By The Defense Compliance Report Editorial Team — an independent trade publication on CMMC 2.0 and DIB compliance · Last verified September 2026
Abacode — now "Abacode by Thrive" — offers readiness and managed-security services for Cybersecurity Maturity Model Certification (CMMC). Thrive describes its role as non-certifying. It can help you prepare and monitor your systems, but that is separate from a Level 2 certification assessment by an authorized or accredited C3PAO (CMMC Third-Party Assessment Organization). The assessment rule keeps those roles separate.
Looking for an Abacode CMMC review? This profile is built from public records, not a paid engagement or a hands-on test. The real question isn't what Abacode is. It's what your proposal actually includes. We found two statements on Abacode's own CMMC page that are outdated or overbroad, an assessment-preparation pitch that needs today's contract context, and one gap between "implementation" and what its service sheet actually lists. All are below, with the questions that close them.
Status check, September 23, 2026: The Department of War (the rules still say Department of Defense, or DoD) suspended CMMC Phase II on July 13, 2026. Phase I self-assessment requirements stay in force. Class Deviation 2026-O0025, Revision 3, dated September 3, 2026, retains the suspension; the official sources checked do not announce a replacement Phase II date. What the suspension changed →
This page is for you if you have an Abacode or "Abacode by Thrive" proposal on your desk, you're an Abacode client rechecking your plan, or you're comparing security providers that also offer CMMC help.
It's not for you if you only need the formal Level 2 assessment — start with our C3PAO list — or you handle only Federal Contract Information (FCI), not Controlled Unclassified Information (CUI), and your contract calls for Level 1. In that case, start with the Level 1 self-assessment checklist.
Go straight to the claim check, the price worksheet, or the 12-point scope-and-proof worksheet.
Abacode at a glance: what we verified and what the company says
Abacode is a Tampa company that sells compliance consulting and around-the-clock security monitoring. Thrive announced its acquisition on July 8, 2025, and launched Abacode Compliance Services on April 22, 2026. Here is what we confirmed on September 23, 2026, and what rests only on the company's word.
| Item | What we found | How we know |
|---|---|---|
| What it sells | Compliance consulting — baseline assessment, policies, audit support, a compliance portal — plus security-monitoring capabilities. The proposal must establish which services are included. | Thrive's April 22, 2026 launch release (company-stated) |
| Cyber AB role | The Cyber AB Marketplace lists "Abacode Inc" in its Registered Practitioner Organization (RPO) category. That is a consulting designation, not assessor authorization. | Marketplace record RPO-53727 and official RPO role description, checked September 23, 2026. No renewal or expiration date was visible. |
| Can this offering certify you? | No. Thrive describes its role as a "non-certifying body." Do not treat that as a finding about every affiliated legal entity or an exhaustive Marketplace search. | Thrive CMMC page |
| Owner | Thrive, announced July 8, 2025 | Thrive press release |
| Current package | Abacode Compliance Services, in four phases: baseline assessment, program implementation, audit and certification support, continuous compliance | Thrive product sheet |
| Security operations | A U.S.-based security operations center (SOC) with 24/7 monitoring and incident-response capabilities | Acquisition release and Abacode CMMC page (company-stated; not independently tested) |
| Ties to an assessor | Announced a partnership with A-LIGN on February 5, 2025, pitched as one program that includes third-party certification | Abacode press release |
| Other credentials | Claims a System and Organization Controls (SOC) 2 Type II report and ISO/IEC 27001 information-security-management certification | Abacode CMMC page (company-stated); ask for the documents and their scope |
| Price | No public CMMC price found in the company pages reviewed | Abacode and Thrive pages, checked September 23, 2026 |
| Independent reviews | G2's seller page shows zero reviews. That does not establish that no independent reviews exist elsewhere. | G2 seller page, September 23, 2026 |
Whether Abacode's kind of help is the right buy depends on facts no profile can see. The help you need — readiness help from an RPO, a Managed Security Service Provider (MSSP) watching your systems, a separate CUI enclave (a controlled environment for CUI work), a governance, risk, and compliance (GRC) platform, or only a C3PAO — depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline. The contract clause sets your level, not a checklist. Because a general answer can't settle those for you, use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right kind of help before you request quotes — and do not submit CUI, drawings, or sensitive contract details.
Can Abacode certify my company for CMMC?
Not through the readiness offering described here: Thrive calls its role non-certifying. Under the CMMC Program rule in Title 32 of the Code of Federal Regulations (CFR), C3PAOs conduct Level 2 certification assessments and issue Certificates of CMMC Status (32 CFR 170.9(a)); government assessors handle Level 3.
The Cyber AB built the RPO designation for organizations that serve the defense supply chain as an advisory firm or as a managed service provider (MSP). Their Registered Practitioners (RPs) help find gaps and plan fixes. That's preparation, not assessment.
Think of Abacode as a trainer and the C3PAO as the judge at the weigh-in. The judge cannot also be your recent coach. The Cyber AB's Code of Professional Conduct (CoPC), section 3.3, which C3PAOs must follow under 32 CFR 170.9(b)(2), bars participation in your Level 2 certification assessment if the C3PAO organization or an assessment-team member consulted to prepare you for any CMMC assessment within the prior three years. Changing the individual assessor does not cure the organization's conflict.
A genuine non-certification assessment has a narrow exception under section 3.4: it must follow the specified formal assessment procedures, give no remedial recommendations or consulting advice, and deliver documented results that the C3PAO retains for three years. Calling consulting a "mock assessment" does not make it exempt.
If your contract calls for Level 2 (Self), nobody certifies you at all. Your company assesses itself at least every three years against the 110 requirements in National Institute of Standards and Technology (NIST) SP 800-171 Revision 2, using the applicable assessment objectives in NIST SP 800-171A (June 2018), and posts the result in the Supplier Performance Risk System (SPRS). Its affirming official — a senior company representative with the required authority — affirms at each assessment and annually thereafter, including a required closeout assessment where applicable (32 CFR 170.16; 170.22). The result is a CMMC status, not a certificate. Revision 3 is not the CMMC Level 2 baseline.
| Who | Does | Doesn't |
|---|---|---|
| Abacode's readiness and managed-security offering | Gap assessment, policies, audit prep and support, security monitoring — as included in the agreement | Replace your company's self-assessment responsibility or an independent certification assessment |
| Your company | Maintains its System Security Plan (SSP), which describes the scoped environment and controls; owns its SPRS submissions and required affirmations | Transfer those CMMC responsibilities merely by hiring a vendor |
| A C3PAO you choose | Performs an authorized Level 2 certification assessment when appropriate, including a voluntary one | Participate despite the three-year preparation conflict or another unaddressed impartiality conflict |
| DCMA DIBCAC | The Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center performs Level 3 and other government-led assessments | Act as the private readiness firm in your proposal |
What about the C3PAO Abacode partners with?
On February 5, 2025, Abacode announced a partnership with A-LIGN, which it pitched as one program covering security, compliance, and third-party certification. That announcement does not establish your current assessor, price, or contract arrangement. A partnership is not automatically disqualifying, but it is not automatically conflict-free either: the C3PAO must identify and address applicable financial, business, and other impartiality risks, as well as the three-year preparation bar (Code of Professional Conduct, sections 3.2–3.3).
A bundled pitch still deserves three questions. Who contracts with the assessor, and will you sign a separate assessment agreement? Does Abacode receive any fee or benefit for the referral? Can you pick a different C3PAO without penalty? Then check the assessor's standing yourself. Our A-LIGN profile and C3PAO list show how.
Do you still need a program like this after the Phase II suspension?
The protection work still matters if your covered systems handle CUI — but you may not need the version you were quoted. The July 13, 2026 suspension paused procurement requirements for Level 2 (C3PAO) and Level 3; it did not suspend DFARS 252.204-7012, the Defense Federal Acquisition Regulation Supplement clause for safeguarding covered defense information and reporting qualifying cyber incidents. Its current deviation text, paragraph (b)(2)(i), explicitly retains NIST SP 800-171 Revision 2 for covered contractor information systems subject to that paragraph. Do not substitute Revision 3 just because it is newer.
| What changed on July 13, 2026 | What didn't change | What it means for an Abacode proposal |
|---|---|---|
| During the suspension, new Department solicitations may designate only Level 1 (Self) or Level 2 (Self) (implementation memo) | Applicable DFARS 252.204-7012 obligations and the Revision 2 baseline in the current deviation | Any line priced around "getting certified by November 10, 2026" deserves a second look |
| The November 10, 2026 Phase II transition remains suspended; no replacement date appears in the official sources checked | Phase I self-assessments, SPRS entries, and required affirmations (current CIO notice) | Budget for the protection and evidence work your applicable requirements still call for, not a suspended deadline |
| The implementation memo directs removal of Level 2 (C3PAO) and Level 3 requirements from active procurements and modification of existing contracts | Your actual contract language needs written clarification or modification; a news story is not a contract amendment | For existing contracts, the memo directs action before the next option or scheduled administrative modification. Check your paperwork before you cut or add anything |
You can still choose a C3PAO assessment voluntarily; the Cyber AB's July 15, 2026 statement confirms that route remains available. See our voluntary assessment guide if a prime or customer asks for one anyway. A private request still needs to be distinguished from the Department's current procurement designation.
Three quick checks tell you most of what you need:
- Does your contract include DFARS 252.204-7012? If yes, identify the covered defense information and systems to which its safeguarding duties apply. The suspension did not remove those duties; it also did not put every company system in scope (current clause text).
- Does your contract or your prime's letter name a CMMC level and an assessment type? "Level 2" alone isn't enough. Ask in writing: Level 2 (Self) or Level 2 (C3PAO)? Our flow-down guide shows how.
- Do drawings or specs arrive marked CUI? If yes, you need to know every system they touch. A missing marking does not settle the question: the clause's covered-defense-information definition also addresses protected information collected, developed, received, transmitted, used, or stored in support of contract performance. Not sure? Start with FCI vs. CUI and get the contract/data question resolved in writing.
No web page — including this one — can tell you your CMMC level. Your contract does. Those three checks are exactly where to look.
If you can answer those three questions, you're most of the way to knowing which assessment — and which kind of help — your situation calls for. Find My CMMC Path is described on its live landing page as a category router using your contract, data, IT environment, timeline, and budget. Use it to organize the next decision, not to replace the requirement in your contract.
What Abacode actually does — and what stays your job
Abacode's current package is described in four phases on Thrive's product sheet, from a baseline assessment to ongoing compliance support. Thrive also offers 24/7 security monitoring; verify whether that is included in your quote. The phase called "program implementation" lists policies, a roadmap, and portal setup — it does not specify who configures your systems. That work may be available, but get it in writing.
These are the vendor's service steps, not the government's CMMC phases.
| Phase (Thrive's product sheet, paraphrased) | What's described | What the description doesn't say | Ask for |
|---|---|---|---|
| 1. Baseline assessment | Interviews, review of your IT environment and processes, a current-state report | Whether the report maps to all 110 requirements and their applicable assessment objectives | A sample gap report with that mapping |
| 2. Program implementation | Required policies, an implementation roadmap, compliance portal setup | Who configures multifactor authentication (MFA), endpoints, logging, backups, and cloud settings | A named task list, with technical work identified as included, separately priced, or excluded |
| 3. Audit and certification | Audit prep, audit support, liaison during the audit | Which assessment type the support covers and who performs any independent certification assessment | Who attends assessor interviews and what support is included |
| 4. Continuous compliance | Monitoring against baselines, documentation upkeep, annual policy and risk-assessment updates | How these service tasks support your own required self-assessment and affirmation duties | The review schedule and who signs what |
A roadmap is a map, not the trip. Thrive's CMMC page separately says it helps implement technical controls. Ask whether that work sits inside your quoted package or is sold on top of it.
If Abacode monitors your in-scope systems, account for its services in your assessment
When an outside provider handles your CUI or provides security protection for your in-scope systems, its relevant services must be accounted for in your CMMC assessment. The rule distinguishes a non-cloud external service provider (ESP) from a cloud service provider (CSP), and treats CUI and security protection data differently (32 CFR 170.19(c)(2)(i), Table 4).
Here's how that plays out. Say Abacode's SOC collects firewall and endpoint logs used to protect your in-scope systems. Those logs are security protection data — information used to protect the assessment environment — so the relevant monitoring service is assessed as a Security Protection Asset, an asset or service performing that protective function. If a non-cloud ESP handles CUI, its relevant services are assessed within your assessment scope. The same scoping questions reach a compliance portal that holds security configurations or vulnerability results for your in-scope systems (32 CFR 170.4; 170.19, Table 4).
Holding CUI does not, by itself, make a portal a cloud service. First identify the actual hosting and service model. If you use an external CSP to store, process, or transmit covered defense information — the contract-related protected information defined in DFARS 252.204-7012 — paragraph (b)(2)(ii)(D) requires you to ensure that the service meets security requirements equivalent to the FedRAMP (Federal Risk and Authorization Management Program) Moderate baseline and complies with paragraphs (c)–(g) on incidents, preservation, access, and damage assessment. The current clause text and CMMC cloud rules make the specific offering and its evidence the issue, not a parent-company badge. Our FedRAMP equivalency guide explains what counts.
A CSP handling only security protection data, not CUI, does not acquire a FedRAMP requirement from CMMC solely on that basis; the relevant protective services still fall within the Security Protection Asset treatment in Table 4. Do not treat "no CUI" as "outside our assessment."
Two things to get before you sign:
- A service description and Customer Responsibility Matrix. The rule calls for these documents, with the applicable responsibilities documented or referenced in your SSP (32 CFR 170.16(c) and 170.19; scoping text). Abacode says a Shared Responsibility Matrix is available on request. Whatever the vendor calls it, it should identify what Abacode does and what you do, match the services you actually buy, and support assessment access to relevant people and evidence. See our responsibility matrix guide.
- Evidence of the provider's own status, if it claims one. A non-cloud ESP may pursue its own Level 2 C3PAO assessment, but the ESP rules do not impose a blanket requirement that every provider have a separate CMMC certificate; they require assessment of the relevant services in your scope (32 CFR 170.19, Table 4). Thrive advertises "CMMC-compliant" services, but that wording is not proof of an official CMMC status. Ask whether the specific service is covered by a current status and unique identifier (UID), and obtain the supporting scope and responsibility records. A provider's certificate does not, by itself, make your organization compliant or remove your shared responsibilities.
More on this in CMMC requirements for outside providers and Is my MSP actually CMMC compliant?
The Abacode claim check: its public pages vs. the rules today
We compared what Abacode and Thrive say publicly with the primary sources as they stood on September 23, 2026. One timeline statement is stale, and one certification statement is overbroad. The assessment-preparation offer is not false simply because Phase II is suspended. The other rows identify claims or scope questions your proposal must resolve.
The findings below describe the pages as retrieved on September 23, 2026. They are not findings about the quality of an actual engagement.
| # | What the page says (paraphrased) | What the source says now | Where it stands | What to ask |
|---|---|---|---|---|
| 1 | Abacode can help you prepare for your C3PAO or DIBCAC assessment | The suspension memo changes procurement requirements, not the truth of an assessment-preparation capability. Voluntary C3PAO assessments remain available. | Needs contract context | Which assessment type does your price assume? |
| 2 | Phase 1 is "scheduled to begin" November 10, 2025 | Phase I began then; the Phase II transition remains suspended (current CIO notice). | Out of date | Send your current read of the timeline in writing |
| 3 | A company that handles CUI must achieve certification, which requires a third-party assessment | Level 2 has distinct self-assessment and C3PAO certification-assessment paths. During the suspension, new Department solicitations may designate only Level 1 (Self) or Level 2 (Self). | Overbroad | Reprice for Level 2 (Self) if that's what your contract says |
| 4 | Microsoft Commercial meets FedRAMP Moderate criteria; without International Traffic in Arms Regulations (ITAR) data, Commercial or Government Community Cloud (GCC) may be enough | The external-cloud clause turns on the particular service and covered defense information, including the paragraph (c)–(g) duties. The absence of ITAR data does not, alone, establish compliance. | Offering-specific evidence needed | Which environment will hold our CUI, and what's the written basis? See GCC vs. GCC High |
| 5 | Relationships with C3PAOs; an A-LIGN partnership that includes certification | The assessor must satisfy the preparation bar and address applicable financial/business impartiality risks (CoPC sections 3.2–3.3). | Ask | Any referral fee or benefit? Who contracts with the assessor? How is independence addressed? |
| 6 | Cyber AB RPO | The Abacode Inc record was readable in the RPO category. RPO registration renews annually; no renewal date was visible on this record. | Listing checked | Current Marketplace link for the entity that signs, and the practitioners assigned |
| 7 | SOC 2 Type II and ISO 27001 | Neither establishes a CMMC status. SOC 2 is an attestation examination/report, not a CMMC certification. | Company-stated | The current SOC 2 report under a nondisclosure agreement: auditor, period, exceptions, and scope; the ISO certificate: issuer, scope, and expiry |
| 8 | Has prepared clients for Level 2 assessments by C3PAOs and by DIBCAC with a C3PAO under JSVA | A Joint Surveillance Voluntary Assessment (JSVA) involved a C3PAO and DIBCAC; see the joint-surveillance recognition rule and a contemporaneous assessor announcement. We did not independently verify Abacode client outcomes. | Company-stated | Two references with a similar scope, assessment type, and date; see our JSVA explainer |
To be fair, Abacode gets a lot right. Its December 2025 CMMC Quick Fact Pack dates the program rule and Phase 1 correctly. It describes Level 2 as a third-party assessment or a self-assessment where the solicitation allows. It also treats Plans of Action and Milestones (POA&Ms) as exceptions rather than a plan, and it pushes data-first scoping. Thrive's own CMMC page says plainly that it doesn't certify anyone. Those accurate distinctions deserve credit. The inconsistent pages still need updating; they do not establish the company's intent or how well it delivers the work. Do not treat a suspended deadline as the reason to buy.
Who Abacode fits — and who should look elsewhere
Abacode's kind of help can fit a company that handles CUI and wants one outside team to build its compliance program and then keep watching its systems — if the proposal actually includes both. A broad Level 2 package is not automatically justified by an FCI-only Level 1 requirement, although that company may still need managed security for other reasons. And readiness support is the wrong category if all you need is the formal assessment.
These are our judgments, drawn from the verified facts above. They don't rate how well Abacode does the work.
| Your situation | Fit for Abacode's kind of help | Why | If not, where to go |
|---|---|---|---|
| You handle CUI, need Level 2, and have thin IT or security staff | Worth comparing if the required work is included | You're considering both the build and someone to watch afterward; verify each is included | — |
| You handle CUI and already have a capable IT provider | Partial | Pay only for the gaps; avoid paying twice for monitoring | Narrower readiness help — see RPO vs. MSP |
| Your CUI sits with a few people or one workflow | Depends | A genuinely separated CUI environment may narrow scope; shared protective services and connections still matter (scoping rule) | Provider categories |
| You're ready and just need the formal assessment | Wrong category | Your next step is an assessor | C3PAO list |
| You handle FCI only and your contract calls for Level 1 | Compare narrower help before a Level 2 package | Level 1 is 15 requirements and a yearly self-assessment with affirmation (CIO summary) | Level 1 checklist |
| You don't know your level or whether you hold CUI | Too early to tell | The contract and the data come first | FCI vs. CUI |
If you can't tell which row is yours, settle that before any sales call. The category comes before the company.
What will Abacode cost?
We did not find public CMMC pricing in the Abacode and Thrive pages reviewed. Request a scoped quote. The useful move is to make every proposal show the same pieces, over the same period, with unknowns left blank instead of counted as zero.
Use this worksheet with Abacode and any provider you compare it to. Pick one comparison period — say, the first 12 months — and note the real contract term separately. It's a scope template, not a price estimate.
| Cost piece | Record it as | Watch for | Provider A amount | Provider B amount | Period | Notes |
|---|---|---|---|---|---|---|
| Your own staff time | One-time hours and hours per month; a loaded hourly cost only if you know it | This may not show up on a vendor quote, but it's real | ||||
| Readiness and advisory work | One-time fee and what it covers | Whether onboarding already includes the gap assessment | ||||
| Hands-on technical work | Project fee or hourly rate | Whether "implementation" means configuration or just a roadmap | ||||
| Recurring compliance service | Monthly or annual fee, billing unit, minimum term | Normalize to the same period before comparing | ||||
| Recurring security monitoring | Monthly or annual fee and what it's billed per (user, device, site) | Paying twice if your current IT provider already monitors | ||||
| Cloud, licenses, equipment | One-time and recurring, listed separately | What's resold, what's included, what you already own | ||||
| Formal assessment, if you need one | Separate assessor price or an explicitly identified bundled line | Level 2 (Self) does not require a C3PAO certification-assessment fee. Include one only for a separately justified voluntary or contractual purchase. | ||||
| Renewal, changes, and exit | Rates or fees in the contract | Price increases, change orders, export and termination fees |
Copy this blank worksheet and complete it in your approved working environment. Do not submit CUI, drawings, or sensitive contract details through this page.
For background on assessment effort versus implementation and recurring services, see our CMMC Level 2 cost guide and managed compliance pricing. Government burden estimates and other providers' prices are not Abacode quotes.
Before you sign: the 12-point scope-and-proof worksheet
A service description tells you what a provider can do. A statement of work tells you what you're buying. Send these twelve checks to Abacode, record each answer, and leave anything unanswered marked that way.
| # | Check | Why it matters | Ask for in writing |
|---|---|---|---|
| 1 | Who signs | Thrive announced the acquisition in July 2025; the Marketplace record is named "Abacode Inc" | The legal entity on the contract, the package name and version, any subcontractors, and whether older Abacode materials are part of the deal |
| 2 | Current RPO status and people | RPO registration renews every year | A current Marketplace link for the signing entity and the names of the Registered Practitioners on your account |
| 3 | Assessment type assumed | New Department solicitations may designate only Level 1 (Self) or Level 2 (Self) during the suspension (current direction) | Which type the price assumes, and what changes if a verified later requirement or a separately chosen voluntary assessment calls for Level 2 (C3PAO) |
| 4 | Scope boundary | How many seats you have doesn't set your assessment scope; CUI flows, protective services, and the asset categories matter (32 CFR 170.19) | A data-flow diagram and asset list for CUI and FCI, relevant protective services, and who approves scope |
| 5 | Documents you'll own | The service sheet lists a baseline report, policies, and a roadmap | A gap report mapped to all 110 Level 2 requirements and applicable assessment objectives; an SSP; a remediation plan for actual gaps; any permitted assessment POA&M; acceptance criteria; and who keeps them current |
| 6 | Advice vs. hands-on work | "Program implementation" lists policies, a roadmap, and a portal (product sheet) | Who configures MFA, endpoints, logging, backups, and cloud settings — and the price if it's separate |
| 7 | Monitoring and incidents | DFARS 252.204-7012 requires rapid reporting within 72 hours of discovering a cyber incident meeting paragraph (c)(1)'s trigger — not every alert. The contractor retains that duty (clause (a), (c)) | Monitoring scope, hours, escalation, who drafts and submits the report, and who preserves the required evidence; see incident reporting |
| 8 | Portal and cloud | The portal may hold documents, evidence, CUI, or security protection data; hosting model and data type determine the applicable route (scoping table) | What it will hold, who hosts it, the service boundary, and — for an external cloud handling covered defense information — the FedRAMP Moderate/equivalency and paragraph (c)–(g) basis |
| 9 | Responsibility matrix | An outside provider's relevant services must be accounted for in your assessment (32 CFR 170.19) | The service description and Customer Responsibility Matrix (or equivalent Shared Responsibility Matrix) mapped to your SSP, plus access to relevant staff and evidence |
| 10 | Assessor independence | The preparation conflict and other impartiality duties still apply to the proposed assessment arrangement (CoPC) | Any referral fee or benefit, who engages the assessor, whether there is a separate agreement, freedom to select an assessor, and the documented independence review |
| 11 | Full price | No public price was found in the company pages reviewed | The completed price worksheet above, with bundled items counted only once |
| 12 | Exit | If your evidence lives in the provider's portal, you need an agreed way to retrieve it | Export formats for your SSP, POA&M and other remediation records, policies, evidence, and logs; admin rights; transition help; deletion terms |
For each check, record:
Copy this blank worksheet and complete it in your approved working environment. Do not submit CUI, drawings, or sensitive contract details through this page.
A Plan of Action and Milestones (POA&M) records gaps and the planned fixes. A working remediation list is not automatically an allowed CMMC assessment POA&M: 32 CFR 170.21 limits which gaps can remain at assessment and when they must be closed. Do not accept "we will put it on the POA&M" as the whole answer.
For each check, record:
"Accepted for our purchasing decision" means you're satisfied enough to buy. It is not a CMMC finding, a score, or proof of compliance. Every check starts as "Not answered," and blank never means yes.
A worked example: a machine shop reads the proposal
This example is fictional. It isn't an Abacode quote, a real customer, or a real outcome.
Say you run a 30-person machine shop. Four engineers open drawings marked CUI. Your prime's letter just says "Level 2." Before anything else, you email the prime one question — Self or C3PAO? The prime writes back: Level 2 (Self). Your contracts lead checks that clarification against the governing agreement before the team scopes the purchase.
Now a proposal arrives. It lists a baseline assessment, policies, an SSP, portal access, quarterly reviews, and 24/7 monitoring. It excludes endpoint configuration and moving email to a government cloud. There are no prices yet.
| Check | What you have | Status | Next step |
|---|---|---|---|
| 3. Assessment type | The proposal talks about "certification support" | Company-stated only | Ask them to price for Level 2 (Self) and show any C3PAO line separately |
| 4. Scope | Four CUI users; the shared file server isn't mapped | Not answered | Map where the drawings travel before accepting a four-seat scope |
| 6. Hands-on work | Endpoint configuration is excluded in writing | Document received — needs review | Get it quoted by Abacode or your current IT provider; the budget isn't complete yet |
| 8. Portal | Nothing about CUI in the portal | Not answered | Keep CUI out of the portal until this is answered |
| 11. Price | Not quoted | Not answered | Leave it blank. Don't total it as zero |
You haven't proved Abacode is good or bad. You've found the missing work and the unknowns — before signing, when they're cheap to fix.
Already an Abacode client? What to recheck now
Two things changed around you: the owner and the CMMC timeline. Neither change, by itself, cancels your agreement or your applicable duty to protect covered information. Both are good reasons to recheck what you're paying for.
- Who you're contracting with. Ask whether your agreement moved to a Thrive entity, and whether your team, SOC, or portal changed.
- Anything tied to the November 2026 date. If you booked a C3PAO slot or paid a rush fee only to beat that deadline, check whether any contract still requires it and what the cancellation terms say. Our spend triage guide walks through it.
- Your exports. Make sure you can pull your SSP, POA&M, policies, and evidence out of the portal today, not just someday.
- Your affirmation. It's still yours. If a senior official at your company signs it, they're vouching for the program, whoever runs it. See annual affirmation.
If you decide to move, our guide to switching CMMC providers mid-engagement covers what to take with you.
What we verified for this Abacode CMMC profile
On September 23, 2026, we read Thrive's acquisition release (July 8, 2025), its Abacode Compliance Services launch release (April 22, 2026), its product sheet and CMMC page, Abacode's CMMC page and CMMC Quick Fact Pack, and Abacode's A-LIGN partnership release. We checked the Cyber AB's RPO role description and Abacode Inc Marketplace record, the Department of War CIO's current CMMC notice, the July 13 implementation memo, Class Deviation 2026-O0025 Revision 3 and its relevant clause text, 32 CFR 170.4, 170.9, 170.16, 170.17, 170.19, 170.20, 170.21, and 170.22, and the Cyber AB's Code of Professional Conduct and July 15 statement. The Sources list identifies those records. We did not locate a published reform task-force outcome in the official records checked; a review deadline does not itself restart Phase II.
We did not test Abacode's service delivery or independently verify a named client outcome. G2's seller page showed zero reviews; that is not an internet-wide finding about customer feedback. The Marketplace record confirmed an RPO listing, but did not show a renewal or expiration date. We did not inspect its SOC 2 report, ISO certificate, a specific cloud authorization package, a customer agreement, or a public CMMC price. That's why this page gives you questions instead of a score. Company material shows what a company says. A registry shows a credential. The rule shows an obligation. We kept those three apart throughout.
Other questions buyers ask
Can we keep our current IT provider and still use Abacode?
Possibly, but nothing public settles how that would work for you. Ask for a written split among your company, your current provider, and Abacode that names who configures systems and who supplies evidence. Both providers' relevant services may count in your assessment, so document each provider's responsibilities in the service descriptions and responsibility matrices, tied to your SSP (32 CFR 170.19). Name a lead for every shared task so it does not disappear between providers.
Does Abacode work in GCC High?
Abacode says it operates within GCC High, and Thrive advertises related government-cloud services. GCC High is a Microsoft 365 government environment; it is not another name for Azure Government, Microsoft's separate cloud platform (Microsoft environment comparison). What matters is where your CUI will live. Ask which specific offering holds it and for the evidence supporting its applicable cloud obligations; the product name alone does not prove compliance.
Can we stop maintaining the program after we post a self-assessment?
No. You must maintain the applicable requirements and complete the required affirmations, rather than treat a historical posted result as permanent proof (32 CFR 170.22). You don't have to keep any particular vendor to do that. You do need someone — your team or a provider — to keep the controls running and the evidence current.
Abacode mentions JSVA. Does that matter for us?
JSVA refers to the Joint Surveillance Voluntary Assessment route involving a C3PAO and DIBCAC; 32 CFR 170.20 addresses recognition of qualifying government assessments, while contemporaneous assessor material documents that arrangement. Abacode says it supported clients through it. That is a claim about past experience, not independent proof of a client result or your future outcome. Ask for a reference whose scope looks like yours.
Still not sure which CMMC path fits your company? Use The Defense Compliance Report's Find My CMMC Path tool to see which path and kind of help fit your contract, CUI, environment, and timeline — before you hire anyone.
Sources
Checked September 23, 2026, unless noted.
- Department of War CIO, CMMC program notice and About CMMC — program posture and level distinctions.
- Department of War CIO, Implementing Suspension of CMMC Phase II, July 13, 2026 — new designations, active procurements, and existing-contract action.
- Defense Pricing, Contracting, and Acquisition Policy, current deviation index and Class Deviation 2026-O0025 Revision 3, September 3, 2026 — continuing suspension and applicable DFARS 252.204-7012 text, including Revision 2, external-cloud duties, and incident reporting.
- 32 CFR Part 170: § 170.4; § 170.9; § 170.16; § 170.17; § 170.19; § 170.21; § 170.22 — definitions, assessor role, assessment methods, provider scope, POA&Ms, and affirmations; compare DFARS 252.204-7012 on Acquisition.gov with the applicable deviation text above.
- Cyber AB, Consulting and Implementation roles; Abacode Inc RPO Marketplace record; Code of Professional Conduct v2.0, sections 3.2–3.4; July 15, 2026 statement on voluntary assessments.
- Thrive, acquisition announcement (July 8, 2025); Abacode Compliance Services launch (April 22, 2026); managed-governance product sheet; CMMC services page — company descriptions, not tested performance.
- Abacode, CMMC page; CMMC Quick Fact Pack (December 17, 2025); A-LIGN partnership announcement (February 5, 2025) — attributed company statements.
- G2 Abacode seller page — platform-specific review count; AICPA SOC 2 examination/report guide description — report terminology; Microsoft cloud-environment comparison — Azure versus Microsoft 365 environments.
- 32 CFR 170.20, standards acceptance, and NSF, JSVA announcement (December 12, 2023) — contemporaneous primary material from a participating assessment organization about the historical arrangement, not proof of an Abacode client outcome.
About The Defense Compliance Report
The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on every claim and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.
We are not affiliated with the Cyber AB, the Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency. This page is educational research, not legal, contractual, or compliance advice. Confirm scope and applicability with a CMMC Registered Practitioner (RP) or a qualified federal-contracts attorney. Commercial relationships are covered in our Editorial & Advertising Policy.