UpCISO Book a call
CMMC Level 1 & Level 2 · Defense Industrial Base

A SPRS score you can defend in the room.

Most contractors posted a self-score years ago and have not revisited it. We reassess against the actual assessment objectives, compute the score exactly as 32 CFR § 170.24 defines it, and produce the SSP and POA&M an assessor will accept.

We get you ready — we do not certify. Ready to self-attest, or ready to hand a third-party assessor something that holds up. For CMMC that assessor is an authorised C3PAO; only they can assess you for certification.

110
Level 2 requirements, assessed to the objective
88
Minimum score for Conditional status
180
Days to close a POA&M before status expires

What makes a score defensible

Four things that most readiness work skips, and an assessor does not.

Assessed at the objective level

§ 170.24(b) decides a requirement on its individual assessment objectives, not on a yes/no at the requirement. One unmet objective makes the requirement NOT MET. We record findings per objective, so the roll-up is the rule, not a judgement call.

Scored from the regulation

42 requirements are worth 5 points, 14 are worth 3, and two — MFA and FIPS-validated encryption — carry partial credit. Those values come from the DoD Assessment Methodology, not from a vendor's interpretation of it.

A POA&M that actually qualifies

Conditional status needs a score of at least 88, nothing over 1 point on the POA&M, and none of six specific requirements left open. A POA&M that breaks any of those is not a plan, it is a rejection waiting to happen.

Evidence in final form

Working papers, drafts and unapproved policies are explicitly unacceptable as evidence. Every requirement carries a reference to where the approved artefact lives in your environment — and a draft is flagged as one.

Start with a coverage map. No charge.

Hand us your existing policy set. We map every section to the requirements it speaks to and tell you what your documentation already covers.

Typical output: “Your documentation addresses 61 of the 110. These 19 are partial — here is the sentence that falls short. These 30 are absent.”

The platform behind it

We built our own rather than reselling a GRC seat, because the scoring had to be exact and the per-client cost had to be near zero. That is why the coverage map above is free.

SPRS scoring engine In development

Score, deductions by requirement, distance to 88, and “fix these five, gain 19 points” ordered by points recoverable per hour of effort.

Objective-level assessment In development

All 110 practices by family, drilled to the NIST SP 800-171A objectives, with per-objective findings, implementation descriptions and evidence references.

SSP generator In development

Built from your implementation descriptions and scope, with a draft-to-approved gate, because drafts are not acceptable evidence.

POA&M manager In development

Generated from NOT MET requirements and validated against § 170.21, with the 180-day closeout clock tracked from your Conditional status date.

Policy coverage mapping In development

Upload an existing policy set; AI maps each section to the requirements it addresses and shows the quoted sentence that justifies the mapping.

Gap-to-product recommendations Planned

Where a gap needs a tool — EDR, MFA, FIPS-validated encryption, logging — we can quote it. We disclose what we earn a margin on and always show alternatives.

Straight answer on status: UpCISO is the platform we are building to deliver this work. It is in active development and the assessments we run today are delivered by us, not by you logging into software. When a module is live, this page will say so.

Two destinations. We prepare you for either.

Self-assessment and affirmation

You assess against all 110, post the score to SPRS and sign the annual affirmation. This is the path almost everyone is on today, and it is a legal obligation right now — not something waiting on the reform.

A third-party assessment

When your contract calls for certification, an external assessor examines you — for CMMC, an authorised C3PAO. We make sure what they find matches what you told us: the scope, the evidence and the SSP all line up before anyone external opens them.

Where CMMC actually stands right now

The Phase 2 transition was suspended on 13 July 2026, and a class deviation on 3 September made that binding. A lot of firms stopped work. That was a mistake.

The reform changes who checks your work. It does not change the obligation. Firms that downed tools in July will restart from zero; the ones that kept going will affirm on time.

Talk to someone who has read the regulation

Bring your contract clauses, your current SPRS score if you have one, and whatever documentation exists. A first call is scoping, not a pitch.