Linkedin
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool
Menu Categories
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool
Linkedin
Cart To use Cart please install WooCommerce plugin
Finish Before the Report: The L1 + L2 Sprint That's Right in Every Outcome | Overwatch Tools
Do It With a Map · Part 6 of 6

Finish Before the Report: The L1 + L2 Sprint That's Right in Every Outcome

The CMMC Reform Task Force reports roughly mid-September. We don't know what it will say — and neither does anyone selling you certainty. Here's the plan that holds up regardless.

By Rob Maupin, founder of Overwatch Tools and author of the CMMC Practical Guides series — Book 1 · CMMC Level 1 and Book 2 · CMMC Level 2

Published August 27, 2026. This article reflects the Department of War announcement of July 13, 2026 and reporting available at the time of writing. The CMMC Reform Task Force is expected to deliver findings roughly mid-September 2026, and guidance may change. We will update this article as the situation develops.

Sometime around the middle of September, the CMMC Reform Task Force delivers its findings.

We don't know what those findings will say. We're not going to guess, and we'd be careful with anyone who does. The Department of War suspended Phase II on July 13 and put a review in motion; officials were explicit that a range of outcomes remained on the table, up to and including significant changes to the program itself. Everything past that is speculation dressed up as insight.

So this piece isn't a prediction. It's a schedule.

Because there's a version of mid-September where you're refreshing the news with a knot in your stomach, and there's a version where you read the headline over coffee, note what changed, and go back to work — because your self-assessment is already finished, packaged, and dated. The difference between those two versions of you is roughly three weeks of mapped work that you could start on Monday.

What We Actually Know

Strip out the speculation and a short list of facts survives every scenario:

  • DFARS 252.204-7012 is contract law, not a CMMC artifact. It predates CMMC and it outlives any decision the Task Force makes. If you handle covered defense information, you are contractually obligated to safeguard it today.
  • NIST SP 800-171 is the standard the Department said it will enforce during the interim. Work you do against 800-171 is not work you do against a program that might be reorganized.
  • Phase I self-assessment requirements remain firmly in place — at Level 1 and Level 2 both. What Phase II would have added for CUI handlers is what got suspended.
  • Primes are still gating awards. Your subcontract's flow-down language is an agreement between you and your prime. A Department rollout phase going into abeyance doesn't amend it.
  • "Select government-led assessments" continue. If you're one of the selected, your documentation is the only thing in the room.

The no-regrets argument, in one line

We built the full four-outcome case in SR6: 60 Days Out — CMMC returns streamlined, CMMC returns as-is, CMMC gets replaced, or CMMC is cancelled outright. In all four columns, a documented self-assessment built on NIST SP 800-171 is still the right thing to be holding. There is no outcome where being able to prove you protect federal data turns out to have been a mistake.

That argument is a year old in this series and it hasn't needed revision. What's new is that you've now watched the entire method get built.

The Sprint Is Realistic Because It's Mapped

"Finish your self-assessment in three weeks" is an absurd thing to say to someone staring at a blank page. It's a reasonable thing to say to someone holding a map. Over the last five pieces, that's what this series has been handing over — piece by piece, the shapeless thing got a shape.

  1. MP1 — Start While It's Quiet. The first 30 minutes: run the free gap assessment, get a prioritized roadmap, and replace the blank page with a starting point.
  2. MP2 — The Map, Unfolded. Fifteen practices decomposed into 142 checkable artifacts across policy, procedure, and evidence. Ambiguity, not volume, is what burns the hours.
  3. MP3 — The Settings Are the Evidence. Device and network configuration guides: what to change on a Windows laptop, a phone, a router — and how the screenshot becomes the proof.
  4. MP4 — From Folder Chaos to a Date-Stamped Package. What "done" actually looks like: organized evidence, a system description, MET/NOT MET recorded against every practice, and an affirmation filed in the Supplier Performance Risk System (SPRS).
  5. MP5 — A Small Enclave Beats a Big Migration. For CUI handlers: shrink the boundary instead of hardening the company. 110 practices against a contained scope, with time estimates on every task.

Read end to end, those five pieces are the whole method. Nothing is being withheld for the sales call. The reason a sprint is possible in the weeks that remain is that none of the weeks get spent deciding what to do — which is where DIY implementations historically lose a month before writing a single policy.

The Sprint Calendar

Here's what the remaining window looks like laid out against a calendar, starting from the week this publishes. Level 1 on top, the Level 2 track running alongside it.

This week Aug 27 – Aug 30

Get a baseline. 90 minutes, total.

Run the free assessment against all 15 Level 1 practices — under 30 minutes, no credit card. Read the gap report with whoever handles IT. Book a kickoff consultation. That's the entire ask for week zero, and it's the step that makes every following week schedulable instead of hypothetical.

Week 1 Aug 31 – Sep 4

Scope and the paper layer.

L1: settle what's in scope and what isn't, draft the system description, and work the policy and procedure artifacts from templates matched to your platform — Microsoft 365 or Google Workspace. L2: this is your enclave scoping decision week, and it's the highest-leverage week in the entire Level 2 effort.

Week 2 Sep 7 – Sep 11

Configuration and evidence capture.

L1: work the device and network configuration guides, then capture the screenshots and exports as you go rather than reconstructing them later. L2: platform variant selected — Microsoft 365 GCC High or Google Workspace — dedicated CUI devices identified, enclave build underway against the config guides.

Week 3 · report window Sep 14 – Sep 18

Package, review, affirm.

L1: evidence into the Evidence Locker, MET/NOT MET recorded against each practice, package assembled and date-stamped, affirmation filed in SPRS. L2: SSP and Risk Register edited from pre-filled templates; POAM framework in place. The Task Force news lands somewhere in here, and it lands on a desk where the work is already done or nearly so.

Week 4 · buffer Sep 21 – Sep 25

The week you'll probably need.

Something always runs long — a router nobody has the password to, a vendor who takes four days to answer, the week your actual job gets busy. Most Level 1 clients complete in two to four weeks; the four-week end of that range exists because real businesses have real interruptions. Plan for this week and you'll be pleasantly surprised if you don't use it.

Our Analysis — not a commitment. This calendar reflects what we typically see across small-contractor Level 1 engagements. It is a planning aid, not a promise. Actual duration varies with your existing infrastructure, how many platforms are in scope, who's available on your side, and how quickly questions get answered. We don't attach a week count to Level 2 at all — the Level 2 build is scheduled off the per-task time estimates in the package, against whatever hours you can actually give it.

Let's build your version of this calendar.

Thirty minutes, free, no pitch deck. We'll look at what your contracts actually require, where your evidence stands today, and what a realistic finish date looks like for a business your size.

Book a Free 30-Minute Consultation →

If You Handle CUI, the Sprint Starts With a Decision, Not a Build

Level 2 doesn't compress the way Level 1 does, and we're not going to pretend otherwise. But the part of Level 2 that determines everything else is a decision, and a decision fits inside this window comfortably.

That decision is scope. As MP5 laid out, the difference between a Level 2 effort that a small business can carry and one that eats a year is whether Controlled Unclassified Information lives in a dedicated enclave or is scattered across the whole company. Draw the boundary small and 110 practices apply to a contained environment. Skip that step and they apply to everything you own — including systems that never needed to be in scope, which is where most wasted Level 2 spending goes.

What fits in the weeks between now and the report:

  • The scoping decision. Where CUI actually enters your business, who touches it, and what the smallest defensible boundary around it looks like.
  • The platform variant choice. Microsoft 365 GCC High or Google Workspace — each with its own dedicated enclave configuration guides.
  • The device decision. Which dedicated CUI-only machines the enclave runs on. We supply the configuration guides; you supply and configure the hardware.
  • The build, started. Working from a pre-filled System Security Plan, a POAM framework, a Risk Register, and an evidence checklist — with a time estimate attached to every task so the work schedules against evenings and slow afternoons instead of demanding a dedicated project team.

L2 CUI Enclave Package — $3,495/year

110 practices mapped to 182 defined artifacts across 14 domains · 12 bi-weekly consulting sessions · dedicated enclave configuration guides for Microsoft 365 GCC High or Google Workspace · pre-filled SSP, POAM framework, Risk Register, evidence checklist · time estimates on every task · no Active Directory, no SIEM, no enterprise IT required.

⚠️ Self-Assessment Programs Only. The L2 CUI Enclave Package is scoped for CMMC Level 2 programs eligible for annual self-assessment. Programs required to use a C3PAO are not in scope.

📘 The CMMC Practical Guides series — both volumes are out

The requirement is finite and the scope is negotiable. The gap between those two facts is where small contractors lose the most money, and it's what both volumes are written to close. Plain English, no fear, no enterprise architecture you don't need — written for the owner, IT lead, or whoever got handed this at a 5- to 50-employee firm.

Volume 1 — Level 1. Fifteen practices under FAR 52.204-21, the artifacts that prove them, and the SPRS submission and annual affirmation that close the loop. Commercial Microsoft 365 or Google Workspace is enough. Get Volume 1 on Amazon →

Volume 2 — Level 2. 110 practices from NIST SP 800-171 — but it starts as a scoping decision. Draw a CUI enclave first and most of your company stays outside the boundary, along with most of the cost. Get Volume 2 on Amazon →

Both available on Amazon in Kindle (from $12.99), paperback, and hardcover. See the series →

Which Sprint Is Yours?

Three honest lanes. Most readers of this series are in the first one.

You handle FCI only — sprint Level 1

You have Federal Contract Information (FCI) from federal contracts, no CUI, and FAR 52.204-21 in your agreements. Fifteen practices is your entire requirement. There is no plan of action and milestones at Level 1, no System Security Plan, and no numeric score — each practice is recorded MET or NOT MET, and you file an annual affirmation. This is a genuinely finishable body of work and the calendar above is built for you.

You handle CUI — Level 2, starting with scope

DFARS 252.204-7012 is in your contract and CUI moves through your business. Your sprint between now and the report is the scoping decision, the platform variant, and the start of the enclave build — not a finished Level 2 self-assessment. Note that Level 2 encompasses Level 1, so this isn't two separate compliance efforts stacked on top of each other; it's one boundary drawn correctly.

You're not sure which one you are — that's the consultation

This is the most common lane, and it's not a knowledge gap you should be embarrassed about. The FCI-versus-CUI question turns on your specific contract language and what actually moves through your systems, and getting it wrong in either direction is expensive: under-scope and you've attested to something you can't defend, over-scope and you've bought an enclave you never needed. We won't give you a legal determination in thirty minutes, but we can usually tell you which questions to take to your contracting officer.

💡 Doing it yourself, or having the artifacts built?

Both are legitimate, and they're different purchases. If you have the time and want to own the knowledge, the books are the method in full — Volume 1 covers Level 1 end to end; Volume 2 takes the CUI side, and the enclave scoping decision gets a full treatment there because it's where the money is won or lost. If what you're short on is time rather than understanding, the packages are the same method with the artifacts already built and someone on the call every other week. One isn't a lesser version of the other. They serve different constraints.

If You Need Both

Some contractors carry FCI on one contract line and CUI on another. For those businesses, the two packages stack.

L1 Turnkey Package

$2,495/year
  • 15 practices → 142 artifacts
  • 8 bi-weekly consulting sessions
  • Microsoft 365 or Google Workspace templates
  • 8 device & network configuration guides
  • Evidence Locker and packaged, date-stamped self-assessment documentation
  • Most clients complete in 2–4 weeks (varies)

Limited time: save $500 off the regular $2,995.

Combined L1 + L2 Stack

$5,990/year
  • Everything in both packages
  • 20 bi-weekly consulting sessions total
  • 324 defined artifacts across both levels
  • One scoping conversation covering FCI and CUI together
  • For contractors carrying both obligations

Both levels, one engagement, one calendar.

⚠️ Self-Assessment Programs Only. The L2 CUI Enclave Package and the combined L1 + L2 stack are scoped for CMMC Level 2 programs eligible for annual self-assessment. Programs required to use a C3PAO are not in scope.

Waiting Is a Choice, and It Has a Price

We'll say this once and calmly, because the alternative is the kind of manufactured panic this series was written against.

Nothing bad happens to you on September 15 if you haven't started. There's no penalty attached to that date and no assessor on a plane. What happens is quieter: the awards being gated on compliance right now go to somebody else. Primes are still asking. Solicitations are still asking. Roughly half your competition read the July announcement as permission to stop, and they will spend the autumn re-reading it while you're bidding with a finished package.

There's a cost angle worth being precise about, too. In its July 13 analysis, the Small Business Administration put total compliance costs at as much as ~$388,600 for firms eligible for self-assessment and as much as ~$593,800 for firms requiring third-party assessment. Those are upper-bound total compliance costs — remediation, tooling, platform migration, documentation, and internal labor — not assessment fees, and not typical invoices.

The number that matters for you is the first one, and here's what's actually inside it: labor and rework. Evenings. Documentation written three times because nobody knew what "done" looked like. Systems hardened that never belonged in scope. That figure is not the price of compliance — it's the price of compliance without a map. Structure is what collapses it, which is the argument this entire series has been making in six installments.

What Happens After the Report

Two things, and we'll commit to both now.

We'll publish our read either way. Whatever the Task Force delivers — streamlined program, replacement framework, cancellation, or something nobody's predicting — we'll write the plain-English version of what actually changed and what it means for a 20-person shop, exactly as we did on July 14. If the news is inconvenient for what we sell, we'll say so.

Your package doesn't expire when the news changes. A finished self-assessment is a description of how your business protects federal data, backed by evidence that the controls run. That artifact answers a prime's questionnaire, satisfies DFARS 252.204-7012, supports a government-led assessment, and maps cleanly onto whatever the program becomes — because it was built against NIST SP 800-171, not against a rollout schedule. Programs get restructured. Documented security posture doesn't stop being documented security posture.

The Map Exists. The Only Variable Left Is Whether You Walk It

Six pieces ago this series started with a specific reader: someone who agreed the self-assessment mattered and hadn't started, because the work had no shape. The shape has now been drawn in public — the starting point, the artifact map, the configuration layer, the finished package, the enclave.

What's left isn't information. It's a calendar with three or four weeks on it and a decision about whether this is the month.

Mid-September is coming either way. The only thing you control is what you're holding when it gets here.

Walk in already done.

Book a free 30-minute consultation and we'll map your sprint against a real calendar — what's in scope, what's realistic before mid-September, and what it takes to finish. If you'd rather start on your own, the free assessment tool gives you a baseline in under 30 minutes.

Book a Free 30-Minute Consultation → Run the Free Assessment

About the author

Rob Maupin is the founder of Overwatch Tools, a CMMC compliance practice for small to medium defense contractors, and the author of the CMMC Practical Guides series — CMMC Level 1: A Practical Guide for Small to Medium GovCon Contractors and CMMC Level 2: A Practical Guide for Small to Medium GovCon Contractors, both available on Amazon in Kindle, paperback, and hardcover. He works with 5- to 50-employee GovCon firms on right-sized compliance and is based in the Kansas City area.

Sources & Further Reading

  • U.S. Department of War — "Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements" (July 13, 2026)
  • U.S. Small Business Administration — statement on the suspension of CMMC Phase II (July 13, 2026)
  • SBA Office of Advocacy — "DoW Requests Information for CMMC Reform Task Force" (July 20, 2026)
  • NIST SP 800-171 Rev. 2
  • Overwatch Tools — "60 Days Out: The Move That's Right No Matter What the Task Force Decides"
  • Overwatch Tools — "The Third-Party Audit Went Away. The Obligation Didn't."

This article is provided for informational purposes and does not constitute legal advice. Contractors should review their specific contract terms and DFARS clauses with qualified counsel.

Share Post
  • Twitter
  • Facebook
  • Pinterest
  • Linkedin
The Part-Time CUI Enclave: How...
The Part-Time CUI Enclave: How Small Businesses Do L2 Without Enterprise IT

Comments are closed

Company Address

  • Overwatch Tools, Inc.
  • 300 Woodards Ford Road
  • Chesapeake Virginia 23322
  • E-Mail: info@overwatchtools.com
  • Outervision Capitol Company
  • Privacy Policy

,Copyright © 2025 Overwatch Tools, Inc.

Home
Shop
Contact us
More
More
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool