We would rather you have an accurate number and shop it than have an inflated number and trust it.

"Can you certify us?"

No, and be wary of anyone who says otherwise. Petronella Technology Group, Inc. is a Cyber AB Registered Provider Organization. We prepare organizations for assessment; we do not perform certification assessments. Level 1 is self-assessed with a senior official affirmation, Level 2 certification is performed by a Certified Third Party Assessment Organization, and Level 3 is assessed by the government's DIBCAC. We prepare you and refer you to an appropriate assessor.

"We already ran a self-assessment and posted a score."

Then the most valuable thing we can do is check whether that number survives contact with an assessor. The most common finding on a re-score is a control marked met on the strength of a purchased tool with no policy, no configuration evidence, and nobody who can describe the process under interview. An overstated SPRS score is the exposure, not an understated one. See how the CMMC self-score math actually works.

Still have a question that is not answered here? Ask it on the call. It is free, it takes about twenty minutes, and there is no obligation at the end of it.

Book my free scoping call
Section 07 / FAQ

CMMC Readiness Assessment: FAQ

The questions defense contractors ask most often before booking a readiness assessment.

CMMC Phase 2 was suspended. Is CMMC cancelled, and should I wait?

It is suspended, not cancelled, and waiting is the expensive option. On July 13, 2026 the Department of War issued memorandum 26-P-1023 suspending CMMC Phase 2, which had been scheduled to begin November 10, 2026, placing pending implementation milestones in abeyance and directing contracting activities to reconsider Level 2 and Level 3 CMMC requirements in solicitations. A CMMC Reform Task Force is conducting a 60-day review and gathering industry input through a public request for information.

What was not suspended matters more for your planning. DFARS 252.204-7012, DFARS 252.204-7019, DFARS 252.204-7020, and the Phase 1 self-assessment requirements all remain in force, which means you are still contractually obligated to implement NIST SP 800-171 and to keep a current, defensible self-assessment score posted in SPRS. The Department stated that it is reducing certification-related burdens rather than lowering the underlying cybersecurity baseline, and that the action does not eliminate the requirement to protect federal data. Treat the pause as a preparation window: measure now, remediate on a normal budget cycle, and be ready before requirements resume.

What is a CMMC readiness assessment?

A CMMC readiness assessment is a structured diagnosis of where your organization stands against the controls a C3PAO or government assessor will measure. It scopes your CUI boundary, grades all 110 NIST SP 800-171 controls, produces your real SPRS self-score, and hands you a prioritized POA&M and a path-to-assessment roadmap. It is the inexpensive first step that lets you budget, sequence, and schedule the rest of the work accurately. It is not a certification - only a Certified Third Party Assessment Organization (C3PAO) or, for Level 3, the government can certify you.

How long does a readiness assessment take?

With ComplianceArmor® automating the documentation, the assessment is measured in days, not months: scoping and discovery in the first working session, an accelerated control-by-control gap analysis, and your SPRS self-score and prioritized roadmap generated directly from the findings. Most single-enclave assessments wrap in about two weeks; larger or multi-site environments extend that. A Level 1 self-assessment package is generated in minutes, and Level 2 / NIST SP 800-171 documentation that historically took months is produced in days. Technical remediation and C3PAO scheduling then scale with your enclave size and starting score.

How can ComplianceArmor® produce Level 2 documentation in days when everyone else takes months?

Because the technical controls are not being invented for each client. Petronella Technology Group, Inc. runs the same stack it deploys: clients operate inside an encrypted enclave with managed detection behind it, meaning extended detection and response, a security information and event management pipeline, and a security operations center. Those platforms carry the bulk of the technical requirements as a deployed baseline, so the guided assessment only has to resolve what is genuinely specific to you, such as your CUI boundary, your roles, your sites, and your subcontractor flow-down. ComplianceArmor® then generates the System Security Plan, policies, procedures, POA&M, and SPRS score on top of that known baseline. It supports CMMC Levels 1, 2, and 3, NIST SP 800-171, NIST SP 800-53, NIST CSF 2.0, SOC 2, PCI DSS, HIPAA, and FTC Safeguards.

Two limits stated plainly. First, the day-scale claim covers the documentation package and the SPRS self-assessment, not certification: Level 2 certification is performed by a Certified Third Party Assessment Organization on its calendar, and Level 3 is government-assessed. Second, assessors want controls operating and producing evidence, so client-side items such as training completion, incident response exercises, and audit review cadence still need a short operating window. Documentation speed is not the same thing as evidence maturity, and any vendor who blurs those two is setting you up for a finding.

Do I need a C3PAO, or is this assessment enough?

They serve different purposes. A readiness assessment, performed by a Registered Provider Organization like Petronella Technology Group, prepares you and tells you where you stand. A C3PAO performs the formal Level 2 certification assessment that yields your CMMC status with the Department of Defense. Cyber AB independence rules generally prevent the same firm from both preparing and certifying you for Level 2 in the same window, so Petronella prepares you and refers you to an appropriate C3PAO for the formal assessment. Level 1 is self-assessed, and Level 3 is assessed by the government (DIBCAC).

What is an SPRS score and why does it matter?

The Supplier Performance Risk System (SPRS) holds the NIST SP 800-171 self-assessment score that DFARS 252.204-7019 requires you to post. The score starts at 110 and deducts points for each unmet control, with 1, 3, or 5 point weights depending on the control. Many contractors are surprised that an honest first score is negative - that is common and not a verdict. The score matters because primes and contracting officers look at it, and because posting an inflated number creates False Claims Act exposure. A readiness assessment produces a score you can actually defend. See how the CMMC self-score is calculated.

What is the difference between Level 2 self-assessment and a certified assessment?

Under the CMMC program, some Level 2 contracts permit a self-assessment while others require a certified third-party assessment by a C3PAO, depending on the sensitivity of the CUI involved and the contract terms. A readiness assessment is valuable in either case, because both paths require the same underlying NIST SP 800-171 implementation, the same defensible SPRS score, and the same System Security Plan. The difference is who validates the result. Petronella's assessment prepares you for whichever path your contract specifies.

What is CUI, and how do I know if I handle it?

Controlled Unclassified Information (CUI) is government information that requires safeguarding but is not classified. You typically handle CUI if your DoD contract includes DFARS 252.204-7012 or if you receive documents marked with banners such as "CUI//SP-PROP," "CUI//SP-PRVCY," or "CUI//SP-CTI." If you handle only Federal Contract Information (FCI) - basic, non-public contract performance information with no covered marking - Level 1 is likely your destination. The scoping phase of a readiness assessment confirms exactly what you hold and where it lives.

Do you work with small contractors and subcontractors in North Carolina?

Yes. Many small contractors carry the same CMMC obligation as their prime, because flow-down requirements under DFARS 252.204-7020 pass CUI handling responsibility down the supply chain. Petronella Technology Group is based in Raleigh and focuses on the North Carolina defense corridor - contractors and engineering firms serving Fort Liberty (Fort Bragg), Seymour Johnson Air Force Base, Camp Lejeune, and the Research Triangle Park community. We size engagements to the organization and frequently work with firms in the 5 to 50 employee range that have a single CUI enclave.

What does a readiness assessment cost?

Pricing is custom and scope-first. The cost depends on your enclave size, CUI flow complexity, asset and user count, current SPRS posture, and target CMMC level. Rather than publish a number that would be wrong for your environment, Petronella scopes first and quotes a fixed price. Start with a free scoping consultation and the CMMC scoping worksheet, or call (919) 348-4912 to walk through the variables. For the factors that move the quote, see the CMMC cost breakdown.

How long does it take to get CMMC Level 1 self-assessment documentation ready for a small contractor?

For a small contractor that handles only Federal Contract Information, CMMC Level 1 covers the 15 basic safeguarding requirements of FAR 52.204-21, and the documentation burden is far lighter than Level 2. With an experienced guide, scoping plus evidence gathering and the written self-assessment can typically be completed in days to a few weeks; doing it unassisted commonly stretches to months because most of the time is lost working out what assessors expect rather than implementing controls. Remediation is the variable: if practices like access control or media handling are not actually in place, they must be implemented before you can truthfully self-assess and file your annual affirmation. Petronella Technology Group supports self-assessments at Level 1 and full readiness at Levels 2 and 3.

Does CMMC Level 1 require a third-party assessment?

No. Level 1 is an annual self-assessment with an affirmation submitted in SPRS by a senior company official. Third-party assessment by a C3PAO enters at Level 2 for most contractors handling Controlled Unclassified Information, and Level 3 adds a government-led assessment on top of Level 2. If your contracts only involve Federal Contract Information, the Level 1 self-assessment is your requirement; the discipline is keeping it current every year and being able to produce evidence if questioned.

Section 08 / Start Here

Book Your Free CMMC Scoping Call

Two required fields, about thirty seconds. A CMMC-RP from Petronella Technology Group, Inc. will walk your DFARS clauses, sketch your enclave, and outline the readiness assessment, at no cost and with no obligation.

What happens after you submit

A credentialed CMMC-RP reviews your details and reaches out to set up a short call. There is no charge for the consultation and no commitment to engage at the end of it. If you would rather not wait, the phone number below reaches a practitioner directly.

  • On the call: we confirm which CMMC level your contracts point toward
  • On the call: we sketch your CUI enclave and the requirements in scope
  • Within two business days: a fixed-scope quote for your ComplianceArmor®-accelerated readiness assessment
  • Yours to keep: the scoping worksheet and our read on your situation, whether or not you engage

Prefer to come prepared? Download the CMMC scoping worksheet first, or skip the form and reach a CMMC-RP directly by phone.

Call (919) 348-4912

2 required fields · about 30 seconds · or call (919) 348-4912

No cost and no obligation. Your details go to a CMMC-RP, not to a mailing list. See our Privacy Policy.

Already at Level 2? CMMC Level 3 readiness is the next competitive edge

Most of the defense industrial base is still working toward CMMC Level 2. A much smaller group of contractors supporting priority and national-security programs may eventually face CMMC Level 3: the 110 NIST SP 800-171 requirements plus 24 enhanced NIST SP 800-172 requirements, 134 in total, assessed by the government's DIBCAC rather than a Certified Third Party Assessment Organization. Level 3 is not a starting point. Under 32 CFR 170.18 a Final Level 2 certification assessment by a C3PAO is a prerequisite before Level 3 can be pursued. Level 2 and Level 3 contract designations are among the requirements placed in abeyance by the July 2026 suspension, so this is readiness work on a proactive timeline, not a mandate. The Department of Defense's own regulatory impact analysis (89 FR 83092) estimates Level 3 implementation at $2.7 million to $21.1 million in nonrecurring cost plus $490,000 to $4.1 million per year recurring, with the range driven by organization size.

Petronella Technology Group, Inc. offers a sovereign path to Level 3 readiness powered by ComplianceArmor®: an AI platform that generates your Level 3 documentation package on hardware you own, so CUI never leaves your boundary to a third-party AI. Start with an AI Level 3 Readiness Sprint (From $12,500, 100% credited toward year one of the license), then sustain readiness with the ComplianceArmor® Level 3 Sovereign License (From $44,995/yr, one sovereign appliance site included; additional sites From $9,900 per site per year). The appliance ships on a Level 2 validated baseline, and a portion of the NIST SP 800-172 enhancements remain organizational process and roadmap work rather than product. Final pricing is confirmed after a scoping call and varies with enclave count, number of sites, and CUI footprint. Payment is 100% upfront at contract execution.

Positioning for priority programs? Explore CMMC Level 3 readiness or talk to our team. Penny, our AI assistant, answers 24/7 at 919-348-4912 and can book your scoping call.

Use the Pause. Get Your Real Number Now

Petronella Technology Group, Inc. is Cyber AB Registered Provider Organization #1449. Book a no-cost scoping call to walk your DFARS clauses, scope your CUI enclave, and start a CMMC Level 1, 2, or 3 readiness assessment, then move into remediation with a defensible number in hand and no clock running.

Or download the free CMMC scoping worksheet and call (919) 348-4912 when you are ready.

Cyber AB Registered Provider Organization badge
Cyber AB RPO #1449
Cyber AB CMMC Registered Practitioner badge
Every practitioner CMMC-RP