CARMhaus Consulting
Home
Services
  • Security Architecture
  • Readiness Assessment
  • Security Leadership
  • Third-Party Risk
Industries
  • Defense and Aerospace
  • Manufacturing and OT
  • Healthcare
  • Financial Services
Frameworks
  • CMMC Level 2
  • NIST SP 800-171
  • SOC 2
  • ISO 27001
  • HIPAA
  • SOX ITGC
Approach
About
Contact
CARMhaus Consulting
Home
Services
  • Security Architecture
  • Readiness Assessment
  • Security Leadership
  • Third-Party Risk
Industries
  • Defense and Aerospace
  • Manufacturing and OT
  • Healthcare
  • Financial Services
Frameworks
  • CMMC Level 2
  • NIST SP 800-171
  • SOC 2
  • ISO 27001
  • HIPAA
  • SOX ITGC
Approach
About
Contact
More
  • Home
  • Services
    • Security Architecture
    • Readiness Assessment
    • Security Leadership
    • Third-Party Risk
  • Industries
    • Defense and Aerospace
    • Manufacturing and OT
    • Healthcare
    • Financial Services
  • Frameworks
    • CMMC Level 2
    • NIST SP 800-171
    • SOC 2
    • ISO 27001
    • HIPAA
    • SOX ITGC
  • Approach
  • About
  • Contact
  • Home
  • Services
    • Security Architecture
    • Readiness Assessment
    • Security Leadership
    • Third-Party Risk
  • Industries
    • Defense and Aerospace
    • Manufacturing and OT
    • Healthcare
    • Financial Services
  • Frameworks
    • CMMC Level 2
    • NIST SP 800-171
    • SOC 2
    • ISO 27001
    • HIPAA
    • SOX ITGC
  • Approach
  • About
  • Contact
An engineer inspecting an aircraft engine in a hangar, the kind of supplier CMMC Level 2 applies to
Scoped, specified, proven.

CMMC Level 2 Consulting

We define the CUI boundary, specify the controls in the language the assessment objectives use, and record who owns which objective. Your team or your provider builds to that specification. We then validate what was delivered and prepare the evidence an assessor will ask for.

Talk through your CMMC scope

The pause changed the schedule. Not the obligation.

What was suspended

What that means for you

What did not change

Third-party assessment. The C3PAO requirement that was set to begin in November 2026 is on hold pending a reform task force review, and solicitations carrying Phase 2 language are being amended.

What did not change

What that means for you

What did not change

Everything that actually protects the data. DFARS 252.204-7012 still applies. NIST SP 800-171 is still the standard. SPRS scoring and annual affirmations are still due. FedRAMP Moderate equivalence for cloud-held CUI still applies.

What that means for you

What that means for you

What that means for you

A false SPRS score was always a False Claims Act exposure and still is. Primes are still flowing down their own requirements on their own timeline. The suspension bought time to do the work properly. It did not remove the work.

Where this usually starts

A flow-down arrives

A plan that describes a different system

A score nobody can reconstruct

A prime sends a questionnaire, or a clause lands in a contract, and the honest internal answer is that nobody can say yet what the score covers or how it was reached.

A score nobody can reconstruct

A plan that describes a different system

A score nobody can reconstruct

There is a number in SPRS. It was produced quickly, under deadline, against a boundary that was never written down, and the person who produced it has often moved on.

A plan that describes a different system

A plan that describes a different system

A plan that describes a different system

System Security Plans written to satisfy a request tend to claim controls the configuration does not enforce. The distance between the document and the running system is the whole problem, and it is a common one.

Three engagements, in the order they usually run

Scope and score

Specify the target state

Specify the target state

We define the CUI boundary and write the basis for the line we draw. Then a full assessment against all 110 requirements at the objective level, a score you can defend, and a Plan of Action that names owners and dates.

Specify the target state

Specify the target state

Specify the target state

Identity and conditional access, endpoint coverage, controlled-data discovery, segmentation and enclave design, access review cycles, and incident response. Written as specifications your team or your provider builds to, with a shared responsibility matrix recording who owns which objective.

Validate and evidence

Specify the target state

Validate and evidence

We review what was delivered against what was specified, then establish the evidence cycle: an artifact per control, on a cadence, with a named owner. The record should accumulate as a byproduct of operating rather than as a project the month before an assessment.

Questions we get asked

The ones that come up most often before a scoping call.

Yes. The 800-171 obligation, the DFARS clause, the SPRS score and the annual affirmation all survive the pause untouched. The reform task force is reviewing how the program assesses, not whether the underlying standard applies. Every organization that treats the pause as a reprieve will restart from behind.


No, and no consultant can. Certification comes from an accredited C3PAO. We prepare the environment and the evidence and stay on the other side of that line. We also do not build what we assess, for the same reason: a firm that configures a control and then attests that it works has graded its own homework.


For a small supplier with a contained boundary, commonly six to twelve months from scoping to assessment-ready. The variable is rarely the controls. It is how much of the environment has to change, and how much evidence history has to accumulate before an assessment window opens.


Whether CUI is confined to an enclave or spread across your whole enterprise. That single decision drives cost more than any other, because everything in scope has to meet the standard, be documented, and generate evidence.


If CUI reaches you, yes. Flow-down does not stop at the first tier. Primes are increasingly asking for evidence rather than assertions, and they are asking earlier in the award cycle.


Yes, and we prefer to. Scoping conversations get useful quickly, and the useful part usually involves details you should not be discussing without one.


© 2026 CARMhaus Consulting LLC. All rights reserved. Cybersecurity · Assurance · Risk Management

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

Accept