A Security Firm You Can Trust
Our Services
- Comprehensive CMMC / NIST 800-171 Gap Assessments
- Actionable Gap Assessment Report with prioritized findings
- Fully developed System Security Plan (SSP)
- Tailored Plan of Action & Milestones (POA&M)
- Accurate SPRS score submission to DoD
- End-to-end remediation support and pre-assessment preparation
- CMMC Security and Compliance Program Development
- vCISO Services to advise and help maintain compliance after a CMMC Assessment
Why Defense Contractors Choose Cyberfox Security
- Lead CMMC Certified Assessor (LCCA), and CISSP-holding practitioners on staff
- 25+ years of real-world experience inside DoD, the U.S. Intelligence Community, and the nation’s largest defense primes (Lockheed Martin, Northrop Grumman, ACS Defense, and multiple FFRDCs) Led by Air Force veterans and former IC professionals who have written, interpreted, and audited against ICD 503, NIST 800-53, 800-171, and CMMC requirements. We know exactly how C3PAOs and DCMA assessors think — because many of us have been in their seats.
*Cyberfox Security is a Trusted CMMC Compliance Partner for the Defense Industrial Base (DIB) and Supply Chain. We deliver mission-critical cybersecurity consulting and compliance services exclusively to DoD contractors, Defense Industrial Base organizations, and Federally Funded Research and Development Centers (FFRDCs).
Recent CMMC 2.0 Updates
CMMC Phase 1 Implementation November 10, 2025 – November 9, 2026
During Phase 1, all Defense Industrial Base (DIB) contractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) must focus on achieving and maintaining compliance with CMMC Level 1 and Level 2 requirements through self-assessments.
Key requirements in Phase 1:
- Level 1 (FCI protection): Annual self-assessment required; results must be submitted and affirmed in the Supplier Performance Risk System (SPRS).
- Level 2 (CUI protection): Annual self-assessment required for most applicable contracts; results must be submitted and affirmed in SPRS by a senior official from the contractor’s corporate office.
- Third-party certification option: DoD program managers and requiring activities retain the authority to mandate a Level 2 Certification Assessment by a C3PAO (third-party assessment organization) for any contract involving CUI, even during Phase 1.
- Applicability: Phase 1 requirements apply to all DoD contractors and subcontractors that process, store, or transmit FCI or CUI under applicable contracts.
This phase establishes the foundational self-attestation process while preserving DoD’s flexibility to require certified assessments when higher assurance is deemed necessary.
A note of caution: We have worked with many companies at both CMMC Level 1 and Level 2 that have conducted self-assessments and calculated an SRPR score in the (+40 to +60) range and submitted those scores to DoD. These companies subsequently ask Cyberfox to conduct gap assessments for them. Results of our gap assessments yielded SPRS scores ranging from (-18 to -200). Under CMMC 2.0 company executives will be required to attest in SPRS that scores they submit are accurate. This potentially leaves them at risk of violating the False Claims Act.