CMMC 2.0 – ASSESSMENTS AND CERTIFICATION

Digital lock with glowing circuitry

The CMMC Timeline Has Changed—Your Cybersecurity Obligations Have Not

DataSoftNow: Your Trusted C3PAO for CMMC Level 2 Assessments

The Department of War has suspended the transition to CMMC Phase 2, which had been scheduled for November 2026. However, this change does not eliminate the cybersecurity responsibilities of Defense Industrial Base contractors and subcontractors.

CMMC Phase 1 self-assessment requirements remain in effect.

Organizations that receive, store, process, transmit, or expect to receive Controlled Unclassified Information should continue implementing the applicable requirements of NIST SP 800-171 and remain prepared to complete a CMMC Level 2 assessment when required.

This pause is an opportunity to strengthen your cybersecurity program—not a reason to delay it.

Requirements That Remain In Force

CMMC Level 1 and applicable CMMC Level 2 self-assessment requirements remain part of the current implementation phase. Contractors may need an active CMMC status and affirmation of continuous compliance in the Supplier Performance Risk System before becoming eligible for certain contract awards.

DFARS 252.204-7012 Safeguarding Obligations

DFARS 252.204-7012 continues to require covered contractors and subcontractors to provide adequate security for Covered Defense Information and comply with applicable NIST SP 800-171 requirements.

The suspension of the CMMC Phase 2 transition does not suspend these contractual safeguarding and cyber-incident-reporting obligations.

Your SPRS Score Still Matters

A current NIST SP 800-171 DoD Assessment score may be required in SPRS for each covered contractor information system supporting a DoD contract.

Your submitted score must accurately represent your actual environment, including:

  • Your defined CUI system boundary
  • Your System Security Plan
  • The controls that are fully implemented
  • Valid Plans of Action and Milestones
  • The systems, people, facilities, and service providers included within scope

An unsupported or overstated SPRS score can create significant contractual, financial, and legal exposure.

DIBCAC Assessments Can Still Occur

The Defense Contract Management Agency’s Defense Industrial Base Cybersecurity Assessment Center may conduct government-led assessments to validate a contractor’s implementation of NIST SP 800-171.

A DIBCAC assessment can identify discrepancies between the cybersecurity practices represented in SPRS and the controls operating within the contractor’s actual environment.

Contractors should be prepared to demonstrate compliance through policies, procedures, technical configurations, records, interviews, and objective evidence.

False Claims Act Exposure Is Real

Knowingly submitting inaccurate cybersecurity representations—or requesting payment while failing to comply with material contractual cybersecurity obligations—may expose an organization to allegations under the False Claims Act.

Recent Department of Justice enforcement actions have involved contractors accused of:

  • Submitting inaccurate NIST SP 800-171 assessment scores
  • Failing to implement required cybersecurity controls
  • Misrepresenting the security of covered systems
  • Continuing to submit claims for payment despite alleged noncompliance

Cybersecurity compliance must be supportable, documented, and consistent with the information submitted to the government.

Why Choose DataSoftNow?

At DataSoftNow, we recognize that CMMC certification is more than a regulatory requirement—it’s a commitment to protecting the Defense Industrial Base and strengthening the nation’s cybersecurity posture.

Our assessment team provides:

  • Independent and impartial CMMC Level 2 assessments
  • Certified CMMC Assessors (CCAs) with extensive cybersecurity expertise
  • Thorough evaluation of all 110 NIST SP 800-171 security requirements
  • Clear communication throughout the assessment lifecycle
  • Consistent and transparent assessment methodology
  • Timely reporting and quality assurance
  • Strict adherence to the CMMC Code of Professional Conduct (CoPC)
  • Professional assessment services performed in accordance with Cyber AB requirements

Assessments Performed in Strict Accordance with the Official CMMC Assessment Process (CAP)

Our Assessment Process

DataSoftNow strictly follows the CMMC Assessment Process (CAP) established by the Cyber AB. This standardized four-phase framework ensures every assessment is conducted consistently, objectively, and in accordance with Department of Defense and Cyber AB requirements.

Phase 1 – Plan & Prepare

We begin by validating the assessment scope, confirming the Organizational Assessment Scope (OAS), identifying in-scope assets, reviewing assessment prerequisites, coordinating logistics, and preparing both parties for a successful assessment.

This phase includes:

  • Assessment planning
  • Scope validation
  • Pre-assessment readiness review
  • Documentation requests
  • Rules of engagement
  • Assessment scheduling

Phase 2 – Conduct Assessment

Our Certified CMMC Assessors evaluate your implementation of the required security practices through the collection of objective evidence.

Assessment activities include:

  • Documentation review
  • Interviews with key personnel
  • Examination of technical evidence
  • Observation of implemented security controls
  • Demonstrations of system functionality
  • Validation of compliance with all applicable CMMC requirements

Every practice is evaluated using the assessment methods prescribed by the CMMC Assessment Guide.

Phase 3 – Report Results

Following completion of the assessment, our team performs a comprehensive quality assurance review to ensure accuracy, consistency, and compliance with Cyber AB assessment standards.

This phase includes:

  • Quality assurance review
  • Validation of assessment findings
  • Preparation of assessment documentation
  • Submission of results through the required Cyber AB processes

Phase 4 – Certification & POA&M Closeout

Upon successful completion of the assessment, organizations meeting certification requirements proceed through the Cyber AB certification process.

When permitted under the CMMC program, organizations may resolve allowable minor deficiencies through an approved Plan of Action & Milestones (POA&M) closeout process before certification is finalized.

This phase includes:

  • Certification recommendation
  • POA&M validation (when applicable)
  • Final quality review
  • Issuance of the CMMC certificate through the Cyber AB certification process

Integrity Through Independence

As an Authorized C3PAO, DataSoftNow maintains the independence required by the CMMC ecosystem.

To preserve the integrity of the certification process and comply with the CMMC Code of Professional Conduct (CoPC), we do not provide consulting, implementation, or remediation services to organizations we assess. Our responsibility is to perform fair, objective, and evidence-based assessments that uphold the credibility of the CMMC program.

Who We Are

DataSoftNow is a leading cybersecurity consulting, compliance, and managed security services firm dedicated to helping organizations strengthen their cybersecurity posture and achieve regulatory compliance. As an authorized Cybersecurity Maturity Model Certification (CMMC) Certified Third-Party Assessor Organization (C3PAO), we provide independent CMMC assessments while also delivering expert consulting services for organizations seeking compliance with industry-recognized cybersecurity frameworks.

Our team consists of highly experienced cybersecurity professionals who hold some of the industry’s most respected certifications, including:

  • Certified Information Systems Security Professional (CISSP)
  • Lead Certified CMMC Assessor (LCCA)
  • Certified CMMC Assessor (CCA)
  • Certified CMMC Professional (CCP)

With extensive experience supporting the Defense Industrial Base (DIB), government agencies, manufacturers, and commercial organizations, DataSoftNow combines technical expertise, regulatory knowledge, and real-world operational experience to help clients protect sensitive information, reduce cyber risk, and navigate complex compliance requirements with confidence.

CISSP logo
LCCA logo
CCA logo
CCP logo

Industries We Serve

DataSoftNow performs CMMC assessments for organizations across the Defense Industrial Base, including:

  • Defense contractors
  • Aerospace and aviation manufacturers
  • Precision machining companies
  • Industrial manufacturers
  • Software developers
  • Engineering firms
  • Information technology providers
  • Managed Service Providers (MSPs)
  • Managed Security Service Providers (MSSPs)
  • Suppliers that create, process, store, or transmit Controlled Unclassified Information (CUI)

Schedule Your CMMC Assessment

Whether you are preparing for your initial CMMC Level 2 certification or planning for recertification, DataSoftNow is ready to provide an independent, professional, and efficient assessment experience.

By following the official Cyber AB CMMC Assessment Process (CAP) from planning through certification, we help ensure every assessment is conducted with consistency, transparency, and the highest standards of integrity.

Protect your business. Validate your cybersecurity. Demonstrate compliance.

Contact DataSoftNow today to schedule your independent CMMC assessment.

People working with multiple computer screens