- What they do
- Enterprise multi-framework
- Who they help
- Tevora is an enterprise multi-framework based in Irvine, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Framework Information Security & Privacy
CMMC/NIST 800-171
The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense (now styled the Department of War) program that verifies defense contractors protect Federal Contract Information and Controlled Unclassified Information.
The program rule at 32 CFR Part 170 took effect December 16, 2024 and the contracting rule in DFARS (48 CFR) took effect November 10, 2025, starting Phase 1. Level 1 is an annual self-assessment against 15 basic requirements.
Level 2 is the 110 requirements of NIST SP 800-171 Revision 2, verified by self-assessment or by a certified third-party assessment organization (C3PAO) depending on the solicitation. Level 3 adds 24 requirements from NIST SP 800-172 and is assessed by the government's DIBCAC. Level 2 certifications last three years with an annual affirmation by a senior official.
Phase 2, which would have made C3PAO Level 2 certification a condition of award for most applicable contracts from November 10, 2026, was suspended on July 13, 2026 pending a 60-day review by a CMMC Reform Task Force. Phase 1 self-assessment requirements, DFARS 252.204-7012, SPRS score submissions and annual affirmations remain in force.
In writing, a contractor needs a System Security Plan describing how each 800-171 requirement is met, policies and procedures for the 14 control families, a plan of action and milestones for gaps, incident response procedures, and records supporting the affirmation.
Who has to comply
Defense contractors and subcontractors that process, store or transmit Federal Contract Information (Level 1) or Controlled Unclassified Information (Levels 2 and 3) under contracts containing DFARS 252.204-7021. The required level is set in each solicitation and flows down the supply chain.
What the assessor asks to see
System Security Plan with boundary and data flows; CUI inventory and data classification; policies and procedures for each NIST 800-171 family; SPRS score and prior self-assessment; access control, MFA and account management records; configuration baselines; audit log samples; vulnerability scans and patching records; incident response plan and records; awareness training completion; POA&M; external service provider and cloud FedRAMP evidence; the senior official affirmation.
Where the requirement sits: 800-171 3.2.1-3.2.3 awareness and training; 3.12.4 SSP; 800-171A assessment objectives '[a] ... is defined'; 3.3 audit and accountability, 3.14 system monitoring are technical
Levels
Level 1 (FCI): 15 requirements from FAR 52.204-21, annual self-assessment. Level 2 (CUI): 110 requirements from NIST SP 800-171 Rev 2, self-assessment or C3PAO certification as specified in the solicitation, valid three years. Level 3 (highest-risk CUI): Level 2 certification plus 24 NIST SP 800-172 requirements assessed by DIBCAC.
Phase-in and the 2026 suspension
Phase 1 began November 10, 2025 (self-assessments). Phase 2 was scheduled for November 10, 2026 and would have expanded C3PAO Level 2 certification as a condition of award; Phases 3 and 4 were scheduled a year apart after that. On July 13, 2026 the Department suspended Phase 2 and later phases pending a 60-day CMMC Reform Task Force review reporting around mid-September 2026.
Contracting officers were told to remove Phase 2 and 3 requirements from existing agreements by modification. Verify the outcome of the review before planning around a date.
What AllyMatter does here
The policy, procedure and training-record layer of CMMC Level 2 / NIST 800-171. Policies alone score nothing at assessment.
AllyMatter publishes this site.
Assessors
Who assesses CMMC/NIST 800-171
Level 1 and Level 2 (self): the organization's own assessment with senior official affirmation. Level 2 (certification): a C3PAO authorized by the Cyber AB, using certified CMMC assessors. Level 3: the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).
Accredited by The Cyber AB (Cybersecurity Maturity Model Certification Accreditation Body), under contract with the Department, authorizes C3PAOs and accredits assessors; DCMA DIBCAC assesses the C3PAOs themselves.
Public register of assessors: https://cyberab.org/Catalog
No firm has claimed a CMMC/NIST 800-171 assessor listing yet. Claim yours →
Consultants
Who helps with CMMC/NIST 800-171
A large ecosystem: Registered Provider Organizations (RPOs) listed on the Cyber AB Marketplace, managed service providers offering enclave solutions, and GRC platforms. They write SSPs and policies, run gap assessments and mock assessments, and manage remediation. Engagements typically run six to eighteen months before a C3PAO assessment.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
Software
Tools for CMMC/NIST 800-171
Tools that name this framework in their own material.
Related reading
- CMMC final rule: key takeaways for defense contractorsLaw firm read of the acquisition rule that puts the CMMC clause in contracts, including affirmations and flow-down to subcontractors.Arnold & Porter
- Defense contractors face a new reality: the final 48 CFR rule brings CMMC into federal acquisitionSets out the phase-in, what a self-assessment versus a C3PAO assessment involves, and the SPRS score a contract now requires.BDO
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for CMMC/NIST 800-171
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Run the Policy Side of CMMC/NIST 800-171 in AllyMatter
Approve the policies CMMC/NIST 800-171 asks for, keep every version, and record a named acknowledgment from each person who has to read them.