On July 13, 2026 the Department of War suspended CMMC Phase 2, and the third-party certification assessments that were due to appear in contracts on November 10, 2026 are on hold pending a review. What did not pause is the part you are already on the hook for. Under DFARS 252.204-7012, 7019, 7020 and 7021 you still safeguard covered defense information, still hold a current NIST SP 800-171 self-assessment score in SPRS, still report incidents, and still sign an annual affirmation of continuing compliance. Standing is built for exactly that obligation: it keeps the measurement current and the paperwork defensible, every quarter, without a consultant on retainer.
What Standing does for you
- Measures your environment instead of asking you about it. Read-only connectors to AWS, Azure, Microsoft 365, Google Workspace, Okta and CrowdStrike pull configuration metadata under least-privilege audit roles. Nothing is installed and no CUI is harvested. Every connector is revocable in about 30 seconds.
- Covers the whole standard, not a sample. All 110 NIST SP 800-171 Rev. 2 requirements, mapped to all 320 SP 800-171A assessment objectives, each finding tied to the control ID it affects.
- Keeps your SPRS number honest. Your score is recomputed each cycle against the DoD Assessment Methodology point-deduction weights, so the number you post is the number your evidence supports. It is a directional estimate produced by software, not a C3PAO assessment.
- Carries the annual affirmation with you. The affirmation is a statement of continuing compliance. Standing keeps the underlying measurement, the POA&M and the evidence current so that statement rests on something you can show.
- Refreshes the document set every quarter. System Security Plan, POA&M, evidence library, CUI scoping package and Customer Responsibility Matrix, rebuilt from your current environment rather than edited by hand.
Why quarterly, and not monthly
A small contractor's environment does not change enough in 30 days to justify a monthly document rebuild, and paying for one is how compliance budgets get wasted. Standing runs a full measurement cycle every quarter, which matches how fast a 10 to 100 person environment actually drifts and keeps the annual cost where a small business can carry it. If your environment changes faster than that, or you have a C3PAO date on the calendar, Standard runs the same work every month.
What Standing is not
- It is not an assessment. Assessments run exclusively through independent Cyber AB-authorized C3PAOs. Enclave AI™ prepares you for one; it never performs one.
- It is not a certification, and it does not submit anything to the government on your behalf. You review each deliverable and you decide what gets filed.
- It does not cover Level 3 (CUI Specified). That is not on the platform today, and the FAQ says so plainly.
- It is not multi-entity. One organization, one CUI scope. Multiple subsidiaries under one contract is Sovereign.
The first hour
- Minute 0. Stripe processes the subscription and the welcome email lands with one link inside.
- Minutes 5 to 15. You answer a short intake about your CUI scope and your prime, then connect whichever clouds you want measured. Connect none and you still get an intake-based gap analysis; connect one or more and the findings are measured from your own configuration data.
- Within the hour. Your first readiness package arrives as a PDF: control-gap analysis across the 110-control baseline, your SPRS estimate against your self-reported score, and a remediation list ordered by point recovery.
- Every quarter after that. The cycle re-runs, the documents rebuild from current data, and the first page shows what changed since last time.
How the evidence holds up
Each piece of collected evidence is hashed with SHA-256 and linked into a custody chain that a verifier walks link by link, so any later alteration is detectable. The audit trail is append-only, enforced by PostgreSQL triggers that reject every UPDATE and DELETE rather than by application convention. Each evidence integrity certificate is signed with an Ed25519 key the platform alone holds, so a C3PAO or a contracting officer can verify it offline against our published public key. That is non-repudiation for the certificate, on top of tamper-evidence for the chain.
Start Standing
$6,000 per year, or $500 per month month-to-month. If you ran the $799 CMMC Readiness Snapshot, it credits in full toward your first year.