CMMC 2.0 – Assessments & Certification

Digital lock with glowing circuitry

Are You Ready to Start Your CMMC Compliance Journey?

DoD Manufacturers & Contractors

If your business has contracts with the US Department of Defense, you know that there is a new cybersecurity mandate that your company must follow.

In this episode of The LIPN Podcast, we spoke with Thomas Nohs of DataSoftNow to learn more about these CMMC protocols.

Who We Are

DataSoftNow is a leading cybersecurity consulting, compliance, and managed security services firm dedicated to helping organizations strengthen their cybersecurity posture and achieve regulatory compliance. As an authorized Cybersecurity Maturity Model Certification (CMMC) Certified Third-Party Assessor Organization (C3PAO), we provide independent CMMC assessments while also delivering expert consulting services for organizations seeking compliance with industry-recognized cybersecurity frameworks.

Our team consists of highly experienced cybersecurity professionals who hold some of the industry’s most respected certifications, including:

  • Certified Information Systems Security Professional (CISSP)
  • Lead Certified CMMC Assessor (LCCA)
  • Certified CMMC Assessor (CCA)
  • Certified CMMC Professional (CCP)

With extensive experience supporting the Defense Industrial Base (DIB), government agencies, manufacturers, and commercial organizations, DataSoftNow combines technical expertise, regulatory knowledge, and real-world operational experience to help clients protect sensitive information, reduce cyber risk, and navigate complex compliance requirements with confidence.

CISSP logo
LCCA logo
CCA logo
CCP logo

CMMC Certification Services

How We Can Help

Independent CMMC Assessments by an Authorized C3PAO

DataSoftNow is an Authorized Cybersecurity Maturity Model Certification Third-Party Assessment Organization (C3PAO) authorized to perform independent CMMC Level 2 assessments for organizations within the Defense Industrial Base (DIB).

Our experienced team of Certified CMMC Assessors (CCAs) conducts objective assessments to validate compliance with NIST SP 800-171 and the Cybersecurity Maturity Model Certification (CMMC) requirements, helping organizations demonstrate their ability to safeguard Controlled Unclassified Information (CUI) and maintain eligibility for Department of Defense (DoD) contracts.

Whether you are pursuing your initial certification or preparing for renewal, DataSoftNow delivers a professional, consistent, and efficient assessment experience grounded in the official CMMC Assessment Process.

Why Choose DataSoftNow?

At DataSoftNow, we recognize that CMMC certification is more than a regulatory requirement—it’s a commitment to protecting the Defense Industrial Base and strengthening the nation’s cybersecurity posture.

Our assessment team provides:

  • Independent and impartial CMMC Level 2 assessments
  • Certified CMMC Assessors (CCAs) with extensive cybersecurity expertise
  • Thorough evaluation of all 110 NIST SP 800-171 security requirements
  • Clear communication throughout the assessment lifecycle
  • Consistent and transparent assessment methodology
  • Timely reporting and quality assurance
  • Strict adherence to the CMMC Code of Professional Conduct (CoPC)
  • Professional assessment services performed in accordance with Cyber AB requirements

Assessments Performed in Strict Accordance with the Official CMMC Assessment Process (CAP)

Our Assessment Process

DataSoftNow strictly follows the CMMC Assessment Process (CAP) established by the Cyber AB. This standardized four-phase framework ensures every assessment is conducted consistently, objectively, and in accordance with Department of Defense and Cyber AB requirements.

Phase 1 – Plan & Prepare

We begin by validating the assessment scope, confirming the Organizational Assessment Scope (OAS), identifying in-scope assets, reviewing assessment prerequisites, coordinating logistics, and preparing both parties for a successful assessment.

This phase includes:

  • Assessment planning
  • Scope validation
  • Pre-assessment readiness review
  • Documentation requests
  • Rules of engagement
  • Assessment scheduling

Phase 2 – Conduct Assessment

Our Certified CMMC Assessors evaluate your implementation of the required security practices through the collection of objective evidence.

Assessment activities include:

  • Documentation review
  • Interviews with key personnel
  • Examination of technical evidence
  • Observation of implemented security controls
  • Demonstrations of system functionality
  • Validation of compliance with all applicable CMMC requirements

Every practice is evaluated using the assessment methods prescribed by the CMMC Assessment Guide.

Phase 3 – Report Results

Following completion of the assessment, our team performs a comprehensive quality assurance review to ensure accuracy, consistency, and compliance with Cyber AB assessment standards.

This phase includes:

  • Quality assurance review
  • Validation of assessment findings
  • Preparation of assessment documentation
  • Submission of results through the required Cyber AB processes

Phase 4 – Certification & POA&M Closeout

Upon successful completion of the assessment, organizations meeting certification requirements proceed through the Cyber AB certification process.

When permitted under the CMMC program, organizations may resolve allowable minor deficiencies through an approved Plan of Action & Milestones (POA&M) closeout process before certification is finalized.

This phase includes:

  • Certification recommendation
  • POA&M validation (when applicable)
  • Final quality review
  • Issuance of the CMMC certificate through the Cyber AB certification process

Integrity Through Independence

As an Authorized C3PAO, DataSoftNow maintains the independence required by the CMMC ecosystem.

To preserve the integrity of the certification process and comply with the CMMC Code of Professional Conduct (CoPC), we do not provide consulting, implementation, or remediation services to organizations we assess. Our responsibility is to perform fair, objective, and evidence-based assessments that uphold the credibility of the CMMC program.

Industries We Serve

DataSoftNow performs CMMC assessments for organizations across the Defense Industrial Base, including:

  • Defense contractors
  • Aerospace and aviation manufacturers
  • Precision machining companies
  • Industrial manufacturers
  • Software developers
  • Engineering firms
  • Information technology providers
  • Managed Service Providers (MSPs)
  • Managed Security Service Providers (MSSPs)
  • Suppliers that create, process, store, or transmit Controlled Unclassified Information (CUI)

Schedule Your CMMC Assessment

Whether you are preparing for your initial CMMC Level 2 certification or planning for recertification, DataSoftNow is ready to provide an independent, professional, and efficient assessment experience.

By following the official Cyber AB CMMC Assessment Process (CAP) from planning through certification, we help ensure every assessment is conducted with consistency, transparency, and the highest standards of integrity.

Protect your business. Validate your cybersecurity. Demonstrate compliance.

Contact DataSoftNow today to schedule your independent CMMC assessment.