Defensible now. Ready for what follows.
CMMC Phase II is suspended, but Phase I self-assessments and DFARS 252.204-7012 remain. PolicyCortex validates your live cloud against all 110 NIST SP 800-171 Rev. 2 requirements, closes technical gaps, and produces the evidence behind your SPRS score — while preserving a clean handoff for any future CMMC assessment.

- CAP-01110 requirements baselinedNIST SP 800-171 Rev. 2 — the interim baseline named by DoW.
- CAP-02Drift < 5sContinuous validation, not point-in-time scans.
- CAP-03C3PAO handoff packageSSP · POA&M · OSCAL · auditor ZIP, organized by control objective.
- CAP-04CUI boundary awareScope auto-derived. GovCloud + GCC High native.
- CAP-05Auto-remediationRollback contract on every action. Type-checked.
- CAP-06Cleared founder engagementDoD Secret + DoE Q. Runs the pilot personally.
- 01ConnectAzure Government · AWS GovCloud · GCC High. Discovery in minutes.
- 02BaselineAll 110 controls validated. Findings with AI confidence.
- 03Hand offOSCAL bundle + auditor ZIP your C3PAO can review, select from, and use for eMASS submission.
- DOE National LabActive consultant
- MITRECybersecurity engineering
- USAAFinancial-grade ops
- FrontierProduction cloud architecture
Founder runs every engagement personally. 4 U.S. patent applications filed.
Did the Department of War cancel CMMC?
No. On July 13, 2026, the Department suspended the Phase II transition and pending and future implementation milestones while a reform task force conducts a 60-day review. All Phase I self-assessment requirements remain in place.
What remains enforceable during the pause?
The Department says NIST SP 800-171 Rev. 2 will be enforced through self-assessments and selected government-led assessments. DFARS 252.204-7012 safeguarding obligations also remain contractually binding.
L2 vs L3 — which do we need?
Most contractors need L2 (handles CUI). L3 is required for organizations supporting high-priority programs. PolicyCortex covers both with the same engine.
What does the $15K pilot include?
Full CMMC L2 baseline, automated gap closure, SSP, POA&M, C3PAO-ready evidence bundle (OSCAL + ZIP), CUI boundary analysis, 30-day platform access, final readiness review with the founder. Flat fee — no overages.
Does PolicyCortex submit to CMMC eMASS?
No. Your C3PAO controls the official assessment package and eMASS submission. PolicyCortex prepares the control-mapped evidence, remediation history, SSP, POA&M, OSCAL bundle, and audit ZIP so the assessor can review, select, and submit with less manual cleanup.
Can we use a different C3PAO?
Yes. PolicyCortex output is C3PAO-agnostic — the OSCAL package and audit ZIP work with any C3PAO. We don't lock you to an assessor.
What about CMMC 2.0 vs 3.0?
Current CMMC final rule (32 CFR Part 170) defines 3 maturity levels. We support L1 (self-attestation), L2 (C3PAO assessment), L3 (DIBCAC assessment). Future revisions tracked automatically.
Know what you can defend. $15K flat.
Connect a cloud account, validate the 110-requirement baseline, close technical gaps, and walk away with the evidence behind your SPRS score. Cleared founder runs the engagement.
