CMMC Compliance Services
From gap assessment to certification day: ASG prepares Connecticut defense suppliers for CMMC Level 1 and Level 2, then keeps the environment compliant after the assessors leave.
- ✓Five Cyber-AB Registered Practitioners (RP) on staff
- ✓3 clients certified at Level 2, 7 more in certification now
- ✓We coordinate directly with an accredited C3PAO
The program moved. The obligation didn't.
The CMMC program rule is final, but the rollout is in flux: in July 2026 the DoD suspended Phase 2 and put a reform task force on it. Phase 1 is untouched, so self-assessment requirements are still appearing in new DoD solicitations. And primes aren't waiting on a task force: if you supply into the Electric Boat, Sikorsky, or Pratt & Whitney chains, flow-down requirements are reaching Connecticut shops now.
- Nov 10, 2025The DFARS contract clause (252.204-7021) takes effect. Phase 1 self-assessment requirements begin, and they remain in force today.
- Jul 13, 2026The DoD suspends Phase 2, the expansion of mandatory third-party C3PAO assessments that had been set for Nov 10, 2026, and stands up a CMMC Reform Task Force.
- ~Sept 13, 2026The task force's recommendations are due to the DoW CIO. Until then, Phase 1 is the live requirement.
Read that suspension carefully, because it's narrower than the headlines suggested. What paused is the expansion of mandatory third-party assessments. What did not pause is your obligation to self-assess against NIST SP 800-171, file the score in SPRS, and have a current score on file before award. DFARS 252.204-7019 and -7020 still say so.
Phase 2 slipped. Your prime's contract language didn't.
And the contract in front of you is written by your prime, not by the task force. Flow-down language is already in circulation across the Connecticut supply chain. The controls take months to implement either way, so the shops treating this as cancelled are the ones who will be scrambling when their next award depends on it.
- ~100authorized C3PAOs
- 80,000+contractors needing Level 2
- Phase 1self-assessment and SPRS scores still required
- under 2%of the defense industrial base certified (March 2026)
The three levels, plainly
- Applies if you handle
- Federal Contract Information (FCI)
- Requirements
- 15 basic safeguarding requirements
- Verified by
- An annual self-assessment
- Applies if you handle
- Controlled Unclassified Information (CUI)
- Requirements
- CMMC Level 2 compliance means all 110 security requirements of NIST SP 800-171
- Verified by
- A third-party (C3PAO) assessment every three years, for most contracts
- Applies if you handle
- The highest-sensitivity programs
- Requirements
- Level 2 plus requirements from NIST SP 800-172
- Verified by
- The government
Which level you need is a contracts question, not an IT question.
It depends on whether FCI or CUI touches your environment. Scoping that boundary correctly is the first thing we do, because it determines everything that follows (and often shrinks the problem).
How we get you certified
Getting certified is a project with a known shape, and we've run it before: three clients certified at Level 2, seven more in certification now. It starts with scoping (finding where CUI actually lives, which usually shrinks the problem), then a gap assessment against all 110 NIST SP 800-171 requirements, then remediation that runs inside managed IT instead of fighting your infrastructure. Five Cyber-AB Registered Practitioners (RP) on staff, plus CCP, CISSP, and Security+ credentials, do this work every week.
One thing an assessor will tell you that a sales rep won't: compliance can't be outsourced.
You stay accountable for all 110 requirements and the 320 assessment objectives behind them (the checkpoints assessors actually grade). Our job is doing the work, documenting it, and keeping your standing visible to you, so accountability never turns into surprise.
Our role on assessment day
By assessment week there should be nothing left to discover.
We coordinate scheduling directly with an accredited C3PAO we regularly work with, assemble the evidence ahead of time, objective by objective, and sit in the room with you for the whole thing. The certification decision belongs to the independent assessor; walking in ready is our job.
Because we run your environment, the assessors also interview us. That's normal (the rule puts your IT provider's services inside your assessment scope), and it works in your favor: the people answering the technical questions are the ones who built the controls and wrote the documentation. A consultant who found your gaps and left can't do that.
Staying certified, the part everyone underestimates
A Level 2 certificate lasts three years, with an affirmation due every year in between, and your next assessor expects the controls to have kept operating the whole time. This is where compliance-as-a-project quietly decays:
- Documentation drifts
- A new hire skips an onboarding step
- A firewall change breaks a control and nobody notices until it costs you
Because the team that got you through the assessment also patches, monitors, and secures your systems, the controls keep running and the evidence accumulates as a byproduct of ordinary operations.
Everything between you and certification
CUI & FCI Scoping
Define exactly where regulated data lives so the compliance boundary (and the cost) stays as small as possible.
Gap Assessment
Your environment measured against the CMMC compliance requirements for your level (all 110 of NIST SP 800-171 for Level 2), with a prioritized remediation roadmap.
System Security Plan (SSP)
The plan assessors read first, written to what they actually ask for instead of a template dump.
Corrective Actions (POA&M)
Plans of Action & Milestones tracked to closure, so open items become closed items before assessment day.
Your DoD Score (SPRS)
Your self-assessment score calculated honestly and submitted to SPRS, then improved on a schedule.
Secure Enclave & GCC High
CUI-safe email, file sharing, and enclave design, including PreVeil deployment and Microsoft GCC High migration when it fits.
Assessment Support
Evidence collection, assessor coordination with an accredited C3PAO we regularly work with, and a team beside you during the assessment.
Managed Compliance
CMMC as a service: continuous monitoring, documentation upkeep, and annual affirmations as part of managed IT after certification.
Compliance help from people who hold the credentials
Credentials held across ASG's compliance and security team.
#1 Connecticut MSP · 2026 Channel Futures MSP 501 (#58 nationally) · 5.0 ★ · 104 Google reviews · Serving CT since 1997
Certification decisions belong to independent assessors. ASG's job is making sure you walk in ready: we prepare you for assessment, remediate gaps, and coordinate directly with an accredited C3PAO we regularly work with.
Questions, answered straight
Related: NIST SP 800-171 complianceIT support for manufacturingCompliance & Risk services
Start with your CMMC gap assessment
Know exactly where you stand within a month: scope, score, and a prioritized roadmap. No deck, no pitch.
