CMMC clauses are now in DoD contracts · Phase 2 assessments begin November 2026
The Infinite Paradigm
Why usProcessL1 vs L2ServicesQ&AVideosPrivacy
Free Checkpoint Free Checkpoint
● CMMC Certified · Boutique Practice

Get CMMC-ready with one certified operator — not a pitch deck.

We get small defense contractors through CMMC Level 1 and Level 2 readiness with fixed fees, plain English, and 21 years of real DoD-prime experience behind every recommendation.

Book a free Readiness Checkpoint → Which level do I need?
21Years in a DoD prime
110NIST 800-171 controls
CCPCMMC Certified Pro
1:1Direct operator access

Why contractors choose us

Most cybersecurity consulting is broken. We built the alternative.

If you've shopped for CMMC help, you've probably hit at least one of these. We fixed all four.

✕ Hidden pricing

We publish every fee

Productized work is flat-priced right on this site. Custom work is quoted in writing. You know the number before you commit.

✕ Borrowed theory

We've actually run it

What we recommend, we've deployed, hardened, audited, or recovered ourselves at DoD-prime scale — for 21 years.

✕ Silent AI use

We disclose our AI

Every engagement includes a written note on which AI tool touched which data. Sensitive data never enters consumer AI.

✕ Generalists, specialist rates

One certified operator

You work directly with a CMMC Certified Professional — not a rotating junior team. Every engagement gets the principal's attention.

How it works

A clear path from "where do I start?" to audit-ready.

1

Scope

We pinpoint exactly where your protected information lives — systems, people, vendors. This is where most projects over-spend; we don't.

2

Gap

We measure you against the controls that actually apply and hand you a documented baseline — not a vague feeling.

3

Plan

A prioritized, realistic roadmap (your POA&M) — what to fix, in what order, by when.

4

Evidence

We build your security plan (SSP) and the proof assessors need. We coach you right up to the C3PAO.

Level 1 or Level 2?

Which level you need depends on the information you handle.

Here's the honest, side-by-side version. Not sure where you land? The free Checkpoint settles it.

CMMC Level 1
If you handle Federal Contract Information (FCI)
  • What it protects: basic contract info not meant for public release.
  • Scope: 15 fundamental safeguards.
  • How it's verified: annual self-assessment + affirmation.
  • The lift: manageable — not a six-figure project.
Level 1 Sprint — $7,500 · 3–4 weeks
CMMC Level 2
If you handle Controlled Unclassified Information (CUI)
  • What it protects: sensitive info a prime flagged as controlled.
  • Scope: all 110 NIST 800-171 controls.
  • How it's verified: self- or third-party (C3PAO) assessment.
  • The lift: heavier — and the one most worth starting early.
Level 2 Assessment — $28K–$45K · 10–14 weeks

What we do · pricing in the open

Seven offerings. Every price listed.

Fixed-fee work ships at the price shown; custom work is quoted in writing after a scoping call.

CMMC Level 1

Level 1 Readiness Sprint

Gap assessment, populated SSP, SPRS-ready package, executive readout.

$7,500 · 3–4 wks
CMMC Level 2

Level 2 Readiness Assessment

110-control gap analysis, SSP, POA&M, evidence index, C3PAO coaching.

$28K–$45K · 10–14 wks
vCISO

Fractional vCISO Retainer

Executive report, risk register, vendor risk, IR on-call, board briefing.

From $4,200/mo
AI Governance

AI Governance Advisory

NIST AI RMF readiness, AUP pack, shadow-AI inventory, ISO 42001 pathway.

From $6,500
Federal Systems

Federal & Facility Systems Security

RMF/ATO packages, UFC 4-010-06, SSPs, SARs, OT/ICS/SCADA advisory.

By engagement
Infrastructure

IT Infrastructure Advisory

Cloud (Azure GCC/High, AWS, GCP), datacenter, vuln, patch, identity.

Quoted
★ Flagship Retainer

Fractional Director of IT Infrastructure & Security

Senior IT leadership and audit-grade security posture in one accountable engagement — for companies that need both but can't justify two full-time hires.

Tier 1 · Advisory
$5,500/mo
~20 hrs/mo. When an internal IT lead is in place.
Tier 2 · Embedded
$7,500/mo
~30 hrs/mo. MSP governance & oversight. Most begin here.
Tier 3 · Unicorn
$12,000/mo
~40 hrs/mo. Full IT + vCISO under one advisor.

Our promises

Six non-negotiables. The deal never bends them.

i.

Operator discipline

What we recommend, we've run, broken, hardened, audited, or recovered ourselves.

ii.

Honesty over politeness

We tell clients when they don't need us, and disagree with auditors when they're wrong.

iii.

AI used transparently

A written AI-use disclosure every engagement. CUI never enters consumer AI.

iv.

Pricing in the open

Hidden pricing is the first sign of a broken relationship. Ours is published.

v.

Boundaries, drawn

We advise, architect, and assess. We're not your MSP. That protects the advice.

vi.

Boutique by intent

Small on purpose. Engagement count is capped. Quality is a capacity constraint.

The operator

21 years inside an active DoD prime — applied to your environment.

The Infinite Paradigm is a one-operator practice by design. Those years were spent running enterprise IT, cybersecurity programs, and compliance against NIST 800-171 and the supply-chain demands of CMMC.

What gets sold here isn't a framework recitation — it's the same operator discipline applied to your shop: certifications held, controls deployed, audits defended, recoveries run. The boutique scale is intentional, so your work gets real attention.

Founder & Principal

The Operator

CMMC Certified Professional · DoD-prime experienced. Each engagement gets the principal's direct attention.

CMMC CCPMCSE CloudCCNP EnterpriseDevNetDCIS · DCES

One honest hour could save you months.

Book a free 60-minute Readiness Checkpoint. We assess where you are, leave you with a written one-page findings summary, and tell you honestly whether you need our help at all. Roughly 1 in 5 companies hear "you don't need us" — in writing.

Request a Checkpoint →

The Knowledge Base

Every question subcontractors ask. Answered.

37 straight answers — grounded in 32 CFR Part 170, not sales copy. Read them below, or watch them answered on camera in The Checkpoint Session.

CMMC (Cybersecurity Maturity Model Certification) is the DoD's program for verifying — through self-assessments and third-party assessments — that contractors actually meet the cybersecurity requirements their contracts have required on paper since 2017. The rules aren't new; the verification is.

The information you touch. Level 1 protects Federal Contract Information (FCI) with 15 basic requirements from FAR 52.204-21, verified by an annual self-assessment. Level 2 protects Controlled Unclassified Information (CUI) with all 110 controls of NIST SP 800-171 — verified, for most contracts, by an independent third-party (C3PAO) assessment.

▶ Watch this answered on camera

Information the government provides, or that you generate for the government under contract, that isn't released to the public. Submittal logs, RFI correspondence, project schedules, non-public pricing, daily reports on a federal job — nearly every federal subcontract involves FCI.

Information a law, regulation, or government-wide policy specifically requires to be safeguarded. On construction and engineering work that commonly means site plans of secure facilities, facility drawings, access schedules, MILCON specification packages, and export-controlled technical data. CUI handling always includes the FCI basics.

Your subcontract clauses decide — not drawing stamps, not what anyone told you verbally. Pull your terms and search five clause numbers:

If your subcontract contains…You likely handle…Which means…
FAR 52.204-21 onlyFCILevel 1 — 15 requirements, annual self-assessment
+ DFARS 252.204-7012CUINIST 800-171 applies now; you're on the Level 2 track
+ DFARS 252.204-7019 / 7020CUIA current SPRS score is required for award
+ DFARS 252.204-7021Per the clauseCMMC is required at the level the clause names
▶ Watch this answered on camera

Not all drawings are CUI — but unmarked does not mean not-CUI, and marking gaps between agencies, primes, and subs are common across the industry. Trade scopes like flooring frequently touch only finish schedules and general arrangement drawings, which are often FCI rather than CUI.

Drawings cross into CUI — typically Controlled Technical Information or facility-related categories — when they show secure or controlled areas, base infrastructure details, or carry distribution statements. Military-construction packages increasingly require exactly this: controlled-area labeling on as-builts and CUI marking on project documentation. The move is to request a written CUI determination from your prime for every job. Either answer protects you — on paper.

▶ Watch this answered on camera

No. Identifying CUI that flows into subcontracts is the prime's responsibility under DFARS 252.204-7012, but the safeguarding obligation lands on whoever holds the data. Request a written CUI determination from your prime for each job.

Yes. The rule applies consistent requirements to all subcontractors handling FCI or CUI, regardless of company size — there is no small-business exemption. There is, however, a much smaller Level 1 path if you only handle FCI, which describes many small trade contractors.

Not all. The level tracks the information, not the contract vehicle. FCI-only work carries Level 1; CUI work carries Level 2, and DFARS clause 252.204-7021 names the level right in the contract. The requirement flows down based on what actually reaches you — a sub receiving only FCI can hold Level 1 even on a Level 2 prime contract.

That said, subs positioned at Level 2 will be eligible for the widest range of federal work as the phase-in completes. That's a business decision, not just a compliance one.

It already has. Phase 1 began November 10, 2025 — Level 1 and Level 2 self-assessment requirements now appear in applicable solicitations, and DoD can already require third-party certification at its discretion. Phase 2 arrives November 10, 2026, when C3PAO Level 2 certification becomes the standard requirement. Phase 3 follows November 10, 2027.

Two consequences. Eligibility: once a solicitation carries a CMMC requirement, you cannot be awarded the contract without the required status posted. No certification, no award. And legal exposure: misrepresenting your compliance — posting a score or affirmation you can't support — carries False Claims Act risk, a far more expensive problem than compliance ever was.

▶ Watch this answered on camera

You can, but the math works against it. Level 2 readiness typically takes 3 to 6 months of real work, and roughly 80,000 defense contractors are expected to need certification against a limited pool of certified assessors. Companies that wait for a contract deadline compete for assessor calendar slots with everyone else who waited.

▶ Watch this answered on camera

Only on that contract, and only until it's modified or recompeted. DFARS 252.204-7012 has required full NIST 800-171 implementation since December 2017 on any contract involving CUI — CMMC adds verification, not new controls. If 7012 is in your subcontract, the 110-control obligation is already live today.

The 15 basic safeguarding requirements in FAR 52.204-21(b)(1): limit system access to authorized users, control connections and removable media, patch systems, run malware protection, sanitize media before disposal, and similar fundamentals. Most well-run IT environments already do much of this.

No. Level 1 is an annual self-assessment against the 15 requirements, plus an affirmation by a senior company official, both posted in SPRS (the Supplier Performance Risk System). No C3PAO, no certification body, no external audit.

No. Level 1 has no partial credit and no Plan of Action and Milestones. All 15 requirements must be MET at the time of the self-assessment. Lower bar — but pass/fail.

For a typical small contractor with a reasonably managed IT environment: 3 to 4 weeks of structured work — scoping, gap review, remediation of the short list, documentation, and the SPRS submission package. DoD's own rule estimates a small entity's self-assessment effort at roughly $6,000 in internal cost. Our fixed-fee Level 1 Readiness Sprint is $7,500, published above.

Annually. The self-assessment and the senior-official affirmation both renew every year.

Implementation of all 110 security controls in NIST SP 800-171 Revision 2, assessed against 320 individual assessment objectives, on every system that processes, stores, or transmits CUI. Revision 2 — not Revision 3 — is the operative standard for current assessments under the DoD's active class deviation.

The clause in your contract decides. Some Level 2 contracts allow self-assessment; most will require certification by an authorized C3PAO, and from November 10, 2026 the C3PAO route becomes the standard requirement in applicable solicitations. The safe planning assumption for any company on the Level 2 track is a C3PAO assessment.

Out of 110 points, with weighted deductions of 1, 3, or 5 points per unimplemented control. A minimum score of 88 — with every remaining gap on a compliant POA&M — is the floor for Conditional status. Certain controls carry no partial credit and must be fully met, including a complete System Security Plan; without the SSP, the assessment does not proceed.

▶ Watch this answered on camera

Conditional means you met the 88-point floor with a limited set of allowable items on a POA&M, and you have 180 days to close them — miss the closeout and the status is lost. Final means every requirement is met outright. A well-run readiness effort aims at Final and uses Conditional only as a deliberate bridge when a deadline demands it.

The System Security Plan is the master document describing your environment, your CUI boundary, and how each of the 110 controls is implemented. Assessors treat it as the entry ticket: no SSP, no assessment. It's also the single document most small contractors have never written.

A Plan of Action and Milestones — the formal, dated remediation plan for any control not yet fully implemented. At Level 2, only certain lower-weight items are POA&M-eligible, the highest-weight controls are not, and the clock is 180 days.

Three years — with an annual affirmation by a senior official in each year between assessments. Certification is a posture you maintain, not a one-time event.

Self-assessment scores go into SPRS, accessed through the PIEE portal. C3PAO certification results are recorded in eMASS and flow to SPRS. Contracting officers check those systems — the official record is what lands there.

Yes — and scoping is the highest-return decision in the entire effort. A defined CUI enclave — a bounded set of systems, users, and data flows where CUI lives — can keep the 110 controls off your entire corporate network. The rule defines five asset categories (32 CFR 170.19), and getting them right early is the difference between a contained project and an enterprise-wide one.

It can be. Cloud services that store or process CUI must meet FedRAMP Moderate (or equivalent) requirements, and encryption used to protect CUI must be FIPS-validated. Commercial-tier tenants frequently fail both tests — one of the most common scope blockers we find, and one of the most expensive to discover late. We check it in the first hour, not the tenth week.

Large firms typically quote $90,000 to $150,000+ for readiness engagements. Our fixed-fee Level 2 Readiness Assessment runs $28,000 to $45,000 over 10 to 14 weeks depending on environment complexity — and the price is published before you ever call. The C3PAO assessment itself is a separate cost paid to the assessor; budget for it independently.

A documented AI-augmented delivery model compresses roughly 180 hours of traditional engagement work to about 60, and we pass the difference through. Two commitments come with it, in writing: every AI workflow is disclosed, and CUI never touches a commercial AI service — evidence processing runs on local, offline tooling only.

▶ Watch this answered on camera

Sometimes, for Level 1. Rarely, for Level 2. CMMC readiness is an assessment discipline — control interpretation, evidence sufficiency, scoping decisions, assessor expectations — and it benefits from someone independent of the systems being assessed. We deliberately don't act as anyone's MSP for exactly that reason: the advice stays independent.

Productized engagements are flat-fee and listed openly on this page. Custom-scope work is quoted in writing after a short scoping call. You'll never get a mystery number.

A free 60-minute Readiness Checkpoint. You describe your contracts and environment; we run a structured diagnostic against the actual requirements; you receive a one-page written findings summary within 48 hours. No pitch deck, no drip sequence, no obligation.

And you should know this before you book: roughly 1 in 5 companies who complete a Checkpoint hear from us that they don't need our services — their situation is simple enough to handle in-house, or a different kind of firm is the right fit. We tell you which one you are, in writing, either way.

▶ Watch this answered on camera

One structural point first, because it protects you: the firm that certifies you cannot be the firm that prepared you — CyberAB conflict-of-interest rules separate the assessor role from the consultant role. That's why we do readiness only, and never assessments. For the certifying side, the CyberAB Marketplace is the authoritative directory. And timing matters: assessor capacity is limited relative to the number of contractors that will need certification, so get in queue early rather than late.

A focused 60-minute session with a CMMC Certified Professional. You bring your situation; we bring the diagnostic. You leave with a one-page written findings summary within 48 hours and an honest recommendation — even if it's "you don't need us yet."

No — and that's deliberate. We advise, architect, and assess readiness; we don't take operational ownership or act as your MSP. That separation keeps our advice independent and honest.

No, by rule and by design. Under 32 CFR Part 170 and CyberAB conflict-of-interest requirements, a firm that consults on your readiness cannot assess the same client for three years. We are a readiness consultancy, not a C3PAO — and we never guarantee certification outcomes. What we deliver is an assessment-ready posture and a clean handoff to the assessor you choose.

No matching questions. Ask us directly — book the free Checkpoint.

Watch instead

The Checkpoint Session — the interviews.

A skeptical subcontractor owner sits down with The Operator and asks every question on this page. Watch the full sitting or the one-minute cuts. Prefer reading? The written answers are above.

The Checkpoint Session — full Q&A interview
Coming soon
Flagship · 17 min

The Checkpoint Session — the full sitting

All 33 questions, one skeptical subcontractor, one operator. 17 minutes, chaptered.

Coming soon
Short · 60s

“Nothing was marked CUI”

Unmarked does not mean not-CUI — the drawings question, answered.

Coming soon
Short · 60s

No certification, no award

What actually happens if you do nothing.

Coming soon
Short · 60s

The five clauses

How to read your own subcontract and settle your level.

Coming soon
Short · 60s

15 vs 110

Level 1 and Level 2 in one minute.

Coming soon
Short · 60s

The 88-point floor

Level 2 scoring, Conditional status, and the 180-day clock.

Coming soon
Short · 60s

The queue

80,000 contractors. Limited assessors. The waiting math.

Coming soon
Short · 60s

“What's the catch?”

Why fixed-fee readiness costs half the big-firm quote.

Coming soon
Short · 60s

1 in 5 hear “you don't need us”

The honest-disqualification policy, on camera.

Narration is AI-generated. All presenters are AI avatars. We disclose our AI use. The Infinite Paradigm LLC is a readiness consultancy, not a C3PAO; nothing in these videos guarantees an assessment outcome.

Get started

Ready for an honest conversation?

Sixty minutes, no pitch deck. Pick whatever channel is easiest.

Email
inquiries@theinfiniteparadigm.com
Phone
970.888.2235
LinkedIn
/the-infinite-paradigm-llc
Request a Readiness Checkpoint →
The Infinite Paradigm Colorado · Serving Nationwide
© MMXXVI The Infinite Paradigm LLC · Operator-grounded. No theater. Privacy Policy

Privacy Policy

Effective 5/30/2026 · Last updated 5/30/2026

On this page

  1. 01 Who we are & what this covers
  2. 02 Information we collect
  3. 03 How we use your information
  4. 04 Advertising & analytics
  5. 05 How we share information
  6. 06 Use of AI tools
  7. 07 Cookies & tracking
  8. 08 Data retention
  9. 09 How we protect information
  10. 10 Your privacy rights
  11. 11 Email communications
  12. 12 Children's privacy
  13. 13 Third-party links
  14. 14 Professional confidentiality
  15. 15 Changes to this policy
  16. 16 Contact us

01Who we are and what this covers

The Infinite Paradigm LLC ("The Infinite Paradigm," "we," "us," or "our") provides cybersecurity, compliance, infrastructure, and AI governance advisory services. This Privacy Policy explains what personal information we collect through our website at theinfiniteparadigm.com, our lead and contact forms, our newsletter, and our advertising — and how we use, share, and protect it.

This policy covers information we collect for marketing, sales, and general business operations. It does not govern information we handle on behalf of clients under a signed engagement — that information is governed by the confidentiality and security terms of the applicable client contract.

By using our website or submitting your information to us, you agree to the practices described in this policy.

02Information we collect

Information you give us directly

When you fill out a contact form, request a Readiness Checkpoint, subscribe to The Infinite Brief, download a resource, or otherwise communicate with us, you may provide:

  • Your name
  • Work email address
  • Company name and job title
  • Phone number (if you provide it)
  • The CMMC level, services, or specific concern you ask about
  • Any other information you choose to include in a message

Information collected automatically

When you visit our website or interact with our ads, we and our service providers may automatically collect:

  • IP address and approximate location
  • Browser and device type
  • Pages viewed, links clicked, and time spent on the site
  • The website or ad that referred you to us
  • Cookie and similar tracking identifiers (see Section 7)

Information from advertising platforms

When you submit a lead form hosted on Meta (Facebook/Instagram), LinkedIn, or Google, those platforms collect the information you enter and pass it to us. Their handling of your data is also governed by their own privacy policies.

03How we use your information

We use the information we collect to:

  • Respond to your inquiries and schedule Readiness Checkpoints
  • Provide, support, and improve our services
  • Send The Infinite Brief and other communications you've requested
  • Send relevant business updates, where permitted by law
  • Measure and improve our website and advertising performance
  • Maintain the security of our systems
  • Comply with our legal and contractual obligations

We do not sell your personal information.

04Advertising and analytics

We use advertising and analytics tools to understand how people find and use our site and to reach the right audiences. These may include:

  • Google Analytics and Google Ads (including conversion tracking)
  • Meta Pixel (Facebook/Instagram advertising)
  • LinkedIn Insight Tag (LinkedIn advertising)

These tools use cookies and similar technologies to collect usage data and may allow us to show ads to people who have visited our site or who resemble our existing audience. You can opt out of many advertising cookies through the controls described in Section 7.

05How we share your information

We share personal information only as needed to run our business:

  • Service providers who work on our behalf — email and newsletter platforms, scheduling tools, CRM software, hosting providers, and analytics and advertising platforms. These providers may only use your information to perform services for us.
  • Advertising platforms (Meta, LinkedIn, Google) in connection with the lead forms and tracking described above.
  • Legal and safety reasons — when we believe disclosure is required by law, regulation, legal process, or to protect the rights, property, or safety of The Infinite Paradigm, our clients, or others.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction.

We do not sell your personal information, and we do not share it for third-party marketing unrelated to our own services.

06Use of AI tools

Consistent with our commitment to transparency about our use of artificial intelligence, we use AI-assisted tools in parts of our marketing and operations. Where personal information is processed using these tools, we work to ensure such use is consistent with this policy and that providers do not use your information to train their models beyond what is necessary to provide their service to us.

07Cookies and tracking technologies

Our website uses cookies and similar technologies to operate the site, remember preferences, measure performance, and support advertising. You can control cookies through your browser settings, and you can opt out of certain advertising cookies through:

  • Google Ads Settings: myadcenter.google.com
  • Digital Advertising Alliance: optout.aboutads.info
  • Network Advertising Initiative: optout.networkadvertising.org
  • Your device's "Limit Ad Tracking" or "Opt out of Ads Personalization" setting

Blocking some cookies may affect how the website functions.

08Data retention

We keep personal information only as long as needed for the purposes described in this policy — to respond to your inquiry, provide services, send communications you've requested, meet our legal obligations, and resolve disputes. When information is no longer needed, we delete or de-identify it.

09How we protect your information

We use reasonable administrative, technical, and physical safeguards designed to protect personal information against loss, misuse, and unauthorized access. As a cybersecurity firm, security is central to how we operate. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10Your privacy rights

Depending on where you live, you may have rights regarding your personal information, including the right to:

  • Access the personal information we hold about you
  • Correct inaccurate information
  • Request deletion of your information
  • Opt out of targeted advertising or the "sale" or "sharing" of your information
  • Obtain a portable copy of your information
  • Not be discriminated against for exercising these rights

Colorado residents

Under the Colorado Privacy Act, Colorado residents have the rights listed above, including the right to opt out of targeted advertising and profiling. You may also appeal a decision we make regarding a rights request.

Other states and regions

Residents of other U.S. states with comprehensive privacy laws (such as California) and individuals in other jurisdictions may have similar rights under applicable law.

How to exercise your rights

Contact us using the details in Section 16. We will verify your request and respond within the timeframe required by applicable law. You may also unsubscribe from emails at any time using the link in any message.

11Email communications

When you subscribe to The Infinite Brief or otherwise opt in, we will send you the communications you've requested. Every marketing email includes an unsubscribe link, and we honor opt-out requests promptly in accordance with the CAN-SPAM Act and other applicable laws. We may still send you non-marketing messages related to an active inquiry or engagement.

12Children's privacy

Our website and services are intended for businesses and professionals. We do not knowingly collect personal information from anyone under the age of 18. If you believe a minor has provided us information, please contact us and we will delete it.

13Third-party links

Our website and communications may link to third-party sites and platforms we don't control. This policy does not apply to those sites. We encourage you to review the privacy policies of any third party you interact with.

14Professional confidentiality

Information you share with us in the course of a consultation or engagement — including a Readiness Checkpoint — is treated as confidential and is not disclosed except as needed to provide our services, with your permission, or as required by law.

15Changes to this policy

We may update this Privacy Policy from time to time. When we do, we'll revise the "Last updated" date above, and material changes will be posted on this page. Your continued use of our website after changes take effect means you accept the updated policy.

16Contact us

If you have questions about this policy or wish to exercise your privacy rights, contact us:

  • The Infinite Paradigm LLC
  • Email: inquiries@theinfiniteparadigm.com
  • Phone: 970.888.2235
  • Colorado · Serving Nationwide

Why us Process Book Services Q&A
0