AI & Security Β· CMMC
Understand where CMMC stands in 2026 and protect controlled unclassified information with Citrix enclaves, security reviews and managed services from Altanora.
The Cybersecurity Maturity Model Certification (CMMC) is the U.S. Department of Defense program that verifies contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Level 1 covers FCI with 15 basic requirements. Level 2 covers CUI with the 110 requirements of NIST SP 800-171 Rev 2. Level 3 adds requirements from NIST SP 800-172 for the most sensitive programs.
Altanora helps defence suppliers keep CUI off endpoints with Citrix enclaves, harden their access environment, and keep evidence ready for self-assessments and future certification.
Sources: DoD, Federal Register and DFARS. Status as of September 2026.
Practical steps to protect CUI and reduce assessment scope.
Keep CUI inside a managed Citrix enclave so it never lands on user devices. Learn more.
Citrix and NetScaler security health checks against hardening guidance and known CVEs.
Citrix SecurAccess ZTNA and Citrix deviceTRUST check every user and device.
Session recording, audit logs and documentation to support your SPRS affirmation.
Gap analysis and remediation planning with our compliance partner.
24/7 monitoring and patching so controls stay in place after the audit.
Where the program stands today.
| Requirement | Status (Sep 2026) |
|---|---|
| Phase 1: Level 1 and Level 2 self-assessments in solicitations | In effect since Nov 10, 2025 |
| Annual affirmation in SPRS | In effect |
| Phase 2: Level 2 third-party (C3PAO) certification | Suspended Jul 13, 2026, pending DoD review |
| DFARS 252.204-7012 and NIST SP 800-171 Rev 2 | Still required |
| False Claims Act enforcement for inaccurate claims | Active |
The suspension does not remove the obligation to protect federal data. Check current DoD guidance before bidding.
Results published by Citrix and delivered by Altanora.
Global engineering organization
2,000+
developers on Citrix SecurSpaces, with zero lines of code on endpoints.
Seagate
100%
secure access coverage after replacing VPN with Citrix Zero Trust access.
Aerospace manufacturer
24/7
VIP Priority Support, Citrix subscriptions and professional services.
Altanora client engagement
From Our Clients
βEvery interaction with Altanora has consistently exceeded my expectations. Their deep technical expertise, combined with a comprehensive understanding of our business challenges, allows them to deliver practical solutions and reliably meet their commitments.βFrederic St-Jean, Director of Information Technology
2026 Citrix Evangelist Partner of the Year and a Citrix Platinum Partner since 2006, with 70+ certified engineers across North America.
We support aerospace and defence suppliers in the U.S. and Canada.
We track CMMC changes and tell you what applies today, not what vendors want to sell.
Eligible Citrix security projects may qualify for Citrix Funded Pro Services.
Phase 2 third-party certification was suspended by DoD on July 13, 2026, pending a program review. Phase 1 self-assessments, SPRS affirmations, DFARS 252.204-7012 and NIST SP 800-171 Rev 2 still apply.
Level 1 covers FCI with 15 requirements. Level 2 covers CUI with the 110 requirements of NIST SP 800-171 Rev 2. Level 3 adds NIST SP 800-172 requirements and a government-led assessment.
Revision 2 remains the reference for DFARS 252.204-7012 and CMMC assessments. Revision 3 is not yet required.
An enclave keeps CUI in a controlled environment and off user devices, which can limit your assessment scope to the enclave.
CMMC certification applies to each contractor. Altanora builds and runs environments engineered to support CMMC Level 2 controls, and helps clients prepare their evidence.
Inaccurate affirmations can create False Claims Act exposure, and DOJ continues to pursue these cases.
Talk to us about protecting CUI and preparing your evidence.
Talk to a CMMC Expert