Cybersecurity Maturity Model Certification (CMMC)

We’ll help you be ready for CMMC with time to spare.
SecurityMetrics spent a great deal of time with me so that I felt confident and comfortable. I feel they went above and beyond. THANK YOU SECURITYMETRICS!
Billye Jo Ritchey
Effingham Surgical Associates
The law can be overwhelming but my support advisor did a great job of taking me through things step by step.
Matthew Sudweeks
Doctor of Physical Therapy (DPT)
Beyond Limits Physical Therapy

We Make CMMC Simple

With 25 years of experience helping businesses of all sizes meet compliance standards, our experts will guide you through each step so you can secure your DoD contracts, regardless of your CMMC level.

Features

Level 1

Level 1 contractors perform a Self-Assessment that requires you to annually attest to your CMMC compliance. 
  • Get guided support from CMMC trained advisors to make sure you fulfill the requirements of the self-assessment and attest through the SPRS system confidently

Level 2

Level 2 contractors must complete an audit of 110 different CMMC controls. 
  • Get a CMMC Readiness Assessment from SecurityMetrics that will prepare you to confidently pass the 110 controls of your Level 2 audit.

Prime Contractors 

A prime contractor must be able to verify that all of their sub-contractors are also CMMC compliant. 
  • SecurityMetrics offers a compliance management portal that makes it easy to track and verify the CMMC status of all sub-contractors that are part of your flowdown.
PCI program solutions for acquirers and ISOs

SecurityMetrics PCI programs are merchant-friendly, keeping them and you happy.

Feature
Basic
Plus
Pro
Advisor
Online Portal
checkcheckcheckcheck
Merchant PCI SAQ
checkcheckcheckcheck
SAQ Pre-Population
checkcheckcheckcheck
ASV scans (1/merch)
checkcheckcheckcheck
PCI Policy Template
checkcheckcheckcheck
24/7 Help Desk
checkcheckcheckcheck
24/7 Scan & SAQ Support
checkcheckcheckcheck
Partner+ Portal
checkcheckcheckcheck
Custom Email Campaigns
checkcheckcheckcheck
Assigned CSM
checkcheckcheckcheck
ASV scans (5/merch)
checkcheck
$100,000 Merchant Premium Service Warranty
checkcheck
Card Data Discovery
checkcheck
Mobile Device Scan
checkcheck
AI-Powered PCI Compliance (Spectre AI)
checkcheck
Anti-Malware Software
check
Get started on your PCI program, request a quote now.
Request a Quote
PANscan
Lite
PANscan
Basic
PANscan
Advanced
Total number of card data found
checkcheckcheck
Files containing card data
checkcheckcheck
Light on system resources
checkcheckcheck
Immediate summary results
checkcheckcheck
Fast Scans (1-3 GB/min)
checkcheckcheck
Tuned to reduce false positives
checkcheckcheck
Unlimited scanning (per machine)
checkcheckcheck
Technical support
checkcheckcheck
View card type
checkcheck
View track data
checkcheck
View file path to payment card data
checkcheck
Navigation to cardholder data
checkcheck
Mark files as false positives
checkcheck
Specify which drives to scan
checkcheck
Save current results
checkcheck
Clear current results
checkcheck
Exclude image files
checkcheck
Exclude executable files
checkcheck
Online scanning
checkcheck
Offline scanning (optional)
check
Exclude specific file types
check
Exclude specific file directories
check
Scan for specific file types
check
Scan specific directories
check
Preserve last access dates
check
Export text report
check
Check for spaces/dashes in card numbers
check
Linux support
check
Mac support
check

PCI for small businesses starting at

$399/year*

Price discounts available depending on merchant processor

  • External Vulnerability Scan (1 IP)
  • Online PCI Self Assessment Questionnaire (SAQ)
  • Online compliance reporting portal
  • Non-compliance notification
  • Compliance reporting to merchant processor
  • Compliance certificate
  • PANscan® (Card discovery software for 1 machine)
  • Service warranty (Up to $100,000 reimbursement in case of a breach)
  • Security Awareness Training (1 seat)
Get Started

*We discount our services for most merchants because of our relationship with their merchant processor.
Looking for Acquirer or PCI program pricing? Click here.

Basic

Starting at
$1,499
USD/year
The Basics
For small practices
Request Quote
Compliance Management
  • Online Portal Access (Software to help you work towards HIPAA compliance)
Services
  • Security Fundamentals Checklist
  • $100,000 Service Guarantee
  • Monthly Perimeter Scans: 1 IPs
  • Risk Analysis
  • Risk Management Plan
  • Monthly HIPAA Newsletter
Compliance Management
  • HIPAA Policies & Procedures (including Breach Notification Policy and Business Associate Agreement Template
  • HIPAA Training: 3 seats
  • 5 Hour Technical Support (inbound tech support only)

Pro

Starting at
$4,999
USD/year
Tools, Training & Unlimited Support
For medium-sized practices
Request Quote
Compliance Management
  • Online Portal Access (Software to help you work towards HIPAA compliance)
Services
  • Security Fundamentals Checklist
  • $100,000 Service Guarantee
  • Monthly Perimeter Scans: 5 IPs
  • Risk Analysis
  • Risk Management Plan
  • Monthly HIPAA Newsletter
Compliance Management
  • HIPAA Policies & Procedures (including Breach Notification Policy and Business Associate Agreement Template
  • HIPAA Training: 25 seats
  • Unlimited Support (specialized HIPAA support agents available for guidance on all HIPAA tools)

Frequently Asked Questions

What exactly is CMMC and why is the DoD requiring it?

The Cybersecurity Maturity Model Certification (CMMC) is a Department of Defense program designed to validate that private companies working with the military have strong cybersecurity. The DoD is moving to a "verify before you trust" model to stop foreign adversaries from stealing intellectual property and national security data from the defense supply chain.

How do I know which CMMC Level applies to my company?

The program works in a tiered system based on the type of data you handle:

  • Level 1 (Introductory): For companies handling Federal Contract Information (FCI). This involves standard practices like passwords and antivirus software.
  • Level 2 (Advanced): For companies handling Controlled Unclassified Information (CUI). This requires strict protocols (NIST standards) and an audit by a CMMC authorized private third party (C3PAO).
  • Level 3 (Expert): For a small subset of companies working on critical programs. This assessment is conducted directly by government officials. (Note: If you’re unclear what level you are, reach out and we can help you figure out your needs.)

Can we just self-certify like we used to in the past?

For most companies, the answer is no. The biggest change under CMMC is the move away from the "honor system" where you could simply sign a paper claiming you followed the rules. While Level 1 still allows for self-assessment, Level 2 and Level 3 now require formal audits by outside assessors to prove compliance.

Is this happening right now, or can I wait to prepare?

You should prepare now. As of late 2025, the phased rollout has begun, and these requirements are already appearing in contracts. CMMC is a "go/no-go" requirement; without the certification in hand, you cannot be awarded the contract. You must determine your level and prepare for assessment to ensure you can win future bids.

Does this requirement apply to my subcontractors?

Yes. If you share Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) with subcontractors to fulfill a contract, they must also achieve the appropriate CMMC level. The program is designed to secure the entire supply chain, meaning you are responsible for ensuring your partners and vendors meet these requirements before sharing data with them.

How often do I need to be re-certified?

It varies by level. Level 1 requires an annual self-assessment and affirmation. Level 2 and Level 3 certifications are generally valid for three years. However, you are still required to submit an "annual affirmation" in the Supplier Performance Risk System (SPRS) to verify that your security remains compliant during the years between your full assessments.

What if I miss a few requirements during my audit? (POA&Ms)

It depends on the severity. For Level 1, you must pass 100% of the requirements immediately; no exceptions are allowed. For Level 2 and 3, if you miss certain non-critical requirements, you may be granted "Conditional" status. This allows you to continue working, but you must create a Plan of Action and Milestones (POA&M) and fix the issues within 180 days. If you do not close out these issues within that timeframe, your conditional certification will expire.

Ready for CMMC Compliance?

Request a Quote

Resources

The following are related resources that we have prepared for you. Find more answers to your questions in our Learning Center.

No items found.

Why choose SecurityMetrics?

More than just checking a box.

We’re not just here to get you CMMC compliant. Figure out how to increase your business’s security for peace of mind.

support_agent
Award-winning support

Get help from a real human who can address your specific needs in real-time.

sync_saved_locally
Tools to simplify compliance

Get the services you need to make compliance less of a chore. Training, policies & procedures, penetration testing, and more.

groups
A partner in compliance

Our goal is to help you not only pass your compliance requirements, but increase your understanding of where you are doing well, and where your security needs to improve.

sell
Straightforward pricing

Your scope is evaluated based on your needs, avoiding unnecessary add-on charges.

Recognition for Outstanding Work

SecurityMetrics has worked hard over the years to provide outstanding products and services. Here are some of the awards the team has won.

The Golden Bridge Award 2020 Gold logo
Global Infosec Award Winner 2024 Logo
Cybersecurity Excellence Award Winner 2023 Logo
We work hard to provide amazing support
Average wait times
Phone
11 sec
Chat
3 sec
Ticket
2.1 hrs

20+ years of experience

QSA | PFI | ASV | P2PE | SSF | SLC | 3DS | QPA | PCIP

PCI Qualified Security Assessor logo
HITRUST Authorized CSF Assessor logo
CISSP logo
HCISPP logo
CISA logo
SecurityMetrics has helped secure 1,000,000+ payment systems

Get PCI DSS Compliant

Get ready for PCI DSS v4.0.1 with the right tools, training, and support.