The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

Public-source provider profile · primary-sourced · last verified September 2026

Abacode CMMC: What It Does, What It Can't, and What to Verify

By The Defense Compliance Report Editorial Team — an independent trade publication on CMMC 2.0 and DIB compliance · Last verified September 2026

Abacode — now "Abacode by Thrive" — offers readiness and managed-security services for Cybersecurity Maturity Model Certification (CMMC). Thrive describes its role as non-certifying. It can help you prepare and monitor your systems, but that is separate from a Level 2 certification assessment by an authorized or accredited C3PAO (CMMC Third-Party Assessment Organization). The assessment rule keeps those roles separate.

Looking for an Abacode CMMC review? This profile is built from public records, not a paid engagement or a hands-on test. The real question isn't what Abacode is. It's what your proposal actually includes. We found two statements on Abacode's own CMMC page that are outdated or overbroad, an assessment-preparation pitch that needs today's contract context, and one gap between "implementation" and what its service sheet actually lists. All are below, with the questions that close them.

Status check, September 23, 2026: The Department of War (the rules still say Department of Defense, or DoD) suspended CMMC Phase II on July 13, 2026. Phase I self-assessment requirements stay in force. Class Deviation 2026-O0025, Revision 3, dated September 3, 2026, retains the suspension; the official sources checked do not announce a replacement Phase II date. What the suspension changed →

This page is for you if you have an Abacode or "Abacode by Thrive" proposal on your desk, you're an Abacode client rechecking your plan, or you're comparing security providers that also offer CMMC help.

It's not for you if you only need the formal Level 2 assessment — start with our C3PAO list — or you handle only Federal Contract Information (FCI), not Controlled Unclassified Information (CUI), and your contract calls for Level 1. In that case, start with the Level 1 self-assessment checklist.

Go straight to the claim check, the price worksheet, or the 12-point scope-and-proof worksheet.

Abacode at a glance: what we verified and what the company says

Abacode is a Tampa company that sells compliance consulting and around-the-clock security monitoring. Thrive announced its acquisition on July 8, 2025, and launched Abacode Compliance Services on April 22, 2026. Here is what we confirmed on September 23, 2026, and what rests only on the company's word.

Item — What we found — How we know
ItemWhat we foundHow we know
What it sellsCompliance consulting — baseline assessment, policies, audit support, a compliance portal — plus security-monitoring capabilities. The proposal must establish which services are included.Thrive's April 22, 2026 launch release (company-stated)
Cyber AB roleThe Cyber AB Marketplace lists "Abacode Inc" in its Registered Practitioner Organization (RPO) category. That is a consulting designation, not assessor authorization.Marketplace record RPO-53727 and official RPO role description, checked September 23, 2026. No renewal or expiration date was visible.
Can this offering certify you?No. Thrive describes its role as a "non-certifying body." Do not treat that as a finding about every affiliated legal entity or an exhaustive Marketplace search.Thrive CMMC page
OwnerThrive, announced July 8, 2025Thrive press release
Current packageAbacode Compliance Services, in four phases: baseline assessment, program implementation, audit and certification support, continuous complianceThrive product sheet
Security operationsA U.S.-based security operations center (SOC) with 24/7 monitoring and incident-response capabilitiesAcquisition release and Abacode CMMC page (company-stated; not independently tested)
Ties to an assessorAnnounced a partnership with A-LIGN on February 5, 2025, pitched as one program that includes third-party certificationAbacode press release
Other credentialsClaims a System and Organization Controls (SOC) 2 Type II report and ISO/IEC 27001 information-security-management certificationAbacode CMMC page (company-stated); ask for the documents and their scope
PriceNo public CMMC price found in the company pages reviewedAbacode and Thrive pages, checked September 23, 2026
Independent reviewsG2's seller page shows zero reviews. That does not establish that no independent reviews exist elsewhere.G2 seller page, September 23, 2026

Whether Abacode's kind of help is the right buy depends on facts no profile can see. The help you need — readiness help from an RPO, a Managed Security Service Provider (MSSP) watching your systems, a separate CUI enclave (a controlled environment for CUI work), a governance, risk, and compliance (GRC) platform, or only a C3PAO — depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline. The contract clause sets your level, not a checklist. Because a general answer can't settle those for you, use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right kind of help before you request quotes — and do not submit CUI, drawings, or sensitive contract details.

Can Abacode certify my company for CMMC?

Not through the readiness offering described here: Thrive calls its role non-certifying. Under the CMMC Program rule in Title 32 of the Code of Federal Regulations (CFR), C3PAOs conduct Level 2 certification assessments and issue Certificates of CMMC Status (32 CFR 170.9(a)); government assessors handle Level 3.

The Cyber AB built the RPO designation for organizations that serve the defense supply chain as an advisory firm or as a managed service provider (MSP). Their Registered Practitioners (RPs) help find gaps and plan fixes. That's preparation, not assessment.

Think of Abacode as a trainer and the C3PAO as the judge at the weigh-in. The judge cannot also be your recent coach. The Cyber AB's Code of Professional Conduct (CoPC), section 3.3, which C3PAOs must follow under 32 CFR 170.9(b)(2), bars participation in your Level 2 certification assessment if the C3PAO organization or an assessment-team member consulted to prepare you for any CMMC assessment within the prior three years. Changing the individual assessor does not cure the organization's conflict.

A genuine non-certification assessment has a narrow exception under section 3.4: it must follow the specified formal assessment procedures, give no remedial recommendations or consulting advice, and deliver documented results that the C3PAO retains for three years. Calling consulting a "mock assessment" does not make it exempt.

If your contract calls for Level 2 (Self), nobody certifies you at all. Your company assesses itself at least every three years against the 110 requirements in National Institute of Standards and Technology (NIST) SP 800-171 Revision 2, using the applicable assessment objectives in NIST SP 800-171A (June 2018), and posts the result in the Supplier Performance Risk System (SPRS). Its affirming official — a senior company representative with the required authority — affirms at each assessment and annually thereafter, including a required closeout assessment where applicable (32 CFR 170.16; 170.22). The result is a CMMC status, not a certificate. Revision 3 is not the CMMC Level 2 baseline.

Who — Does — Doesn't
WhoDoesDoesn't
Abacode's readiness and managed-security offeringGap assessment, policies, audit prep and support, security monitoring — as included in the agreementReplace your company's self-assessment responsibility or an independent certification assessment
Your companyMaintains its System Security Plan (SSP), which describes the scoped environment and controls; owns its SPRS submissions and required affirmationsTransfer those CMMC responsibilities merely by hiring a vendor
A C3PAO you choosePerforms an authorized Level 2 certification assessment when appropriate, including a voluntary oneParticipate despite the three-year preparation conflict or another unaddressed impartiality conflict
DCMA DIBCACThe Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center performs Level 3 and other government-led assessmentsAct as the private readiness firm in your proposal

What about the C3PAO Abacode partners with?

On February 5, 2025, Abacode announced a partnership with A-LIGN, which it pitched as one program covering security, compliance, and third-party certification. That announcement does not establish your current assessor, price, or contract arrangement. A partnership is not automatically disqualifying, but it is not automatically conflict-free either: the C3PAO must identify and address applicable financial, business, and other impartiality risks, as well as the three-year preparation bar (Code of Professional Conduct, sections 3.2–3.3).

A bundled pitch still deserves three questions. Who contracts with the assessor, and will you sign a separate assessment agreement? Does Abacode receive any fee or benefit for the referral? Can you pick a different C3PAO without penalty? Then check the assessor's standing yourself. Our A-LIGN profile and C3PAO list show how.

Do you still need a program like this after the Phase II suspension?

The protection work still matters if your covered systems handle CUI — but you may not need the version you were quoted. The July 13, 2026 suspension paused procurement requirements for Level 2 (C3PAO) and Level 3; it did not suspend DFARS 252.204-7012, the Defense Federal Acquisition Regulation Supplement clause for safeguarding covered defense information and reporting qualifying cyber incidents. Its current deviation text, paragraph (b)(2)(i), explicitly retains NIST SP 800-171 Revision 2 for covered contractor information systems subject to that paragraph. Do not substitute Revision 3 just because it is newer.

What changed on July 13, 2026 — What didn't change — What it means for an Abacode proposal
What changed on July 13, 2026What didn't changeWhat it means for an Abacode proposal
During the suspension, new Department solicitations may designate only Level 1 (Self) or Level 2 (Self) (implementation memo)Applicable DFARS 252.204-7012 obligations and the Revision 2 baseline in the current deviationAny line priced around "getting certified by November 10, 2026" deserves a second look
The November 10, 2026 Phase II transition remains suspended; no replacement date appears in the official sources checkedPhase I self-assessments, SPRS entries, and required affirmations (current CIO notice)Budget for the protection and evidence work your applicable requirements still call for, not a suspended deadline
The implementation memo directs removal of Level 2 (C3PAO) and Level 3 requirements from active procurements and modification of existing contractsYour actual contract language needs written clarification or modification; a news story is not a contract amendmentFor existing contracts, the memo directs action before the next option or scheduled administrative modification. Check your paperwork before you cut or add anything

You can still choose a C3PAO assessment voluntarily; the Cyber AB's July 15, 2026 statement confirms that route remains available. See our voluntary assessment guide if a prime or customer asks for one anyway. A private request still needs to be distinguished from the Department's current procurement designation.

Three quick checks tell you most of what you need:

  1. Does your contract include DFARS 252.204-7012? If yes, identify the covered defense information and systems to which its safeguarding duties apply. The suspension did not remove those duties; it also did not put every company system in scope (current clause text).
  2. Does your contract or your prime's letter name a CMMC level and an assessment type? "Level 2" alone isn't enough. Ask in writing: Level 2 (Self) or Level 2 (C3PAO)? Our flow-down guide shows how.
  3. Do drawings or specs arrive marked CUI? If yes, you need to know every system they touch. A missing marking does not settle the question: the clause's covered-defense-information definition also addresses protected information collected, developed, received, transmitted, used, or stored in support of contract performance. Not sure? Start with FCI vs. CUI and get the contract/data question resolved in writing.

No web page — including this one — can tell you your CMMC level. Your contract does. Those three checks are exactly where to look.

If you can answer those three questions, you're most of the way to knowing which assessment — and which kind of help — your situation calls for. Find My CMMC Path is described on its live landing page as a category router using your contract, data, IT environment, timeline, and budget. Use it to organize the next decision, not to replace the requirement in your contract.

See which assessment type your contract points to

What Abacode actually does — and what stays your job

Abacode's current package is described in four phases on Thrive's product sheet, from a baseline assessment to ongoing compliance support. Thrive also offers 24/7 security monitoring; verify whether that is included in your quote. The phase called "program implementation" lists policies, a roadmap, and portal setup — it does not specify who configures your systems. That work may be available, but get it in writing.

These are the vendor's service steps, not the government's CMMC phases.

Phase (Thrive's product sheet, paraphrased) — What's described — What the description doesn't say — Ask for
Phase (Thrive's product sheet, paraphrased)What's describedWhat the description doesn't sayAsk for
1. Baseline assessmentInterviews, review of your IT environment and processes, a current-state reportWhether the report maps to all 110 requirements and their applicable assessment objectivesA sample gap report with that mapping
2. Program implementationRequired policies, an implementation roadmap, compliance portal setupWho configures multifactor authentication (MFA), endpoints, logging, backups, and cloud settingsA named task list, with technical work identified as included, separately priced, or excluded
3. Audit and certificationAudit prep, audit support, liaison during the auditWhich assessment type the support covers and who performs any independent certification assessmentWho attends assessor interviews and what support is included
4. Continuous complianceMonitoring against baselines, documentation upkeep, annual policy and risk-assessment updatesHow these service tasks support your own required self-assessment and affirmation dutiesThe review schedule and who signs what

A roadmap is a map, not the trip. Thrive's CMMC page separately says it helps implement technical controls. Ask whether that work sits inside your quoted package or is sold on top of it.

If Abacode monitors your in-scope systems, account for its services in your assessment

When an outside provider handles your CUI or provides security protection for your in-scope systems, its relevant services must be accounted for in your CMMC assessment. The rule distinguishes a non-cloud external service provider (ESP) from a cloud service provider (CSP), and treats CUI and security protection data differently (32 CFR 170.19(c)(2)(i), Table 4).

Here's how that plays out. Say Abacode's SOC collects firewall and endpoint logs used to protect your in-scope systems. Those logs are security protection data — information used to protect the assessment environment — so the relevant monitoring service is assessed as a Security Protection Asset, an asset or service performing that protective function. If a non-cloud ESP handles CUI, its relevant services are assessed within your assessment scope. The same scoping questions reach a compliance portal that holds security configurations or vulnerability results for your in-scope systems (32 CFR 170.4; 170.19, Table 4).

Holding CUI does not, by itself, make a portal a cloud service. First identify the actual hosting and service model. If you use an external CSP to store, process, or transmit covered defense information — the contract-related protected information defined in DFARS 252.204-7012 — paragraph (b)(2)(ii)(D) requires you to ensure that the service meets security requirements equivalent to the FedRAMP (Federal Risk and Authorization Management Program) Moderate baseline and complies with paragraphs (c)–(g) on incidents, preservation, access, and damage assessment. The current clause text and CMMC cloud rules make the specific offering and its evidence the issue, not a parent-company badge. Our FedRAMP equivalency guide explains what counts.

A CSP handling only security protection data, not CUI, does not acquire a FedRAMP requirement from CMMC solely on that basis; the relevant protective services still fall within the Security Protection Asset treatment in Table 4. Do not treat "no CUI" as "outside our assessment."

Two things to get before you sign:

  • A service description and Customer Responsibility Matrix. The rule calls for these documents, with the applicable responsibilities documented or referenced in your SSP (32 CFR 170.16(c) and 170.19; scoping text). Abacode says a Shared Responsibility Matrix is available on request. Whatever the vendor calls it, it should identify what Abacode does and what you do, match the services you actually buy, and support assessment access to relevant people and evidence. See our responsibility matrix guide.
  • Evidence of the provider's own status, if it claims one. A non-cloud ESP may pursue its own Level 2 C3PAO assessment, but the ESP rules do not impose a blanket requirement that every provider have a separate CMMC certificate; they require assessment of the relevant services in your scope (32 CFR 170.19, Table 4). Thrive advertises "CMMC-compliant" services, but that wording is not proof of an official CMMC status. Ask whether the specific service is covered by a current status and unique identifier (UID), and obtain the supporting scope and responsibility records. A provider's certificate does not, by itself, make your organization compliant or remove your shared responsibilities.

More on this in CMMC requirements for outside providers and Is my MSP actually CMMC compliant?

The Abacode claim check: its public pages vs. the rules today

We compared what Abacode and Thrive say publicly with the primary sources as they stood on September 23, 2026. One timeline statement is stale, and one certification statement is overbroad. The assessment-preparation offer is not false simply because Phase II is suspended. The other rows identify claims or scope questions your proposal must resolve.

The findings below describe the pages as retrieved on September 23, 2026. They are not findings about the quality of an actual engagement.

# — What the page says (paraphrased) — What the source says now — Where it stands — What to ask
#What the page says (paraphrased)What the source says nowWhere it standsWhat to ask
1Abacode can help you prepare for your C3PAO or DIBCAC assessmentThe suspension memo changes procurement requirements, not the truth of an assessment-preparation capability. Voluntary C3PAO assessments remain available.Needs contract contextWhich assessment type does your price assume?
2Phase 1 is "scheduled to begin" November 10, 2025Phase I began then; the Phase II transition remains suspended (current CIO notice).Out of dateSend your current read of the timeline in writing
3A company that handles CUI must achieve certification, which requires a third-party assessmentLevel 2 has distinct self-assessment and C3PAO certification-assessment paths. During the suspension, new Department solicitations may designate only Level 1 (Self) or Level 2 (Self).OverbroadReprice for Level 2 (Self) if that's what your contract says
4Microsoft Commercial meets FedRAMP Moderate criteria; without International Traffic in Arms Regulations (ITAR) data, Commercial or Government Community Cloud (GCC) may be enoughThe external-cloud clause turns on the particular service and covered defense information, including the paragraph (c)–(g) duties. The absence of ITAR data does not, alone, establish compliance.Offering-specific evidence neededWhich environment will hold our CUI, and what's the written basis? See GCC vs. GCC High
5Relationships with C3PAOs; an A-LIGN partnership that includes certificationThe assessor must satisfy the preparation bar and address applicable financial/business impartiality risks (CoPC sections 3.2–3.3).AskAny referral fee or benefit? Who contracts with the assessor? How is independence addressed?
6Cyber AB RPOThe Abacode Inc record was readable in the RPO category. RPO registration renews annually; no renewal date was visible on this record.Listing checkedCurrent Marketplace link for the entity that signs, and the practitioners assigned
7SOC 2 Type II and ISO 27001Neither establishes a CMMC status. SOC 2 is an attestation examination/report, not a CMMC certification.Company-statedThe current SOC 2 report under a nondisclosure agreement: auditor, period, exceptions, and scope; the ISO certificate: issuer, scope, and expiry
8Has prepared clients for Level 2 assessments by C3PAOs and by DIBCAC with a C3PAO under JSVAA Joint Surveillance Voluntary Assessment (JSVA) involved a C3PAO and DIBCAC; see the joint-surveillance recognition rule and a contemporaneous assessor announcement. We did not independently verify Abacode client outcomes.Company-statedTwo references with a similar scope, assessment type, and date; see our JSVA explainer

To be fair, Abacode gets a lot right. Its December 2025 CMMC Quick Fact Pack dates the program rule and Phase 1 correctly. It describes Level 2 as a third-party assessment or a self-assessment where the solicitation allows. It also treats Plans of Action and Milestones (POA&Ms) as exceptions rather than a plan, and it pushes data-first scoping. Thrive's own CMMC page says plainly that it doesn't certify anyone. Those accurate distinctions deserve credit. The inconsistent pages still need updating; they do not establish the company's intent or how well it delivers the work. Do not treat a suspended deadline as the reason to buy.

Who Abacode fits — and who should look elsewhere

Abacode's kind of help can fit a company that handles CUI and wants one outside team to build its compliance program and then keep watching its systems — if the proposal actually includes both. A broad Level 2 package is not automatically justified by an FCI-only Level 1 requirement, although that company may still need managed security for other reasons. And readiness support is the wrong category if all you need is the formal assessment.

These are our judgments, drawn from the verified facts above. They don't rate how well Abacode does the work.

Your situation — Fit for Abacode's kind of help — Why — If not, where to go
Your situationFit for Abacode's kind of helpWhyIf not, where to go
You handle CUI, need Level 2, and have thin IT or security staffWorth comparing if the required work is includedYou're considering both the build and someone to watch afterward; verify each is included
You handle CUI and already have a capable IT providerPartialPay only for the gaps; avoid paying twice for monitoringNarrower readiness help — see RPO vs. MSP
Your CUI sits with a few people or one workflowDependsA genuinely separated CUI environment may narrow scope; shared protective services and connections still matter (scoping rule)Provider categories
You're ready and just need the formal assessmentWrong categoryYour next step is an assessorC3PAO list
You handle FCI only and your contract calls for Level 1Compare narrower help before a Level 2 packageLevel 1 is 15 requirements and a yearly self-assessment with affirmation (CIO summary)Level 1 checklist
You don't know your level or whether you hold CUIToo early to tellThe contract and the data come firstFCI vs. CUI

If you can't tell which row is yours, settle that before any sales call. The category comes before the company.

See which kind of help your situation calls for

What will Abacode cost?

We did not find public CMMC pricing in the Abacode and Thrive pages reviewed. Request a scoped quote. The useful move is to make every proposal show the same pieces, over the same period, with unknowns left blank instead of counted as zero.

Use this worksheet with Abacode and any provider you compare it to. Pick one comparison period — say, the first 12 months — and note the real contract term separately. It's a scope template, not a price estimate.

Abacode price-completeness worksheet
Cost pieceRecord it asWatch forProvider A amountProvider B amountPeriodNotes
Your own staff timeOne-time hours and hours per month; a loaded hourly cost only if you know itThis may not show up on a vendor quote, but it's real
Readiness and advisory workOne-time fee and what it coversWhether onboarding already includes the gap assessment
Hands-on technical workProject fee or hourly rateWhether "implementation" means configuration or just a roadmap
Recurring compliance serviceMonthly or annual fee, billing unit, minimum termNormalize to the same period before comparing
Recurring security monitoringMonthly or annual fee and what it's billed per (user, device, site)Paying twice if your current IT provider already monitors
Cloud, licenses, equipmentOne-time and recurring, listed separatelyWhat's resold, what's included, what you already own
Formal assessment, if you need oneSeparate assessor price or an explicitly identified bundled lineLevel 2 (Self) does not require a C3PAO certification-assessment fee. Include one only for a separately justified voluntary or contractual purchase.
Renewal, changes, and exitRates or fees in the contractPrice increases, change orders, export and termination fees

Copy this blank worksheet and complete it in your approved working environment. Do not submit CUI, drawings, or sensitive contract details through this page.

Copy controls need JavaScript. You can still select and copy the visible worksheet or use your browser's print command.

For background on assessment effort versus implementation and recurring services, see our CMMC Level 2 cost guide and managed compliance pricing. Government burden estimates and other providers' prices are not Abacode quotes.

Before you sign: the 12-point scope-and-proof worksheet

A service description tells you what a provider can do. A statement of work tells you what you're buying. Send these twelve checks to Abacode, record each answer, and leave anything unanswered marked that way.

Abacode 12-point scope-and-proof worksheet
#CheckWhy it mattersAsk for in writing
1Who signsThrive announced the acquisition in July 2025; the Marketplace record is named "Abacode Inc"The legal entity on the contract, the package name and version, any subcontractors, and whether older Abacode materials are part of the deal
2Current RPO status and peopleRPO registration renews every yearA current Marketplace link for the signing entity and the names of the Registered Practitioners on your account
3Assessment type assumedNew Department solicitations may designate only Level 1 (Self) or Level 2 (Self) during the suspension (current direction)Which type the price assumes, and what changes if a verified later requirement or a separately chosen voluntary assessment calls for Level 2 (C3PAO)
4Scope boundaryHow many seats you have doesn't set your assessment scope; CUI flows, protective services, and the asset categories matter (32 CFR 170.19)A data-flow diagram and asset list for CUI and FCI, relevant protective services, and who approves scope
5Documents you'll ownThe service sheet lists a baseline report, policies, and a roadmapA gap report mapped to all 110 Level 2 requirements and applicable assessment objectives; an SSP; a remediation plan for actual gaps; any permitted assessment POA&M; acceptance criteria; and who keeps them current
6Advice vs. hands-on work"Program implementation" lists policies, a roadmap, and a portal (product sheet)Who configures MFA, endpoints, logging, backups, and cloud settings — and the price if it's separate
7Monitoring and incidentsDFARS 252.204-7012 requires rapid reporting within 72 hours of discovering a cyber incident meeting paragraph (c)(1)'s trigger — not every alert. The contractor retains that duty (clause (a), (c))Monitoring scope, hours, escalation, who drafts and submits the report, and who preserves the required evidence; see incident reporting
8Portal and cloudThe portal may hold documents, evidence, CUI, or security protection data; hosting model and data type determine the applicable route (scoping table)What it will hold, who hosts it, the service boundary, and — for an external cloud handling covered defense information — the FedRAMP Moderate/equivalency and paragraph (c)–(g) basis
9Responsibility matrixAn outside provider's relevant services must be accounted for in your assessment (32 CFR 170.19)The service description and Customer Responsibility Matrix (or equivalent Shared Responsibility Matrix) mapped to your SSP, plus access to relevant staff and evidence
10Assessor independenceThe preparation conflict and other impartiality duties still apply to the proposed assessment arrangement (CoPC)Any referral fee or benefit, who engages the assessor, whether there is a separate agreement, freedom to select an assessor, and the documented independence review
11Full priceNo public price was found in the company pages reviewedThe completed price worksheet above, with bundled items counted only once
12ExitIf your evidence lives in the provider's portal, you need an agreed way to retrieve itExport formats for your SSP, POA&M and other remediation records, policies, evidence, and logs; admin rights; transition help; deletion terms

For each check, record:

Check number and name:Provider's answer:Document or evidence (name and date):Included / priced separately / excluded / unanswered:Our owner:Next step and due date:Status: Not answered | Company-stated only | Document received — needs review | Accepted for our purchasing decision | Not applicable — reason recorded

Copy this blank worksheet and complete it in your approved working environment. Do not submit CUI, drawings, or sensitive contract details through this page.

Copy controls need JavaScript. You can still select and copy the visible worksheet or use your browser's print command.

A Plan of Action and Milestones (POA&M) records gaps and the planned fixes. A working remediation list is not automatically an allowed CMMC assessment POA&M: 32 CFR 170.21 limits which gaps can remain at assessment and when they must be closed. Do not accept "we will put it on the POA&M" as the whole answer.

For each check, record:

"Accepted for our purchasing decision" means you're satisfied enough to buy. It is not a CMMC finding, a score, or proof of compliance. Every check starts as "Not answered," and blank never means yes.

A worked example: a machine shop reads the proposal

This example is fictional. It isn't an Abacode quote, a real customer, or a real outcome.

Say you run a 30-person machine shop. Four engineers open drawings marked CUI. Your prime's letter just says "Level 2." Before anything else, you email the prime one question — Self or C3PAO? The prime writes back: Level 2 (Self). Your contracts lead checks that clarification against the governing agreement before the team scopes the purchase.

Now a proposal arrives. It lists a baseline assessment, policies, an SSP, portal access, quarterly reviews, and 24/7 monitoring. It excludes endpoint configuration and moving email to a government cloud. There are no prices yet.

Check — What you have — Status — Next step
CheckWhat you haveStatusNext step
3. Assessment typeThe proposal talks about "certification support"Company-stated onlyAsk them to price for Level 2 (Self) and show any C3PAO line separately
4. ScopeFour CUI users; the shared file server isn't mappedNot answeredMap where the drawings travel before accepting a four-seat scope
6. Hands-on workEndpoint configuration is excluded in writingDocument received — needs reviewGet it quoted by Abacode or your current IT provider; the budget isn't complete yet
8. PortalNothing about CUI in the portalNot answeredKeep CUI out of the portal until this is answered
11. PriceNot quotedNot answeredLeave it blank. Don't total it as zero

You haven't proved Abacode is good or bad. You've found the missing work and the unknowns — before signing, when they're cheap to fix.

Already an Abacode client? What to recheck now

Two things changed around you: the owner and the CMMC timeline. Neither change, by itself, cancels your agreement or your applicable duty to protect covered information. Both are good reasons to recheck what you're paying for.

  • Who you're contracting with. Ask whether your agreement moved to a Thrive entity, and whether your team, SOC, or portal changed.
  • Anything tied to the November 2026 date. If you booked a C3PAO slot or paid a rush fee only to beat that deadline, check whether any contract still requires it and what the cancellation terms say. Our spend triage guide walks through it.
  • Your exports. Make sure you can pull your SSP, POA&M, policies, and evidence out of the portal today, not just someday.
  • Your affirmation. It's still yours. If a senior official at your company signs it, they're vouching for the program, whoever runs it. See annual affirmation.

If you decide to move, our guide to switching CMMC providers mid-engagement covers what to take with you.

What we verified for this Abacode CMMC profile

On September 23, 2026, we read Thrive's acquisition release (July 8, 2025), its Abacode Compliance Services launch release (April 22, 2026), its product sheet and CMMC page, Abacode's CMMC page and CMMC Quick Fact Pack, and Abacode's A-LIGN partnership release. We checked the Cyber AB's RPO role description and Abacode Inc Marketplace record, the Department of War CIO's current CMMC notice, the July 13 implementation memo, Class Deviation 2026-O0025 Revision 3 and its relevant clause text, 32 CFR 170.4, 170.9, 170.16, 170.17, 170.19, 170.20, 170.21, and 170.22, and the Cyber AB's Code of Professional Conduct and July 15 statement. The Sources list identifies those records. We did not locate a published reform task-force outcome in the official records checked; a review deadline does not itself restart Phase II.

We did not test Abacode's service delivery or independently verify a named client outcome. G2's seller page showed zero reviews; that is not an internet-wide finding about customer feedback. The Marketplace record confirmed an RPO listing, but did not show a renewal or expiration date. We did not inspect its SOC 2 report, ISO certificate, a specific cloud authorization package, a customer agreement, or a public CMMC price. That's why this page gives you questions instead of a score. Company material shows what a company says. A registry shows a credential. The rule shows an obligation. We kept those three apart throughout.

Other questions buyers ask

Can we keep our current IT provider and still use Abacode?

Possibly, but nothing public settles how that would work for you. Ask for a written split among your company, your current provider, and Abacode that names who configures systems and who supplies evidence. Both providers' relevant services may count in your assessment, so document each provider's responsibilities in the service descriptions and responsibility matrices, tied to your SSP (32 CFR 170.19). Name a lead for every shared task so it does not disappear between providers.

Does Abacode work in GCC High?

Abacode says it operates within GCC High, and Thrive advertises related government-cloud services. GCC High is a Microsoft 365 government environment; it is not another name for Azure Government, Microsoft's separate cloud platform (Microsoft environment comparison). What matters is where your CUI will live. Ask which specific offering holds it and for the evidence supporting its applicable cloud obligations; the product name alone does not prove compliance.

Can we stop maintaining the program after we post a self-assessment?

No. You must maintain the applicable requirements and complete the required affirmations, rather than treat a historical posted result as permanent proof (32 CFR 170.22). You don't have to keep any particular vendor to do that. You do need someone — your team or a provider — to keep the controls running and the evidence current.

Abacode mentions JSVA. Does that matter for us?

JSVA refers to the Joint Surveillance Voluntary Assessment route involving a C3PAO and DIBCAC; 32 CFR 170.20 addresses recognition of qualifying government assessments, while contemporaneous assessor material documents that arrangement. Abacode says it supported clients through it. That is a claim about past experience, not independent proof of a client result or your future outcome. Ask for a reference whose scope looks like yours.

Still not sure which CMMC path fits your company? Use The Defense Compliance Report's Find My CMMC Path tool to see which path and kind of help fit your contract, CUI, environment, and timeline — before you hire anyone.

Sources

Checked September 23, 2026, unless noted.

About The Defense Compliance Report

The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on every claim and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.

We are not affiliated with the Cyber AB, the Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency. This page is educational research, not legal, contractual, or compliance advice. Confirm scope and applicability with a CMMC Registered Practitioner (RP) or a qualified federal-contracts attorney. Commercial relationships are covered in our Editorial & Advertising Policy.

See my CMMC path