CMMC Certification Now Required for New DoD Contracts
I'm John Koontz. I've built compliant infrastructure for government contractors and partners and achieved numerous compliance certifications at startups and enterprises.
Now I help DoD contractors meet CMMC requirements without the confusion or delays.
As of November 10, 2025, new DoD contracts require CMMC certification.
If you handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), you need to be certified to win new contracts.
Most small contractors don't know where to start. The regulations are complex, consultants are expensive, and time is running out.
I translate CMMC requirements into practical action plans you can actually implement.
Fixed-scope packages designed for defense contractors. No surprises, no endless engagements.
2 weeks delivery
For contractors handling FCI only who need self-assessment
Get Started with Level 130 days delivery
For contractors who need complete compliance, not just paperwork
Get Full Compliance Support90 days delivery
For contractors handling CUI who need third-party certification
Prepare for Level 2No junior consultants
You work directly with me
No endless engagements
Fixed scope, clear deliverables
No compliance theater
Focus on real security and audit satisfaction
I speak both languages
Technical and executive/compliance
While CMMC is my primary focus for defense contractors, my compliance experience extends across multiple frameworks including SOC 2, GDPR, FedRAMP assistance, and security assessments like penetration testing.
View additional services →Yes, if you handle FCI or CUI. Prime contractors will flow down CMMC requirements to all subs who touch their data.
You can! Level 1 is self-assessed. But most contractors find the requirements confusing and miss critical controls. A failed assessment can delay contracts.
DoD estimates assessment fees for small businesses, plus annual affirmation fees. Remediation costs (fixing gaps) vary widely based on your current security posture. Contact me for a detailed quote based on your specific situation.
You can't bid on or win new DoD contracts that require CMMC. Existing contracts may not be affected immediately, but renewals and option exercises will likely require compliance.
Yes. The final rule went into effect November 10, 2025. CMMC certification is now mandatory for new DoD contracts that require it.
Level 1 assessments take 2-4 weeks minimum. Remediation depends on your current state but typically 30-90 days. Level 2 can take 3-6 months including C3PAO assessment.
Level 1 is for contractors handling only FCI - requires self-assessment against 15 basic controls. Level 2 is for CUI - requires meeting 110 NIST 800-171 controls and third-party assessment starting in 2026.
Schedule a free 30-minute consultation to discuss:
No sales pressure. If you just need guidance on where to start, I'm happy to point you in the right direction.
Schedule Free ConsultationEmail: johnkoontz@alphaverify.io
Location: Champaign, IL | Available nationwide