Book your playbook briefing
UPDATE — JULY 13, 2026: DoW suspended the CMMC Phase 2 third-party (C3PAO) assessment requirement pending a 60-day program review. Your DFARS 252.204-7012 / NIST SP 800-171 obligations — and False Claims Act exposure for inaccurate self-attestation — remain fully in force. Reform RFI closes Aug 14, 2026. Official release ↗
THE CMMC LEVEL 2 PLAYBOOK · BY LIONFISH CYBER SECURITY

CMMC Level 2 isn't a cost. It's a moat.

We wrote the playbook that turns certification into a recoverable investment — 12 steps to certified, 8 steps to reimbursed, and the contract-clause leverage most contractors never use. We don't publish it. We run it with you. The briefing is where it opens — and after July 13, it matters more, not less.

30 minutes with our engineering lead · No pitch deck · Bring your contract clauses, leave with your window

Days
Hours
Mins
Secs

until the CMMC Reform Task Force is due to report (60-day review begun July 13, 2026). The audit is paused — the obligation is not (DFARS 252.204-7021)

0%
of the DoW contractor base is NOT yet certified
0
authorized C3PAOs for ~300,000 firms — the queue re-forms when Phase 2 resumes
$0K
average small-business Level 2 investment — recoverable
~0 wks
how fast certification can pay for itself on one $4M contract*

*Illustrative worked example — full math unlocked in your briefing. Sources: DoD CIO CMMC Program · Cyber AB

CMMC PHASE 2 — C3PAO audits SUSPENDED Jul 13, 2026 · 60-day review underway DFARS 252.204-7012 — NIST SP 800-171 · 72-hr incident reporting DFARS 252.204-7020 — SPRS score submission DFARS 252.204-7019/7020 — SPRS score + annual affirmation STILL required FAR 31.201-2 — your certification costs may be allowable & recoverable 110 controls — NIST SP 800-171 · 3-year certification validity

Eleven sections. Every one answers a question that costs you money.

Here's the table of contents. The contents themselves — the steps, the tables, the math, the exact clause language to use with your Contracting Officer — open in your briefing, and we execute them with you when you hire us.

🔒
§1 · FOUNDATION

Understanding the Landscape

The 2-year window, why 90% uncertified is your opening, and who's actually in scope.

Unlocked in your briefing
🔒
§2 · CONTRACTS

The Four Critical Contract Clauses

Which clauses trigger obligations — and which quietly grant you cost-recovery rights.

Unlocked in your briefing
🔒
§3 · RISK

The Self-Attestation Trap

Why an undefendable SPRS score is the single biggest legal risk in the DIB today.

Unlocked in your briefing
🔒
§4 · COST RECOVERY

Direct vs. Indirect Costs

A 17-line categorization table that decides how much of your spend comes back.

Unlocked in your briefing
🔒
§5 · CERTIFICATION

The 12-Step Certification Guide

Gap assessment to C3PAO certificate, in the only order that doesn't waste money.

Unlocked in your briefing
🔒
§6 · REIMBURSEMENT

The 8-Step Reimbursement Strategy

Evidence book → indirect rates → KO conversation → REA. The money path.

Unlocked in your briefing
🔒
§7 · CASE STUDY

The $4M Contract Example

Real math: how one certification turns cash-flow positive — with the full 3-year model.

Unlocked in your briefing
🔒
§8 · STRATEGY

The Competitive Moat

Why early movers win twice — on eligibility now, and on C3PAO scarcity later.

Unlocked in your briefing
🔒
§9–11 · EXECUTION

Special Cases, Resources & Action Plan

Subs, MSPs, FOCI, M&A due diligence — plus your 30-60-90 day action plan.

Unlocked in your briefing

The window is real, dated, and closing.

NOV 2025

Requirements go live

CMMC clauses appear in new DoW solicitations; Phase 1 self-assessment obligations begin.

JUL 13, 2026

Phase 2 suspended

C3PAO audits paused; Reform Task Force begins 60-day review. DFARS 7012 + NIST 800-171 + SPRS obligations continue.

SEP 2026

Task Force reports

Industry RFI closes Aug 14; recommendations due ~60 days in. Contractors who kept readiness are positioned for whatever comes next.

RESUMPTION

The queue re-forms

When third-party assessment returns — current program or reformed — ready contractors go first. Dismantled programs start over, at the back.

The most expensive number in your company might be your SPRS score.

If you've posted a self-attested score you can't defend with evidence, you haven't bought compliance — you've bought False Claims Act exposure: treble damages, six-figure per-claim penalties — and it's actively enforced: in June 2026 a defense contractor paid $507,144 to settle FCA allegations over unimplemented NIST SP 800-171 controls on two Navy contracts (DOJ). With no mandatory third-party audit during the suspension, your self-attestation is now the primary enforcement surface. Section 3 of the playbook shows what "defendable" actually requires — and the briefing tells you whether your current score is an asset or a liability.

DOJ · False Claims Act · 31 U.S.C. §3729

Ask yourself, honestly:

  • Could you produce evidence for every point of your posted SPRS score — today?
  • Is your System Security Plan current, complete, and assessment-grade?
  • Did you post a score before doing a formal gap assessment?

If any answer is "no" or "not sure," the briefing is not optional. It's urgent.

The $4M contract example — the math your CFO will want to see.

One mid-size DoW contract. One certification investment. A 3-year model your CFO can defend in a DCAA audit. We'll walk your actual numbers in the briefing — here's the shape of it:

$4M
contract value
$888K
3-year recovery path
+$888K
net 3-yr position
88.8%
G&A rate move
$8.8M
portfolio-scale outcome
~6 wks
illustrative payback

Figures are illustrative, not guarantees — grounded in FAR 31.201-2 allowability and DCAA-auditable methodology. Your model gets built on your contracts.

Run my numbers in a briefing →
YOUR
CERTIFICATION

Certify once. Collect the moat for 3 years.

  • Bid solicitations that ~90% of your competitors are locked out of
  • 3-year certification validity across your entire DoW portfolio
  • A capability-statement differentiator primes actively search for in subs
  • Settled, auditable indirect rates before the 2026 pricing surge
  • A due-diligence asset if you ever raise capital or sell
  • Voluntary Level 2 certification remains available during the pause — the Cyber AB calls it the best insurance against FCA risk, and almost no competitor will hold one
FOR SUBCONTRACTORS · THE FAST LANE

Reading the playbook is knowing. Rapid Deployment is doing.

If you're a sub racing your prime's flow-down, pair the playbook with our secure enclave: 65+ of the 110 controls inherited on Day 1, assessment-ready in under 6 months — without becoming a cybersecurity company.

See Rapid Deployment → Or just book the briefing

How it works when you work with us

STEP 01

The Briefing (free, 30 min)

We open the playbook against your actual contracts: which clauses you carry, where your window is, what your recovery path looks like.

STEP 02

Your Gap Plan & Cost Model

Engagement begins: formal gap assessment, defendable SPRS score, SSP/POA&M, and a CFO-grade cost-recovery model built on your rates.

STEP 03

Certified & Recovering

We drive you to C3PAO assessment-ready, then help you put the recovery strategy to work in your rates, options, and proposals.

THE NEXT MOVE IS 30 MINUTES

Book your CMMC Playbook briefing.

One conversation with our engineering lead. Your clauses, your score, your window, your math. If we're not the right fit, you'll still leave knowing exactly where you stand.

Loading scheduling calendar…

Scoping details you share are held in corporate confidence. Briefings are closed-loop sessions with our engineering lead.