CMMC 2.0 certification. Required to keep—and win—DoD contracts.
The Department of Defense began enforcing CMMC 2.0 requirements in late 2024. Defence contractors and subcontractors handling Controlled Unclassified Information (CUI) must now demonstrate certification—not just self-attest. Sentrix maps your security controls to CMMC Level 1 and Level 2 practices and prepares your System Security Plan for third-party assessment.
Level 1 self-attestation. Level 2 C3PAO assessment. Sentrix prepares both.
CMMC 2.0 simplified the original five-level model to three levels. Level 1 (17 practices) applies to Federal Contract Information and allows annual self-attestation. Level 2 (110 practices, aligned to NIST SP 800-171) applies to CUI and requires triennial third-party assessment by a Certified Third-Party Assessor Organization (C3PAO).
- Level 1: 17 foundational practices, annual self-attestation by senior official
- Level 2: 110 advanced practices (NIST 800-171), C3PAO assessment every 3 years
- Level 3: 24 additional practices from NIST 800-172, government-led assessment
- SPRS score tracking—Sentrix calculates your Supplier Performance Risk System score continuously
CMMC Level 2 · Domain coverage
110 PRACTICESFrom SPRS score to C3PAO assessment package.
800-171 control mapping
All 110 CMMC Level 2 practices mapped directly to their NIST SP 800-171 counterparts. Continuous evidence collection means your assessment package is complete before your C3PAO schedules the first call.
SPRS score tracking
Your Supplier Performance Risk System score is calculated continuously based on your current control implementation status. Sentrix tracks your score over time and alerts you when changes affect it.
System Security Plan
The SSP is required for CMMC assessment. Sentrix generates your SSP from your actual control implementations—system boundary, control descriptions, implementation status, and responsible parties all populated automatically.
POA&M management
Every open practice gap gets a Plan of Action and Milestones entry. Track remediation owners, scheduled completion dates, and evidence of closure—in the format your C3PAO expects to review.
CUI data flow mapping
CMMC requires you to know where CUI lives. Sentrix maps CUI data flows from your cloud and on-premise systems, identifying which environments are in scope for assessment.
CPCSC crosswalk
Canadian defence suppliers pursuing both CMMC and CPCSC manage both from one Sentrix program. The two frameworks share substantial control overlap—Sentrix maps the common ground automatically.
See your CMMC Level 2 readiness and SPRS score live.
We map your practices to your actual infrastructure and calculate your score before the call ends.