The Defense Compliance Report Editorial Team · Last reviewed: August 2026 · Last verified: August 29, 2026
The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on regulatory claims and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.
Not affiliated with the Cyber AB, the Department of War / Department of Defense, DCMA DIBCAC, NIST, the SBA, Project Spectrum, any APEX Accelerator, or any U.S. government agency. This is educational research, not legal, contractual, or compliance advice.
Yes — APEX Accelerator CMMC help is real, it is usually free, and most defense contractors should use it before they spend a dollar on a consultant. A counselor can help you locate the controlling clause, work through the difference between Federal Contract Information and Controlled Unclassified Information, walk you through CMMC Level 1, and navigate SAM, PIEE, and SPRS access. What ordinary counseling will not do is take ownership of your System Security Plan, configure your network, sign your CMMC affirmation, or certify you.
Here's the part nobody prints: there is no standardized national APEX CMMC service package. We read the Department's own funding announcement and the published CMMC or cybersecurity pages of accelerators around the country on August 29, 2026. What they actually deliver ranges from a page of links to up to 60 hours of published state-funded cybersecurity consulting. Same national program. Wildly different value, depending on your ZIP code and the local programs layered on top of it.
That gap is worth real money to you, and almost nobody knows how to ask for it. This page shows you exactly what to ask, what can be free, and where the free path stops.
⚠️ Current status — read this before you plan anything
CMMC Phase 1 began November 10, 2025 and is still the active phase. It was originally scheduled to run through November 9, 2026. On July 13, 2026, the Department announced an immediate suspension of the transition to Phase 2, which had been scheduled to begin November 10, 2026. During the suspension, new procurement designations are limited to Level 1 (Self) and Level 2 (Self); new Level 2 (C3PAO) and Level 3 (DIBCAC) designations are suspended. Active solicitations and existing contracts do not rewrite themselves — the Department's implementation memo directs contracting officers to amend or modify them. Department CMMC status · Implementation memo
Practical translation: the transition to new Phase 2 certification requirements is paused. Phase 1 self-assessments are not. DFARS 252.204-7012, applicable DFARS 252.204-7019/-7020 assessment obligations, and the CMMC requirements already written into an applicable solicitation or contract still have to be read exactly as written. The Department directed its Reform Task Force to deliver a report within 60 days of July 13; no final report was posted on the official CMMC pages when we verified this article on August 29, 2026.
Who this page is for — and who should go elsewhere
Use APEX first if you're a supplier who just got hit with a CMMC clause, a prime's flow-down letter, or a readiness quote that made your eyes water, and you need to know what the written requirement actually says.
Use APEX alongside Project Spectrum if you want no-cost training and a readiness tool you can run at your own pace.
You'll still need paid help if you need someone else to own Level 2 scoping, write or repair the SSP, implement technical safeguards, design a CUI environment, organize assessment evidence, or conduct a formal assessment. Start with our CMMC provider categories guide or Who to Hire First for CMMC before you request quotes.
Talk to a federal-contracts lawyer before you talk to anyone else if you believe a NIST SP 800-171 DoD Assessment score, CMMC self-assessment result, or affirmation your company already submitted may have been materially false or misleading. That is a different problem from simply having work left to do, and the order of your phone calls matters.
What APEX Accelerator CMMC help actually includes
Answer capsule: APEX Accelerators are government-contracting assistance centers funded through cost-shared cooperative agreements. For CMMC, the centers we reviewed publish a mix of clause orientation, Level 1 help, SAM/PIEE/SPRS access guidance, training, and referrals. APEX Accelerators are not CMMC certification bodies and do not conduct official Level 2 certification assessments.
Primary sources: FY2026 APEX Accelerator funding announcement · 32 CFR Part 170
Before the table, four definitions we'll use throughout:
- FCI (Federal Contract Information) — information not intended for public release that is provided by or generated for the government under a contract, excluding public information and simple transactional information. The 15 Level 1 safeguarding requirements come from FAR 52.204-21.
- CUI (Controlled Unclassified Information) — information the government creates or possesses, or that an entity creates or possesses for or on behalf of the government, that law, regulation, or government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. When DFARS 252.204-7012 applies to a covered contractor information system, it requires the specified safeguarding and incident-reporting obligations. DFARS 252.204-7012
- C3PAO (CMMC Third-Party Assessment Organization) — an organization authorized or accredited to conduct official CMMC Level 2 certification assessments. The expansion is CMMC, not “Certified.” 32 CFR §§ 170.9 and 170.17
- RPO / RP (Registered Practitioner Organization / Registered Practitioner) — Cyber AB Marketplace designations for advisory providers and practitioners. They can help prepare you; they do not grant a CMMC status.
Here is the whole job, broken into the work that actually has to happen and who owns the result.
| The work | What APEX commonly does | Project Spectrum | Who owns the result |
|---|---|---|---|
| Locate the CMMC and DFARS clauses in a solicitation, contract, or flow-down | Core government-contracting counseling | Educational material | Your company; the written instrument controls |
| Identify the CMMC status named in the written requirement | Helps interpret the clause and formulate questions | Program overview | Contracting officer, prime, and your company based on the written requirement |
| Separate FCI questions from CUI questions | Walks through definitions and asks what documents identify the information | Training and readiness tools | Your company, with the government data owner, contracting officer, prime, or counsel where needed |
| Work through CMMC Level 1's 15 requirements | Common published service; some centers run cohorts | Cyber readiness content | Organization Seeking Assessment (OSA) |
| Frame Level 2 scoping questions | Orientation and referral; depth varies | Readiness content | OSA, often with a paid scoping specialist |
| Navigate SAM, PIEE, and SPRS access | Common procurement-assistance work | Not the primary function | Authorized company users |
| Conduct and submit a Basic NIST SP 800-171 DoD Assessment under DFARS 252.204-7019/-7020 | May explain the mechanics | Readiness support | Contractor |
| Conduct a CMMC Level 1 or Level 2 self-assessment | Some counselors or cohorts walk through the process | Readiness support | OSA |
| Enter the CMMC self-assessment result in SPRS | May demonstrate the workflow | Does not submit it | OSA's authorized user |
| Make the CMMC affirmation | No | No | Your Affirming Official |
| Create or repair an SSP | Usually referral; some partner cohorts and state-funded programs go farther | Templates and guidance | OSA or paid provider |
| Create and close an allowed Level 2 POA&M | Usually referral; Level 1 POA&Ms are not permitted | Guidance | OSA or paid provider |
| Implement MFA, FIPS-validated cryptography, logging, segmentation, or a CUI enclave | No ordinary counseling ownership | No implementation | Your IT team, MSP, MSSP, or enclave provider |
| Run a readiness or mock assessment | Usually referral; funded state programs may cover it | Self-service readiness only | RPO, consultant, or C3PAO under the applicable independence rules |
| Conduct an official Level 2 certification assessment | Never as APEX | No | Authorized or accredited C3PAO |
| Advise on a potentially false prior submission | Not the right first call | No | Qualified federal-contracts attorney |
SPRS is not one number
Here is the distinction most pages miss: “your SPRS score” does not describe every submission. Contractors can have several different records in the same system, and confusing them is how otherwise careful people answer the wrong question.
| SPRS record | What it is | Cadence or currency rule | Who acts |
|---|---|---|---|
| NIST SP 800-171 DoD Assessment summary score under DFARS 252.204-7019/-7020 | A numeric summary score, such as 95 out of 110, produced under the DoD Assessment Methodology | Generally current if not more than three years old unless the solicitation requires a shorter period | Contractor submits a Basic Assessment; DoD posts Medium/High results |
| CMMC Level 1 self-assessment result | The Level 1 assessment record and compliance result; it is not the old 110-point score | Annual; Level 1 POA&Ms are not permitted | OSA enters the result |
| CMMC Level 2 self-assessment result | The assessment score/status data for the 110 Level 2 requirements | Assessment every three years; limited conditional status and POA&M use under 32 CFR § 170.21 | OSA enters the result |
| CMMC affirmation | A separate affirmation of continuous compliance tied to the applicable CMMC UID | After each assessment and annually thereafter where required | Affirming Official |
Primary sources: DFARS 252.204-7019 · DFARS 252.204-7020 · DFARS 252.204-7021 · 32 CFR §§ 170.15–170.22
Our editorial conclusion, and we'll defend it: APEX owns the front door of the CMMC job — written requirements, basic information types, Level 1 navigation, access, training, and referral. Paid technical and assessment providers own the point where somebody must produce, implement, evidence, or independently assess the work.
The handoff point is not universally the first page of the SSP. That was too neat. A partner cohort may help you build Level 1 documentation; a state program may fund real consulting; a capable company may write its own Level 2 SSP. The hard handoff comes when the remaining work needs technical ownership, defensible evidence, contractual advice, or assessment independence that the counselor is not offering.
You may have read elsewhere that APEX Accelerators offer “free gap assessments.” Be careful with that. We found no national APEX requirement to deliver one. Some local programs fund consultant hours that can include gap work, but that is a local or state layer — not a promise attached to the APEX name everywhere.
➡️ Walk into the first call with a real agenda.
Start with our CMMC readiness checklist, then take the 12 APEX questions below. You will get more from a free hour when the counselor can see the written requirement and the exact decision you need resolved.
Do not submit CUI, drawings, technical data, incident details, or sensitive contract files to this or any general web form.
The right provider isn't the same for every contractor
The right CMMC provider isn't the same for every contractor — the category you need depends on the required CMMC status, whether you handle FCI or CUI, the assessment type, your cloud and IT environment, and the contract timeline. The written solicitation, contract, or valid subcontract flow-down sets the requirement — not a checklist and not a website quiz.
If the written requirement is still unclear, use our CMMC Levels guide first. When the requirement is clear but the provider category is not, use Find My CMMC Path to map the situation before you request quotes. Do not submit CUI, drawings, or sensitive contract details.
Is APEX Accelerator CMMC help really free?
Answer capsule: Most APEX assistance is free, but “APEX is always free” is too absolute. The Department's FY2026 funding announcement says most assistance is free and expressly permits program income from client fees. Every center we reviewed offered no-cost counseling, while two published partner-delivered Level 1 cohort models carried a one-time $200 technology fee.
Primary source: FY2026 APEX Accelerator funding announcement, including cost share and program-income provisions
Here's the honest part
There is no standardized national APEX CMMC service package. That's the one thing we'd want you to know before you pick up the phone, and it's the thing most pages on this topic gloss over.
The national program is real and funded. But service depth is built locally by the host — a university, economic development organization, chamber, or state program — and by the partners that host chooses. One center may give you a resource page. Another may run a hands-on cohort. Another may refer you into consultant hours somebody else is paying for.
We know how that sounds. Here's why it's actually good news.
The variation runs in your favor — if you ask correctly
Because the ceiling is much higher than most contractors realize:
- Ohio University APEX currently publishes up to 15 hours of cybersecurity consulting for eligible Ohio businesses preparing for Level 1, with possible additional counseling for businesses expecting to pursue Level 2. Published eligibility includes an Ohio location, fewer than 500 employees, SBDC registration, and an APEX referral. Ohio University APEX services
- Ohio's CyberSECURE launch notice published up to 60 hours of free one-on-one consulting, beginning with an initial 10-hour engagement, for eligible defense contractors. The official March 10, 2025 notice listed a 2-to-500-employee range or the applicable SBA size standard and required connection to an Ohio APEX Accelerator or SBDC. The program is still described on Ohio APEX's program page, but the main state CyberSECURE page returned a 404 when we rechecked it on August 29, 2026. That means the 60-hour figure is a published program cap, not a current seat guarantee. Ohio launch notice · Ohio APEX programs
Two Ohio numbers — 15 and 60 — both officially published, but not interchangeable. Ask which program you are being referred into, how many hours are currently funded, and what the consultant is allowed to deliver. That question can be worth more than most consulting hours you will buy this year.
Now the fee side, stated plainly:
- Washington. Washington APEX publishes a CMMC Level 1 cohort model with a one-time $200 technology fee per person, per company, with cohorts listed through March 2027 when we checked. The program includes structured sessions, templates, Q&A, and partner software access. Washington APEX cohort page
- Tennessee. The Tennessee APEX Level 1 workshop page on the delivery partner's platform publishes the same one-time $200 technology fee, payable to Govology, and describes Totem Technologies training, office hours, templates, and a software trial. Published Tennessee workshop page
Read that carefully, because the detail matters. The published fee is tied to the training platform and software delivery model. It is not proof that ordinary APEX counseling costs $200.
The funding structure explains why local delivery varies. The FY2026 notice anticipated roughly 90 cost-shared cooperative agreements. The federal share is generally capped at 65 percent, or 85 percent for service in a distressed area, and statutory ceilings differ for statewide, sub-state, and tribal service areas. Local hosts and partners build the rest of the service around that structure.
Our take: $200 for a structured Level 1 program that covers scoping, documentation, self-assessment, and SPRS reporting can be an exceptional price-to-value ratio. But do not buy the cohort because of the APEX name alone. Ask whether it is current, what the fee buys, whether attendance is restricted, and what you will have in hand when it ends.
➡️ Find the center that actually serves your business.
Use the Department's APEX locator or the National APEX Accelerator Alliance directory. Then ask about cybersecurity programs, funded consultant hours, cohorts, partner fees, and current eligibility — not just “Do you help with CMMC?”
Why does APEX CMMC help vary so much by location?
Answer capsule: APEX Accelerators operate under individual cost-shared cooperative agreements with separate host organizations. The national funding notice defines broad procurement-assistance outcomes; it does not impose one CMMC curriculum or deliverable list. In our August 29, 2026 review, published service depth fell into five useful tiers.
The Department's FY2026 notice anticipated approximately 90 awards and set federal funding ceilings as high as $1.5 million for statewide coverage and $750,000 for less-than-statewide coverage, with separate limits for certain Bureau of Indian Affairs service areas. The notice expected award issuance between March 31 and July 31, 2026; that was an anticipated schedule, not proof that every award issued on those dates. FY2026 APEX funding notice
The five tiers of APEX CMMC help
This is our classification, not an official APEX designation. Use it to identify what your center actually provides — then ask whether a partner program can move you up a tier.
| Tier | What you get | Verified published example | Typical published cost |
|---|---|---|---|
| 1. Resource bridge | Official links, alerts, and referral to Project Spectrum or other resources | Virginia APEX maintains a CMMC resource page and posted the July 2026 Phase 2 suspension the next day | Free |
| 2. One-on-one navigation | Clause orientation, Level 1 help, registrations, and referral upward | New Hampshire and NorCal publish Level 1 navigation and a clear “not a certifier” boundary | Free |
| 3. Structured training | Workshops or webinars led by an outside practitioner or program partner | APEX-hosted Level 1 and self-assessment webinars appear in public SBA event listings | Often free; verify each event |
| 4. Partner cohort | Multi-session program with templates, office hours, and software access | Washington and Tennessee partner-delivered programs | Published one-time $200 technology fee |
| 5. Funded consulting | One-on-one cybersecurity consulting paid through a state or partner program | Ohio's published 15-hour and up-to-60-hour pathways | Free to eligible businesses while funded |
What we found when we read the network's own pages
We pulled published APEX cybersecurity and CMMC pages on August 29, 2026 and recorded what each page promised, whether a fee was shown, and whether its program-status language was current. This is a dated website review, not a mystery-shopper study and not a judgment about counselor competence.
| Accelerator or program | What the public page showed | Tier | Currency finding |
|---|---|---|---|
| Ohio University APEX | Up to 15 consultant hours for eligible Level 1 preparation; possible additional Level 2 counseling | 5 | Current hour cap published |
| Ohio CyberSECURE launch notice | Official launch notice published up to 60 hours; current Ohio APEX page still describes the program | 5 | Main state landing page returned 404 on recheck; confirm availability |
| Washington APEX | Multi-session Level 1 cohort with $200 technology fee | 4 | Cohorts listed into 2027, but its broader resource page still carried stale timing language |
| Tennessee APEX partner program | Level 1 workshop, Q&A, templates, software trial, $200 technology fee | 4 | Current partner page; verify local enrollment |
| New Hampshire APEX | Level 1 navigation, higher-level framework guidance, tools, and accredited third-party referrals; states it is not a certification body | 2 | Boundary language is current enough to be useful |
| NorCal APEX | Personalized help, Level 1 events, and referrals; states APEX is not a certifier | 2–3 | The same live page also carried obsolete 2020-era CMMC language |
| Virginia APEX | Resource library, Project Spectrum routing, counselor contact, and current suspension alert | 1–2 | The July 14, 2026 suspension post was one of the fastest updates in the sample |
Two findings are worth your attention.
First: the network shares a boundary, but not a service standard. New Hampshire and NorCal publish strikingly similar language: Level 1 navigation is within the counselor's lane; higher-level work gets framework guidance, tools, and referral to independent third parties. That is evidence of a shared operating pattern. It is not a national guarantee that every center provides the same work.
Second: a live APEX page can be stale without the counselor being stale. NorCal's live cybersecurity page still included five-level, 2020-era CMMC language when we checked. Washington's broader resource page carried outdated implementation timing. Virginia, by contrast, posted the July 13 suspension on July 14. This is a website-maintenance finding, not a competence finding. Counselors can receive updates that never make it into the CMS.
That hands you one practical instruction: do not take the date off the webpage. Ask the counselor what changed on July 13, 2026 and what did not. A clean answer should distinguish the Phase 2 transition from Phase 1 Level 1 and Level 2 self-assessments, the continuing DFARS 252.204-7012 baseline, and the need for formal solicitation or contract changes.
Two fast ways to date any CMMC page
- Level 1 is 15 requirements, not 17 practices. Seventeen was the old CMMC 1.0 practice count. A five-level model is also obsolete.
- NIST's current catalog version is not automatically the CMMC-controlling version. NIST withdrew SP 800-171 Revision 2 in May 2024 and superseded it with Revision 3. NIST also withdrew the February 2021 edition of SP 800-172 in May 2026 and superseded it with Revision 3. But 32 CFR Part 170 still incorporates SP 800-171 Revision 2 for CMMC Level 2 and the February 2021 SP 800-172 edition for CMMC Level 3. Unless the Department amends the rule or the applicable contract changes the baseline, a page that silently swaps Revision 3 into the current CMMC control set is wrong. NIST SP 800-171 Rev. 2 record · NIST SP 800-171 Rev. 3 · NIST SP 800-172 record · 32 CFR § 170.2
➡️ Walk in with the questions that surface the good stuff.
The 12-question agenda below is the difference between a pleasant conversation and a documented next step. Print it. Put the written clause next to it. Ask Question 7 even if the counselor never mentions funding.
Can APEX help with CMMC Level 1?
Answer capsule: Yes — Level 1 is the best fit for ordinary APEX CMMC assistance. Level 1 covers information systems that process, store, or transmit FCI for the contract and uses the 15 safeguarding requirements in FAR 52.204-21. The OSA performs an annual self-assessment, enters the result in SPRS, and an Affirming Official makes the required affirmation. Level 1 POA&Ms are not permitted.
Primary sources: 32 CFR § 170.15 · DFARS 252.204-7021
Level 1 is where free help can genuinely close most of the process, for one reason: the requirements are basic safeguarding measures, not the 110-requirement Level 2 architecture. Limit access to authorized users. Control information posted to public systems. Sanitize media before disposal or reuse. Update malicious-code protection. A counselor or structured cohort can translate those into a usable work session.
What a counselor or cohort may help you do:
- Locate the written Level 1 requirement and the relevant clause
- Identify the systems that touch FCI so you can define the Level 1 boundary
- Work through the 15 requirements in plain language
- Document how your company meets each requirement
- Navigate PIEE and SPRS access
- Walk through the mechanics of entering the self-assessment result
What stays yours, no matter who helps:
- The actual safeguards. The requirement is not satisfied because a checklist was completed.
- The assessment result. The OSA owns the self-assessment.
- The affirmation. Your Affirming Official makes it — not the counselor and not the consultant.
- The accuracy of the submission. Help with the screen does not transfer responsibility for what goes into it.
Our closure test: APEX may be enough when the unresolved work is understanding the written Level 1 requirement, mapping the 15 safeguards, and getting through the access and submission process. Escalate when the remaining issue is actual network remediation, managed IT ownership, a disputed information type, or a prior submission you believe may be materially wrong.
For the requirement-by-requirement detail, use our CMMC Level 1 self-assessment checklist.
Can APEX help with CMMC Level 2?
Answer capsule: Partly. CMMC Level 2 uses the 110 security requirements in NIST SP 800-171 Revision 2, organized into 14 families, for applicable CUI environments. During the current Phase 2 suspension, new CMMC procurement designations are limited to Level 1 (Self) and Level 2 (Self). APEX can orient, train, and refer. It does not turn a 110-requirement implementation project into a counseling appointment.
Primary sources: 32 CFR §§ 170.14 and 170.16 · NIST SP 800-171 Revision 2 · Current Department CMMC status
The honest arithmetic: at Level 1 you have 15 requirements and an annual self-assessment. At Level 2 you have 110 requirements across 14 families, a System Security Plan, a scored assessment, evidence for each assessment objective, and — only where the rule permits it — a limited POA&M path that must close within 180 days. A Level 2 self-assessment is generally valid for three years only while the annual affirmation remains current.
That is a project with an owner and a budget, not a counseling session.
Where an APEX counselor is still worth your hour at Level 2:
- Locating the exact written CMMC status and DFARS clauses before you buy anything
- Helping you frame the scope questions that need a definitive technical or contractual answer
- Identifying state programs, MEP services, grants, cohorts, or funded consultant hours
- Routing you to Project Spectrum's no-cost materials
- Referring you to the correct provider category instead of the first company that calls itself “CMMC ready”
Where you usually need someone with paid technical ownership: SSP development or repair, control implementation, GCC High or CUI enclave decisions, External Service Provider and Cloud Service Provider analysis under 32 CFR § 170.19, evidence management, mock assessments, and formal assessment work.
The required category depends on the gap. Use CMMC provider categories, the CMMC Level 2 assessment guide, and our CMMC Level 2 cost guide before you compare proposals.
Version warning: NIST SP 800-171 Revision 3 may be NIST's current publication, but it is not the CMMC Level 2 control set under the current 32 CFR rule. NIST SP 800-172 is relevant to selected Level 3 requirements, not the Level 2 control set. See NIST SP 800-171 vs. SP 800-172 for the clean separation.
Can an APEX Accelerator certify me or perform a C3PAO assessment?
Answer capsule: No. An APEX Accelerator cannot grant a CMMC status. Only an authorized or accredited CMMC Third-Party Assessment Organization may conduct an official Level 2 certification assessment under 32 CFR § 170.17. Level 3 assessments are conducted by DCMA's Defense Industrial Base Cybersecurity Assessment Center.
Primary sources: 32 CFR §§ 170.9, 170.17, and 170.18 · Cyber AB Marketplace
Four roles, and they do not blur:
| Role | What it does | What it cannot do |
|---|---|---|
| APEX Accelerator | Government-contracting counseling, orientation, access help, training, and referral | Grant a CMMC status or conduct the official Level 2 certification assessment |
| RPO / RP | Readiness and advisory work as a Registered Practitioner Organization or Registered Practitioner | Certify the client |
| C3PAO | Official Level 2 certification assessments when authorized or accredited; may also offer other assessment services subject to conflict rules | Promise certification or ignore independence requirements |
| DIBCAC | Level 3 assessments and government-led assessment work | Act as your readiness consultant |
Two things follow from that table, and both save money.
One: the independence rule is more specific than “the same firm can never help and assess.” Under the Cyber AB Code of Professional Conduct, a C3PAO and its assessment team cannot conduct a Level 2 certification assessment for an organization if they served as a consultant to prepare that organization for any CMMC assessment within the previous three years. Ask the prospective readiness provider and C3PAO to disclose the legal entities, personnel, and conflict analysis in writing before you rely on the relationship. Cyber AB Code of Professional Conduct and CAP downloads
Two: a marketplace listing is a status check, not a quality guarantee. Confirm the organization's current Cyber AB status, confirm the people assigned to your engagement, and read the scope of work. The Cyber AB's CMMC Assessment Process explains the operational assessment process; 32 CFR Part 170 and the applicable contract remain controlling.
We do not print a fixed C3PAO or assessor count here. Those counts change, and the current Marketplace is the right place to verify supply.
Is anything I tell an APEX counselor reported to the government?
Answer capsule: Many APEX centers publish their counseling as confidential, but the exact policy is local and counselor confidentiality is not attorney-client privilege. Ask the center what it retains, what it shares, and what secure channel it uses before sending documents. If a prior government submission may have been materially false or misleading, speak with a qualified federal-contracts attorney first.
This is the question contractors think about and rarely ask, so let's answer both halves.
The reassuring half. APEX exists so businesses can ask ordinary government-contracting questions: “What clause is this?” “How do I get access?” “What does my prime need?” “Where do I start?” Centers routinely describe that counseling as confidential. Have those conversations.
The half you need to hear. It is not legal privilege. And the legal issue is not mere imperfection. The Department of Justice's Civil Cyber-Fraud Initiative focuses on knowing failures and false cybersecurity representations under the False Claims Act. If your company already submitted a score, assessment result, or affirmation that you believe was materially false or misleading, that deserves legal advice before a general counseling discussion. DOJ Civil Cyber-Fraud Initiative
Most readers are not in that territory. Many are simply trying to understand a new requirement or close a real gap. That is exactly where the free channel is useful. But “we still have work to do” and “we may have submitted something materially false” are different facts, not two descriptions of the same fact.
And one practical safety note nobody mentions: do not email drawings, technical data, system diagrams, incident details, export-controlled material, or anything marked CUI to a general intake address. Ask what secure channel the center uses. A counselor can help enormously from the clause page, a redacted system description, and general questions without receiving a controlled document.
APEX vs. Project Spectrum vs. MEP vs. a paid provider — where do I start?
Answer capsule: Most contractors should use APEX and Project Spectrum together, then add paid help only where documentation, implementation, evidence, legal analysis, or assessment independence requires it. NIST MEP pricing is local: NIST's own published success stories include both fixed-price CMMC work and a no-cost cybersecurity assessment.
Project Spectrum is now more than a temporary outreach site. Section 1807 of the FY2026 National Defense Authorization Act directs the Department to establish and maintain it as an online platform of digital resources, training, and services for registered small and medium businesses that contract with or seek to contract with the Department. The Department's CMMC page currently directs small and medium businesses to create a no-cost account, watch the webinar, and contact a Cyber Advisor. FY2026 NDAA § 1807 · Department Project Spectrum instructions
So the correct mental model is not “APEX or Spectrum.” It is this: your APEX counselor is the front door and translator. Project Spectrum is the toolbox.
| Channel | What you actually get | Who it serves | Cost reality | Where it stops |
|---|---|---|---|---|
| APEX Accelerator | One-on-one procurement counseling, written-requirement orientation, access help, training, and referrals; some states add funded consulting | Any business pursuing or performing eligible government contracts or subcontracts, subject to local intake rules | Most assistance free; local programs and cohorts can charge disclosed fees | No formal CMMC authority; technical ownership varies locally |
| Project Spectrum | Online resources, training, cyber-readiness tools, and Cyber Advisor access | Registered small and medium businesses contracting with or seeking to contract with the Department | No-cost platform | Does not implement controls, make your affirmation, or certify you |
| NIST MEP center | Manufacturer-focused cybersecurity assessment and implementation support | Manufacturers | Local — NIST publishes both fixed-price and no-cost examples | Not the official Level 2 certifier unless a separate authorized C3PAO engagement applies |
| SBDC / SCORE | General small-business counseling and cyber basics | Small businesses | Often free | Not a substitute for CMMC technical or assessment work |
| State cyber program | Grants, funded consulting, gap work, or remediation planning | Eligibility varies sharply | Can be free while funded | Availability and scope can change |
| Paid RPO / consultant / MSP / MSSP / enclave provider / C3PAO | Documentation, implementation, managed environment, evidence, readiness, or assessment — depending on category | Contractors with an unresolved technical or assessment need | Market rates | Each category has a defined lane; no single provider automatically does everything |
A note on MEP, because the pricing is easy to flatten into a rule that does not exist. NIST's own Arizona MEP case study describes a fixed-price CMMC engagement that included a gap assessment, SSP, and draft POA&M. A separate NIST Impact Dakota case describes a no-cost cybersecurity assessment. Do not assume MEP is free. Do not assume it is paid. Ask the local center for the exact scope and price in the first conversation. Arizona MEP case · Impact Dakota case
Does the July 2026 Phase 2 suspension mean I should wait?
Answer capsule: No — not if you have an active safeguarding, self-assessment, SPRS, or contractual obligation. The suspension halted the transition to Phase 2 and new Phase 2 assessment designations. It did not eliminate Phase 1 Level 1 and Level 2 self-assessment requirements or DFARS 252.204-7012. Read the current written solicitation or contract after any formal amendment or modification.
| What changed | What did not change |
|---|---|
| Transition to Phase 2, originally scheduled for November 10, 2026, was suspended | Phase 1 remains active; it began November 10, 2025 |
| New procurement designations for Level 2 (C3PAO) and Level 3 (DIBCAC) are suspended during the interim | New Level 1 (Self) and Level 2 (Self) designations may continue |
| Pending and future later-phase implementation milestones were put on hold | DFARS 252.204-7012 safeguarding and 72-hour cyber-incident reporting remain where the clause applies |
| Active solicitations and existing contracts are to be amended or modified under the Department memo | A press release alone does not erase text already written into a solicitation, contract, or flow-down |
| The Reform Task Force was directed to report within 60 days | NIST SP 800-171 Revision 2 remains the CMMC Level 2 baseline under the current rule |
| New Phase 2 certification demand in procurements is paused | Applicable DFARS 252.204-7019/-7020 NIST DoD Assessment records and Phase 1 CMMC self-assessment/affirmation records remain distinct obligations |
Primary sources: Department suspension announcement · Implementation memo · DFARS 252.204-7012
Three things follow.
One: the requirement to be accurate did not go down. The government's reliance on self-assessment and government-led assessment did not turn a false representation into a harmless one. Accuracy still matters; knowing falsehoods can create federal exposure.
Two: you have breathing room to scope before you buy. Use the pause to get the written requirement, information types, boundary, and provider category straight. Do not use it to pretend DFARS 252.204-7012 disappeared.
Three: do not plan off a webpage — including this one — without a verification date. The Task Force report or a new Department instruction could change the implementation path. Our CMMC deadlines and timeline carries the running status.
When free APEX help isn't enough
Answer capsule: Free help usually stops where somebody must accept technical ownership, produce defensible documentation, implement controls, organize evidence, give legal advice, or perform an independent assessment. The provider category depends on the unresolved decision — not on who has the loudest sales page.
Use this to figure out what you're actually shopping for.
| If your unresolved next step is… | Free help may get you… | The category you probably need |
|---|---|---|
| “I don't know what the written requirement says” | All the way to a clear clause question | APEX first; contracting officer, prime, or counsel for authoritative resolution |
| “I need to complete Level 1 and enter the result” | Most or all of the process if the safeguards are actually implemented | APEX counselor, free workshop, or Level 1 cohort |
| “I need a Level 2 SSP or an allowed POA&M” | Templates, orientation, and possibly funded state help | RPO, CMMC consultant, or CMMC-focused MSP |
| “I need someone to implement the controls” | Referral | MSP or MSSP with CUI/CMMC experience |
| “I need to decide whether GCC High or an enclave is justified” | A list of questions, not the architecture | Experienced MSSP, cloud architect, or CUI enclave provider |
| “I need to organize evidence across 110 requirements” | Readiness materials | GRC platform as a supporting layer plus a human owner |
| “I need an independent readiness assessment” | Referral; sometimes funded consulting | Qualified readiness assessor, RPO, consultant, or C3PAO under conflict rules |
| “My contract requires an official Level 2 certification assessment” | Referral | Authorized or accredited C3PAO, with independence checked |
| “I think we already submitted something materially false” | Nothing useful as the first move | Qualified federal-contracts attorney |
A word on sequencing, since it is where money gets wasted. Contractors who buy before they define scope can pay to protect systems that never needed to be in the assessment boundary. Scope first. Buy second. Use APEX to identify the written requirement and frame the scope question; pay for technical or contractual validation where the decision exceeds the counselor's lane.
➡️ Map the unresolved decision before you request quotes.
Tell us your level, scope, environment, and timeline, and Find My CMMC Path will route you to the provider category that fits the problem. It takes about two minutes, does not require CUI, and does not obligate you to hire anyone.
Disclosure: The Defense Compliance Report may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category framework, or Cyber AB status checks. We have no compensation relationship with any APEX Accelerator, the National APEX Accelerator Alliance, Project Spectrum, or any government agency. See our editorial and advertising policy.
How to get APEX Accelerator CMMC help: 5 steps
Answer capsule: Find the center serving your business, register as a client, ask specifically for the counselor who handles cybersecurity, bring the written requirement and a redacted agenda, and open a no-cost Project Spectrum account in parallel. Local intake requirements, current programs, fees, and event eligibility vary.
1. Find yours. Use either the Department-managed APEX Accelerator locator or the National APEX Accelerator Alliance directory. Some states have one statewide host; others divide coverage among regional organizations.
2. Register as a client. Ordinary counseling is generally free. Local forms and onboarding steps vary, so do not assume you will get a same-day appointment.
3. Ask for the right counselor. Not every procurement counselor specializes in cyber. Ask for the person who handles CMMC, then ask whether your state has funded consultant hours, a cyber grant, a cohort, an MEP partnership, or an outside training partner.
4. Bring the agenda. Bring the 12 questions below and the page of the solicitation, contract, or flow-down containing the relevant cyber language. Redact sensitive details that are not needed for the first conversation.
5. Open Project Spectrum the same week. Create the no-cost account, use the training and readiness tools, and bring the output as a discussion aid — not as proof that you are compliant.
Bonus: APEX-hosted events also appear in public event listings, including SBA's calendar. Some online sessions accept attendees outside the host state; others restrict enrollment. Confirm eligibility before you plan around another state's workshop.
The 12 questions to ask an APEX counselor about CMMC
Answer capsule: A prepared first meeting produces a written next step instead of a general conversation. The highest-value questions establish the exact written requirement, distinguish the records that belong in SPRS, reveal what the local center delivers, and surface funding before you buy anything.
- What exact CMMC status and DFARS clauses appear in this solicitation, contract, or flow-down, and where are they written?
- Does the government or prime identify what we handle as FCI, CUI, or both — and what document makes that identification?
- What changed on July 13, 2026, and what remained in force for this specific procurement?
- Which SPRS record are we talking about: a DFARS 252.204-7019/-7020 NIST DoD Assessment score, a CMMC self-assessment result, a CMMC affirmation, or more than one?
- Can you walk us through the 15 Level 1 requirements, or do you refer that work to a cohort or partner?
- Do you run CMMC workshops or cohorts, what do they deliver, and is there a fee?
- Does our state have funded cybersecurity consultant hours, a cyber grant, or an MEP cost-share we may qualify for?
- Do you have a Project Spectrum Cyber Advisor or program contact you can introduce us to?
- What can you not help with, so we know exactly where the handoff occurs?
- When you refer clients out, do you refer by provider category or named firm — and are any referred firms sponsors, subrecipients, or paid partners?
- What information do you retain or share, and what secure channel should we use if documents are genuinely necessary?
- What is the next documented decision we should resolve, and what is a realistic timeline for that step?
Question 7 is the one nobody asks. Ask it.
And bring these: the solicitation or contract number, the page containing the cyber clauses, a rough non-sensitive list of systems that touch government information, your SAM/PIEE access status, and the type and date of any SPRS records you know exist. Do not bring or email drawings, technical data, incident details, export-controlled information, or CUI unless you have confirmed both the need and an authorized secure channel.
What we verified, and how
We think you should be able to check our work, so here is exactly what this page is built on.
Regulatory baseline. We checked the current 32 CFR Part 170 text, the 2025 DFARS acquisition rule, current DFARS 252.204-7012/-7019/-7020/-7021/-7025 text, FAR 52.204-21, NIST's publication records for SP 800-171 Revisions 2 and 3 and SP 800-172, and the Department's July 13, 2026 suspension materials.
APEX program structure. We read the FY2026 APEX Accelerator Notice of Funding Opportunity, including its description of free assistance, program income, cost share, anticipated award count, statutory funding ceilings, and anticipated award dates. Department program data published December 2, 2025 reported 92 accelerators, $55 million in federal funding, 26,232 new business clients, and 6,284 training events for the program year running April 1, 2024 through March 31, 2025. Department APEX program-impact data
Local service evidence. We reviewed the public pages named in this article, including Ohio University APEX, Ohio CyberSECURE notices, Washington, Tennessee's partner page, New Hampshire, NorCal, and Virginia. We recorded what each page published, not what we assume the counselor provides off-page.
Assessment ecosystem. We checked the Cyber AB Marketplace and current public downloads for the CMMC Assessment Process and Code of Professional Conduct. We used the current Marketplace instead of preserving a dated secondary-source count of C3PAOs or assessors.
What we did not do. We did not interview a counselor, attend a cohort, receive compensation from a center, or test the registration process in every state. Totem Technologies and Govology appear because they are named in published APEX program materials, not because we endorse them.
What we could not verify. We could not verify that every accelerator offers CMMC assistance, that the Ohio 60-hour pathway has current openings, that any specific cohort still has seats, or that a center has not changed its service since updating its website. Treat every fee, hour cap, and program description as a dated snapshot and confirm it with the center serving your business.
Editorial method. The five service tiers, the “SPRS is not one number” comparison, the two website-currency tests, and the handoff framework are our synthesis of the cited sources. They are editorial decision tools, not regulatory categories. See our methodology, editorial standards, and corrections policy.
This is educational research, not legal, contractual, or compliance advice. Confirm applicability, information classification, scope, and contractual obligations with the appropriate government or prime-contract contact and qualified advisors. The written requirement and the information your systems process, store, or transmit set the path — not this page.
Frequently asked questions
Is APEX Accelerator CMMC help really free?
Most APEX assistance is free, and every center we reviewed offered no-cost counseling. The Department's FY2026 funding notice also permits disclosed client fees as program income. Published partner cohorts in Washington and Tennessee carried a one-time $200 technology fee.
Can an APEX Accelerator certify my company for CMMC?
No. An APEX Accelerator cannot grant a CMMC status. Only an authorized or accredited CMMC Third-Party Assessment Organization conducts an official Level 2 certification assessment, and DIBCAC conducts Level 3 assessments.
What's the difference between an APEX Accelerator and a PTAC?
APEX Accelerator is the current name for the Procurement Technical Assistance Program network formerly known as PTACs. The rebrand began in December 2022 as program management moved from the Defense Logistics Agency to the Department's small-business organization.
Do I have to be a small business to use an APEX Accelerator?
No national small-business-only rule appears in the FY2026 funding notice. It says clients may include any business pursuing or performing the covered contracts or subcontracts. Local intake rules and state programs can impose their own eligibility limits.
Will an APEX counselor post my SPRS score for me?
Do not reduce this to one score. A counselor may explain access and mechanics, but your company owns the Basic NIST DoD Assessment submission and CMMC self-assessment result. Your Affirming Official makes the separate CMMC affirmation.
Can APEX help with CMMC Level 2?
Yes for orientation, written-requirement questions, training, state-program discovery, and referrals. Usually not as the owner of your Level 2 scope, SSP, implementation, evidence, or formal assessment. Some state-funded programs go farther than ordinary counseling.
Is Project Spectrum the same thing as an APEX Accelerator?
No. Project Spectrum is a no-cost online platform with digital resources, training, readiness tools, and advisor access for eligible small and medium defense businesses. APEX Accelerators are local counseling organizations. Use them together.
Does APEX pay for CMMC consultants?
Not as a universal national benefit. Some state and partner programs fund consultant hours through or alongside APEX. Ohio published a 15-hour pathway and an up-to-60-hour CyberSECURE pathway for eligible businesses. Current funding and openings must be confirmed.
Is CMMC still required after the July 2026 suspension?
Phase 1 Level 1 and Level 2 self-assessment requirements remain active. The transition to Phase 2 and new Level 2 C3PAO and Level 3 procurement designations were suspended. DFARS 252.204-7012 remains where it applies, and written solicitations and contracts must be read after any formal amendment or modification.
Is NIST SP 800-171 Revision 3 the current CMMC Level 2 standard?
No. NIST Revision 3 is the current NIST catalog publication, but the current CMMC rule still incorporates NIST SP 800-171 Revision 2 for Level 2. That changes only when the controlling rule or applicable contract changes.
Is what I tell an APEX counselor confidential?
Many centers publish confidential counseling, but the exact policy is local and it is not attorney-client privilege. Ask what the center retains and shares. Do not send CUI or sensitive technical material through a general intake channel.
How do I find my local APEX Accelerator?
Use apexaccelerators.us or the National APEX Accelerator Alliance directory. Confirm that the office serves your business location and ask specifically for its CMMC or cybersecurity counselor.
What if my state's accelerator doesn't do CMMC?
Use Project Spectrum, ask the counselor for regional or national online training, check whether your local NIST MEP center has a cyber service, and ask whether a state program funds consulting. Then use the provider categories guide for the work that remains.
The bottom line
If you take one thing from this page, take this: call your APEX Accelerator before you call anyone you would have to pay. Free counseling costs you an hour. It may prevent a five-figure scoping mistake, reveal a cohort you did not know existed, or route you into funded consulting your first search never showed you.
Then be realistic about the edge. Free help can get you to a clear written requirement, a better scope question, and — for many Level 1 contractors — through most of the self-assessment process. It does not transfer ownership of your safeguards, sign your affirmation, erase a bad prior submission, or grant a CMMC status.
When you hit that line, the question stops being “Who is cheapest?” and becomes “What kind of firm does this unresolved decision require?” Getting that answer wrong is one of the most expensive mistakes in CMMC.
Need help deciding what type of CMMC provider you need? Tell us your level, scope, environment, and timeline, and we'll match the unresolved decision to source-checked provider categories.
Find My CMMC Path → or Request CMMC provider options →
Do not submit CUI, drawings, technical data, incident details, or sensitive contract files.
The Defense Compliance Report is an independent trade publication on CMMC and Defense Industrial Base compliance. Not affiliated with the Cyber AB, the Department of War / Department of Defense, DCMA DIBCAC, NIST, the SBA, Project Spectrum, any APEX Accelerator, or any U.S. government agency. Commercial relationships are disclosed under our editorial and advertising policy. Corrections? See our corrections policy.
