The Cybersecurity Maturity Model Certification (CMMC) is a Department of War informational security compliance requirement mandated under 32 CFR Part 170 and enforced through FAR 52.204-21 and DFARS 252.204-7012.
Compliance is mandatory for ALL prime contractors and subcontractors who handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI).
FCI is a broad category covering generic data provided by or generated for the government under a contract to develop or deliver a product or service.
Everyday examples of FCI include contract performance emails, delivery schedules, and project statements of work.
CUI is government-created or owned information that requires specialized safeguarding or dissemination controls consistent with federal laws. While CUI is not officially classified as Secret or Top Secret, it remains restricted from public view due to its sensitivity.
Common examples of CUI include technical blueprints, military hardware design schematics, and proprietary research funded by the government.
As of November 10, 2025, Phase I self-assessments became mandatory for ALL federal prime and subcontractors who handle FCI and CUI. On July 13, 2026, Phase II third-party validation is currently suspended pending a comprehensive 60-day federal review however, Phase 1 self assessments are still mandatory.
Phase 1: The Self-Assessment Milestone
Phase 1 officially kicked off on November 10, 2025. It transitions cybersecurity from a background task into a strict condition for winning new government contracts.
Phase 2: The Third-Party Validation Milestone
Phase 2 enforcement was originally scheduled to begin on November 10, 2026, but has been temporarily paused by federal government.
In response to the increasing and multifaceted cyberthreats, the U.S. government established the CMMC framework to safeguard critical Controlled Unclassified Information (CUI) and Federal Contract Information (FCI).
If your company works on DoD or NASA contracts you are required to be at least CMMC Level 1. If you work DHS contracts there are similar requirements that we can help you meet.
If your company has a contract that contains Controlled Unclassified Information (CUI) or if your company has IT systems that process or transfer CUI you are required to be CMMC Level 2 compliant.
If your company processes classified information you are required to work with the DoD to receive CMMC level 3 certification.
The cost of Lava Valley Solutions services varies depending on the specific needs of each client. We offer flexible pricing plans that are tailored to the unique requirements of your business.
We are able to provide all CMMC Level 1 and Level 2 assessment services at the best value you will find! We encourage you to shop around for the best quote and we are confident that you will find we provide the best value.
Contact us today to learn more about our pricing and to receive a customized quote.
Copyright © 2026 Lava Valley Solutions - All Rights Reserved.
We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.