BlueKey IT

CMMC Compliance Services for Defense Contractors

Schedule your FREE IT Assessment. Use the form below or call us at (866) 844-0536 today.

CMMC Compliance Services for Defense Contractors

BlueKey IT helps defense contractors meet CMMC Level 1 and Level 2. Our CyberAB Registered Practitioners and Certified CMMC Professionals scope your CUI environment, run gap assessments against NIST SP 800-171, calculate your SPRS score, write your SSP, POA&M, and policies, and set up a GRC platform to keep you ready.

CMMC Level 1 and Level 2 · CyberAB RPs and CCPs on staff · SPRS, SSP, POA&M, and policies · GRC platform setup

Where CMMC Stands Today

Status as of October 1, 2026: On July 13, 2026, the Department of War suspended CMMC Phase II, which would have required third-party (C3PAO) assessments in contracts starting November 10, 2026. A September 3 class deviation directs contracting officers to remove third-party CMMC requirements from solicitations and contracts. The CMMC Reform Task Force delivered its recommendations to the Department of War CIO in September, and they have not been published yet. We will update this page when they are.

What has not changed: Phase I is still in effect. Level 1 and Level 2 self-assessments, SPRS scores, and annual affirmations are still required, DFARS 252.204-7012 still requires NIST SP 800-171 for CUI, and inaccurate cybersecurity attestations still carry False Claims Act risk. The suspension changed how compliance is verified, not what is required. For background, read What Is CMMC Certification.

CMMC Level 1CMMC Level 2
ProtectsFederal Contract Information (FCI)Controlled Unclassified Information (CUI)
Requirements15 basic safeguarding requirements (FAR 52.204-21)110 requirements of NIST SP 800-171 Rev. 2
Assessment todayAnnual self-assessment and affirmationSelf-assessment with an SPRS score, plus annual affirmation. Third-party certification is paused under the Phase II suspension.
What we deliverScoping, controls, policies, and affirmation supportScoping, gap assessment, SPRS score, SSP, POA&M, policies, remediation, and GRC setup

What’s Included in BlueKey CMMC Compliance

  • Server rack with status lights in a data center
    CUI scoping and enclavesIdentify where FCI and CUI live and draw a tight boundary, including enclave options that shrink the scope and the cost.
  • Laptop showing analytics charts during a technology assessment
    Gap assessmentA formal review against all 110 NIST SP 800-171 requirements, or the 15 Level 1 requirements, with findings ranked by risk.
  • Person reviewing compliance paperwork with a calculator
    SPRS scoreAn accurate, defensible SPRS score calculated with the DoD Assessment Methodology and ready to post.
  • Two people reviewing and signing vendor contract documents
    SSP and POA&MA System Security Plan that documents every requirement and a Plan of Action and Milestones for the gaps that remain.
  • Binder of written security policies and procedures on a desk
    Policies and documentationWritten security policies, procedures, and supporting documentation that match how your business actually operates.
  • Laptop keyboard lit in blue representing endpoint detection and response
    Remediation and technical controlsMulti-factor authentication, encryption, logging, endpoint protection, and the other controls needed to close your gaps.
  • IT team working at computers with monitoring dashboards on screen
    GRC platform setupWe help you choose and set up a governance, risk, and compliance platform to track controls, evidence, and tasks.
  • Engineer wearing safety glasses working in a manufacturing lab
    Ongoing compliance and readinessAnnual affirmation support, evidence upkeep, and C3PAO coordination if you pursue voluntary certification.

How It Works

  • 1. Scope and assess

    We confirm which data you handle, define your CMMC boundary, and run a gap assessment with an SPRS score.

  • 2. Remediate and document

    We close gaps with technical controls and write your SSP, POA&M, and policies, organized in a GRC platform.

  • 3. Maintain and affirm

    We keep controls and evidence current, support your annual affirmation, and prepare you for any future assessment.

Support requests for in-scope systems follow our standard help desk response times: 1 business hour for critical issues, 2 hours for high, 4 hours for medium, and 8 hours for low priority requests.

Who It’s For

Defense contractors and subcontractors that handle FCI or CUI, including manufacturers, machine shops, engineering firms, and professional services firms in the Defense Industrial Base. Have an in-house IT team? We work alongside them through co-managed IT. Need ongoing security leadership? See our vCISO packages.

Local CMMC Support

We support defense contractors nationwide, with local CMMC services in Arizona, Colorado, Texas, Utah, and Tennessee.

Pricing

CMMC engagements are scoped to the size of your environment and the level you need. Gap assessments and documentation are quoted as projects, and ongoing compliance can be added to a managed IT or co-managed IT plan.

CMMC Compliance FAQ

What is CMMC?

The Cybersecurity Maturity Model Certification (CMMC) is the Department of War program that verifies defense contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Level 1 covers FCI with 15 basic safeguarding requirements, and Level 2 covers CUI with the 110 requirements of NIST SP 800-171.

Is CMMC still required after the Phase II suspension?

Yes. On July 13, 2026, the Department of War suspended Phase II, which would have required third-party (C3PAO) assessments in contracts. Phase I is still in effect, so Level 1 and Level 2 self-assessments, SPRS scores, and annual affirmations are still required, and DFARS 252.204-7012 still requires NIST SP 800-171 for CUI.

Which CMMC level does my business need?

If you only handle Federal Contract Information, you likely need Level 1. If you handle Controlled Unclassified Information, you need Level 2, which is where most defense subcontractors that receive drawings, specifications, or technical data land. Your contract clauses and the data you receive determine the level, and we help you confirm it during scoping.

What is an SPRS score?

An SPRS score is the result of a NIST SP 800-171 self-assessment using the DoD Assessment Methodology. The maximum score is 110, with points deducted for each requirement not met, and the score is posted in the Supplier Performance Risk System (SPRS) where contracting officers can see it.

What are an SSP and a POA&M?

A System Security Plan (SSP) documents how your environment meets each security requirement. A Plan of Action and Milestones (POA&M) lists the requirements not yet met and how and when you will close them. Both are required for NIST SP 800-171 and CMMC Level 2.

Can BlueKey IT certify our business?

No. Only an authorized CMMC Third-Party Assessment Organization (C3PAO) can perform a certification assessment. Our Registered Practitioners and Certified CMMC Professionals prepare you, and if you pursue a voluntary certification we help coordinate the assessment with a C3PAO.

What is a GRC platform, and do we need one?

A governance, risk, and compliance (GRC) platform tracks your controls, policies, evidence, and remediation tasks in one place. It is not required, but it makes self-assessments, annual affirmations, and future assessments much easier. We help you choose and set one up, then keep it current.

Can you manage our IT and CMMC compliance together?

Yes. Many defense contractors use BlueKey IT for managed or co-managed IT so the same team that maintains your systems also maintains the controls and evidence CMMC requires.

Get a Free Compliance Gap Assessment

Find out where you stand against CMMC Level 1 or Level 2. We review your environment, the data you handle, and your current documentation, then give you a clear plan and quote. No obligation.

Related services: cybersecurity and compliance, vCISO and IT consulting, endpoint security, and managed IT services.

Last updated: October 2026