Certification Readiness for the
Defense Industrial Base.
CMMC requirements are appearing in DoD solicitations now. GiaMetrics® supports contractors from initial gap assessment through control implementation, documentation, and readiness for a C3PAO assessment, delivered by Cyber AB credentialed practitioners.
Governance is the foundation. Assurance is the proof.
The Requirement
What CMMC Requires, and Why It Is Urgent Now
The Cybersecurity Maturity Model Certification program verifies that defense contractors have implemented the security requirements needed to protect Federal Contract Information and Controlled Unclassified Information. It replaces self-attestation with verified assessment for most work involving CUI.
For most contractors the practical question is not whether to pursue certification. It is how much work stands between the current state and a defensible assessment, how long that work takes, and whether the assessment scope has been drawn correctly.
Scoping deserves particular attention. Organizations routinely bring far more of their environment into the assessment boundary than their contracts require, which multiplies both implementation cost and the ongoing maintenance burden for the full three-year certificate period.
GiaMetrics practitioners hold Cyber AB credentials as Registered Practitioner and Certified CMMC Professional.
Four Things to Know
- Protects CUI and FCI. The requirement follows the information, not the organization.
- Mandatory for award. Certification is a condition of eligibility, not a differentiator.
- Flows down to subcontractors. Primes are responsible for ensuring subs comply.
- Annual affirmation required. The certificate runs three years; the obligation is continuous.
Certification Levels
Which Level Applies to You
Your required level is specified in your DoD contract and depends on the sensitivity of the information your systems handle.
Rollout Schedule
The Four-Phase Phase-In
Requirements roll out across DoD contracts in four phases through 2028. Where your contracts fall in this schedule determines your urgency.
Enforcement Begins
CMMC requirements now appear in applicable new DoD contracts. Level 1 and Level 2 self-assessments are required on applicable solicitations. A valid certification is required for award, and there is no grace period.
C3PAO Assessments Required
DoD solicitations and contracts may require Level 2 certificates issued by Certified Third-Party Assessment Organizations for CUI-sensitive work. Begin C3PAO preparation at least six months ahead.
Level 3 Enters Scope
Higher-sensitivity programs may require Level 2 C3PAO assessments or Level 3 government-led DIBCAC assessments. Contractors on critical programs should anticipate Level 3 requirements.
Full Mandatory Compliance
CMMC requirements apply across all applicable DoD contracts, including options exercised on existing awards. No further phase-in remains.
How We Help
CMMC Support Services
Engagements are scoped to where you actually are, whether that is a first look at the requirement or final preparation before an assessment window.
Gap Assessment & Readiness Review
A control-by-control evaluation against NIST SP 800-171, with a current SPRS score, an honest picture of what stands between you and a defensible assessment, and a realistic time estimate.
CUI Scoping & Enclave Design
Organizations routinely bring far more of their environment into assessment scope than the contract requires. Scoping decisions made early determine both implementation cost and the ongoing maintenance burden.
SSP & POA&M Development
A System Security Plan that an assessor can actually follow, and a POA&M with real owners and real dates rather than placeholders that will not survive examination.
Control Implementation & Remediation
Prioritized remediation that distinguishes blocking gaps from manageable ones, sequenced against your contract timeline rather than against the control catalog order.
C3PAO Assessment Support
Preparation and support through the formal assessment, delivered by practitioners holding Cyber AB Registered Practitioner and Certified CMMC Professional credentials.
Continuous Compliance & Annual Affirmation
Certification is valid for three years but requires annual affirmation. Control state and evidence are maintained through the FutureFeed platform rather than reconstructed each cycle.
A Score You Can Defend and Evidence You Can Show
Certification is an evidence exercise. Through the FutureFeed platform, control state, SPRS scoring, and supporting artifacts are maintained continuously rather than reconstructed under deadline before an assessment window opens.
Certification Workflow
What the Formal Assessment Looks Like
From first contact with a C3PAO through certificate issuance, with defined milestones at each phase.
Confirm Scope: Entities, CAGE Codes & ESPs
The C3PAO verifies the legal entities to be assessed, collects CAGE codes, and determines whether External Service Providers fall within scope. Your assessment unique identifier is established.
Frame the Assessment
Logistics, schedule, personnel, evidence accessibility, and the formal CMMC Assessment Scope are agreed. On-site versus virtual format is determined and confirmed with your SSP in hand.
Resolve Conflicts of Interest
C3PAOs must comply with ISO/IEC 17020:2012 impartiality requirements. A Lead CCA is proposed and approved. Conflicts are disclosed, documented, and mitigated before the assessment proceeds.
Execute Contractual Agreement & NDA
A formal written agreement including a mutual Non-Disclosure Agreement is executed between the C3PAO and your organization. The DoD and the Cyber AB are not parties to this contract.
Phase 1: Pre-Assessment
The C3PAO evaluates whether your organization has sufficiently prepared, reviewing SSP completeness, documentation readiness, and control implementation status. The Pre-Assessment Information Form is submitted to eMASS.
Phase 2: Assessment Conformity
The core evaluation. All 110 NIST SP 800-171 requirements are assessed across depth and coverage objectives through interviews, document reviews, and direct observation, following 32 CFR 170.17 and NIST SP 800-171A.
Phase 3: Report Assessment Results
Findings are documented and delivered. Results are uploaded to eMASS and flow to SPRS, where contracting officers verify status before award.
Phase 4: Issue Certificate & Close POA&Ms
The certificate is issued with a three-year validity. Any POA&M items eligible for deferral must be closed within 180 days, and annual affirmation obligations begin.
Common Failure Modes
Where Organizations Get Stuck
Most CMMC efforts do not fail on technical controls. They fail on structural questions that were never answered: who owns this system, what is actually in scope, where did this evidence come from, and who accepted this risk.
This is why we approach certification as an application of a governance foundation rather than as a standalone documentation project. Organizations that establish ownership, boundaries, and evidence structurally find that the assessment becomes a mapping exercise against work already done.
It also means the work does not have to be repeated. The same foundation supports RMF and FedRAMP obligations that may follow.
- Assessment scope defined far more broadly than the contract requires
- CUI never formally identified or located across the environment
- System Security Plan written once and never maintained
- POA&M items with no named owner and no real date
- Evidence assembled only in the weeks before assessment
- Inherited controls from service providers never documented
- Subcontractor flow-down clauses never updated
- SPRS score stale or inconsistent with actual posture
Evidence Maintained, Not Reconstructed
GiaMetrics is a certified FutureFeed partner. FutureFeed is a FedRAMP High-authorized compliance platform running on AWS GovCloud, purpose-built for CMMC and NIST SP 800-171 evidence management.
Live SPRS ScoringKnow your score before a contracting officer does.
SSP & POA&M GenerationProduced from live control state.
CUI DiscoveryFind controlled information before an assessor does.
Annual AffirmationEvidence current when affirmation comes due.
Common Questions
CMMC, Answered Directly
Is CMMC actually required right now?
Yes. The CMMC Acquisition Rule at 48 CFR became effective November 10, 2025. Contracting officers are now including CMMC requirements in applicable new DoD solicitations. Contractors without the required certification level are ineligible for award on those contracts, and there is no grace period.
How do I know which level I need?
Your required level is specified in the DoD contract or solicitation. As a general matter, handling only FCI with no CUI points to Level 1. Contracts involving CUI most commonly require Level 2. Level 3 applies to the most sensitive national security programs. We can review your contract vehicles and data flows to confirm which level applies.
What changed between CMMC 1.0 and what exists now?
The original model used five levels and required third-party assessment for all contractors. The current model streamlined this to three levels, aligned requirements with existing NIST standards, and introduced self-assessment for Level 1 and some Level 2 scenarios. What is now simply called CMMC is what is currently in effect.
Do requirements flow down to my subcontractors?
Yes. Any subcontractor that processes, stores, or transmits FCI or CUI covered by your prime contract must achieve the appropriate level. As the prime you are responsible for ensuring subcontractor compliance and must update subcontract templates with proper flow-down clauses.
What if we are not fully compliant yet?
Limited use of Plans of Action and Milestones is permitted for certain non-compliant items, but not all requirements are POA&M-eligible. Some must be fully implemented before certification. We help identify which gaps are blocking versus manageable, build a realistic POA&M, and prioritize remediation before your next opportunity closes.
How long does Level 2 certification take?
It varies substantially with your current posture. Organizations starting from a low SPRS score with incomplete documentation should budget six to eighteen months of preparation before engaging a C3PAO. The formal assessment itself takes several weeks to months depending on organization size. Starting early is strongly recommended, since assessor availability is constrained relative to the scale of the requirement.
What is SPRS and why does it matter?
The Supplier Performance Risk System is where certifications, self-assessment scores, and annual affirmations are tracked. Contracting officers verify CMMC status through SPRS before award. Inaccurate records affect contract eligibility, and misrepresentation may create False Claims Act exposure.
Service-Disabled Veteran-Owned Small Business
GiaMetrics® is an SDVOSB verified through the U.S. Small Business Administration. Federal agencies and prime contractors can apply GiaMetrics work toward SDVOSB subcontracting goals under FAR Part 19.
Get Started
Have a Project? Let’s Talk.
We work with organizations at every stage, from those addressing governance for the first time to those with mature programs facing a new requirement. Tell us about your situation and we will outline a clear path forward.
Send Us a Message
Whether you are exploring your options or ready to start, we are here to help. All inquiries are confidential.