CMMC Level 2, Answered Straight
The questions Defense Industrial Base contractors actually ask us. No hedging, and no pretending the program is simpler than it is.
Straight Answers
Yes, with an important distinction. In July 2026 the Department of Defense suspended the transition to later CMMC phases while a reform task force reviews the program, which paused new third-party (C3PAO) certification requirements. It did not pause anything else. DFARS 252.204-7012 remains contractually binding, NIST SP 800-171 implementation is still required, and Phase 1 self-assessment obligations remain in force. The certification mechanism is under review. The security standard is not.
Compliant and audit-ready means every applicable NIST SP 800-171 control is implemented, documented in a System Security Plan, and backed by evidence an assessor could review today. Certified means an accredited C3PAO has formally assessed your environment and issued a certification.
They are not the same claim, and any provider who blurs them is doing you a disservice. TRANUSA gets you to compliant and audit-ready, and prepares you for the formal assessment.
Federal Contract Information and Controlled Unclassified Information carry different obligations. FCI alone generally maps to a lower level with a much smaller control set; CUI triggers the full NIST SP 800-171 requirement.
The catch is that most small suppliers have never actually determined which they hold, because it turns on contract clauses, technical data packages and drawings — not on assumption. Establishing what is in scope is the first thing to settle, before any tooling decision gets made.
A narrow enclave looks cheaper on the quote and often costs more to live with. Policing a partition means keeping CUI inside it, keeping everyone else out, and proving both on demand — and that segregation is a business function you have to sustain every day, not a technical control a provider can take off your hands. When a partition is not sustained, spills follow.
For most small and mid-sized manufacturers we recommend enterprise-wide scope, because it removes ongoing work from your team rather than adding it.
No — and that is an architectural boundary, not a policy promise. TRANUSA's tooling sits adjacent to your environment and processes Telemetry Data only: logs, alerts and metadata. Controlled content never leaves your boundary and never enters ours.
This is written into our mutual NDA, and it is a large part of why the architecture is defensible under ITAR and EAR.
Your System Security Plan, your POA&M, your policies and procedures, your evidence repository, your assessment result and your posted SPRS score. All of it is yours outright, and none of it is affected by the engagement ending.
A provider who has to hold your compliance documentation hostage to keep you is telling you something about the work. We would rather be kept because the program runs well.
For a shop of 15 to 75 people with no System Security Plan in place, the realistic range from gap assessment to audit-ready runs several months. What actually drives it is how much network and identity remediation the environment needs, and how quickly evidence can be collected and kept current.
Anyone quoting you a fixed timeline before scoping your CUI boundary is guessing. A readiness call establishes the range for your specific environment.
It removed third-party assessment from contract language, and nothing else. DFARS Class Deviation 2026-O0025, Revision 3, signed 3 September 2026, supersedes Revision 2 of 16 July and carries forward the instruction from the Department of War CIO memorandum of 13 July 2026. It directs contracting officers to remove CMMC third-party assessment requirements from new solicitations by amendment, and from existing contracts by modification — before the next option is exercised or at the next scheduled administrative modification. Read the rest of the memorandum and very little has moved. Requiring activities may still include CMMC Level 1 (Self) or Level 2 (Self) assessments in procurement requests. Baseline compliance with NIST SP 800-171 Rev 2 under DFARS 252.204-7012 is named explicitly and is unchanged. And under DFARS 252.204-7020 the government keeps the right to conduct Basic, Medium and High assessments of your environment, with your cooperation required. The clause is being deleted. The obligation behind it is not.
Longer than most shops realize, and this is the answer to "we will wait." DFARS 252.204-7012 has been in defense contracts since 2015, and the deadline to have all 110 NIST SP 800-171 controls implemented was 31 December 2017 — not working toward them, implemented. That is more than eight years ago. CMMC came afterwards: the SPRS scoring and posting clauses took effect on 30 November 2020, and third-party certification was going to be the verification layer on top of an obligation that already existed. So the requirement is roughly nine years old and has not changed. What arrived in 2020 was a number you had to post. What left in 2026 was the party who would have checked that number. A shop that is not compliant today has been out of compliance since 2017, and every invoice submitted in that window was a claim for payment on a contract it was not meeting. That is precisely what the LOGZONE settlement was: alleged noncompliance from May 2021 to March 2025. Not a CMMC case — a DFARS 252.204-7012 case.
Not a staffed watch floor, and we will not describe it as one. What we operate is continuous SIEM alerting with 24/7 escalation to TRANUSA on-call engineering, staffed by U.S. Persons.
That distinction matters during an incident, which is the wrong moment to find out what a provider actually meant.
No. Certification is issued by an accredited C3PAO, and no firm can both prepare a client and certify that same client. We get you to a defensible, audit-ready position and support you through the formal assessment.
We also take no fee from any C3PAO, under any circumstances — your assessor's independence is what makes the result worth having.
Book a CMMC Readiness Call
Thirty minutes. We review your contract requirements, identify your top compliance gaps, and give you a realistic timeline to audit readiness. No pitch decks, no obligation.
Book Your Call →