Industries
Defense Industrial Base
If your contract carries DFARS 252.204-7012, you handle Controlled Unclassified Information and owe a NIST SP 800-171 self-assessment, a System Security Plan, a POA&M, an SPRS score and an annual affirmation. The July 2026 CMMC suspension paused the third-party audit. It did not pause any of that.
Where contractors usually are
Just received a flow-down
A prime is asking what you handle
Assessed once, then stopped
You have an SSP from two years ago
Suspension confusion
You stopped work in July 2026
Subcontracting out
You flow CUI down to others
Eight free tools for this work
No signup, no email capture. Seven of the eight serve obligations that the suspension left untouched.
What we do for DIB contractors
Scoping and gap assessment, remediation and documentation, and the penetration testing that Level 2 practices call for. Details on the CMMC readiness page.
We hold CMMC Registered Practitioner status. We are not a C3PAO and cannot certify you, which is the correct separation: the people who prepare you should not be the people who assess you.
Not sure whether you handle CUI?
That is the question worth answering first, and it usually takes one conversation.
