Cybersecurity Maturity Model Certification (CMMC)
Get complete CMMC 2.0 compliance services and flow down management.
Over 25 Years of Compliance Experience
QSA | PFI | ASV | P2PE | SSF | SLC | 3DS | QPA | PCIP | RPO

Jump to Section
Your Contracts May Be at Risk
CMMC requirements are mandatory, impacting every DoW contractor handling sensitive information. Without being compliant, contractors run the risk of being breached and losing their government contracts. We’re here to help.

Find Your CMMC Level and Get Pricing
Try our CMMC EstimatorSolutions
Primes
Manage Your Entire Contractor Flowdown with Link
- Automated Compliance Dashboard: Link, our CMMC portal, streamlines the entire contractor management process by tracking subcontractor compliance profiles and giving you a simplifed, high-level overview of your network.
- Custom Reporting and Contractor Organization: Contractors can organize subcontractors into tailored groups based on specific contracts or locations to organize compliance management.
- 360° View of Contractors and Data Exports: Download comprehensive reports for detailed compliance metrics and create monthly snapshots to track historical subcontractor status over time.
- Effortless Subcontractor Onboarding: Users can quickly review existing contractors or add new partners to their portfolio by searching for their cage code in our ever-growing database of contractors.
Level 2 Contractors
Complete CMMC Validation with Expert Guidance
- Simplified Self-Assessment for Every Requirement: Navigate every CMMC requirement in CMMC Assess, our self-assessment portal for Level 2 in simple, manageable steps.
- Start-to-Finish CMMC Consultation: Get flexible consulting with a certified CMMC expert, a dedicated support team, and a customized plan built around your organization’s needs, budget, and timeline.
- Full Organizational Scoping & Gap Analysis: Receive scope optimization, detailed gap report, and compliance score breakdown all work to help you to fully prepare and pass your CMMC assessment.
- 25+ Years of Compliance Experience: SecurityMetrics has worked hand-in-hand with leaders in every major industry and with businesses of all sizes for over two decades.
Level 1 Contractors
Get Fully-Supported Self Assessment Tools
- Free Compliance Profile: Add your compliance status to our platform for free, advertise your compliance status, and connect with primes.
- Self-Assessment Portal: Access our portal that guides you through each control in easy-to-understand terms with our CMMC self assessment portal.
- 24-Hour Live Support Backed by Compliance Experts: Contact our 24/7/365 support team to get hands-on help, wherever you’re at in your CMMC journey.
- Get a Ready-to-Submit Report on Compliance: Get a report on your compliance that you can submit to the DoD/DoW official SPRS website.
PCI program solutions for acquirers and ISOs
SecurityMetrics PCI programs are merchant-friendly, keeping them and you happy.
Feature
Basic
Plus
Pro
Advisor
Online Portal
Merchant PCI SAQ
SAQ Pre-Population
ASV scans (1/merch)
PCI Policy Template
24/7 Help Desk
24/7 Scan & SAQ Support
Partner+ Portal
Custom Email Campaigns
Assigned CSM
ASV scans (5/merch)
$100,000 Merchant Premium Service Warranty
Card Data Discovery
Mobile Device Scan
AI-Powered PCI Compliance (Spectre AI)
Anti-Malware Software
Get started on your PCI program, request a quote now.
Request a QuoteLite
Basic
Advanced
PCI for small businesses starting at
Price discounts available depending on merchant processor
- External Vulnerability Scan (1 IP)
- Online PCI Self Assessment Questionnaire (SAQ)
- Online compliance reporting portal
- Non-compliance notification
- Compliance reporting to merchant processor
- Compliance certificate
- PANscan® (Card discovery software for 1 machine)
- Service warranty (Up to $100,000 reimbursement in case of a breach)
- Security Awareness Training (1 seat)
*We discount our services for most merchants because of our relationship with their merchant processor.
Looking for Acquirer or PCI program pricing? Click here.
Basic
- Online Portal Access (Software to help you work towards HIPAA compliance)
- Security Fundamentals Checklist
- $100,000 Service Guarantee
- Monthly Perimeter Scans: 1 IPs
- Risk Analysis
- Risk Management Plan
- Monthly HIPAA Newsletter
- HIPAA Policies & Procedures (including Breach Notification Policy and Business Associate Agreement Template
- HIPAA Training: 3 seats
- 5 Hour Technical Support (inbound tech support only)
Plus
- Online Portal Access (Software to help you work towards HIPAA compliance)
- Security Fundamentals Checklist
- $100,000 Service Guarantee
- Monthly Perimeter Scans: 3 IPs
- Risk Analysis
- Risk Management Plan
- Monthly HIPAA Newsletter
- HIPAA Policies & Procedures (including Breach Notification Policy and Business Associate Agreement Template
- HIPAA Training: 15 seats
- Unlimited Support (specialized HIPAA support agents available for guidance on all HIPAA tools)
Pro
- Online Portal Access (Software to help you work towards HIPAA compliance)
- Security Fundamentals Checklist
- $100,000 Service Guarantee
- Monthly Perimeter Scans: 5 IPs
- Risk Analysis
- Risk Management Plan
- Monthly HIPAA Newsletter
- HIPAA Policies & Procedures (including Breach Notification Policy and Business Associate Agreement Template
- HIPAA Training: 25 seats
- Unlimited Support (specialized HIPAA support agents available for guidance on all HIPAA tools)
Basic
- Portal access
- 1 payment path supported
- User-initiated scanning process
- Fulfills req’s. 6.4.3 & 11.6.1
- Add-on consultation credits available
- Partner discounts available
Plus
- Portal access
- 1 payment path supported (option to add on)
- Automated scanning process
- Fulfills req's. 6.4.3 & 11.6.1
- Add-on consultation credits available
- Partner discounts available
Pro
- Portal access
- 3 payment paths supported (option to add on)
- Automated scanning process
- Fulfills req's. 6.4.3 & 11.6.1
- Forensic annual baseline assessment
- 12 annual consultation credits included
- Partner discounts available
SecurityMetrics Podcast featuring Katie Arrington (Former CISO for the DoD) and mother of the CMMC
Frequently Asked Questions
Level 1 contractors handle FCI (Federal Contract Information) and must complete a self-assessment of 15 different CMMC controls. You’re also required to annually attest their CMMC compliance.
Whether you're new to CMMC or have no security-framework background, SecurityMetrics guides you from start to finish.
Trained CMMC experts can help you fulfill CMMC deadlines, report your compliance status to the Supplier Performance Risk System (SPRS) website, and connect with Prime contractors.
Level 2 contractors handle CUI (Controlled Unclassified Information) and must complete at least a self assessment of 110 different CMMC controls, which assists in your preparation for a full audit with a C3PAO.
CMMC Audit controls are based entirely on the 110 controls in the NIST SP 800-171 framework.
Our audit team can assist with all of these controls and requirements. We have extensive experience with NIST frameworks and can perform a CMMC Readiness Assessment to efficiently scope your CMMC environment and conduct a thorough Gap Analysis.
As a prime contractor, you must be able to verify that all of their subcontractors are also CMMC compliant.
We offer Prime contractors a compliance management database and platform that tracks and verifies the CMMC status of all subcontractors, making your CMMC program simple to organize and manage.
The Cybersecurity Maturity Model Certification (CMMC) is a Department of War program designed to validate that private companies working with the military have strong cybersecurity. The DoW is moving to a "verify before you trust" model to stop foreign adversaries from stealing intellectual property and national security data from the defense supply chain.
- This assessment is conducted directly by government officials. The program works in a tiered system based on the type of data you handle:
- Level 1: For companies handling Federal Contract Information (FCI). This involves standard practices like passwords and antivirus software.
- Level 2: For companies handling Controlled Unclassified Information (CUI). This requires strict protocols (NIST standards) and an audit by a CMMC authorized private third party (C3PAO).
- Level 3: For a small subset of companies working on critical programs.
For most companies, the answer is no. The biggest change under CMMC is the move away from the "honor system" where you could simply sign a paper claiming you followed the rules.
Since November 10, 2025, Level 2s are encouraged to Self-Assess and attest to this in SPRS (unless their DoW contract states otherwise). Level 2s should expect to be asked to assess once every 3 years by a certified C3PAO assessor. They must also affirm in SPRS annually (years between C3PAO assessment). The DoW reserves the right to delay Level 2 requirements in a given contract at their discretion. But generally new contracts from the DoW will include the Level 2 assessment requirements as stated above.
You should prepare now. The phased rollout has begun, and these requirements are already appearing in contracts. CMMC is a "go/no-go" requirement; without the certification in hand, you cannot be awarded the contract and may be passed over for other contractors who are compliant. You must determine your level and prepare for assessment to ensure you can win future bids.
Yes. If you share Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) with subcontractors to fulfill a contract, they must also achieve the appropriate CMMC level. The program is designed to secure the entire supply chain, meaning you are responsible for ensuring your partners and vendors meet these requirements before sharing data with them.
It varies by level. Level 1 requires an annual self-assessment and affirmation. Level 2 and Level 3 certifications are generally valid for three years. However, you are still required to submit an "annual affirmation" in the SPRS to verify that your security remains compliant during the years between your full assessments.
It depends on the severity. For Level 1, you must pass 100% of the requirements immediately; no exceptions are allowed. For Level 2 and 3, if you miss certain non-critical requirements, you may be granted "Conditional" status. This allows you to continue working, but you must create a Plan of Action and Milestones (POA&M) and fix the issues within 180 days. If you do not close out these issues within that timeframe, your conditional certification will expire.
Resources
The following are related resources that we have prepared for you. Find more answers to your questions in our Learning Center.
Trusted by 300,000+ companies










































































































Get PCI DSS Compliant
Get ready for PCI DSS v4.0.1 with the right tools, training, and support.
Why choose SecurityMetrics?
Trusted by Over 450,000 Businesses
With 25 years of experience guiding companies to achieve detailed compliance frameworks like PCI, HIPAA, HITRUST, NIST, CISSP, and more, SecurityMetrics offers CMMC certification for DoD contractors and guides you through each step of meeting CMMC demands, regardless of your contractor level.
We’ve worked hand-in-hand with leaders in every major industry and with businesses of all sizes. Our team is ready to help you with the rigorous requirements for full CMMC compliance, enabling you to focus on winning contracts.
Award-winning support
Get help from a real human who can address your specific needs in real-time.
Tools to simplify compliance
Get the services you need to make compliance less of a chore. Training, policies & procedures, penetration testing, and more.
A partner in compliance
Our goal is to help you not only pass your compliance requirements, but increase your understanding of where you are doing well, and where your security needs to improve.
Straightforward pricing
Your scope is evaluated based on your needs, avoiding unnecessary add-on charges.
See how we've helped our clients succeed
When you succeed, we succeed. That's why we pay such close attention to detail and provide award-winning support. Let's work together!
Recognition for Outstanding Work
SecurityMetrics has worked hard over the years to provide outstanding products and services. Here are some of the awards the team has won.




