CMMC Compliance Services for Defense Contractors
BlueKey IT helps defense contractors meet CMMC Level 1 and Level 2. Our CyberAB Registered Practitioners and Certified CMMC Professionals scope your CUI environment, run gap assessments against NIST SP 800-171, calculate your SPRS score, write your SSP, POA&M, and policies, and set up a GRC platform to keep you ready.
CMMC Level 1 and Level 2 · CyberAB RPs and CCPs on staff · SPRS, SSP, POA&M, and policies · GRC platform setup
Where CMMC Stands Today
Status as of October 1, 2026: On July 13, 2026, the Department of War suspended CMMC Phase II, which would have required third-party (C3PAO) assessments in contracts starting November 10, 2026. A September 3 class deviation directs contracting officers to remove third-party CMMC requirements from solicitations and contracts. The CMMC Reform Task Force delivered its recommendations to the Department of War CIO in September, and they have not been published yet. We will update this page when they are.
What has not changed: Phase I is still in effect. Level 1 and Level 2 self-assessments, SPRS scores, and annual affirmations are still required, DFARS 252.204-7012 still requires NIST SP 800-171 for CUI, and inaccurate cybersecurity attestations still carry False Claims Act risk. The suspension changed how compliance is verified, not what is required. For background, read What Is CMMC Certification.
| CMMC Level 1 | CMMC Level 2 | |
|---|---|---|
| Protects | Federal Contract Information (FCI) | Controlled Unclassified Information (CUI) |
| Requirements | 15 basic safeguarding requirements (FAR 52.204-21) | 110 requirements of NIST SP 800-171 Rev. 2 |
| Assessment today | Annual self-assessment and affirmation | Self-assessment with an SPRS score, plus annual affirmation. Third-party certification is paused under the Phase II suspension. |
| What we deliver | Scoping, controls, policies, and affirmation support | Scoping, gap assessment, SPRS score, SSP, POA&M, policies, remediation, and GRC setup |
What’s Included in BlueKey CMMC Compliance
CUI scoping and enclavesIdentify where FCI and CUI live and draw a tight boundary, including enclave options that shrink the scope and the cost.
Gap assessmentA formal review against all 110 NIST SP 800-171 requirements, or the 15 Level 1 requirements, with findings ranked by risk.
SPRS scoreAn accurate, defensible SPRS score calculated with the DoD Assessment Methodology and ready to post.
SSP and POA&MA System Security Plan that documents every requirement and a Plan of Action and Milestones for the gaps that remain.
Policies and documentationWritten security policies, procedures, and supporting documentation that match how your business actually operates.
Remediation and technical controlsMulti-factor authentication, encryption, logging, endpoint protection, and the other controls needed to close your gaps.
GRC platform setupWe help you choose and set up a governance, risk, and compliance platform to track controls, evidence, and tasks.
Ongoing compliance and readinessAnnual affirmation support, evidence upkeep, and C3PAO coordination if you pursue voluntary certification.
How It Works
1. Scope and assess
We confirm which data you handle, define your CMMC boundary, and run a gap assessment with an SPRS score.
2. Remediate and document
We close gaps with technical controls and write your SSP, POA&M, and policies, organized in a GRC platform.
3. Maintain and affirm
We keep controls and evidence current, support your annual affirmation, and prepare you for any future assessment.
Support requests for in-scope systems follow our standard help desk response times: 1 business hour for critical issues, 2 hours for high, 4 hours for medium, and 8 hours for low priority requests.
Who It’s For
Defense contractors and subcontractors that handle FCI or CUI, including manufacturers, machine shops, engineering firms, and professional services firms in the Defense Industrial Base. Have an in-house IT team? We work alongside them through co-managed IT. Need ongoing security leadership? See our vCISO packages.
Local CMMC Support
We support defense contractors nationwide, with local CMMC services in Arizona, Colorado, Texas, Utah, and Tennessee.
Pricing
CMMC engagements are scoped to the size of your environment and the level you need. Gap assessments and documentation are quoted as projects, and ongoing compliance can be added to a managed IT or co-managed IT plan.
CMMC Compliance FAQ
What is CMMC?
The Cybersecurity Maturity Model Certification (CMMC) is the Department of War program that verifies defense contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Level 1 covers FCI with 15 basic safeguarding requirements, and Level 2 covers CUI with the 110 requirements of NIST SP 800-171.
Is CMMC still required after the Phase II suspension?
Yes. On July 13, 2026, the Department of War suspended Phase II, which would have required third-party (C3PAO) assessments in contracts. Phase I is still in effect, so Level 1 and Level 2 self-assessments, SPRS scores, and annual affirmations are still required, and DFARS 252.204-7012 still requires NIST SP 800-171 for CUI.
Which CMMC level does my business need?
If you only handle Federal Contract Information, you likely need Level 1. If you handle Controlled Unclassified Information, you need Level 2, which is where most defense subcontractors that receive drawings, specifications, or technical data land. Your contract clauses and the data you receive determine the level, and we help you confirm it during scoping.
What is an SPRS score?
An SPRS score is the result of a NIST SP 800-171 self-assessment using the DoD Assessment Methodology. The maximum score is 110, with points deducted for each requirement not met, and the score is posted in the Supplier Performance Risk System (SPRS) where contracting officers can see it.
What are an SSP and a POA&M?
A System Security Plan (SSP) documents how your environment meets each security requirement. A Plan of Action and Milestones (POA&M) lists the requirements not yet met and how and when you will close them. Both are required for NIST SP 800-171 and CMMC Level 2.
Can BlueKey IT certify our business?
No. Only an authorized CMMC Third-Party Assessment Organization (C3PAO) can perform a certification assessment. Our Registered Practitioners and Certified CMMC Professionals prepare you, and if you pursue a voluntary certification we help coordinate the assessment with a C3PAO.
What is a GRC platform, and do we need one?
A governance, risk, and compliance (GRC) platform tracks your controls, policies, evidence, and remediation tasks in one place. It is not required, but it makes self-assessments, annual affirmations, and future assessments much easier. We help you choose and set one up, then keep it current.
Can you manage our IT and CMMC compliance together?
Yes. Many defense contractors use BlueKey IT for managed or co-managed IT so the same team that maintains your systems also maintains the controls and evidence CMMC requires.
Get a Free Compliance Gap Assessment
Find out where you stand against CMMC Level 1 or Level 2. We review your environment, the data you handle, and your current documentation, then give you a clear plan and quote. No obligation.
Related services: cybersecurity and compliance, vCISO and IT consulting, endpoint security, and managed IT services.
Last updated: October 2026





