Introduction
In March I published an overview of CMMC written from the outside. I had spent twelve years in government, close to accreditation and control implementation but never inside this particular machine, and I had just started as Director of Technology at Rise8. The post ended on a comfortable line about how the framework becomes legible once you stop treating it as fog.
Five months later, on 25 August 2026, CISEVE issued Rise8 a Final CMMC Level 2 certificate. All 110 NIST SP 800-171 controls, all 320 assessment objectives, no open items. It runs to 24 August 2029.

What the work actually was
CMMC is not one system going through an RMF ATO. It is a system of systems, and the size of ours was a decision, not an inheritance. Rise8 had been self-assessing and carrying a score, and that self-assessment was in good shape. What changed the shape of the work was a call made shortly before we committed to a third-party assessment: bring a subset of our development, and therefore our development environment, inside the assessment boundary. That is more scope than most companies take on. It was the right call for the work we do, and it meant a great deal of change on roughly six months of runway.
The rest is the difference between the two exercises. A C3PAO is not a stricter grade on your self-assessment, it is a different question. It wants the implementation written down in the requirement's own terms, the artifact that proves each objective, and the person who runs the system able to walk an assessor through it live. Producing that for an expanded boundary, on that timeline, is most of what the year was.
The number that matters is not 110 controls. It is the coordination cost behind each one. A control almost never resolves into a switch somebody flips. You pull the thread on a single requirement, discover the practice it describes is spread across dozens of tools and touches teams who have never heard of NIST SP 800-171, and now you are booking time with people whose quarter is already full, agreeing what the requirement means in our context, changing the thing, and then producing evidence that it stayed changed. One requirement can be a week of other people's calendars. That is the part nobody budgets for, and it is the reason my only real advice is to start much earlier than you think you need to.
We were doing it while standing up an entire technology department and hiring into it, and while the platform and tooling changes the boundary decision implied worked their way through every team. Months of work, compressed, with everyone's day job still running underneath it.
The certificate records our assessment period as 10 to 24 August. The part that will stay with everyone who lived it was the four days in the middle of that window, most of them full ones, walking control by control with the assessors and demonstrating that each requirement is not merely written down but actually operating. You do not get to gesture at a policy. Someone opens the system, in front of you, and the evidence either holds or it does not. It is a grinding way to spend a week and it is the most honest read of your own program you will ever get.
Every one of the 110 controls and all 320 objectives came back Met, with no POA&M items, which is why the certificate reads Final rather than Conditional.
The Cyber AB publishes the ecosystem numbers at a monthly town hall, and the August 2026 session put Certificates of CMMC Status at 2,105 Final and 66 Conditional, with 159 Level 2 assessments in progress. Rise8 is one of the 2,105, against a defense industrial base the Department sizes in the tens of thousands of companies that will need Level 2.
The people who earned it
Certificates carry one company name. This one has about thirty people behind it, from several departments, most of whom had no reason to care about NIST SP 800-171 until we asked them to.
Ryan Ruddock, Chase Cast, Lakshmi Sadasiv, Kyle Dozier and Wayland Pearce carried the technical weight of it for months. Lloyd Evans, Kenny Slater and Jamie Kayes covered the ground that sits outside engineering entirely, and Kenny went and earned his CMMC CCP certification while he was helping us. Samuel McQueen and Justin Joseph gave time they did not owe us. One of our infrastructure platform teams answered questions about their own work on no notice, and Eric Whitman and Andrew McFarland picked up their end of it without being asked twice.
I led this effort as Director of Technology, which mostly meant deciding what we would evidence, in what order, and whose week that was going to cost. I also wrote the System Security Plan, ran the evidence collection, and kept the assessor package together across every team feeding it, which is less a boast than an explanation of why I have opinions about documentation further down. And I am the affirming official, so the attestation behind our score has my name on it. That last part is worth understanding before you take on a program like this: somebody signs, and the signature is not ceremonial. The part I did not have to manufacture was willingness. What made the difference was not any individual's depth; it was that a lot of people reporting to different leaders, on different schedules, with different priorities, pulled in the same direction for months and did not drop it when it got tedious. Assessors test whether the people who run a system can describe it without a script. Ours could, across every team we pulled in, and that is a large part of why the evidence held. Getting to lead a group like that is the good fortune in this story.
Bryon Kroger pushed the team on something that changed how we made calls all year: the difference between managing risk and avoiding it. Avoidance is seductive because it looks like rigor. It is also unachievable, because there is always someone with a phone who can photograph a screen, and the controls that would stop that person stop everyone else first. Lock the machines down hard enough and you have not removed the risk, you have relocated it into whatever unmanaged tool people start using to get their jobs done. We made a number of decisions differently because of that framing, and every one of them held up under assessment.
The rest of the company earned this too, largely by putting up with us. Security work of this kind is subtractive before it is anything else. We changed how people sign in, what they can install, where files are allowed to live, and which tools they had been using happily right up until the week we asked them to stop. That is not the trade my department likes to make. Our instinct is to hand somebody a better version of what they had, and for stretches of this year we were doing the opposite, taking away a convenience and asking for patience while the replacement caught up.
People gave us that patience, and then they went further and volunteered. Nobody was obliged to sit through a walkthrough of a control family that had nothing to do with their day, and plenty of them did it anyway. Several of the answers that held up under assessment came from people with no stake in the outcome beyond wanting it to go well for everybody else. You cannot put that in a project plan. It is the honest reason this took months instead of years, and it is most of why I like working here.
Congratulations to all of you. This is your certificate.
The assessor and the advisors
Our C3PAO was CISEVE, with Michael Dempsey as the authorized certifying official and Stuart Foster as lead assessor. An assessment is an adversarial exercise by design, and it can still be a professional one. Ours was. They gave us no answers, and I would not have wanted any. What they gave us was a fair, unambiguous read: by the end of the week it was clear where we were strong and clear where we have room to improve, which is the entire product you are buying.
Two lines from the week stayed with me. The first came after we walked through one of the tools we built to handle CUI markings:
That's really good, by the way. What I've seen from these assessments is often not as thorough as what you have there.
Stuart Foster, CISEVE
And the second came at the close of the week:
Not every company is this easy to work with and we could visibly see all the work that went into this behind the scenes.
Stuart Foster, CISEVE
The compliment I am proudest of landed on our system environment description, because we earned it by cutting rather than adding:
That was a great environment description and the most succinct one I've ever seen.
Michael Dempsey, CISEVE
Our advisory support came from Biorn Group Cyber, where Khanh Tran, Jeff Morrow and Brandon Mercer spent months on our scoping calls, our boundary arguments and our documentation. They kept us from several expensive detours and told us plainly when we were wrong.
Overall the level of detail with which you describe the implementation of the controls as well as the way you specifically reference evidence and artifacts is exemplary here.
Jeff Morrow, Biorn Group Cyber
I recommend both firms without reservation. Both are ethical and mission focused, which sounds like a throwaway line until you understand the incentives in this market, and I will come back to that below.
What months of this taught us
The certificate is the result. The lessons are the part we get to keep, and most of them are about how we write rather than what we implemented.
Write it for us, not for the assessor. Our internal review record read like it had been produced for an audience of one, on one week of the year. The content was largely right and the point of view was wrong, because the document that survives is the one our own engineers use.
Assess for effectiveness rather than existence. Our method largely asked whether a control is operating. The requirement asks whether it is effective. Those are different questions, and the second one is harder and more useful.
Say less. We spent months making our documentation more complete, and completeness past the objective turns out to be a liability. Explaining why we have a control is not the same as describing how we implemented it, and every extra paragraph is another thing that has to be true. The test I use now is whether a new senior engineer can read a section and understand how we actually implemented the requirement. If a sentence does not serve that, it goes.
Make it defensible per control: who reviewed it, what they found, the determination, and the artifact that proves it, filed where next year's version can find it.
Why we finished after the suspension
On 13 July, a month before our assessment, the Department of War suspended the CMMC Phase II requirement for third-party certification as a condition of award, along with the other pending implementation milestones. Phase II had been set to take effect on 10 November 2026. The Department stood up a CMMC Reform Task Force and a 60-day review, and the request for information closed on 14 August, which was the last day we were sitting in front of our assessors.
I was not surprised, and the arithmetic is the reason. The August 2026 town hall counted 113 authorized or accredited C3PAOs, with 564 still sitting in the applicant queue. Those 113 firms are the only route to a certificate for a base sized in the tens of thousands. At 2,105 certificates after several years of trying, and 159 assessments in flight, there was no version of November 2026 where the rest of that base got through the door. The bottleneck is not enthusiasm. It is throughput. Suspending the certification gate leaves the underlying obligation exactly where it was, and the distinction is worth laying out:
| Still binding | Suspended |
|---|---|
| DFARS 252.204-7012, including 72-hour incident reporting | The Phase II requirement for a C3PAO certificate as a condition of award |
| FAR 52.204-21 basic safeguarding | The pending Phase II and later implementation milestones in current contracts |
| Implementing the 110 NIST SP 800-171 requirements | |
| SPRS score submission and annual affirmation | |
| Phase I self-assessments, and C3PAO assessments where the government asks for one |
C3PAOs can still certify. The self-assessment and the attestation behind your SPRS score were never paused. And here is the part that made continuing an easy call for me: a defensible self-assessment needs the same things a C3PAO assessment needs, which is an SSP with implementation statements, policies and procedures that support those statements, and artifacts demonstrating that each control is operating. The reason CMMC exists at all is that self-reported SPRS scores did not match reality. If your score is not defensible, you are exposed to loss of contract and to the False Claims Act, and no suspension changes that.
The volume of the response settles the question of whether this is going away. By the August town hall the task force had taken in nearly 1,100 responses to its request for information, put more than 1,300 people through listening sessions, and collected over 10,500 pages of submitted data. The Department's CIO office described the result as "locked and loaded" and said the defense industrial base "brought the fire to target CMMC complexity," with final recommendations headed to the CIO. Ten thousand pages of comment is not what indifference looks like. It is what a base that has already spent real money on this looks like when it is asked whether the next version could be made workable. The requirement is being reshaped, not repealed, and a company that stopped in July would be starting over against whatever comes out the other side.
We were four months into the readiness push with the evidence built and the assessors booked. Stopping would have saved us a week and cost us the only independent read we were ever going to get.
What I would tell the reform task force
The government asked for feedback, so here is mine, and it lines up with what I heard from people who have run this at scale. I was at Prodacity in Nashville the week after our assessment closed, and several sessions there said the thing better than I can.
Start with why any of this exists. CMMC was created because self-attestation did not work. Companies scored themselves in SPRS, the scores went into the system, and the scores did not match what was actually running. Some of that was optimism and some of it was not, and the government had no way to tell the difference. That is the problem an independent assessment solves, and it is the reason I would keep it even after living through one.
Suzette Kent, the fourth federal CIO of the United States, put the failure mode in one sentence: "Compliance as a checklist is not generally helpful to the mission." Chris Hughes made the mechanical version of the same argument. We run snapshot-in-time assessments on multi-year cycles against systems that change by the hour. His analogy was checking one of his kids' rooms and then treating that snapshot as the state of the room ninety days later. Containers live for a minute, agents spin up and disappear, and he compared our assessment rhythm to a rotary telephone. If code deploys in seconds, the authorization has to be validated in seconds, which means machine-readable evidence and APIs rather than assessors collecting screenshots into a spreadsheet.
Lloyd Evans and his panel made the version of this I keep thinking about: architect the system so that being compliant is a byproduct of how you already work, and let the assessment come out of the pipeline instead of a document review. Then ask honestly whether you can fix findings at the rate a machine can now find them.
I have now lived the screenshot version. Our assessment package was 1,590 files across 320 objective folders. It is honest work and it is defensible, and nearly every file in it is a photograph of a control operating, taken once, by hand.
So: keep the independent assessment, and fix the cadence and the medium. Let an organization stream control state instead of assembling a package. Let evidence be generated by the system that implements the control, instead of by a person capturing a console. Compress the requirement set the way FedRAMP 20X is trying to, and score whether a control works, which is the harder question and the one the requirement already asks.
Then fix the cost, because it is the part that decides who gets to play. The assessment fee is the small line. The large one is months of a company working backwards to compliant while it keeps delivering, plus tooling, plus advisors, plus the staff you have to hire to carry it. A company our size can absorb that. A ten-person shop with one genuinely useful product cannot, and every one of them we price out is capability the Department does not get. The answer is not to lower the bar, because if you want to hold the government's data you need to secure the government's data. The answer is to make the evidence cheap to produce, which is the same automation argument as above, arriving from the direction of the budget instead of the architecture. If the control state streams out of the platform, the marginal cost of being assessable approaches the cost of running the platform, and it stops mattering whether you can afford a four-month readiness program. Fund reference implementations and let small companies inherit them. Recognize the same evidence across FedRAMP, CMMC and the rest instead of making each program a fresh photograph of the same control. The goal is not a cheaper audit. It is a world where the small company with the genuinely useful product is assessable by Tuesday because the platform it already builds on emits the proof.
One more, and it is the uncomfortable one. Think carefully about how C3PAOs get paid. A firm that assesses you has a commercial interest in you needing another assessment, and nothing in the current structure removes that tension. I want to be precise here, because it did not happen to us: both firms we worked with were straight with us, and I would put either in front of anyone. That is the point. We should not be relying on individual integrity to cancel out a structural incentive. Publish outcome statistics by assessment body so the market can see who fails everyone, and decouple the fee from the number of visits. There is already an appeals route that does not run through the firm that made the call, and almost nobody uses it, which tells you either that it is not visible enough or that companies believe an appeal costs them more than the second assessment does. Both are fixable, and neither gets fixed by not talking about it. The current answer is to find an ethical assessor, and we did, twice. That is a hope rather than a design.
What happens now
Our certificate runs to 24 August 2029, and the annual self-assessment comes around in August 2027. This time we are writing it for us, in the requirement's own vocabulary, with a determination and an artifact per control, filed where the following year's version can find it. CMMC is not a thing you pass. It is a thing you keep operating, and the self-assessment is where that either stays true or quietly stops being true.
What the certificate actually says to a program office is narrow and worth stating plainly. An accredited third party examined how Rise8 handles controlled unclassified information, tested all 110 requirements and all 320 objectives, and found every one of them met with nothing left open. Our claims about how we protect that data are not our claims any more. Somebody independent checked. For a partner deciding whether to trust us with their data, that is a materially different conversation than a self-reported score, and it is the conversation we can now have on day one instead of month six.
In March I wrote that CMMC becomes legible once you stop treating it as fog, and it does. What I understand now is that the legibility decays the moment you stop maintaining it, which makes the certificate the beginning of the maintenance rather than the end of the project.
Congratulations again to everyone above.
See the associated LinkedIn post.

Comments
To leave feedback or questions, simply login using your preferred social network. I will read and answer your comments promptly, but please keep in mind that they will be public.