CMMC LEVEL 1 AND LEVEL 2 COMPLIANCE

Defense Contracts, that include the handling of CUI, Require Cybersecurity Certification.

The best time to start this process was a year ago. The second-best time to start is today.

Pilot Systems guides you from gap analysis to certification-readiness, in a fraction of the time it takes most firms to figure it out on their own.

On July 13th, 2026, the DoW announced a 60-day pause on the requirement of 3rd party assessment to achieve NIST/CMMC Compliance.

Every contract, dealing with CUI, from the DoW, continues to contain DFARS 252.204-7012. Given extensive experience and research conducted by Pilot Systems, there are no changes to DFARS clause 252.204-7012. That clause requires CUI handling companies to implement NIST 800-171 controls, including the related 320 Assessment Objectives. The difference between NIST/CMMC requirements and NIST 800-171 requirements are 14 policies (one for each of the 14 families) and the third-party certification by a C3PAO (a person or company certified by Cyber AB, the exclusive company to manage all certifiers and certifications of NIST/CMMC).

So, what is still required? Implementation of all NIST 800-171 one hundred and ten (110) controls. Also, a self-assessment score in SPRS, which requires a supporting System Security Plan (SSP). With the suspension of requirements for 3rd party assessments, the complete responsibility of self-certification falls solely on the Affirming Official of the company. The DOJ continues to remain vigilant, prosecuting companies for false representation of their cybersecurity readiness under the False Claims Act. Six to seven figure penalties and/or prison time have already been established as a precedent for future cases.

Please remember that POAMs, Plan of Action and Milestones, your plans for how to get a control implemented, do not have any value when conducting (calculating) a self-assessment score.

  • The need for an experienced and qualified NIST/CMMC services provider has been increased with this suspension and the increasing activity of Whistle Blowers.
  • Pilot recommends that self-assessing companies have the 3rd party assessment to mitigate the increased vulnerability of the signer of the company’s attestation. Pilot can provide this assessment.

Historically

Self-assessments, and the provision of SPRS scores, began so that contracting officers could determine which company was further along in achieving cyber security (e.g., NIST/CMMC compliance). Then NIST/CMMC was mandated, and the Phase In process started on 16 December 2024. Prior to the delay, explained above, this mandate was scheduled to be fully in effect by 2028. This mandate required a 3rd party assessment, which gave companies an increased incentive to meet all 110 controls.

With the recent delay in requiring a 3rd party assessment, the self-assessment, including the accuracy of any submissions, is the responsibility of the person who logs in the SPRS score.

Pilot Systems continues to offer support for the engagement of a third-party assessor. We also offer mock assessment if you want a full determination of your status (artifact verification included).

Contact us, at bnarodzonek@pilotsi.com, for more information.


WHY PILOT SYSTEMS?

Forty Years of Regulatory Compliance. NIST/CMMC Is the Newest Discipline.

Pilot Systems has guided automotive OEMs, Tier 1 suppliers, and startups through some of the most demanding Federal Regulatory compliance regimes on earth — EPA emissions certification, CARB approval, NHTSA safety standards, ISO 26262 functional safety, and ISO/SAE 21434 automotive cybersecurity. We have been the regulatory compliance management office for companies that needed to move fast, get it right, and prove it to a federal regulator.

NIST/CMMC is a different set of requirements, but the discipline is the same: interpret a complex government framework, gap-analyze your current state, build the documentation, execute remediation, and conduct a third-party audit with confidence. We have done this for forty years in the automotive sector. Our Director of NIST/CMMC Services, with her 10 years of related experience, now allows Pilot to bring that same approach to the Defense Industrial Base.


OUR PROCESS

Five Steps to NIST/CMMC Certification

Every NIST/CMMC engagement follows the same arc. Pilot performs the first four steps; the final step is, by federal mandate, an independent third-party audit. We prepare you so thoroughly that the C3PAO assessment is a confirmation, not a discovery.

1  Scope AssessmentPILOT Responsible,

We identify every system, process, asset and person handling Controlled Unclassified Information. The planned scope determines everything that follows. Get this wrong and you either over-certify (expensive) or under-certify (audit failure).

2  Gap AnalysisPILOT Responsible,

We evaluate your current state against all 110 NIST SP 800-171 practices across 14 security domains. You receive a detailed report showing which practices are currently met, which are partial, and which require remediation — Pilot defines the specific evidence needed for each NIST/CMMC requirement.

3  Remediation PlanPILOT Responsible,

We build a Plan of Action & Milestones (POA&M) that turns every gap into a specific task with an owner, a deadline, and a priority. Pilot can execute the remediation directly, work alongside your IT team, or hand off the plan for in-house execution — whichever fits your structure.

4  DocumentationPILOT Responsible,

We produce the System Security Plan, evidence package, and supporting artifacts a C3PAO will demand on audit day. This is the deliverable that determines whether you pass or fail. This is also the archived set of documents that your firm will use if you have an issue in the future or if you are audited. Our automotive regulatory discipline shows here.

5  C3PAO Assessment (WHEN NEEDED)C3PAO Responsible

An independent Certified Third-Party Assessment Organization conducts the formal certification audit. By federal mandate, this step cannot be performed by your preparation team. Pilot stays engaged through the assessment to support evidence requests and respond to assessor questions. Pilot is available to facilitate the engagement of a C3PAO


WITH WHOM DO WE WORK?

If You Bid on and conduct DoW Contracts, This Applies to You.

NIST/CMMC affects approximately 80,000 companies in the Defense Industrial Base. Pilot's NIST/CMMC service is built for three audiences in particular:

Tier 1 and Tier 2 DoW Suppliers
If you handle CUI as part of a prime contractor relationship, your prime is already asking when you will be certified. We have decades of experience working alongside Tier 1 and Tier 2 organizations and understand how compliance work fits into a busy supplier operation.

Automotive Suppliers Pivoting Into Defense
Many of our long-standing automotive clients are exploring or actively bidding on DoW contracts as defense electrification, ground vehicle modernization, and autonomous systems programs expand. We can guide the same companies we have known for years through this new regulatory regime.

Mid-Sized Engineering and Manufacturing Firms
Companies with 50 to 500 employees often have the technical capability to comply but lack the dedicated compliance staff to execute. We provide that staff for the duration of your NIST/CMMC project — and only for the duration of your NIST/CMMC project.


FREQUENTLY ASKED

Common Questions

How long does a typical NIST/CMMC engagement take?
Six to nine months from kickoff to a passed self or C3PAO assessment, depending on your starting security posture and your availability to support the NIST/CMMC L2 process. Companies with mature IT security programs, available internal staff (e.g., IT personnel) and existing NIST 800-171 alignment can move faster. Companies starting from scratch should plan on the full nine months.

What does it cost?
NIST/CMMC engagements vary based on company size, system complexity, and remediation scope. The cost is affected by current readiness, your availability to support the processes, the boundary conditions of Cyber Security effected areas, and post assessment (carry on) services. We provide a fixed-fee scope after the initial scoping conversation, so you know what you are committing to before signing anything.

Can Pilot perform the 3rd party certification audit?
No — by federal mandate, 3rd party certification audits must be performed by an independent Certified Third-Party Assessment Organization (C3PAO). We prepare you for self-assessment or that audit. We can recommend C3PAOs we have worked with successfully; Pilot will stay engaged through the audit itself to support evidence requests.

What happens if we fail the 3rd party assessment?
We work to ensure that does not happen. Our process is built around preparing you so thoroughly that the C3PAO audit is confirmation, not discovery. If a finding does emerge during assessment, we help you build a corrective action plan and reset. With proper (e.g., Pilot led and provided) preparation, this is rare. In our team’s 10-year history, every assessment has been successful.

We are not currently bidding on DoW contracts. Should we still pursue NIST/CMMC?
If there is a reasonable possibility your business will bid on CUI related DoW contracts, in the next three years, directly or as a subcontractor to a prime, the answer is yes. NIST/CMMC certification takes months, not weeks, and most companies discover the certification requirement too late to act on it before a specific bid window. This can lead to a delay in the receiving of DoW related contracts.


LET'S TALK

The Sooner We Start, the Sooner You Can Qualify to Receive a DoW CUI Contract.

A 30-minute scoping call is the fastest way to understand where your organization stands against NIST/CMMC and what the path to certification looks like. There is no charge for the scoping conversation, and no commitment beyond the call itself.