CMMC 2.0 Certification

Get CMMC 2.0 certified, and stay certified.

CMMC Phase II is suspended and under review, but Phase I self-assessment requirements and the underlying obligations to protect FCI and CUI remain in force. RESTIV takes you from CUI scoping to an assessor-ready evidence chain across all 110 NIST SP 800-171 controls, then keeps it current with continuous control testing.

  • Aligned to all 110 NIST SP 800-171 controls
  • Phase II suspended; Phase I remains in force
  • Continuous evidence, not a point-in-time audit
  • SCIFAI: zero-egress AI for CUI and ITAR/EAR work

Current programme status

CMMC Phase II is suspended. Phase I remains in force.

On July 13, 2026, the U.S. Department of War suspended the transition to Phase II and paused pending and future rollout milestones while it reviews the programme. Phase I self-assessment requirements and the underlying obligations to protect FCI and CUI remain active, including applicable NIST SP 800-171 and DFARS requirements.

Source: U.S. Department of War announcement, July 13, 2026

ON HOLD

Phase II rollout

Since July 13, 2026

What CMMC 2.0 certification actually takes.

Not advisory hours and a binder. An operational programme that proves control effectiveness the day a prime, a C3PAO assessor, or a government client asks.

CUI scoping & SPRS

Define the Controlled Unclassified Information boundary, inventory the systems that touch it, and produce a defensible SPRS score — keeping certification effort proportionate to real risk.

Continuous control testing

Operational effectiveness under adversarial conditions, not point-in-time configuration checks. The evidence stays current between assessments instead of being rebuilt each cycle.

Audit-grade evidence chain

Every one of the 110 controls links to live evidence — logs, configurations, attestations — that a C3PAO assessor can verify on demand. No last-minute evidence scramble.

SCIFAI — sovereign AI

The air-gapped Compliance Copilot edition built under NRC-IRAP Project 1041303. Zero data egress and full attribution, so teams can use AI on CUI and ITAR/EAR work without breaching contract.

Your path to CMMC 2.0 certification.

A continuously-tested control programme that is ready the day the assessor calls — each stage producing the evidence the next one depends on.

01

Scope

Define the CUI boundary

Identify Controlled Unclassified Information, map the systems that store, process, or transmit it, and draw the assessment boundary. Scope discipline keeps certification cost and effort proportionate.

CUI InventoryAsset MappingBoundary Definition
02

Assess

Gap analysis against 110 controls

Measure the current programme against all 110 NIST SP 800-171 practices. Every gap is documented with the evidence required to close it and the assessment objective it maps to.

NIST SP 800-171Gap AnalysisSPRS Scoring
03

Remediate

Close gaps with continuous testing

Implement and operate the missing controls, then prove they work under adversarial conditions. Remediation is verified by continuous control testing, not a one-time checkbox.

Control ImplementationPOA&MContinuous Testing
04

Evidence

Build the audit-grade chain

Every control links to live evidence — logs, configurations, attestations — in an audit-grade chain that a C3PAO assessor can verify on demand.

Evidence ChainImmutable LogsAssessor-Ready
05

Certify

C3PAO assessment, maintained

Walk into the C3PAO assessment ready, then stay ready. The programme keeps the evidence current so certification holds across the contract lifecycle, not just at award.

C3PAO AssessmentContinuous ComplianceRecertification

Built for both ends of the supply chain.

Certification is a shared obligation. We align primes and their suppliers so the whole chain clears CMMC 2.0 together.

Prime Contractors

De-risk your supplier base

A single supplier with weak controls can put an award at risk. We give primes visibility into supplier readiness and a repeatable path to strengthen SMEs while Phase I requirements remain active and Phase II is reviewed.

CMMC 2.0DFARS 252.204-7012NIST SP 800-171

SME Suppliers

Certify without an in-house team

Most SME suppliers have no CISO and no compliance team. We run the programme for you — scoping, remediation, and evidence — so a small supplier can meet the same bar as a prime.

CMMC 2.0ITAR / EARISO 27001

Government & NATO

Sovereign, accreditation-ready AI

SCIFAI gives government and NATO-aligned programmes a certified AI environment with zero data egress and full attribution — presented at ONE Conference The Hague as a candidate industry standard.

NATO CSDMCMMC 2.0ITAR / EAR

Frequently asked questions.

Direct answers to the questions buyers, assessors, and executive teams ask most often.

Is CMMC Phase II still scheduled for November 10, 2026?
No. On July 13, 2026, the U.S. Department of War suspended the transition to CMMC Phase II and paused pending and future rollout milestones while it reviews the programme. Phase I self-assessment requirements remain in force, along with applicable obligations to protect FCI and CUI under NIST SP 800-171 and DFARS.
What does CMMC Level 2 require?
CMMC Level 2 verifies implementation of the 110 security requirements in NIST SP 800-171 Revision 2 for systems that process, store, or transmit Controlled Unclassified Information. The required assessment type depends on the applicable contract.
Can Compliance Copilot award CMMC certification?
No. RESTIV supports scoping, readiness, remediation, continuous testing, and assessor-ready evidence. Final CMMC status is determined through the applicable self-assessment or authorized third-party assessment process.

Validated where it counts

Phase I

July 2026 — Phase II suspended; Phase I remains active

110

NIST SP 800-171 controls assessed

CAD 240K

NRC-IRAP defence contract — Project 1041303

Use the pause to get genuinely ready.

A CMMC readiness call is a private working session with the RESTIV team — your CUI scope, your gaps against the 110 controls, and the fastest credible path to an assessor-ready programme.