Stealth Technology Group

CMMC Phase 2 is paused.

Your NIST 800-171 affirmation isn’t.

Third-party certification is on hold while DoD’s Reform Task Force finishes its review. The 110 controls, DFARS 7012, your SPRS score, and the annual affirmation your executive signs are still in force — and primes are still asking for proof. We get defense contractors evidence-ready in six weeks, not six months.

Google

average rating

5.0

DoD paused CMMC Phase 2 certification on July 13, 2026. NIST 800-171, your SPRS score, and your signed affirmation did not pause. This page reflects the status as of September 2026 and will be updated when the Reform Task Force reports.

The assessor is paused. Your signature isn’t.

What changed on July 13 — and what every DoD contractor still has to live up to today.

Paused (July 13, 2026)

  • Third-party (C3PAO) Level 2 certification as a condition of contract award
  • DIBCAC Level 3 assessments during the review period
  • DFARS 252.204-7021 certification language in active solicitations

Still required today

  • All 110 NIST SP 800-171 controls (DFARS 252.204-7012)
  • Level 1 / Level 2 self-assessment in solicitations
  • SPRS score submission
  • Annual executive affirmation — False Claims Act exposure
  • Prime flow-down — primes are setting their own deadlines

Prepare for CMMC with a Cyber AB Registered Practitioner Organization

CMMC Consulting &
Readiness Services

Stealth Technology Group helps defense contractors and subcontractors prepare for CMMC Level 1 and Level 2 requirements with practical consulting, implementation support, and readiness guidance. Third-party assessments are paused; the 110 controls, your SPRS score, and your executive affirmation are not.

As a Cyber AB Registered Practitioner Organization with multiple Registered Practitioners on staff, we help organizations identify gaps, implement required practices, document controls, and prepare for self-attestation or third-party certification. CyberAB notes that RPs provide CMMC implementation consulting, gap identification, and mitigation support for organizations preparing for assessment.

Compliance documentation review — CMMC readiness
CMMC support built into managed IT operations

CMMC Support Built for
Defense Contractors

Whether your organization handles Federal Contract Information or Controlled Unclassified Information, CMMC readiness requires more than a checklist. It requires clear scoping, documented processes, technical controls, user awareness, and ongoing evidence.

Stealth helps you move from uncertainty to readiness with a structured, business-aligned approach.

Our CMMC Services

CMMC Level 1 Readiness For organizations preparing to protect Federal Contract Information and complete required self-assessment activities.

Office building — CMMC readiness for defense contractors

CMMC Level 2 Readiness

For organizations handling CUI and preparing for self-assessment or C3PAO certification.

  • CMMC Level 2 gap assessment
  • NIST SP 800-171 control mapping
  • System Security Plan support
  • POA&M development and remediation planning
  • Technical control implementation
  • Assessment preparation and evidence review

The DoD identifies CMMC Level 1 and Level 2 self-assessments as a focus of Phase 1 implementation and provides official scoping and assessment guides for both levels.

How Stealth Helps

Our Approach

Assess

Assess

We review your current environment, policies, systems, users, and data flows to determine where CMMC requirements apply.

Plan

We create a practical remediation roadmap based on risk, contract needs, control gaps, budget, and certification timeline.

Implement

Our team helps deploy and configure the security controls, processes, documentation, and monitoring needed to support CMMC readiness.

Prepare

We help organize evidence, validate control maturity, and prepare your team for self-attestation or a formal certification assessment.

Why Work with Stealth

Cyber AB Registered
Practitioner Organization

Multiple Registered Practitioners on staff

Cybersecurity-focused
MSP expertise

Practical implementation, not just advisory reports

Support for both Level 1 and Level 2 readiness

Experience with Microsoft security, identity, endpoint, monitoring, and compliance controls

Why work with Stealth Technology Group — integrated IT, security, and compliance
Client result: a Stealth client passed its C3PAO CMMC Level 2 assessment in 2026 with a perfect 110 of 110 — and a metal fabrication shop we prepared passed its Level 2 assessment in July. Certification didn’t pause. Neither did we. Read the 110/110 story · Read the manufacturer’s story

Questions defense contractors are asking now

Straight answers on the pause, the controls, and the cost.

Written in September 2026. We revise this the day the Task Force reports.

What changed on July 13, 2026 — and what didn’t?

DoD suspended CMMC Phase 2 (third-party C3PAO certification as a condition of award) while its Reform Task Force reviews the program. Phase 1 did not change: NIST SP 800-171 self-assessment, your SPRS score, and the annual executive affirmation remain contract requirements.

Should we wait for the Task Force before doing anything?

No. Every active DoD contract with DFARS 252.204-7012 still requires all 110 NIST 800-171 controls, and an inaccurate SPRS score or affirmation carries False Claims Act exposure today. Primes are also setting their own supplier deadlines.

What is the difference between readiness services and certification?

Readiness is the work of implementing the 110 controls, documenting them, and packaging the evidence. Certification is the assessment itself, performed by an authorized C3PAO. Stealth prepares you; the C3PAO assesses you.

What documentation do we need before a Level 2 assessment?

A System Security Plan, a POA&M, network and data-flow diagrams, an asset inventory that shows where CUI lives, and evidence for each control — screenshots, configurations, policies, and records that an assessor can verify.

How long does it take to get assessment-ready?

A scoped environment with committed leadership is typically evidence-ready in about six weeks. Full remediation from a low starting point runs three to six months depending on your posture and whether a managed CUI enclave is the right approach.

What is a managed CUI enclave?

A secure, isolated environment where CUI is stored and handled. It shrinks the assessment scope to the enclave instead of your whole network, which is usually the fastest route to a defensible SPRS score.

How much does a Gap Assessment cost?

Gap Assessments start at $7,500, with the full scope quoted in writing before you sign. All 110 controls are assessed, documented, and evidence-mapped.

Can our internal IT team handle this?

Your IT team is essential to the work — they know the environment. What they usually lack is assessment experience: control interpretation, evidence packaging, and knowing what an assessor will and will not accept. Stealth works alongside internal IT rather than replacing it.

Entry offer

CMMC Gap Assessment

from $7,500fixed fee, scope quoted before you sign
  • All 110 NIST SP 800-171 controls assessed, documented, and evidence-mapped
  • SPRS score you can sign an affirmation on
  • Prioritized remediation plan with owners and dates
  • Managed CUI enclave option for compliance in about 60 days
  • Executive briefing — what an assessor would find today
Book my roadmap call

Delivered by a Cyber AB Registered Practitioner Organization with Registered Practitioners on staff. Stealth prepares you for assessment; certification decisions belong to the C3PAO.

The pause is a head start — for the contractors who use it.

Bring your SPRS score, your contract flow-downs, and your current environment. We’ll show you what is still required, what is paused, and what we would do first — and put it in writing.

Security shield over a laptop — cybersecurity and compliance services
Scroll to Top