CMMC Compliance Services for Your Industry
A DFARS 252.204-7012 clause doesn't care what industry you're in. Wherever your business sits, whether you're supplying parts, providing a service, or delivering a product that ends up in a defense contract, that clause binds you to the same NIST SP 800-171 requirements as a traditional defense contractor the moment it appears in your agreement. We help businesses across every sector determine what their specific contract requires and build a compliance program around it, without forcing your operation into a framework built for someone else's industry.
The Program Paused. Your Contract Didn't.
The Department of War suspended CMMC Phase 2 on July 13, 2026, putting mandatory third-party certification on hold while a Reform Task Force reviews the program's structure. That pause changed nothing about Phase 1. Self-assessment obligations are in force today, and DFARS 252.204-7012 and NIST SP 800-171 Rev 2 apply to any contract or subcontract that references them, regardless of your industry.
Businesses outside the usual defense-contractor mold often assume this doesn't apply to them until a prime contractor or contracting officer says otherwise. By then, the gap between what the contract requires and what you have in place.
Where Compliance Exposure Sits in a Business Like Yours
From Contract Language to a Program You Can Run
Signs It's Time to Start
Don't wait for a Phase 2 restart date. Start when a new contract or renewal includes unfamiliar security language, when a prime contractor or client raises the topic, or when you're unsure whether an existing agreement already put you in scope. Any of these is reason enough, independent of where the federal certification timeline currently stands.
Common Questions About CMMC
How do we know if CMMC applies to our business?
Check the contracts and subcontracts you hold. If any of them reference DFARS 252.204-7012 or require compliance with NIST SP 800-171, you're in scope regardless of your industry.
Phase 2 is suspended. Does that mean we can wait?
No. Phase 1 self-assessment requirements remain active, and your contractual obligation under DFARS 252.204-7012 exists independently of the certification timeline.
What is CUI, and how would we recognize it in our business?
Controlled Unclassified Information is sensitive government-related data that isn't classified but still requires protection. It can appear in specifications, drawings, reports, or other materials connected to a defense contract, depending on what your business provides.
We're a small business. Do the same 110 controls apply to us?
Yes, the control requirements don't scale down by company size. What changes is how you implement them, which is why your remediation plan needs to fit your actual resources.
What's the difference between self-assessment and third-party certification?
Self-assessment is your organization's own evaluation, which you submit to SPRS, currently the active requirement. Phase 2 had scheduled third-party certification through a C3PAO to become mandatory, and that requirement is now on hold.
How do we find out if our current contract already puts us in scope?
Review the clauses in your existing agreements for references to DFARS 252.204-7012 or NIST SP 800-171. If you're unsure how to interpret the language, we can review it with you directly.
Can our vendors or subcontractors affect our compliance status?
Yes. If you share CUI with vendors or subcontractors, their security practices become part of your compliance picture, not just your own systems.
How long does a gap assessment typically take?
It depends on the size of your environment and how many systems or contracts the assessment covers. We provide a specific timeline after reviewing your situation.
What happens if we find gaps during our self-assessment?
Gaps go into a Plan of Action and Milestones with a defined remediation timeline. Whether there's a hard deadline to close them depends on your specific contract terms.
Do we need certification to bid on new contracts right now?
It depends on the specific solicitation. Review the contract language directly, since requirements vary and the Reform Task Force is still reviewing the certification structure.
What should we prepare before a compliance conversation?
Copies of contracts or subcontracts with defense-related language, a general sense of where sensitive data moves through your business, and a point of contact familiar with your IT setup.
How do you help us stay current as CMMC requirements change?
We track Reform Task Force recommendations and Department of War guidance as they come out and update your compliance plan accordingly, so you're not working from outdated assumptions.