Need-to-Know Info for Companies with CMMC Requirements
Last year, the Department of Defense announced a 3-phase implementation ultimately requiring all DoD contractors to become CMMC compliant. The implementation follows a phased rollout with a deadline approaching this November.
- November 10, 2025 (Phase 1): Official program launch. Contracting officers begin including CMMC Level 1 and 2 self-assessment requirements in new solicitations.
- November 10, 2026 (Phase 2): Mandatory C3PAO certification requirements begin for applicable Level 2 contracts.
- November 10, 2027: Mandatory CMMC certification required for all DoD solicitations and contracts, including Level 3 requirements.
- November 10, 2028: Full program implementation across all contracts and option periods.
In previous years, companies with CMMC requirements were allowed to self-assess their organization and follow NIST standards to protect sensitive information and CUI. As of November 10th, contractors with level 2 requirements must now undergo a third party assessment from a Certified Third-Party Assessment Organization.
What this means for those who haven’t completed a C3PAO Assessment
Simply put, it’s not too late to take action, however, it’s vital to do so quickly! If an organization with CMMC level 2 requirements does not have the required CMMC 2.0 certification, the Department of Defense will not award a new contract, task order, or delivery order. Organizations who fail to meet requirements also cannot renew or extend any existing contracts and are at risk of contract termination.
How HiView Can Help
Preparing for a C3PAO Assessment can seem daunting if your company is not familiar with all of the fine details of the CMMC 2 requirements and how Google Workspace features come into play. Furthermore, requesting an assessment before your team is ready can result in failing, and being handed a list of work to complete before retaking for another try. This is where our team can help!
As a Google Workspace Premier Partner, we help customers to get the appropriate Workspace licenses in place at discounted rates and have a CMMC 2.0 Workspace Readiness Assessment that helps customers have the right Workspace controls in place so they can pass a third-party assessment. This 5-week engagement involves having our team evaluate and compare your Workspace environment using Google’s own CMMC 2.0 Implementation Guide that goes through every control that is evaluated during a C3PAO assessment.

Tip: For an in-depth breakdown of how licensing and technical controls mesh with compliance, read our guide on CMMC 2.0 and Workspace Data.
Our CMMC 2.0 Workspace Readiness Assessment & Implementation
Over the course of 5 weeks, we work with you to highlight gaps and implement necessary changes with limited time required from your team. We will conduct Technical Discovery sessions to analyze existing features and controls in place related to the areas a C3PAO will review including Access Control, Audit & Accountability, Configuration Management, Identification & Authentication, Systems and Communications Protection, Systems & Information Integrity, and so on. We then share a CMMC 2.0 Security Assessment Scorecard to establish a baseline for compliance readiness and to further lay out an Implementation Plan we will follow to get your account properly configured in each area to be assessed. We finally execute the Implementation Plan through a series of configuration sessions while providing change management support to notify your team about upcoming changes.
How to Get Started

Regardless of where you are in your journey of becoming CMMC compliant, we can help. Reach out to [email protected] to start the conversation with one of our Senior Account Executives or to get a quote for an expedited readiness assessment & implementation.


