On July 13, 2026 the Department of War suspended the November 2026 transition to CMMC Phase 2 pending the DoW CIO’s 60-day review. During the suspension, solicitations may require only CMMC Level 1 (Self) or Level 2 (Self), and DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, remains in effect (DoW memorandum, Attachment 1, Cybersecurity Maturity Model Certification Procedures, cleared July 13, 2026). What did not pause is the part you are already on the hook for. Where a contract requires CMMC Level 2 (Self), you submit your self-assessment results in SPRS (32 CFR 170.16), and your Affirming Official affirms continuing compliance after each assessment and annually thereafter (32 CFR 170.22). Standing is built for that obligation: it keeps the compliance state behind your affirmation evidenced, re-scanning your connected sources about every 7 days and rebuilding the documents from that state every 90 days, without a consultant on retainer.
What Standing does for you
- Measures your environment instead of asking you about it. Read-only connectors to AWS, Azure, Microsoft 365, Google Workspace, Okta and CrowdStrike pull configuration metadata. Nothing is installed in your environment and no CUI is harvested. You can revoke any connector at any time by deleting the role, app or token.
- Covers the whole standard in your documents. Your System Security Plan addresses all 110 NIST SP 800-171 Rev. 2 requirements and all 320 SP 800-171A assessment objectives, and each measured finding is tied to the control ID it affects. The connectors measure the controls your connected sources expose; the rest are drawn from your intake and recorded evidence. Your framework target is your choice: NIST SP 800-171 Rev. 2 (110 requirements, 320 assessment objectives; required and scored) by default, or NIST SP 800-171 Rev. 3 (97 requirements, 422 assessment objectives; emerging, no DoD score exists), selected at intake or from your workspace. CMMC Level 2 is bound to NIST SP 800-171 Rev. 2 today: 32 CFR 170.14(c)(3) states that the CMMC Level 2 security requirements are identical to the requirements in NIST SP 800-171 R2.
- Recomputes your SPRS estimate each cycle. The estimate applies the DoD Assessment Methodology point-deduction weights to your measured findings, so you can compare it with the score you have on file before you post or affirm. It is a directional estimate computed by the agents, not a C3PAO assessment.
- Carries the annual affirmation with you. The affirmation is a statement of continuing compliance. Standing keeps the underlying measurement, the POA&M and the evidence current so that statement rests on something you can show.
- Refreshes the document set every 90 days. System Security Plan, POA&M, evidence library, CUI scoping package and Customer Responsibility Matrix, rebuilt from your current environment rather than edited by hand.
Why every 90 days, and not every 30
Standing rebuilds the full document set every 90 days, which keeps the annual cost at $8,340. Your connected sources are still re-scanned about every 7 days in between, and any control that regresses shows in your workspace. If your environment changes faster than that, or you have a C3PAO date on the calendar, Standard runs the same work every 30 days.
What Standing is not
- It is not an assessment. Self-assessments are yours; certification assessments are conducted by Cyber AB-authorized C3PAOs or by DCMA DIBCAC (32 CFR 170.16 to 170.18). Enclave AI™ helps you prepare; it never performs an assessment.
- It is not a certification, and it does not submit anything to the government on your behalf. You review each deliverable and you decide what gets filed.
- It does not cover CMMC Level 3 (selected NIST SP 800-172 requirements, assessed by DCMA DIBCAC under 32 CFR 170.18). That is not on the platform today, and the FAQ says so plainly.
- It is not multi-entity. One organization, one CUI scope. Multiple subsidiaries under one contract is Sovereign.
The first hour
- Minute 0. Stripe processes the subscription and the welcome email lands with two links: your onboarding page and your asset register.
- Minutes 5 to 15. You answer a short intake about your environment, your self-reported SPRS score and your DFARS 252.204-7012 flow-down, then connect whichever clouds you want measured. Connect none and you still get an intake-based gap analysis; connect one or more and the findings are measured from your own configuration data.
- Within minutes of intake. Your first readiness package arrives as a PDF: control-gap analysis across the 110-control baseline, your SPRS estimate against your self-reported score, and a remediation list ordered by point recovery.
- Every 90 days after that. The cycle re-runs, the documents rebuild from current data, and your workspace shows the score change since the last cycle.
How the evidence holds up
Each API response the connectors collect is hashed with SHA-256 and kept on file. The evidence integrity certificate commits to your assessment record as the platform holds it: your evidence artifact manifest with the hash you record for each file, your control attestations, your CUI scope and your affirmation. Re-hashing a file and comparing it with the hash in the manifest shows whether that file changed after its hash was recorded; the files themselves stay in your environment. The audit trail is append-only, enforced by PostgreSQL triggers that reject DELETE and block changes to recorded content on UPDATE, rather than by application convention. Each evidence integrity certificate is signed with an Ed25519 key the platform alone holds, so a C3PAO or a contracting officer can verify it offline against our published public key. That shows the certificate came from the platform’s key and the record it covers has not changed since it was signed. It is tamper-evidence, not proof that the underlying configuration was compliant.
Start Standing
$8,340 per year, or $695 per month month-to-month. If you received your $999 CMMC Level 2 Readiness Snapshot PDF within the last 30 days and start a Level 2 subscription with the same billing email, the $999 is credited in full: against your first invoice, with any amount above that invoice applied to the invoices after it. The 30 days count from receipt of the Snapshot PDF, under the Refund Policy.