Cybersecurity Maturity Model Certification (CMMC)

CMMC Level 2 Compliance

When the cost of getting it wrong is not an option.

CMMC compliance, managed security, and IT operations for defense contractors who cannot afford to fail.

CMMC Phase 2 is paused pending a DoD program review, but your Phase 1 self-assessment, SPRS reporting, and DFARS 252.204-7012 obligations are still fully in force. If you handle CUI or FCI under a DoD contract, your risk did not pause with the timeline. We close the gaps, build the documentation, and get you ready for whatever comes next.

CMMC Phase 2 is paused pending DoD review · Phase 1 self-assessment and SPRS obligations remain fully in force · Prime contractors are still flowing down requirements regardless of the pause
The Problem

The pause does not mean the risk went away.

Phase 2 third-party certification is on hold pending review. Your existing obligations are not: lost contracts, removed from supply chains, and legal exposure under the False Claims Act remain live risks tied to your self-assessment accuracy today.

  • !

    Self-Assessment Still Governs

    Phase 1 self-assessment and SPRS scoring are unaffected by the pause. An inflated or inaccurate score is a liability with or without Phase 2.

  • Supply Chain Pressure

    Prime contractors are still writing CMMC-adjacent requirements into contracts regardless of the DoD’s own timeline. Your certification posture is increasingly a condition of staying on the team.

  • §

    Legal Exposure

    False Claims Act enforcement tied to misrepresented cybersecurity compliance has continued since the pause, not slowed. A senior company official must personally certify compliance.

  • The Window Is an Advantage, If You Use It

    A complete CMMC Level 2 remediation takes three to six months. Contractors who use this pause to get ready will be positioned to compete the moment a finalized framework returns, while others are starting from zero.

Understanding CMMC

Three levels. One framework. Obligations that did not pause.

CMMC assesses defense contractor compliance with information safeguarding requirements for FCI and CUI. The level required depends on the type of information your organisation handles.

Level 1

Basic Safeguarding

Applies to: FCI

Foundational cybersecurity practices covering 15 security requirements under FAR 52.204-21.

Requirement: Annual self-assessment and annual affirmation of compliance.
Level 2

Broad Protection of CUI

Applies to: CUI

110 security requirements aligned with NIST SP 800-171 Rev 2. This is the level most defense contractors are required to achieve.

Requirement: Independent assessment by a Cyber-AB authorized C3PAO every three years, plus annual affirmation.
Level 3

Higher Level Protection

Applies to: CUI against advanced threats

24 additional requirements from NIST SP 800-172 on top of full Level 2 compliance. Reserved for the most sensitive defense programs.

Requirement: DCMA DIBCAC assessment every three years. Level 2 certification is a prerequisite.

Not sure where you stand? That is completely normal.

Most contractors we talk to are not certain whether they handle CUI, how many systems are in scope, or what level they actually need. You do not need to figure that out before you talk to us. Answer a few quick questions about your situation and we will do the diagnostic work. We will tell you what you have, what you need, and what it will take to get there.

How We Help

We get you assessment-ready.

You focus on the mission. We manage your compliance from first gap assessment through C3PAO certification and beyond.

110

Controls stand between you and full CMMC compliance.

Most contractors have implemented fewer than half. Ikaan identifies every gap, builds the strategy, and executes the remediation so you show up to your assessment fully prepared with documented evidence for every control.

STEP 01

Gap Assessment

We evaluate your environment against all 110 NIST SP 800-171 controls. You receive your SPRS score, gap report, POA&M, and System Security Plan with a clear picture of exactly where you stand.

STEP 02

Remediation

We prioritize what to fix and in what order. High-risk gaps close first. Evidence is documented at every step. Most remediation happens in the background without disrupting your operations.

STEP 03

Managed Compliance

Compliance is not a one-time event. We manage your ongoing security infrastructure including monitored endpoints, automated control updates, and continuous evidence collection so you stay certified.

STEP 04

C3PAO Support

Most firms walk away at assessment time. We stay. Ikaan acts as your technical liaison throughout the C3PAO assessment, managing documentation requests and supporting assessor questions so nothing falls through the cracks.

Your DoD contract is on the line. Find out where you stand.

Answer five questions in under two minutes. We will come to your consultation already focused on your specific situation with direct answers about what you need to do, how long it will take, and what it will cost.

Prefer email? Reach us at cmmc.ready@ikaanconsulting.com

Have questions first? Browse our FAQ.

Scroll to Top