CMMC Phase 2 suspended July 13, 2026 / DFARS 252.204-7012 still applies

Know Your Real CMMC Score While the Clock Is Paused

On July 13, 2026 the Department of War suspended CMMC Phase 2 and opened a reform review, so third-party Level 2 certification is not currently a condition of award. DFARS 252.204-7012 never paused, and neither did your obligation to protect Controlled Unclassified Information. A CMMC readiness assessment reveals your true SPRS self-score, your full NIST SP 800-171 gap list, and a prioritized remediation path while you have room to work at a sane pace. Delivered by a fully credentialed consulting team and Cyber AB Registered Provider Organization #1449. The scoping call is free. Start there.

  • Free scoping call, no obligation
  • Cyber AB RPO #1449
  • Every practitioner CMMC-RP
  • Advisory only, never your assessor
#1449 Cyber AB RPO Registered Provider Organization
100% Team CMMC-RP Every practitioner credentialed
2002 Established BBB A+ since 2003
110 Controls Scored NIST SP 800-171 gap analysis
Why the pause is the moment

Phase 2 Is Suspended. Your DFARS Obligations Are Not.

On July 13, 2026 the Department of War suspended CMMC Phase 2 (memo 26-P-1023) and stood up a CMMC Reform Task Force running a 60-day review with a public request for information. There is no certification countdown right now. There is also nothing stopping a prime from asking for your SPRS score tomorrow.

The Department of Defense built the Cybersecurity Maturity Model Certification to verify that the cybersecurity protections defense contractors have long been required to implement are actually in place. The suspension changes the verification mechanism, not the protections. DFARS 252.204-7012, 252.204-7019, and 252.204-7020 remain in force, your NIST SP 800-171 implementation obligation is unchanged, and the Department has been explicit that it is reducing certification burden rather than lowering the cybersecurity baseline. Read the pause for what it is: the reform work is aimed at how contractors prove compliance, not at whether they have to be compliant.

That makes this a prep window, and prep windows close. Every contractor that handles Controlled Unclassified Information still has exactly the gaps it had in June, and the reform review does not close a single one of them. Measuring and remediating now, with no clock forcing the pace, is the low-stress and lower-cost path. Doing the same work later under a restored schedule, competing for the same limited pool of practitioners and assessors, is the expensive one. Start with the CMMC compliance program overview or the underlying NIST 800-171 compliance requirements.

One more reason the pause is the right moment: remediation is sequential. You cannot compress a year of engineering into a quarter by spending more money. Multifactor authentication has to be deployed before you can evidence it. Audit logging has to run long enough to produce reviewable records. Security awareness training has to be delivered, documented, and repeated. Policies have to be approved and then actually followed, because an assessor asks your staff what they do, not only what your binder says. Organizations that treat the suspension as permission to stop will restart from the same line they are standing on today, only with less runway.

No clock right now is exactly why to move. A free scoping call sizes the work, confirms which level your contracts require, and gets you a fixed-scope quote within two business days.

Call (919) 348-4912
What CMMC Level 2 requires

Level 2 Means All 110 NIST SP 800-171 Controls, Assessed by a C3PAO

CMMC Level 2 applies whenever your organization processes, stores, or transmits Controlled Unclassified Information. It aligns to NIST SP 800-171, and for most CUI-flowing contracts it requires a triennial third-party assessment by a Certified Third Party Assessment Organization.

The compliance obligations

  • 110 controls implemented. Every practice in NIST SP 800-171 must be in place across your in-scope CUI enclave, not just documented.
  • A defensible SPRS score. Your NIST SP 800-171 self-assessment score, posted under DFARS 252.204-7019, must reflect reality.
  • A System Security Plan and POA&M. The SSP describes how each control is met, and the POA&M tracks the gaps you are closing.
  • Continuous monitoring. Audit logging, vulnerability scanning, and event correlation are mandatory and cannot be deferred.
  • A C3PAO assessment. For most CUI contracts, an independent assessor validates the 110 controls before certification.

Why readiness comes first

  • It prices the project accurately. A scored gap list lets us build a fixed-scope plan instead of an open-ended retainer.
  • It protects your SPRS posture. Posting an inflated self-score creates False Claims Act exposure. The assessment produces a number you can defend.
  • It sequences the spend. The POA&M lets you close the controls that move your score the most, first.
  • It de-risks the C3PAO. A mock-graded environment means no surprises in the room that decides your contracts.
  • It is the prerequisite for everything. The SSP, the remediation, and certification all build on the assessment baseline.

Not sure whether Level 2 even applies to you, or how CMMC compares to a framework you already run? See how CMMC stacks up in our CMMC versus ISO 27001 comparison, and how the underlying NIST 800-171 controls map to your environment.

Which level applies to you

Level 1, Level 2, and Level 3 Are Different Problems

The single most expensive mistake in CMMC is scoping the wrong level, because the level is driven by the kind of government information your contracts put in your hands. Getting this right on a twenty-minute call can save a year of misdirected engineering.

Level 1 covers Federal Contract Information

Federal Contract Information, or FCI, is information provided by or generated for the government under a contract that is not intended for public release. Delivery schedules, statements of work, and process documentation frequently qualify. If your contracts put FCI in your systems but never CUI, you are almost certainly a CMMC Level 1 organization. Level 1 is 15 basic safeguarding requirements drawn from FAR 52.204-21, and it is self-assessed and annually affirmed by a senior company official. It is not trivial, but it is a matter of weeks of focused work rather than a multi-year program, and it does not require an outside assessor.

Level 2 covers Controlled Unclassified Information

Controlled Unclassified Information is the category that changes everything. Technical drawings, specifications, export-controlled data, and program information marked CUI or covered by DFARS 252.204-7012 pull you into all 110 NIST SP 800-171 requirements. Level 2 is where the System Security Plan, the POA&M, continuous monitoring, and the SPRS score all become load-bearing. For most CUI-flowing contracts, Level 2 is verified by a Certified Third Party Assessment Organization on a three-year cycle, though a subset of contracts allow a Level 2 self-assessment. Which one applies to you is a contract-language question, not a technology question, and it is one of the first things we read on a scoping call.

Level 3 is a small, specialized population

Level 3 applies to a much narrower group of contractors supporting priority and national-security programs. It is the 110 NIST SP 800-171 requirements plus 24 enhanced requirements from NIST SP 800-172, 134 in total, and it is assessed by the government's Defense Industrial Base Cybersecurity Assessment Center rather than by a Certified Third Party Assessment Organization. Level 3 is not an entry point. Under 32 CFR 170.18, a Final Level 2 certification assessment performed by a C3PAO is a prerequisite before Level 3 can be pursued at all. The Department of Defense's own regulatory impact analysis (89 FR 83092) estimates Level 3 implementation at $2.7 million to $21.1 million in nonrecurring cost plus $490,000 to $4.1 million per year recurring, with that wide range driven by organization size rather than by timing. Level 2 and Level 3 contract designations are among the requirements placed in abeyance by the July 2026 suspension, so any Level 3 work today is proactive readiness on your own timeline. If your programs are heading that direction, read the CMMC Level 3 readiness overview.

Enclave scoping is where the money is won or lost

Almost every dollar of a CMMC program is a function of how many systems, users, and data flows sit inside the assessment boundary. A contractor that lets CUI sprawl across the general corporate network has just scoped every laptop, every file share, and every user into a 110-requirement program. A contractor that channels CUI into a deliberately small enclave, with a documented boundary and controlled data flows, assesses a fraction of that footprint. This is why boundary design is the first phase of our engagement rather than an afterthought, and why we will push back if your instinct is to declare the whole company in scope. See how we design and build a CMMC enclave once the boundary is agreed.

Scoping also decides which assets are in the boundary at all. CMMC scoping guidance separates CUI assets from security protection assets, contractor risk managed assets, specialized assets, and out-of-scope assets, and each category carries different documentation and assessment obligations. Getting an asset into the right category, with the reasoning written down, is ordinary work that pays for itself several times over during an assessment.

Not sure which level your contracts require? That is the first question we answer, and it costs nothing to ask.

Call (919) 348-4912
Inside the engagement

What a CMMC Readiness Assessment Actually Covers

A readiness assessment is not a vulnerability scan with a logo on it. It is a control-by-control evidence review across the fourteen NIST SP 800-171 families, conducted the way an assessor conducts one, so the result survives contact with a real assessment.

The fourteen control families we grade

  • Access Control and Identification and Authentication. Who can reach CUI, from what device, with what authentication strength. Multifactor coverage and privileged account separation are the two findings that recur most often.
  • Audit and Accountability. Whether logs exist, whether they capture the right events, whether anyone reviews them, and whether they are retained and protected from alteration.
  • Awareness and Training and Personnel Security. Role-based training that is actually delivered and recorded, plus screening and the offboarding steps that revoke access on the day someone leaves.
  • Configuration Management and Maintenance. Baselines, change control, least functionality, and how maintenance is performed on in-scope systems including by outside parties.
  • Incident Response. A plan that has been exercised, and the DFARS 252.204-7012 reporting path to DIBNet within 72 hours of discovering a cyber incident.
  • Media Protection, Physical Protection, and Risk and Security Assessment. Media handling and sanitization, facility controls around in-scope systems, and a documented, repeated risk assessment cycle.
  • System and Communications Protection and System and Information Integrity. Boundary protection, encryption of CUI at rest and in transit, and flaw remediation with evidence of timeliness.

How each requirement gets graded

  • Document review. Policies, procedures, network diagrams, contracts, and any existing SSP or POA&M are read against the requirement text and the NIST SP 800-171A assessment objectives.
  • Technical validation. Configuration evidence is pulled from the systems themselves. A policy that says accounts lock after failed attempts is graded on the actual setting, not the sentence.
  • Interviews. Practitioners talk to the people who run the systems and the people who use them, because an assessor will. Gaps between written process and daily practice are findings.
  • Objective-level scoring. Requirements are met, not met, or partially met, with the specific assessment objective that failed identified by name so remediation is unambiguous.
  • Evidence mapping. Every requirement scored as met is tied to the artifact that proves it, so you are not rebuilding the evidence package from memory a year later.

What you receive in writing

The deliverable is a package you own outright, regardless of whether you engage Petronella Technology Group, Inc. for the remediation that follows. It contains your CUI boundary and data-flow diagram, the graded control matrix covering every applicable requirement with its assessment objectives, your SPRS score calculation worksheet showing exactly how the number was derived, a prioritized Plan of Action and Milestones sequenced by score impact and dependency, and a path-to-assessment roadmap with realistic durations. Where remediation is warranted, a fixed-scope quote follows within two business days so you can budget against a number instead of a feeling.

We deliberately write the findings so a non-technical executive can read the summary and a systems administrator can act on the detail. A readiness report that only a consultant can interpret is a report that quietly expires the moment the consultant leaves.

The number that follows you

How SPRS Scoring Works, and Why Honest Scores Go Negative

The Supplier Performance Risk System holds the NIST SP 800-171 self-assessment score that DFARS 252.204-7019 requires contractors to post. Primes read it. Contracting officers read it. Most contractors have never seen how it is calculated.

The scoring methodology starts every organization at 110, one point for each requirement, and subtracts points for each requirement that is not fully implemented. The deductions are weighted by security impact. Most unmet requirements cost one point. A significant group cost three points. A small set of requirements whose absence leaves the environment fundamentally exposed cost five points each. Because the deductions are weighted but the starting value is not, the arithmetic runs below zero as soon as an organization is missing a meaningful share of the heavier requirements. A first honest score in negative territory is common, it is not a moral judgment, and it is dramatically better information than an inflated positive number.

Two subtleties trip people up. First, partial implementation generally does not earn partial credit; a requirement is either implemented or it is not, with narrow exceptions where the methodology permits partial values for multifactor authentication and FIPS-validated cryptography. Second, an unimplemented requirement tracked on a POA&M still costs its points until it is actually closed. A POA&M documents your plan honestly, which matters, but it does not restore the score.

This is where the accuracy of the number stops being an academic question. A self-assessment score posted to SPRS is a representation to the government. Posting a figure that overstates your implementation creates False Claims Act exposure, and enforcement actions in recent years have made that risk concrete for contractors who certified compliance they did not have. The purpose of a readiness assessment is not to manufacture a flattering number. It is to produce a number you can stand behind, with the calculation worksheet that shows how you got there and the POA&M that shows where you are going.

The practical sequence we recommend is simple. Score honestly, post the honest score, then improve it deliberately and re-post as milestones close. A contractor whose score is climbing on a documented plan reads far better to a prime than a contractor whose score has been suspiciously perfect since the day it was first entered.

How to start

Start With a Call. Move at the Pace Your Contracts Demand

You do not have to commit to a full program to get moving. Begin with a free scoping call, engage the readiness assessment that sizes the work, then grow into the certification-readiness and managed-security engagement that fits your contracts. Every engagement below is consulting and advisory work, scoped on a call.

Step 1 / Start here

Free CMMC Scoping Call

About twenty minutes with a credentialed CMMC-RP. We read your DFARS clauses, confirm whether your contracts put FCI or CUI in your systems, sketch the likely enclave boundary, and tell you plainly what the readiness assessment would involve for an environment your size. The call is free and carries no obligation.

If an engagement makes sense, a fixed-scope quote follows within two business days.

$0 The call, not the assessment Call (919) 348-4912
Step 2 / The diagnosis

CMMC Readiness Assessment

A paid, standalone deliverable and the foundation for everything after it. We scope your CUI boundary, grade every applicable requirement against the NIST SP 800-171A assessment objectives, calculate your defensible SPRS self-score, and hand you a prioritized POA&M and path-to-assessment roadmap. You own the findings outright, whether or not you engage us for the remediation. Duration depends on enclave size and how much documentation already exists.

Scope and fee are confirmed on the free scoping call, because enclave size, user count, and CUI flow drive both.

Know
your number
Scoped on a short call Call (919) 348-4912

Step 3 / Choose your readiness path

Good

Readiness Program

Project engagement / scoped on a short call

The full remediation and documentation program that carries you to a defensible NIST SP 800-171 and CMMC Level 2 posture across your in-scope enclave, ending in an evidence package ready for a self-assessment or a C3PAO.

  • Scoped CUI boundary and 110-requirement gap analysis
  • SSP, POA&M, and full policy library
  • Monitoring, audit correlation, and vulnerability scanning stood up
  • Defensible SPRS score calculated and posted by you
Call (919) 348-4912
Best

Managed Security Partner

Annual engagement / scoped on a short call

Your outsourced security department and a platform for the contracts ahead, with compliance upkeep folded into day-to-day operations.

  • Everything in Continuously Managed Readiness
  • Enterprise-wide managed XDR across all endpoints
  • Full vCISO, risk register, and DFARS 7012 incident response support
  • Dedicated engineer, priority response, and Level 3 readiness advisory
Call (919) 348-4912

Every engagement is scoped before it is priced, because no two CUI environments are alike and enclave size, user count, asset inventory, and current posture all move the number. Call (919) 348-4912 and we will size it on the phone. All fixed-fee milestones are 100 percent upfront at contract execution. Petronella Technology Group, Inc. is a Cyber AB Registered Provider Organization providing consulting and advisory services only. We prepare your evidence the way an assessor will review it. We are not a C3PAO, we are not your assessor, we do not certify anyone, and we make no guarantee of any assessment outcome.

The readiness process

How Petronella Runs Your Readiness Assessment

A focused engagement measured in days, not months. ComplianceArmor® handles the documentation-heavy work while a CMMC-RP runs the interviews and evidence review, then feeds directly into remediation and assessment readiness.

PHASE 01 Day 1

Scoping and Discovery

A kickoff workshop to identify which contracts impose CMMC, where CUI lives today, and the tightest defensible enclave boundary. See how we design and build a CMMC enclave once that boundary is set.

PHASE 02 Week 1

Gap Analysis

A control-by-control assessment against all 110 NIST SP 800-171 controls, combining asset discovery, evidence review, and interviews.

PHASE 03 Week 2

SPRS Scoring

Translation of the gap analysis into a defensible SPRS self-score with the supporting calculation, ready to post under DFARS 252.204-7019.

PHASE 04 Week 2

Roadmap Handoff

A prioritized POA&M and path-to-assessment roadmap, with a fixed-scope quote for remediation and C3PAO timing guidance.

The delivery engine / ComplianceArmor®

The documentation that takes most firms months, produced in days

ComplianceArmor® is the compliance automation platform built by Petronella Technology Group, Inc. It generates your System Security Plan, your full policy library, and your POA&M from the evidence we gather, compressing documentation work that commonly runs for months down to days. For CMMC Level 1, a complete self-assessment package can be produced in minutes.

That speed matters because documentation is where readiness engagements usually stall. The technical remediation is finite and well understood. Writing, cross-referencing, and maintaining a control-by-control System Security Plan against every assessment objective is the part that quietly consumes calendar quarters, and it is the part that goes stale the moment your environment changes. Automating the drafting lets your practitioners spend their hours on the boundary design and the control work that actually moves your score.

Every package is reviewed and attested by our CMMC-RP team, so you get software speed with practitioner accountability. That is what lets a readiness engagement move as fast as your contracts demand. Call (919) 348-4912 and we will walk you through what it produces against an environment like yours.

Why a credentialed RPO

A Real CMMC Consultant, Not a Generic IT Firm

Anyone can claim CMMC expertise. The Cyber AB Marketplace is the authoritative list of firms credentialed to prepare contractors for assessment, and Petronella Technology Group, Inc. is listed there as Registered Provider Organization #1449.

Cyber AB Registered Provider Organization #1449. An RPO is a company authorized by the Cyber AB, the accreditation body of the CMMC ecosystem, to provide readiness, consulting, and advisory services. RPOs sign a code of professional conduct, and their practitioners individually hold the CMMC-RP credential. You can verify any consultant at the official Cyber AB marketplace.

Every practitioner holds CMMC-RP. Not just the principal. We prepare your evidence the way a C3PAO will assess it, and because we are a Registered Provider Organization rather than the assessor, we keep a clean referral path to the C3PAOs that fit your contract type, geography, and CUI profile. We do not certify you, and we do not promise an assessment outcome we cannot control.

What an RPO can do, and what it cannot

What we can do: assess your current state against the requirements, design and document the enclave boundary, write the System Security Plan and the policy set, build and sequence the POA&M, calculate the SPRS score and show the work, implement and configure the technical controls, train your staff, prepare your evidence package, and sit beside you through the process. That is the entire body of readiness and remediation work, and it is where a contractor's real risk lives.

What we cannot do: certify you, assess you for certification purposes, grade our own work, sign your senior official's affirmation, or promise a result. Only a Certified Third Party Assessment Organization can perform a Level 2 certification assessment, and only the government assesses Level 3. This is not a limitation we regret. It is the point.

Why the independence line protects you

Cyber AB conflict-of-interest rules generally prevent the same organization from both preparing a contractor and certifying that contractor for Level 2. The reason is obvious once stated: a firm that grades its own remediation has an incentive to grade generously, and the value of the certificate depends on that incentive not existing. Any vendor offering to both build your program and certify it is describing a conflict, not a convenience.

The practical benefit for you is that our findings have no commercial reason to flatter you. If your first honest SPRS score is deeply negative, we tell you, because the alternative is that you find out from an assessor after you have already spent the budget. When you are ready for the formal assessment, we refer you to a C3PAO whose scheduling, sector experience, and geography actually fit your situation, and we prepare your team for what that assessment will ask.

Read the practice overview at our CMMC compliance services hub, or compare this engagement against the standalone CMMC readiness assessment page for a deeper walk through the deliverable itself.

Founded in 2002, BBB A+ since 2003. Petronella Technology Group, Inc. has engineered, defended, and forensically investigated networks for more than two decades from Raleigh, North Carolina. That operating history matters during an assessment, because organizational maturity is itself a signal assessors weigh, and it means we can pair CMMC readiness with a full managed XDR and vCISO practice for the contracts that come after certification.

The people on your engagement

Meet the Team Behind Your CMMC Readiness

Readiness work is done by named engineers, not a faceless queue. These are the practitioners who assess your controls, build your SSP and POA&M, and prepare your evidence the way a C3PAO will review it.

Craig Petronella, Founder and CEO of Petronella Technology Group, Inc.
Craig Petronella Founder and CEO, CMMC-RP
Blake Rea, Senior Security and Infrastructure Engineer at Petronella Technology Group, Inc.
Blake Rea Senior Security and Infrastructure Engineer
Jonathan Wood, Infrastructure and Systems Engineer at Petronella Technology Group, Inc.
Jonathan Wood Infrastructure and Systems Engineer
Justin Summers, Technical Support Manager at Petronella Technology Group, Inc.
Justin Summers Technical Support Manager
Scott Hendrix, Senior AI Engineer at Petronella Technology Group, Inc.
Scott Hendrix Senior AI Engineer

Every Petronella Technology Group, Inc. practitioner holds the CMMC-RP credential. View the full team.

FAQ

CMMC Readiness Assessment: Common Questions

The questions defense contractors ask most before booking a readiness assessment.

What is a CMMC readiness assessment?

It is a structured diagnosis of where your organization stands against the controls a C3PAO or government assessor will measure. It scopes your CUI boundary, grades all 110 NIST SP 800-171 controls, produces your real SPRS self-score, and delivers a prioritized POA&M and a path-to-assessment roadmap. It is not a certification. Only a Certified Third Party Assessment Organization, or for Level 3 the government, can certify you.

CMMC Phase 2 was suspended. Does readiness still matter?

Yes. On July 13, 2026 the Department of War suspended CMMC Phase 2, which had been scheduled for November 10, 2026, and opened a 60-day reform review with a public request for information (memo 26-P-1023). What is suspended is the third-party certification requirement. DFARS 252.204-7012, 252.204-7019, and 252.204-7020 are untouched, CMMC Phase 1 self-assessment requirements are untouched, and the Department has said it is reducing certification burden rather than lowering the cybersecurity baseline. Primes are still asking subcontractors for a current SPRS score. The practical read is that there is no countdown right now, which is exactly why measuring your gaps and remediating them at a workable pace beats doing the same work later under a restored schedule.

How much does the CMMC readiness assessment cost?

The scoping call is free and carries no obligation. The readiness assessment itself is a paid, standalone deliverable, and so is any remediation that follows. We scope before we price rather than publishing a number that would be wrong for your environment, because cost depends on your enclave size, CUI flow, asset and user count, existing documentation, and current SPRS posture. Call (919) 348-4912 and we will size it with you on the phone, then confirm a fixed-scope quote in writing within two business days. All fixed-fee milestones are 100 percent upfront at contract execution.

Is the readiness assessment free?

No, and we would rather be direct about it. The scoping call is free: about twenty minutes with a credentialed CMMC-RP to read your DFARS clauses, confirm your level, and sketch the boundary. The assessment is a paid engagement, because it is real work by credentialed practitioners producing a deliverable you own permanently. You keep the boundary diagram, the graded control matrix, the SPRS calculation worksheet, and the POA&M whether or not you ever hire us again.

Do you guarantee we will pass our CMMC assessment?

No. Petronella Technology Group, Inc. is a Cyber AB Registered Provider Organization providing consulting and advisory services only. We are not a C3PAO, we are not your assessor, and no consultant can guarantee the outcome of an assessment performed by an independent organization. Any firm that offers you a guaranteed pass is either misunderstanding the ecosystem or misrepresenting it. What we do commit to is preparing your evidence the way an assessor will review it, telling you honestly where you stand, and not letting you walk into an assessment we think you are not ready for.

How long does a readiness assessment take?

The assessment itself is measured in days to a few weeks depending on enclave size, how many people we need to interview, and how much existing documentation there is to review. Remediation is the longer phase, and its duration is driven by what the assessment finds. An organization that already runs multifactor authentication, centralized logging, and formal change control is in a very different position from one starting with a flat network and no written policy. We will give you a realistic range on the scoping call rather than an optimistic one.

We already did a self-assessment. Do we still need this?

Often yes, and the reason is usually the same. Most internal self-assessments grade the requirement text rather than the NIST SP 800-171A assessment objectives underneath it, so a requirement gets marked implemented when two of its five objectives are actually met. That is how a score of 95 turns into a score of 30 the first time someone grades it the way an assessor does. If your self-assessment was objective-level, evidence-backed, and performed by someone who has seen an assessment, you may be in good shape and we will tell you so on the call.

What do we need to have ready before the call?

Very little. Bring the contract or subcontract language that mentions DFARS 252.204-7012, 252.204-7019, or 252.204-7020, a rough sense of how many people touch government data, and whatever network documentation exists even if it is out of date. If you have an existing SSP, POA&M, or a posted SPRS score, have those handy. If you have none of that, the call is still worth taking, because the first job is figuring out what you are actually obligated to do.

Do I need a C3PAO, or is this assessment enough?

They serve different purposes. A readiness assessment, performed by a Registered Provider Organization like Petronella Technology Group, Inc., prepares you and tells you where you stand. A C3PAO performs the formal Level 2 certification assessment. Cyber AB independence rules generally prevent the same firm from both preparing and certifying you for Level 2, so we prepare you and refer you to an appropriate C3PAO. Level 1 is self-assessed, and Level 3 is assessed by the government.

What is an SPRS score and why does it matter?

The Supplier Performance Risk System holds the NIST SP 800-171 self-assessment score that DFARS 252.204-7019 requires you to post. The score starts at 110 and deducts points for each unmet control. Many contractors find that an honest first score is negative, which is common and not a verdict. It matters because primes and contracting officers look at it, and because posting an inflated number creates False Claims Act exposure. A readiness assessment produces a score you can defend.

Do you work with small contractors and subcontractors?

Yes. Many small contractors carry the same CMMC obligation as their prime, because flow-down requirements under DFARS 252.204-7020 pass CUI handling responsibility down the supply chain. Petronella Technology Group, Inc. is based in Raleigh, North Carolina and regularly works with firms in the 5 to 50 employee range that have a single CUI enclave. Small does not mean exempt, and it does not mean the work has to be enterprise-sized either, because a tightly scoped enclave keeps a small contractor's program small. Start with the free scoping call at (919) 348-4912.

Start here

Book Your Free CMMC Scoping Call

The fastest path is the phone. Call (919) 348-4912 and a credentialed CMMC-RP from Petronella Technology Group, Inc. will confirm your level, sketch your enclave, and tell you what a readiness engagement would involve. Prefer to be called back? Use the form and we will reach out.

The fastest way to start is to call

Call (919) 348-4912

About twenty minutes with a credentialed CMMC-RP. The call is free and there is no obligation at the end of it.

  • We confirm which CMMC level your contracts actually require
  • We sketch your CUI enclave and which requirements come into scope
  • We explain how your SPRS score would be calculated and what drives it
  • If an engagement makes sense, you receive a fixed-scope quote within two business days

Petronella Technology Group, Inc. is a Cyber AB Registered Provider Organization. We provide consulting and advisory services only, we are not a C3PAO, and we make no guarantee of any assessment outcome.

The scoping call is free and carries no obligation. We use your details only to prepare for it. Prefer to talk now? Call (919) 348-4912.

Know Your SPRS Score Before an Assessor Does

CMMC Phase 2 is suspended, but DFARS 252.204-7012 is not, and a prime can ask for your SPRS score any week. Petronella Technology Group, Inc. is Cyber AB Registered Provider Organization #1449, providing consulting and advisory services only. Take a free, no-obligation scoping call to walk your DFARS clauses, scope your CUI enclave, and start a defensible path toward CMMC Level 2 readiness with no clock running.