Cyberfox Security  CMMC Services Phone Icon(833) 463-6804

CMMC 2.0, NIST 800-171r2, FAR 52.204-21

Compliance Experts

REQUEST A FREE CONSULT


A Security Firm You Can Trust

Our Services                                                               

  • Comprehensive CMMC / NIST 800-171 Gap Assessments                                                                      
  • Actionable Gap Assessment Report with prioritized findings                                              
  • Fully developed System Security Plan (SSP)                                                  
  • Tailored Plan of Action & Milestones (POA&M)                                               
  • Accurate SPRS score submission to DoD                                                
  • End-to-end remediation support and pre-assessment preparation
  • CMMC Security and Compliance Program Development
  • vCISO Services to advise and help maintain compliance after a CMMC Assessment

Why Defense Contractors Choose Cyberfox Security                                                                       

  • Lead CMMC Certified Assessor (LCCA), and CISSP-holding practitioners on staff
  • 25+ years of real-world experience inside DoD, the U.S. Intelligence Community, and the nation’s largest defense primes (Lockheed Martin, Northrop Grumman, ACS Defense, and multiple FFRDCs) Led by Air Force veterans and former IC professionals who have written, interpreted, and audited against ICD 503, NIST 800-53, 800-171, and CMMC requirements. We know exactly how C3PAOs and DCMA assessors think — because many of us have been in their seats.

*Cyberfox Security is a Trusted CMMC Compliance Partner for the Defense Industrial Base (DIB) and Supply Chain. We deliver mission-critical cybersecurity consulting and compliance services exclusively to DoD contractors, Defense Industrial Base organizations, and Federally Funded Research and Development Centers (FFRDCs).                                                                                                                        

Recent CMMC 2.0 Updates

CMMC Phase 1 Implementation November 10, 2025 – November 9, 2026

During Phase 1, all Defense Industrial Base (DIB) contractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) must focus on achieving and maintaining compliance with CMMC Level 1 and Level 2 requirements through self-assessments.

Key requirements in Phase 1:

  • Level 1 (FCI protection): Annual self-assessment required; results must be submitted and affirmed in the Supplier Performance Risk System (SPRS).
  • Level 2 (CUI protection): Annual self-assessment required for most applicable contracts; results must be submitted and affirmed in SPRS by a senior official from the contractor’s corporate office.
  • Third-party certification option: DoD program managers and requiring activities retain the authority to mandate a Level 2 Certification Assessment by a C3PAO (third-party assessment organization) for any contract involving CUI, even during Phase 1.
  • Applicability: Phase 1 requirements apply to all DoD contractors and subcontractors that process, store, or transmit FCI or CUI under applicable contracts.

This phase establishes the foundational self-attestation process while preserving DoD’s flexibility to require certified assessments when higher assurance is deemed necessary.

A note of caution: We have worked with many companies at both CMMC Level 1 and Level 2 that have conducted self-assessments and calculated an SRPR score in the (+40 to +60) range and submitted those scores to DoD. These companies subsequently ask Cyberfox to conduct gap assessments for them. Results of our gap assessments yielded SPRS scores ranging from (-18 to -200).  Under CMMC 2.0 company executives will be required to attest in SPRS that scores they submit are accurate.  This potentially leaves them at risk of violating the False Claims Act.


Contact us today to schedule your new client consultation
or to learn about our services.

(833) 463-6804


About Us

The owner and founder of our security firm has been in this industry for over 25 years. He is a retired Air Force veteran and has worked with and advised many companies to include ACS Defense Inc., Lockheed Martin Corp., Northrop Grumman Corp., and several Federally Funded Research and Development Centers (FFRDCs). You can trust the knowledge and experience that he brings to your table. We offer a wide variety of personalized business relationships with our partners. Our business model is best-value pricing and we work hard to help clients make optimal security decisions without attempting to oversell.


Thank you for your interest. We look forward to hearing from you soon.

Phone
(833) 463-6804
By Appointment Only

Mailing Address
Cyberfox Security Consulting
PO Box 183
Norfolk, MA 02056

Service Area
United States

Follow
Facebook Twitter linkedin

Share