CMMC 2.0 · NIST 800-171 · DFARS 252.204-7012
CMMC compliance for the U.S. defense contractors who can’t afford to lose the contract.
Final rule December 16, 2024. Phase I self-assessments remain in force. Phase II, originally November 10, 2026, is suspended. We get U.S. defense contractors and government subcontractors, from coast to coast, from current-state to assessment-ready, then run the long-term controls afterward.
- Level 1 and Level 2 scoping, gap, and remediation
- SSP authoring + POA&M tracking + evidence library
- GCC High migration + Sentinel + Defender XDR
- 24/7 SOC for continuous monitoring controls
CMMC 2.0 timeline
Three dates to know.
DoW has been clear about the phased rollout. The dates are not moving. If you carry FCI or CUI on a current contract, or want to bid on the next one, the timeline below is non-negotiable.
-
01
Dec 16, 2024
CMMC final rule published
32 CFR Part 170 published in the Federal Register. Rule officially in force.
-
02
Nov 10, 2025
Phase 1 enforcement begins
Self-assessment requirements (Level 1 and self-Level 2) appear in new DoW solicitations.
-
03
July 13, 2026
Phase II suspended
Third-party C3PAO requirement paused. Phase I self-assessments remain in force.
CMMC services in Honolulu & the Pacific Defense Industrial Base
A Honolulu-headquartered CMMC partner for Pacific defense contractors.
Cyberuptive is headquartered in Honolulu at 401 Kamakee St, serving Pacific defense subcontractors and INDOPACOM supply-chain firms across all CMMC 2.0 levels. The Pacific Defense Industrial Base, the manufacturers, shipyards, MRO providers, integrators, software shops, and professional-services firms supporting Pacific Air Forces (PACAF), Pacific Fleet (PACFLT), Marine Forces Pacific (MARFORPAC), and U.S. Army Pacific (USARPAC), faces the same CMMC requirements as Atlantic-coast primes, but with shorter assessor pipelines and tighter time-zone overlap with HQ-side compliance teams.
Our CMMC level 1 services and CMMC level 2 services in Honolulu cover the same nationwide scope, scoping the CUI boundary, NIST SP 800-171 gap assessment, SSP authoring, POA&M tracking, SPRS scoring support, GCC High migration, and 24/7 continuous monitoring, with the addition of HST-based scoping calls, Pacific-time SOC operations, and personal relationships with the C3PAO assessors covering Region IX. If your CMMC assessment services need to map to a Honolulu-headquartered prime or a JBPHH-, Schofield-, or Wheeler-adjacent subcontractor footprint, the work is already familiar to us.
CMMC 2.0 services we deliver to Pacific contractors
- CMMC Level 1 services in Honolulu, the 15 basic safeguarding requirements for contractors handling Federal Contract Information (FCI). Annual self-assessment, SPRS posting, and the controls baseline to support it.
- CMMC Level 2 services in Honolulu, all 110 NIST SP 800-171 controls for contractors handling Controlled Unclassified Information (CUI). C3PAO-ready evidence packs, SSP, POA&M, and the long-term operational controls (SOC, SIEM, vulnerability management, incident response) that the assessment requires you to keep running afterward.
- CMMC 2.0 services in Honolulu, SPRS & DFARS support, calculating, posting, and defending the SPRS score; mapping NIST 800-171 control implementations to DFARS 252.204-7012 expectations; and producing the rapid 72-hour incident reporting evidence trail.
- CMMC assessment services in Honolulu, mock C3PAO assessment with assessor-style questioning, evidence-pack QA, and the remediation lift between mock and live assessment.
Why a Honolulu-based CMMC partner matters
For CUI engagements, Cyberuptive scopes advisory and managed-security work to U.S. persons working from U.S. soil. Many Pacific defense subcontractors operate small IT teams without 24/7 SOC capability, and the natural fallback: outsourcing to a continental U.S. MSSP, can introduce time-zone friction (a 0200 HST incident hits the East Coast MSSP at 0700, queued behind their overnight backlog) and occasionally CUI-handling complications when the MSSP's analyst rotation includes non-U.S. persons. A Honolulu-headquartered partner with U.S.-citizen analysts and HST primary coverage removes both problems.
Engagement model
From scoping to assessment-ready, with the long-term controls already running.
-
01
Scope
Define the CUI boundary. Inventory in-scope assets, users, data flows. Confirm Level 1 vs Level 2.
-
02
Gap
Score current-state against all 15 (L1) or 110 (L2) controls. Output: scored gap report + remediation roadmap.
-
03
Remediate
Close gaps. GCC High migration, Defender + Sentinel deployment, SOC + VM stand-up, IR retainer.
-
04
Document
SSP authored, POA&M live, evidence library populated, mock assessment with C3PAO-style questioning.
Built for U.S. defense contractors
Your contracts are on the line. We’re the guide that gets you assessment-ready.
CMMC 2.0 reaches every primes-and-subs corner of the Defense Industrial Base, manufacturers, integrators, software shops, professional services, and engineering firms across all 50 states. If your contracts touch Federal Contract Information or Controlled Unclassified Information, the compliance bar is the same whether you’re in Huntsville, Hartford, or San Diego.
We operate as your CMMC readiness partner: scoping the CUI boundary, scoring against NIST SP 800-171, authoring the SSP, running the POA&M, posting your SPRS score, and standing up the long-term controls, SIEM, SOC, vulnerability management, and incident response, that DFARS 252.204-7012 expects you to keep running after the C3PAO leaves.
- • Nationwide engagements for DoW primes and subcontractors
- • NIST 800-171, DFARS 252.204-7012, and SPRS scoring expertise
- • Evidence library, SSP, and POA&M built to C3PAO standards
- • U.S.-based analysts handling CUI under DFARS-aligned controls
Control families we operate long-term
Pass the assessment. Stay passed.
The hardest-to-sustain control families are continuous monitoring, audit logging, and incident response. We run those as managed services so you do not have to staff them.
AC · Access Control
Conditional Access, Entra ID PIM, role review, session controls.
AU · Audit & Accountability
Sentinel SIEM with 1-year retention, alert review, integrity protection.
CM · Configuration Management
Baselines, change control, deviation tracking, periodic review.
IR · Incident Response
24/7 SOC triage, IR retainer, tabletop exercises, post-incident review.
RA · Risk Assessment
Continuous vulnerability scanning, KEV/EPSS prioritization.
SI · System & Information Integrity
Defender XDR, threat hunting, flaw remediation tracking.
The CMMC 2.0 model
Three levels. Your solicitation, not a vendor, sets the target.
CMMC is a contract requirement framework for unclassified contractor systems that process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). 32 CFR Part 170 establishes the program; the CMMC clause in a solicitation tells a contractor which level, assessment type, and systems are in scope. That applies to a prime and to a subcontractor when its work or information system falls inside the contract requirement.
Level 1: foundational protection for FCI
Level 1 is for contractors handling FCI but not CUI. It maps to the 15 basic safeguarding requirements in FAR 52.204-21. The organization performs a self-assessment and a senior official makes the required annual affirmation in SPRS. A Level 1 status must be final, not conditional, when the solicitation requires Level 1 at award.
Level 2: broad protection for CUI
Level 2 uses the 110 requirements in NIST SP 800-171 Rev. 2. During the current Phase I pause, the Department of War may require Level 2 self-assessments; the solicitation controls whether a C3PAO assessment is required. The correct question is not “are we a Level 2 company?” but “which systems will process, store, transmit, or protect CUI for this award?”
Level 3: highest-priority CUI programs
Level 3 is reserved for selected higher-priority programs. It builds on Level 2 with a subset of NIST SP 800-172 requirements and a government-led assessment. It is not a default requirement for every CUI subcontractor. Contract language and program-office direction determine whether it applies.
The acquisition rule matters as much as the program rule. Under DFARS 204.7502, a contracting officer cannot award when the offeror lacks the CMMC status specified in the solicitation for systems used to process, store, or transmit FCI or CUI. Read every prime-flowdown and subcontract clause early: a small supplier can be in scope even when it never connects directly to a government network.
Assessment readiness
What a Level 2 assessment actually tests.
An assessor is looking for a defensible implementation, not a binder of generic policies. The System Security Plan (SSP) should define the CUI boundary, responsible roles, technology, and how each NIST SP 800-171 requirement is met. Interviews, examination of evidence, and technical testing must tell the same story. A Plan of Action & Milestones (POA&M) can document allowable, time-bounded remediation; it is not a substitute for an implemented control.
The Cyber AB ecosystem: prepare, assess, and keep the roles independent
A C3PAO is the independent organization that conducts an official Level 2 assessment when the contract requires one. An RPO is a registered advisory organization in the Cyber AB Marketplace ecosystem: it can help with readiness, remediation, evidence, and assessment preparation, but it does not issue a CMMC status. CCPs and CCAs are qualified individuals who support and conduct assessment work within the C3PAO model. Cyberuptive provides RPO-track readiness advisory and managed-security support; Cyberuptive does not represent itself as a C3PAO.
Five recurring Level 2 failures
- An undefined CUI boundary. CUI sits in email, shared storage, endpoints, backups, or an MSP workflow that never made it into scope.
- An SSP that is not the environment. The document names controls and owners that do not match the tenant configuration, logs, or daily operating process.
- Identity evidence without consistent enforcement. MFA, least privilege, privileged-account separation, and periodic access review must be implemented and demonstrable: not merely policy statements. NIST SP 800-171 Rev. 2 requirement 3.5.3 specifically addresses MFA.
- Logging with no review process. Collecting events is not enough. The organization needs retained evidence of alert triage, investigation, escalation, and corrective action across the AU and IR control families.
- Unowned shared responsibilities. Cloud platforms, managed service providers, and internal teams may each operate part of a control, but nobody has recorded the handoff or retained the evidence.
A Shared Responsibility Matrix makes those handoffs explicit. It maps each in-scope control activity, such as patching, log review, account approvals, backup recovery tests, and incident escalation, to the contractor, the cloud provider, and any managed-security partner. It also identifies the evidence owner and review cadence. That matrix turns a plausible architecture into an assessable operating model.
For a cost baseline, see our managed SOC pricing guide. For the detection and response layer that supports continuous monitoring, review our managed detection and response service. Defense contractors in Hawaiʻi can also explore our Hawaii cybersecurity services, and procurement teams comparing providers can use our 2026 MSSP comparison.
-
When does CMMC 2.0 actually start affecting my contracts?
The CMMC final rule was published December 16, 2024. Phase 1 enforcement began November 10, 2025, with self-assessment requirements appearing in new DoW solicitations. On July 13, 2026 the Department of War suspended Phase II, which had been scheduled for November 10, 2026. Phase I self-assessments remain in force. If you bid on DoW work touching CUI, the safeguarding duty did not pause.
-
What level do I need?
If you handle Federal Contract Information (FCI) only, Level 1 (15 requirements, annual self-assessment). If you handle Controlled Unclassified Information (CUI), Level 2 (110 controls from NIST 800-171, third-party C3PAO assessment for most). Level 3 is for the highest-priority programs and is rare for subcontractors. We do a 1-hour scoping call to confirm.
-
What does a CMMC engagement actually look like?
Four phases: (1) Scoping, define the CUI boundary, identify in-scope assets, classify data flows. (2) Gap assessment, current-state against all 110 controls, scored. (3) Remediation, close gaps, deploy GCC High where required, harden M365, build SOC + VM + IR programs. (4) Documentation & assessment prep, SSP, POA&M, evidence library, mock assessment. Typical duration: 6–12 months depending on starting maturity.
-
What does a CMMC readiness partner actually do?
A CMMC readiness partner does the work most defense contractors can’t staff in-house: scoping the CUI boundary, running the gap assessment against NIST SP 800-171, authoring the System Security Plan, maintaining the POA&M, posting and defending the SPRS score, and operating the long-term controls, SIEM, 24/7 SOC, vulnerability management, and incident response, that DFARS 252.204-7012 expects you to keep running. We do this for U.S. defense contractors and government subcontractors nationwide, with U.S.-based analysts handling CUI.
-
Do you produce the SSP and POA&M, or just review what we have?
Both. Most engagements include authoring the System Security Plan from scratch (or a substantial rewrite) and standing up a working POA&M with quarterly review. We produce evidence-ready documentation that matches what your C3PAO will request: not generic templated language.
-
Can you operate the long-term controls (SOC, VM, IR)?
Yes, that is the most cost-effective model. Continuous monitoring (SI.L2-3.14.6), audit logging (AU family), and incident response (IR family) are the controls medium and large contractors most often lack. Our managed SOC, vulnerability management, and IR retainer satisfy all three with one provider, US-based, and assessment-mapped. See SOC as a Service.
-
What about GCC High?
If you handle CUI in Microsoft 365, you almost certainly need GCC High, commercial M365 will not satisfy DFARS 252.204-7012 by itself. We scope, license, migrate, and document the tenant. See Microsoft 365 services.
-
How much does this cost?
Honest answer: it depends on size and starting maturity. A 25-person defense subcontractor starting from minimal NIST 800-171 maturity typically invests $80K–$180K across 9–12 months for full Level 2 readiness, plus ongoing managed services. We scope to the environment: not a fixed package. Lost contract revenue from non-compliance is a much bigger number.
Talk with a CMMC advisor
Need a real CMMC plan, not a spreadsheet?
A 30-minute scoping call tells us your level, your boundary, and your runway. From there we build a fixed-scope roadmap: not a sales pitch.