Your prime just added CMMC Level 2 to the RFP. You have until the next award to be ready.
300,000+ DIB contractors will need a current CMMC Level 2 certificate to bid on DoD work by 2028. Most aren’t ready. The 110 NIST 800-171 Rev 3 controls, the CUI handling program, the SSP + POA&M, and the C3PAO assessment don’t build themselves. We run the platform mechanics continuously and walk the C3PAO assessment with you.
Not selling to DoD? Non-DoD manufacturers still work with us for OT/ICS security, IEC 62443, and enterprise SOC 2. The CMMC track below is where most manufacturing conversations start. It’s not the only one. Reach out.
§ I · Why This RFP Landed Different
The CMMC 2.0 clock has been ticking since December.
The Final Rule is in effect. The assessment ecosystem is standing up. DoD contracting officers are inserting DFARS 252.204-7021 into new solicitations on a phased schedule. The rollout dates on the left set the calendar. The clauses on the right are what your solicitation will cite, and what each really enforces beneath the surface text.
- Dec 16 2024CMMC Program Final Rule effective · 32 CFR Part 170 · self-assessment, C3PAO, and DIBCAC tracks all binding
- May 2024NIST SP 800-171 Rev 3 published · 110 controls · ODP-parameter withdrawals reshaped every C3PAO’s assessment procedures
- Q1 2026Phase 1 contract flow-down active · CMMC L1/L2 self-assessment requirements begin appearing in new solicitations, phased by NAICS
- 2028Phase 4 · full DIB coverage · CMMC required on effectively every new DoD contract at the specified Level; suppliers without cert lose award eligibility
DFARS 252.204-7012 In force since 2017
Every DoD contractor has been under this since the last administration. Most treated the SPRS self-assessment as vanity; the score didn’t matter because nobody was pulling it. CMMC 2.0 changes the enforcement, not the clause. If your evidence is thin, 7012 is where the audit trail was supposed to live.
DFARS 252.204-7020 The SPRS floor
Your posted SPRS score is what a prime pulls before award. In 2026, primes are setting minimum SPRS thresholds in RFP language on their own initiative. 88 out of 110 is common, higher on classified adjacencies. That threshold game beats you to the CMMC L2 requirement by six months.
DFARS 252.204-7021 The CMMC clause
Phased flow-down. Not applied to your backlog; applied to your next new solicitation once your NAICS phases in. Your Program Manager’s phase-in date is the timeline that actually matters, and nobody at your prime knows it either. Getting the answer requires calling the acquisition office.
FAR 52.204-21 The federal floor
Fifteen controls. Every federal contract, not just DoD. GSA, DHS, DOE flow this down too. Most contractors treat it as CMMC’s little cousin and skip the evidence work. Real risk: an OIG audit under FAR is a faster enforcement vector than a C3PAO assessment.
ITAR §120-130 Parallel regime
If you touch munitions-list data, ITAR isn’t a layer on top; it’s a separate enforcement regime with criminal penalties. Overlap with 800-171 §3.1 and §3.9 is real, but ITAR pre-shipment reviews are their own beast that CMMC doesn’t cover. Handle both, not one.
§ II · Where CMMC Costs Land
Three moments turn CMMC from a compliance line item into a contract loss.
Every DIB supplier walks through all three. The cost of missing one shows up in lost awards, extended C3PAO cycles, and remediation billing.
Platform Track
Continuous evidence collection against every 800-171 Rev 3 control. Auto-generated SSP, POA&M with remediation targets, and CUI-boundary attestation. Ready to hand a C3PAO on Day 1, not built the week before.
Advisory Track (Other20)
Real vCISO in your assessment interviews. Pre-mission briefing for control owners. Post-assessment POA&M triage. Not a partner-network handoff. Our people on your calls, priced by the hour.
§ III · Outcomes on the Line
What a completed run looks like on paper.
Eight to twelve weeks after kickoff, this is the readiness summary you hand your prime, before the C3PAO shows up.
§ IV · When the Prime Sends the Data Call
Your written response gets pasted straight into the prime’s proposal, word for word.
Every prime assembling a major DoD bid sends a CMMC compliance data call to their subcontractors, usually 30 to 60 days before the proposal is due. Whatever you write comes back verbatim in their Technical Volume. If it reads uncertain, the prime lowers their proposed technical rating to absorb your risk, or drops you from the team. If it reads decisive and evidenced, it becomes a strength claim in their writeup and the reason you keep the seat.
The AFTER response → is what the prime pastes into their Technical Volume. The BEFORE is the reason a competing subcontractor gets the seat instead.
§ IVa · Program Horizon 2026-2028
The next 24 months of DoD cyber flow-down, on one chart.
The DoD rollout is phased. Different CMMC Levels apply to different contract types across a 24-month window. Below is the sequence, with the rule number driving each phase.
Sources: DoD Program Executive Office · 32 CFR Part 170 · FAR Council rulemaking calendar. Dates reflect our current tracked signal; we brief you when they move.
§ V · What Ships
The deliverables list. Every artifact, named and linked.
Each is an artifact your C3PAO will ask for. Some the platform produces continuously; some Other20 authors on the mission clock. Click through to the feature or service page that owns the artifact.
§ VII · Is this you?
The DIB supplier moments we walk through the most.
Six situations we see repeatedly. If you’re inside any of them, the pre-mission briefing is where we start.
Your prime added CMMC Level 2 as a gating clause on your next bid, and your last SPRS score is more than a year old.
You subcontract on a program you can’t afford to lose, and the DFARS 252.204-7021 flow-down memo landed in your inbox this quarter.
Your CUI lives across cloud, on-prem, and a few engineer workstations, and nobody has drawn the actual data-flow diagram in two years.
You have 30+ sub-tier suppliers under you and no register that proves who’s L1 self-assessment ready and who isn’t.
You’re staring down a NIST 800-171 Rev 3 gap analysis and you don’t know whether to hire a consultant, buy software, or do both.
Your CFO wants a fixed number for CMMC readiness and every quote you’ve gotten is either “$X million” or “call for pricing.”
Advisory · Other20
The pre-mission briefing before your C3PAO cycle.
Every serious CMMC engagement starts with a 45-minute working session. No sales cycle, no NDA hoops. The assessment world runs on classified-briefing rhythm, so ours does too.
Fractional CISO, 20+ years in the field, US Air Force background. Yolonda has walked the exact assessment cadence your C3PAO will follow. This is what the 45 minutes covers.
Agenda · 01 · Scope
Your CUI boundary. Contract count in play. Subcontractor tier depth. Where your SSP already covers you, where it doesn’t.
Agenda · 02 · Timeline
C3PAO scheduling reality. What’s achievable in 8-12 weeks vs. 16-20. Where your prime’s award calendar forces the choice.
Agenda · 03 · Package
Platform + Other20 scope. Fixed monthly retainer or hourly. Explicit deliverables list from § V above. No mystery pricing.
§ VIII · Common Questions
What DIB program managers ask us.
What's the difference between CMMC Level 1, Level 2, and Level 3?
Level 1 covers Federal Contract Information (FCI): the 15 controls in FAR 52.204-21, verified by annual self-assessment. Level 2 covers Controlled Unclassified Information (CUI): all 110 NIST 800-171 Rev 3 controls, verified either by self-assessment or by a C3PAO third-party assessment depending on the contract. Level 3 covers the most sensitive DoD programs (APT-in-scope): 110 Rev 3 controls plus a subset of NIST 800-172 enhanced requirements, assessed by DIBCAC. Your contracting officer specifies the Level required for each award.
Can Other20 attend my C3PAO assessment interviews?
Yes. Your vCISO participates as a program-team member: briefing control owners in advance, sitting through interviews as a subject-matter resource, and supporting POA&M triage if the C3PAO surfaces findings. We don't role-play as your employee, but we do show up as a named advisor on your program team, which is standard practice and well within CMMC assessment norms.
What if we're a subcontractor to a prime? Do we still need Level 2?
If you process, store, or transmit CUI in performance of the subcontract, yes. DFARS 252.204-7021 flows down. The prime is contractually required to verify your Level before award, and most primes are now using a supplier's SPRS score and CMMC status as a pre-bid gate. If you don't touch CUI, Level 1 (self-assessment) is often sufficient. We help you make that determination in the readiness call.
How long does the platform + Other20 combined engagement typically take?
8-12 weeks from kickoff to C3PAO scheduling for a typical DIB supplier with reasonably mature IT hygiene. Longer (16-20 weeks) for organizations rebuilding an SSP from scratch, running heterogeneous cloud + on-prem environments, or with more than three tiers of subcontractor flow-down to organize. The readiness call gives you a scoped timeline before you commit.
Is Other20 an authorized C3PAO?
No. That's intentional. C3PAOs perform the formal assessment, and Cyber-AB rules prohibit an assessor from also serving as the readiness partner for the same organization. We prepare you for the assessment; a separate authorized C3PAO conducts it. We can recommend C3PAOs whose scheduling and scope match your target window.
Do you handle NIST 800-171 for non-DoD federal contracts too?
Yes. The 800-171 control catalog is used by GSA, DHS, DOE, and other civilian agencies via various contract clauses (and FAR Part 40 rulemaking is expanding this reach). Our platform's evidence collection is 800-171-native, and Other20's readiness process works the same whether the assessor is a C3PAO, a civilian agency IG, or a prime auditor.
You’re on a bid cycle. Get on the briefing calendar.
CMMC L2 readiness is measured in weeks, not quarters. But only if the clock starts today. Book the briefing, walk into your next prime call with a scoped timeline, and stop watching awards go to competitors who moved first.
Founder & Principal Advisor · Other20
45-min working session
USAF · Carnegie Mellon CISO Cert
NIST 800-171 Rev 3 · CUI · ITAR overlap