02Discipline
Cybersecurity Assessments & Compliance
CUI protection, NIST SP 800-171, and CMMC readiness — assessed honestly, documented properly, and grounded in the facility the data actually lives in.
What We Do
Assessment first, artifacts second, theater never
Most compliance work fails in one of two ways: a binder that describes an environment nobody runs, or a score that cannot survive its own evidence. We work backward from what an assessor will ask to see.
- Scoping — where CUI actually lives, moves, and is processed; enclave versus enterprise; and the boundary decision that drives every dollar that follows
- NIST SP 800-171 gap assessment — control-by-control, against the current revision, with evidence noted rather than asserted
- SPRS score development — a defensible score with the arithmetic shown, and remediation sequenced by point value and effort
- System Security Plan — an SSP that describes the environment you operate, written so a stranger can verify it
- POA&M — real milestones, real owners, real dates, sized against your actual capacity
- CMMC readiness & mock assessment — Level 1 self-assessment support, Level 2 preparation, and a dry run against the assessment guide before anyone external arrives
- CUI program — marking, handling, media and destruction, incident reporting paths, subcontractor flow-downs, and the training that makes it stick
- Annual affirmation support — because the affirmation is a personal accountability instrument, not a checkbox
Current State
Where CMMC actually stands, today
Phase 1 of the CMMC acquisition rule has been in effect since 10 November 2025. On 13 July 2026 the Department suspended Phase 2 — the phase that would have made third-party C3PAO certification a condition of award — along with Phases 3 and 4, and stood up a reform task force to review the program.
What did not change is the obligation. DFARS 252.204-7012 still applies. NIST SP 800-171 implementation still applies. SPRS score posting and annual affirmations still apply. Government-led assessments still happen.
The companies now exposed are the ones that treated a phase date as the deadline instead of treating the requirement as the requirement. If your score is stale, your SSP describes a network you no longer run, or your POA&M has no dates, the suspension bought you time — not absolution.
We track this file continuously and will tell you what applies to your contracts as they read today.
Status · as of August 2026
- Phase 1
- In effect since 10 Nov 2025 — self-assessment levels designated in solicitations
- Phase 2–4
- Suspended 13 Jul 2026, pending program review
- Still binding
- DFARS 252.204-7012 · -7019 · -7020
- Still binding
- NIST SP 800-171 implementation
- Still binding
- SPRS posting & annual affirmation
- Program rule
- 32 CFR Part 170
Read: what the Phase 2 suspension actually means →
Regulatory status changes. We confirm current applicability against your specific contracts at engagement — this page is a summary, not advice on your obligations.
The Convergence
A third of the cyber standard is a building problem
NIST SP 800-171 and 800-53 both carry physical protection requirements, and CUI protection depends on facility controls: who gets into the room, how media is handled and destroyed, how visitors and maintenance are escorted, what happens to a drive when it leaves.
Most cyber consultancies write those controls from a template and never walk the building. Most physical security firms never read the control catalog. The seam between them is where findings live — an unlocked media closet, a shared badge, a contractor with unescorted access to a room full of engineering drawings, a building management system on the same flat network as everything else.
We assess both, against one threat picture, and write the physical controls from what the facility actually is.
Who This Serves
Typical starting points
01
First DoD contract
A commercial company — often in aerospace, autonomy, or advanced manufacturing — that just won or is bidding work with security clauses attached, and needs to know what it actually signed up for.
02
Stale score, real risk
An SPRS score posted years ago, an SSP that no longer matches the environment, and an affirmation coming due. Personal accountability makes this urgent even without a phase deadline.
03
Prime pressure
A prime or program office asked for evidence, not assertions — and the flow-downs you passed to your own subcontractors need to hold up too.
04
Data center serving federal tenants
Operators courting federal, defense, or IC-adjacent tenants whose requirements arrive with control families and ICD numbers attached, and whose diligence covers the physical layer too.
Questions
On CMMC and cyber compliance
Where does CMMC actually stand right now?
Are you a C3PAO? Can you certify us?
What is a realistic SPRS score problem?
Why would a physical security firm do cyber compliance?
Next Step
Know what you owe — and prove you meet it.
Start with a scoped gap assessment. It is the fastest way to find out whether your score, your SSP, and your reality agree with each other.
Prefer to talk? 866.960.7475 · info@orbitalfederal.com