The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

Apptega CMMC Review: Independent Profile, CUI Limits, and What to Verify

By The Defense Compliance Report Editorial Team — an independent trade publication on CMMC 2.0 and DIB compliance · Last verified September 2026

Looking for an Apptega CMMC review? Apptega is governance, risk, and compliance (GRC) software that organizes assessments, evidence, and your security plan and fix-it plan. It doesn't fix controls or certify you. Apptega says its product isn't designed to store Controlled Unclassified Information (CUI), and uploading system settings, scans, or logs — or letting an integration pull them in — can put its services inside your assessment scope.

That last point surprises most buyers. The scope map below shows exactly where the line sits, and the 30-minute demo script shows how to test everything else before you sign.

Program status, checked September 24, 2026: CMMC (the Cybersecurity Maturity Model Certification program) remains in Phase 1. On July 13, 2026, the Department of War — still the Department of Defense in the rule text — suspended the planned Phase II transition that had been set for November 10, 2026, along with later implementation milestones. During the suspension, new procurement documents may designate only Level 1 (Self) or Level 2 (Self). We found no replacement Phase II date or published final Reform Task Force outcome in the official materials reviewed. Where a controlling solicitation, contract, or flow-down requires a CMMC self-assessment, the SPRS record and annual affirmation still apply; DFARS 252.204-7012 also remains binding wherever it is in the contract. The current RFO index lists Class Deviation 2026-O0025, Revision 3, dated September 3, 2026, so read the provision and clause numbers in the instrument you actually received. None of this changes what Apptega is — only whether and when new Level 2 (C3PAO) or Level 3 procurement designations return. What the suspension changed →

This page is for you if Apptega was pitched to you, your managed service provider (MSP) wants to run your CMMC program in it, or you're an MSP weighing it for defense clients.

Start somewhere else if you don't yet know whether you handle CUI or only Federal Contract Information (FCI) — read FCI vs. CUI first — or if you only need the Level 1 basics, where our Level 1 self-assessment checklist may be all you need.

Apptega at a glance

Apptega is software that organizes a compliance program across many frameworks, and it's built mainly for the MSPs and consultants who run programs for clients. For CMMC, three things decide the purchase: what data the service will process, store, or transmit; whether its CMMC content follows the current rule; and what the full quote covers.

Question — Short answer (checked September 24, 2026)
QuestionShort answer (checked September 24, 2026)
What is it?Multi-framework GRC software delivered as a cloud service. Apptega describes it as purpose-built for managed service and security providers and consultants; it also sells to in-house teams
What kind of help is it?A GRC platform. Not an assessor, not a consultant, not a managed security provider, and not a secure place for CUI
What it does for CMMCLevel 1 and Level 2 assessment questionnaires, evidence and tasks, crosswalks to NIST SP 800-171 and other frameworks, and System Security Plan (SSP) and Plan of Action and Milestones (POA&M) reports (company-stated)
What it can't doImplement controls, decide your scope, submit your affirmation in SPRS, or give you a CMMC Status
Can it hold CUI?Not under its current public product boundary. Apptega says the product isn't designed to store CUI or other regulated data; we found no Apptega offering in the official FedRAMP Marketplace on September 24, 2026
Where it lands in your scopeDepends on the data it processes, stores, or transmits — including data pulled through integrations; see the scope map below
"CMMC Level 2" badgeShown in its Trust Center; the assessment type, date, boundary, and covered systems aren't public
PriceThree plans; no public dollar price; 14-day no-card trial; no free plan shown on the official pricing page
Best fitMSPs and consultants running programs for several clients; in-house teams carrying CMMC alongside other frameworks while keeping CUI out of Apptega
Start elsewhere ifYou haven't scoped CUI, nobody owns implementation, or your immediate need is a service approved and documented for a CUI workflow
User-rating snapshotsG2 4.7/5 (157 reviews, checked September 23); Capterra 4.6/5 (25 reviews, checked September 24) — usability signals, not CMMC outcomes

Whether Apptega is the right buy depends on things this page can't see: your required CMMC level, whether you handle FCI or CUI, your assessment type, where your systems and data live, and your contract timeline. The contract clause sets your level, not a checklist. Because a general answer can't settle those for you, use The Defense Compliance Report's Find My CMMC Path tool to see whether your next step is a GRC platform like Apptega, readiness help from a Registered Practitioner Organization (RPO), a Managed Security Service Provider (MSSP), or a CUI enclave — before you sit through a demo or request quotes — and do not submit CUI, drawings, or sensitive contract details.

What we checked, and when. On September 23–24, 2026, we read the CMMC Program rule at 32 CFR Part 170; FAR 52.204-21; DFARS 252.204-7012, 252.204-7021, and 252.204-7025; the incorporated NIST publications; official SPRS CMMC and NIST materials; the Department's CMMC page, suspension procedures, and current RFO class-deviation index; Apptega's CMMC, pricing, AI, guide, Trust Center, and community pages; FedRAMP's official Marketplace and data; and dated G2 and Capterra listings. We did not test the product, take a demo, interview Apptega, inspect its private SOC 2 report or customer responsibility matrix, or receive a quote. We could not confirm what its "CMMC Level 2" badge covers, whether it has a private FedRAMP-equivalency package, whether it submits anything directly to SPRS, or whether its in-product CMMC templates share the problems in its public guide.

Where does Apptega land in your CMMC assessment scope?

Apptega's place in your scope depends on the data its service processes, stores, or transmits — including data pulled by integrations — not on the product label alone. If the service handles neither CUI nor Security Protection Data (SPD), it does not meet CMMC's External Service Provider (ESP) definition for that use. If it handles SPD, the services it provides enter the applicable Level 2 or Level 3 assessment scope and are assessed as Security Protection Assets. Put CUI in the cloud service and the FedRAMP requirement applies — while Apptega says the product isn't designed for CUI.

The rule behind this is short. Under 32 CFR 170.4, an ESP is an external person or organization that uses its own people, processes, and technology to provide a service to an Organization Seeking Assessment and, in doing so, processes, stores, or transmits CUI or SPD on the ESP's assets. SPD includes configuration data, log files, data about the configuration or vulnerability status of in-scope assets, and passwords that grant access to the in-scope environment. Then Table 4 of § 170.19 gives the Level 2 result; Table 6 gives the parallel Level 3 result.

What Apptega would process, store, or transmit — CUI or Security Protection Data? — Where that puts the service (§ 170.19, Table 4 for Level 2; Table 6 for Level 3) — What you have to do
What Apptega would process, store, or transmitCUI or Security Protection Data?Where that puts the service (§ 170.19, Table 4 for Level 2; Table 6 for Level 3)What you have to do
Task lists, control owners, plain policy text, and status notes with no system details — with no integration pulling protected dataUsually neitherIt does not meet the CMMC ESP definition for that serviceWrite down what may and may not enter the tool, include integrations in the rule, and spot-check actual use
Configuration exports or screenshots, vulnerability-scan results, log excerpts, data pulled from in-scope cloud or security tools, lists of in-scope assetsSecurity Protection DataThe services are in the applicable Level 2 or Level 3 assessment scope and assessed as Security Protection Assets under the level-specific rulesDocument Apptega in your asset inventory, SSP, and network diagram as appropriate; describe the relationship; get its service description and customer responsibility matrix (CRM)
Passwords, API keys, or service-account credentials for in-scope systemsSecurity Protection DataSame SPD result as the row aboveDon't store them in a GRC tool. Use an approved password vault and rotate any credential already uploaded
SSP or POA&M text that describes system configuration, vulnerabilities, boundaries, or security weaknessesOften SPD; it may also contain CUI depending on the content, source, markings, and contractAt least the SPD result when it contains security-protection details; the CUI row applies if the content is CUIClassify the content before upload. Don't infer the answer from the filename, and keep CUI out of Apptega under its current public product boundary
CUI itself — drawings, controlled technical data, CUI-marked contract files, or screenshots that show CUICUIFor a cloud service, the offering must be FedRAMP Authorized at Moderate or higher under the rule's wording, or meet FedRAMP Moderate equivalency under DoD policy, with the CRM documented in your SSPKeep it out. Apptega says the product isn't designed for CUI, and we found no Apptega offering in the official FedRAMP Marketplace when checked September 24, 2026

At Level 3, Table 6 reaches the same ESP scoping result. Under Table 5, Security Protection Assets receive a limited check against Level 2 and are assessed against the Level 3 requirements relevant to the capabilities they provide.

Think of Apptega as a filing cabinet about your security. Put only index cards in it — who owns what and what's done, with no protected system detail — and it may not meet the ESP definition for that use. Put copies of settings or scan reports in it, and the cabinet becomes part of what the assessor examines. Put CUI itself in it, and the cloud service has to meet the separate CUI-hosting requirements.

Apptega's own position tracks the SPD branch of the rule. Its community notice (read September 24, 2026; the page shows no publication date) says the product "is not designed to store sensitive information such as CUI." It adds that Apptega believes it handles SPD and that its services will be assessed as part of the contractor's CMMC assessment. In plain words: when Apptega processes SPD for your program, plan for its services to be in scope.

That's not a hypothetical data flow. Apptega's March 2025 release notes and current Microsoft Defender for Cloud integration page say the integration pulls cloud-security evidence, auto-completes controls, and updates shared-control scores. Configuration and vulnerability-status data from in-scope assets fit the rule's SPD definition.

Is Apptega a "cloud service provider" under CMMC?

Apptega's hosted software appears to fit the rule's Cloud Service Provider (CSP) definition because it delivers cloud services through a hosted platform. Confirm the classification and data flow in your assessment-scope documentation rather than relying on this label alone. For SPD without CUI, Table 4 reaches the same result for a CSP or another ESP: the services are in scope and assessed as Security Protection Assets. The classification changes the CUI branch because a CSP storing or transmitting CUI must meet the DFARS 252.204-7012 FedRAMP requirement.

If your MSP runs Apptega for you

If your MSP uses its own systems, tools, or people to process your configuration, scan, credential, or log data — in Apptega or anywhere else — the MSP's relevant services are also part of your ESP analysis. Ask your MSP and Apptega for service descriptions and CRMs, document both relationships in your SSP, and map which party owns each requirement. Our guides to CMMC requirements for MSPs and external service provider requirements cover the rest.

If you only handle FCI (Level 1)

Table 4 and the Security Protection Asset rules above are Level 2 rules. At Level 1, the assessment scope includes the people, technology, facilities, and external service providers that process, store, or transmit FCI (§ 170.19(b)). If Apptega will hold FCI, include the service in your Level 1 scope analysis.

Check your own setup: the Apptega Fit Check

Answer five questions and the check tells you where Apptega lands for the use you selected and what to do before you buy. It uses only the choices on the screen — nothing you type — and nothing leaves your browser. If you'd rather not click, the scope map above gives the same answers.

Do not enter CUI, drawings, contract details, network diagrams, credentials, or customer names. This check uses only the choices below and sends nothing anywhere.

Q1. Who is buying?
Q2. What CMMC level does your written solicitation, contract, subcontract, or flow-down require?
Q3. Does your company handle CUI?
Q4. What would go into Apptega?
Q5. What do you need most right now?

Apptega for CMMC: CUI, FedRAMP, GovCloud, and the "CMMC Level 2" badge

No — not under Apptega's current public product boundary. Apptega says its product isn't designed to store CUI, and we found no Apptega offering in the official FedRAMP Marketplace when checked September 24, 2026. Its Trust Center says it leverages AWS GovCloud, but the rule looks at the specific cloud service offering you use: Apptega's application and service boundary, not AWS infrastructure alone.

What the rules say. If you use an outside cloud service for CUI, DFARS 252.204-7012(b)(2)(ii)(D) requires security requirements equivalent to the FedRAMP Moderate baseline. The CMMC rule says the cloud "product or service offering" must be FedRAMP Authorized at Moderate or higher in the Marketplace, or meet Moderate equivalency under DoD policy, with its CRM documented in your SSP (§ 170.16(c)(2) for Level 2 (Self); § 170.17(c)(5) for Level 2 (C3PAO)). FedRAMP's Marketplace changed its display language in 2026 to FedRAMP Certified and Class C (Moderate), but the controlling CMMC and DFARS text still uses "Authorized at Moderate."

What we found. On September 24, 2026, we searched the official Marketplace and its published data and found no Apptega offering. The Marketplace lists AWS GovCloud at Class D (High). Apptega's own notice says external-assessor FedRAMP or CMMC certification isn't on its immediate roadmap; it describes an internal assessment based on FedRAMP guidelines instead. A missing Marketplace listing does not tell us whether Apptega holds an unpublished private equivalency package, so ask directly — but do not upload CUI while that question is unresolved.

Why GovCloud isn't the answer. Renting an office in a secure federal building doesn't mean your office's own locks were inspected. AWS GovCloud's certification covers the AWS offering and boundary. Apptega's application, access controls, administrators, support processes, and customer responsibilities sit on top. For more on that distinction, see AWS GovCloud for CMMC and FedRAMP equivalency for cloud providers.

The "CMMC Level 2" badge. Apptega's Trust Center shows it next to SOC 2 Type II, PCI, NIST CSF, and NIST 800-171 badges. The public page doesn't identify the assessment type, CMMC Status Date, system boundary, assessor, or covered service. Apptega's notice says outside-assessor CMMC certification isn't on its immediate roadmap, so ask before you rely on the badge. Section 170.19 lets a service provider voluntarily obtain a relevant CMMC assessment to reduce effort during the customer's assessment; the scope and type have to match the service you use.

Ask Apptega these six questions, in writing:

  1. Is the badge based on a Level 2 (Self) status, a Level 2 (C3PAO) status, or an internal review against the requirements?
  2. What was assessed — Apptega, a corporate network, or the production platform and support boundary customers use?
  3. What's the CMMC Status Date, and is the status Final or Conditional?
  4. What is the CMMC Unique Identifier? If it is a Level 2 (C3PAO) status, what certificate or assessment evidence identifies the C3PAO and assessed scope? (Our guide to verifying a company's CMMC status explains what a customer can and can't see.)
  5. Can you review the SOC 2 Type II report, including its period, system description, exceptions, and any bridge letter?
  6. What's in Apptega's CRM — which requirements and evidence does Apptega own, and which stay with the customer?

What Apptega does for CMMC — and what it doesn't

Apptega organizes CMMC work: questionnaires, evidence, tasks, crosswalks, and SSP and POA&M reports. It doesn't do the work. It won't configure a firewall, classify your information, decide your assessment scope, submit your affirmation in SPRS, or assess you.

Does (company-stated) — Doesn't — and who does
Does (company-stated)Doesn't — and who does
CMMC Level 1 and Level 2 questionnaires; Apptega says it released the v2.13 framework, assessment, and task pack for both levels in April 2025Implement or operate any control — you, your MSP, or an MSSP
Crosswalks between CMMC, NIST SP 800-171, and other frameworks (Plus and Premium)Decide your binding level — the written solicitation, contract, subcontract, or flow-down does
Evidence storage and integrations (integrations are an add-on)Store CUI under Apptega's current public product boundary
Task assignment, owners, and remindersAffirm your status in SPRS — your Affirming Official does that (§ 170.22)
SSP and POA&M reportsPerform or replace an assessment by a C3PAO (CMMC Third-Party Assessment Organization) or by DCMA DIBCAC (the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center)
Audit Manager for sharing evidence with outside users (add-on on Essentials)Turn draft or AI-generated text into final evidence — the rule accepts only final evidence (§ 170.24(b)(1))
Risk register, third-party risk, policy manager, AI remediation suggestions, and AI-assisted assessment featuresDecide whether an uploaded document is safe to process; Apptega's Assessment Completion Agent explicitly reads uploaded security documents
Multi-tenant workspaces and service-provider packagesProve tenant separation, clean client export, or the complete price without a live demonstration and written terms

Is software your next step right now?

A GRC platform earns its keep when someone already owns implementation and the bottleneck is organizing scope, the SSP, evidence, tasks, scores, and recurring reviews. If you don't know where CUI lives, or nobody is building and operating the controls, software can organize the problem without solving it. Three quick checks usually settle the order.

  • Does your contract or subcontract include DFARS 252.204-7012? If it applies, you owe the NIST SP 800-171 safeguards for covered contractor information systems regardless of the Phase II suspension.
  • Can you point to where CUI lives today? If not, scoping comes before software.
  • Is someone already implementing and operating the safeguards? If not, you need people before a platform.
If this is you — Do this first — Where to go
If this is youDo this firstWhere to go
You don't know if you handle CUISort FCI vs. CUI and scope your environmentFCI vs. CUI, scoping guide
CUI sits in an unverified commercial Microsoft 365 tenant or ordinary file sharesVerify and remediate the CUI environment before softwareManaged enclaves, Microsoft GCC High
Controls aren't built and no one's doing the workReadiness help or an MSP/MSSPRPO vs. MSP, software vs. consultant
FCI only, Level 1The 15-requirement checklist may be enoughLevel 1 checklist
Someone owns implementation; SSP and evidence are scattered in spreadsheetsA GRC tool — Apptega is a candidateThe 12-point check and demo script below
You're an MSP serving several defense clientsApptega's service-provider model is built for this use — mind your own ESP dutiesCMMC requirements for MSPs
You're considering a voluntary C3PAO assessment during the suspensionEvidence export, hashing, contract timing, and the reason to proceed matter mostProgram rule vs. acquisition rule, what the suspension changed

If two rows fit — or none do — settle that before any demo. Find My CMMC Path asks a few questions about your contract, whether you handle FCI or CUI, your environment, and your timeline, and shows which kind of help fits.

See which kind of help comes first →

The Apptega CMMC buyer's check: 12 proof points

Don't ask a vendor "do you support CMMC?" Ask it to prove the product follows the rule and fits your data boundary. Each row below is a rule-based or clearly labeled diligence point, what to ask or test, what passing looks like, and when to stop.

No web page — including this one — can tell you whether Apptega will support your assessment successfully, and none of the user reviews we read reports a CMMC assessment result. Apptega currently offers a 14-day trial; use fake data only and run this table and the demo script that follows.

Use fake data only. Never enter CUI, drawings, system exports, credentials, or scans into a vendor demo.

# — What the rule or diligence point says — Ask or test — Pass — Walk away if — Public record (September 2026)
#What the rule or diligence point saysAsk or testPassWalk away ifPublic record (September 2026)
1Level 1 is the 15 requirements in FAR 52.204-21(b)(1)(i)–(xv); no POA&Ms at Level 1 (§ 170.14(c)(2), § 170.21(a)(1))Count the Level 1 items; try to add a POA&M to oneExactly 15; POA&M blockedIt shows 17, or allows a Level 1 POA&MApptega's public CMMC guide says Level 1 has 17 controls
2Level 2 requirements are identical to NIST SP 800-171 Rev. 2, assessed with the objectives in NIST SP 800-171A (June 2018) (§ 170.14(c)(3))Is the content Rev. 2? Are the 800-171A objectives shown? If Rev. 3 is available separately, does CMMC scoring stay on Rev. 2?Rev. 2 with objectives, source dates, and update historyRev. 3 is treated as the current CMMC baselineApptega released a v2.13 pack in April 2025. See Rev. 2 vs. Rev. 3
3Start at 110; subtract 1, 3, or 5 per unmet requirement; partial credit exists only for IA.L2-3.5.3 and SC.L2-3.13.11 (§ 170.24)Run the scoring test belowShows 97Shows a cross-framework "percent compliant" as the CMMC scoreApptega's Defender integration syncs shared-control scores across frameworks; that makes a CMMC-specific score test essential
4Conditional status requires score ÷ 110 of at least 0.8, POA&M-eligible items only, none of six named excluded requirements, and closeout within 180 days (§ 170.21)Does the tool flag POA&M-ineligible items and count 180 days from the Conditional CMMC Status Date?Flags IA.L2-3.5.3 and RA.L2-3.11.2 in the testNo eligibility logic, or a 90-day clockApptega's public guide cites a 90-day window. See POA&M closeout
5A current SSP must exist or the assessment can't be completed; the SSP and related scope documentation must cover applicable service-provider relationships and CRM responsibilities (§ 170.24, § 170.19(c)(2)(ii))Export a sample SSP from a fictional programBoundary, per-requirement implementation, service-provider sections, and CRM ownership survive the exportA generic narrative you must rebuild from scratchApptega says it generates SSP and POA&M reports; current format not public. See SSP software
6Assessment evidence must be final, not draft (§ 170.24(b)(1))How are draft, approved, expired, and AI-generated materials marked?Clear approval status and historyDraft or AI-generated text appears as completed evidence without reviewApptega lists AI remediation and document-reading assessment features; validation remains the customer's job
7For Level 2 (Self), assessment artifacts are retained six years from the CMMC Status Date (§ 170.16(c)(4))What can you export, in what formats, and what happens when you cancel?Complete export in usable formats before deletionNo complete export, or export only by an unspecified paid serviceTrust Center says Apptega deletes customer data on request — keep your own required archive
8For a Level 2 C3PAO assessment, evidence files are hashed with a NIST-approved algorithm and the hash list goes to the assessor (§ 170.17(c)(4))Can it produce an artifact hash list or clean exports you can hash?Hash list or clean, stable exportsEvidence is locked inside the platformNot stated publicly. See assessment evidence
9An ESP relationship involving CUI or SPD must be documented through the service relationship, service description, and CRM (§ 170.19(c)(2)(ii))Ask for the CRM, service description, data-flow summary, and badge detailsWritten documents match the service and data flow you will use"You're covered" with nothing in writingBadge shown; no public CRM or badge detail
10CUI in a cloud service needs the FedRAMP Moderate result described in DFARS 252.204-7012 and the CMMC rule, or approved equivalencyConfirm the workflow keeps CUI out of ApptegaWritten approved-data list and technical controls that match itA representative suggests uploading CUI without product-boundary evidenceNo Apptega Marketplace offering found; Apptega says product isn't designed for CUI
11Your Affirming Official affirms in SPRS after each assessment, including closeout, and annually thereafter (§ 170.22)Who prepares, enters, and affirms each record?Tool helps prepare; authorized company users handle SPRS and the Affirming Official affirmsVendor claims the dashboard itself creates the official CMMC Status or files the affirmationNothing public shows Apptega submitting CMMC records to SPRS. See SPRS score and record types
12Good diligence, not a standalone CMMC requirement: know which integrations, AI features, identity providers, and subprocessors touch your dataDemonstrate the Assessment Completion Agent, integrations, subprocessor list, retention/training terms, and SAML SSO on your planEvery data destination and responsibility is answered in writingAn AI model or integration reads evidence and nobody can identify the provider, retention, or approved dataApptega's Assessment Completion Agent says it reads uploaded security documents; Trust Center says a subprocessor list is available; SAML SSO appears on Plus and Premium

A 30-minute demo script, with a scoring test

A vendor tour shows you what the vendor wants. This script shows you what CMMC needs. Use only fake data — never real CUI, drawings, system exports, credentials, or scans — and ask the representative to drive while you watch.

Use fake data only. Never enter CUI, drawings, system exports, credentials, or scans into a vendor demo.

Minutes — Ask them to show — What it proves
MinutesAsk them to showWhat it proves
0–3Open a new CMMC program; show the framework version, source date, update history, and Level 1 item countCurrent content (15 Level 1 requirements)
3–8Map IA.L2-3.5.3 (multifactor authentication) to an owner, implementation text, evidence, and a task; show its 800-171A objectivesEvidence and ownership connect to the incorporated requirement and assessment objectives
8–13Enter the scoring test belowThe score follows § 170.24 and the POA&M logic follows § 170.21
13–18Export the SSP, POA&M, evidence index, and score worksheet; show how draft, approved, and expired material is markedWhether "audit-ready" claims survive an export
18–22Show approved file types, classification guidance, permissions, retention, deletion, activity logs, AI data flow, and exactly what each integration pulls inWhether your planned use creates SPD or sends data somewhere you didn't approve
22–26MSPs: create a second fictional client, show role separation and a clean client export. Single contractors: show time-limited outside-user accessTenant isolation, collaboration, and offboarding
26–30Put the complete quote on screen and ask for the service description, CRM, approved-data list, badge evidence, renewal terms, and exit process in writingTotal cost and what Apptega will contractually stand behind

The scoring test (fictional company)

Northstar Fabrication is a made-up 40-person machine shop with a Level 2 (Self) requirement. Its drawings live in a separate government cloud. Its self-assessment finds five unmet requirements:

Requirement — Why it's not met — Points off (§ 170.24)
RequirementWhy it's not metPoints off (§ 170.24)
IA.L2-3.5.3 Multifactor authenticationOnly admins and remote users have it−3 (partial credit)
SC.L2-3.13.11 CUI encryptionEncryption is used, but it isn't FIPS-validated−3 (partial credit)
RA.L2-3.11.2 Vulnerability scanningSome in-scope servers were never scanned−5
AU.L2-3.3.4 Audit logging failure alertsNot set up−1
CM.L2-3.4.9 User-installed softwareNo control in place−1

Score: 110 − 13 = 97. That's 97 ÷ 110 = 0.8818, above the 0.8 conditional-status floor.

Can Northstar use a POA&M? Not yet. POA&M items can generally be worth only 1 point, with one exception: SC.L2-3.13.11 at 3 points when encryption is used but isn't FIPS-validated (§ 170.21(a)(2)). IA.L2-3.5.3 and RA.L2-3.11.2 must therefore be fixed before Northstar can post a Conditional Level 2 (Self) status. Fix those two and the score becomes 105. Assuming Northstar satisfies every other conditional-status rule, SC.L2-3.13.11 and the two 1-point items can go on a POA&M that must be closed within 180 days.

What a rule-following tool should do: show 97, flag IA.L2-3.5.3 and RA.L2-3.11.2 as POA&M-ineligible, and start the 180-day clock only from the Conditional CMMC Status Date. If it shows a crosswalk "percent compliant" instead, that isn't the CMMC score for this self-assessment. And don't confuse the CMMC record with the separate legacy NIST SP 800-171 DoD Basic Assessment record that SPRS also stores. See our SPRS score and record guide.

Stop the demo if the representative asks you to upload real CUI or sensitive evidence, offers "we run on GovCloud" or the badge as proof you're covered, can't show the framework version, can't export the SSP and POA&M, can't explain which AI features read documents, or won't put the complete price and exit terms in writing.

What Apptega's CMMC pages say vs. what the rule says

Several statements on Apptega's public CMMC pages, rechecked September 24, 2026, don't match the current rule or current program status. That doesn't prove the in-product templates are wrong. It tells you exactly which content and logic to test before you rely on them.

What Apptega's page says — What the rule or current program says — Why you should care
What Apptega's page saysWhat the rule or current program saysWhy you should care
Its CMMC framework page has the browser title "Get CMMC Certified with Compliance Software"A Level 2 certification assessment is performed by a C3PAO and Level 3 by DCMA DIBCAC; a self-assessment produces a CMMC Status, not a certificate (§ 170.4)Software organizes the work; it can't issue your status or certificate
Its CMMC guide describes Level 1 as 17 controlsCurrent Level 1 is 15 FAR 52.204-21 requirements (§ 170.14(c)(2))Count the live Level 1 template before relying on it
The guide says a failed audit leaves a 90-day window to fix issuesConditional status exists only when the eligibility rules are met, and POA&M closeout is due within 180 days (§ 170.21)Test the clock and eligibility logic
The guide describes C3PAOs helping find gaps and plan, and says they provide consultative adviceA CMMC Ecosystem member that provided consulting services to prepare the organization for a CMMC assessment within the prior three years may not participate in that organization's Level 2 certification assessment (§ 170.8(b)(17)(ii)(G))Keep readiness consulting and the formal assessment independent. See RPO vs. C3PAO
The guide says Level 2 requires documenting and performing maturity "processes"Current Level 2 requirements are identical to NIST SP 800-171 Rev. 2 (§ 170.14(c)(3))Don't confuse vendor maturity language with the requirement set the assessor scores
The guide says rulemaking isn't finalized and that a CMMC-AB-certified consultant is required if you lack expertise32 CFR Part 170 took effect December 16, 2024, and the DFARS acquisition rule took effect November 10, 2025; no rule requires hiring a consultant. The organization formerly branded CMMC-AB is now The Cyber ABDon't buy readiness services on a false mandatory-consultant premise
The guide doesn't mention the July 13, 2026 suspensionDuring the suspension, new procurement documents may designate only Level 1 (Self) or Level 2 (Self); issued instruments require written amendments or modifications to change (implementation procedures)Vendor timing claims may be stale even when the product's framework content is current

To be fair, Apptega's guide also says CMMC doesn't explicitly require GCC High, recognizes that Rev. 3 isn't yet the CMMC baseline, and describes three-year third-party status with annual affirmations. If Apptega corrects the stale passages, we'll update this table and note the date.

What does Apptega cost for CMMC?

Apptega doesn't publish dollar prices on its current pricing page. It lists three plans — Essentials, Plus, and Premium — and says a 14-day trial is available without a credit card. The official page shows no free plan. The number that matters is the written all-in annual price for your frameworks, users, client environments, modules, integrations, onboarding, support, renewal, and exit.

Plan feature (checked September 24, 2026) — Essentials — Plus — Premium
Plan feature (checked September 24, 2026)EssentialsPlusPremium
Frameworks with assessments135
Framework crosswalkingNoYesYes
Document storage50 GB100 GB300 GB
Gap assessment reports1025Unlimited
Audit ManagerAdd-onIncludedIncluded
Third-Party Risk ManagerNoAdd-onIncluded
IntegrationsAdd-onAdd-onAdd-on
SAML single sign-onNot shown in comparison tableYesYes
Dedicated account managerNoYesYes
Client subaccountsNoAdd-onAdd-on
Multiple workspacesNoNoAdd-on
Custom dashboardsNoNoYes
Public dollar priceNot shownNot shownNot shown

The pricing page lists "SSO" in the Essentials summary, but its comparison table shows SAML-based SSO only on Plus and Premium. Ask which authentication method and identity-provider features your plan includes. Apptega also says service-provider packages include branding, multi-tenancy, and provider-specific capabilities; obtain the exact package and limits in writing.

Get these in the written quote before you sign:

  • Base annual subscription, minimum term, and billing schedule
  • Whether CMMC and NIST SP 800-171 count as one framework or two
  • Included internal users, client subaccounts, workspaces, and outside users
  • Audit Manager, Third-Party Risk Manager, integrations, API access, AI features, and branding add-ons
  • Storage limits, overage charges, file limits, and retention
  • Onboarding, data migration, implementation, and training
  • Support tier, response times, and named account contact
  • Multi-year assumptions, renewal increase or cap, and early-termination terms
  • Full export formats, export assistance, offboarding timeline, and deletion confirmation
  • Professional-services rates and every item still marked "to be scoped"

The subscription is only one cost category. Budget separately for implementation, internal labor, outside readiness help, changes to the CUI environment, and any assessment that actually applies. Our CMMC Level 2 cost guide separates those categories.

Who Apptega fits — and who should start somewhere else

Apptega fits teams that have an implementation owner and need one place to run assessments, evidence, risk, tasks, and reports — especially MSPs serving several clients or organizations carrying several frameworks. It's the wrong first buy for a shop that hasn't scoped CUI, nobody is operating the controls, or the immediate need is a place approved and documented for CUI.

Buyer — Fit — Verify before buying
BuyerFitVerify before buying
MSP or MSSP with several defense clientsLikely fitTenant separation, subaccount/workspace pricing, client export, approved data types, your own ESP duties
RPO or compliance consultantLikely fitCurrent CMMC content, SSP/POA&M depth, evidence approval, client transfer, license model
In-house team running CMMC plus SOC 2, ISO 27001, or NIST CSFPossible strong fitCrosswalk scoring versus CMMC scoring, integrations, AI data flow, total cost
Single Level 2 contractor with controls and ownership in placePossible fitWhether a CMMC-focused tool is simpler; export quality; data boundary
Level 1 contractor with one frameworkMay be more tool than you needCompare the Level 1 checklist before buying broad GRC
Contractor without a defined CUI boundaryNot the first buyScoping and readiness first
Team that needs CUI stored in its GRC workflowWrong current Apptega product boundaryAn exact Marketplace-listed Class C offering or an enclave, with the boundary, CRM, and data flow verified
Team that needs controls implemented and operatedWrong tool on its ownAn MSP/MSSP, internal operators, or readiness provider
Team that only needs a formal assessmentWrong toolA C3PAO when the written requirement and current program status call for one

Landed in the "start somewhere else" rows? See which step should come first for your contract and data.

Map my CMMC path →

If you need a Marketplace-listed GRC offering at Class C (Moderate)

Some government editions of GRC products appear in the official FedRAMP Marketplace at Class C (Moderate). FedRAMP now displays qualifying offerings as FedRAMP Certified; the CMMC rule and DFARS still use the older legal phrase FedRAMP Authorized at Moderate. We checked the exact Marketplace offerings below on September 24, 2026. This is a status check, not a ranking, endorsement, or conclusion that the commercial edition or your planned CUI workflow is covered.

FedRAMP says Classes A–D describe the depth of the certification package, not the product's overall security. Class C carries the historical Moderate parenthetical; the exact service boundary, package, CRM, dependencies, and customer configuration still decide whether the offering fits the planned use.

Exact offering — Marketplace status and ID — Current class — Certified since
Exact offeringMarketplace status and IDCurrent classCertified since
Constellation GovCloud (Marketplace record lists Hyperproof Gov as a certified service)FedRAMP Certified — FR2206159758Class C (Moderate)February 17, 2026
Paramify CloudFedRAMP Certified — FR2428769635XLClass C (Moderate)March 6, 2026
Vanta Government CloudFedRAMP Certified — FR2525556241XMClass C (Moderate)April 24, 2026
Secureframe PlatformFedRAMP Certified — FR2529360449Class C (Moderate)June 23, 2026
Drata Trust Management PlatformFedRAMP Certified — FR2600167032Class B (Low) — below the rule's Moderate referenceDecember 5, 2025
ApptegaNo offering found in the official Marketplace when checked——

Check that the exact offering you're buying is the one in the Marketplace; a vendor's commercial product and government edition can have different boundaries. Then obtain the package identifier, service description, CRM, approved-data statement, dependencies, authorization/certification history, and customer configuration duties. A Marketplace row does not authorize every way a contractor might use the product, and FedRAMP says it does not endorse vendor-submitted product descriptions.

If what you really need is something else, pick the category first:

If what you really need is… — Category — Our guides
If what you really need is…CategoryOur guides
A CMMC-first SSP and POA&M workflowCMMC-focused documentation toolsParamify, FutureFeed alternatives, Totem
One program across SOC 2, ISO, and CMMCBroad GRC platformsHyperproof, Vanta, Drata, Secureframe, GRC software guide
A controlled home for CUICUI enclave or government cloudManaged enclaves, PreVeil alternatives, GCC High
Someone to scope, implement, or operate controlsRPO/RP or CMMC-focused MSP/MSSPRPO vs. MSP, provider categories
The formal assessmentC3PAOC3PAO list, Cyber AB Marketplace guide

What users say about Apptega

The dated review snapshots were positive overall on ease of use, crosswalking, and support, with recurring complaints about integrations, reporting, search, performance, and scoring clarity. None of the reviews we read reports a CMMC assessment result, so treat them as product-usability signals only.

Source (checked) — Rating snapshot — Often praised — Often criticized
Source (checked)Rating snapshotOften praisedOften criticized
G2 (September 23, 2026)4.7/5 from 157 reviewsEase of use, managing several frameworks, evidence and task tracking, customer-success supportFeature and integration limits, report formatting, shared-control scoring clarity, slow pages
Capterra (September 24, 2026)4.6/5 from 25 reviewsCentral dashboard, cross-framework mapping, supportSmall sample; individual reviewers raised support, interface, content-search, reporting, and price concerns

Both sites label some reviews as incentivized, and review counts change. Capterra's sample is small. Neither source establishes how Apptega handles current CMMC scoring, CUI, SPD, exports, or an assessment — which is why the rule-based test above matters more than a star average.

Apptega, the company

Apptega, Inc. is based in Atlanta. Dave Colesante is CEO, and the company named Jeff Cate chief financial officer on July 30, 2026. It's backed by growth investor Mainsail Partners. Apptega's current homepage says more than 15,000 programs use the platform; that is a company-stated figure, not one we independently audited. Its December 2025 platform expansion included Policy Manager and broader risk, vulnerability, and service-provider management features.

Edge cases

We already use Apptega. What should we do this week?

Inventory what's actually uploaded and what every integration or AI feature reads. Stop new CUI uploads and unapproved feeds. If CUI or credentials were uploaded, preserve the facts and follow your incident-response and contract-reporting process before deleting material that may be evidence; rotate exposed credentials, obtain written deletion and backup-retention details from Apptega, and confirm the data is gone from every applicable location. If Apptega processes configuration, vulnerability, scan, credential, or log data from the in-scope environment, document the service and data flow, update the relevant scope artifacts, and ask Apptega for its service description and CRM. Then run the scoring test against a safe fictional copy of your findings and compare the result with your CMMC self-assessment record — not the separate NIST SP 800-171 DoD Basic Assessment record SPRS also stores.

During the suspension, is a tool still worth it?

No rule requires software. But a Level 2 (Self) requirement still means a current SSP, a scored CMMC self-assessment in SPRS, and annual affirmations; DFARS 252.204-7012 also remains binding where it applies. A tool can help when documentation, evidence ownership, and recurring review are the bottleneck. See annual affirmations.

If you leave Apptega

For Level 2 (Self), the rule requires the assessment artifacts described in § 170.16(c)(4) to be retained for six years from the CMMC Status Date; Level 2 C3PAO assessments have related six-year evidence and hash requirements in § 170.17(c)(4). Export the applicable records before cancellation in formats you can open without Apptega, verify the export, and keep it under your own retention controls.

A voluntary C3PAO assessment

A Level 2 C3PAO assessment requires a hash list of assessment evidence files using a NIST-approved algorithm (§ 170.17(c)(4)). If Apptega can't produce one, export stable copies and hash them through an approved process before the assessment. The July suspension limits new procurement designations; it does not erase the voluntary-assessment path in 32 CFR Part 170. See program rule vs. acquisition rule.

Your prime asks for your SPRS score or SSP

Don't automatically send a full SSP or raw Apptega export. Confirm what the subcontract or supplier request actually requires, provide only the status, CMMC UID, score, or artifact you're authorized and required to share, and use a secure approved channel. An SSP may contain SPD or CUI depending on its content. See how to prove CMMC compliance to a prime.

Running SOC 2 or ISO 27001 alongside CMMC

Crosswalks can reduce duplicate evidence work. But a crosswalk "percent compliant" is not your CMMC score, a shared control can have framework-specific evidence, and each framework may count toward your plan limit. Score and approve CMMC on its own terms.

Frequently asked questions

Is Apptega CMMC compliant or certified?

A software product doesn't hold your organization's CMMC Status. Apptega shows a "CMMC Level 2" badge but doesn't publicly identify what was assessed, the assessment type, date, boundary, or covered service; its separate notice says outside-assessor CMMC certification isn't on its immediate roadmap. Ask for the CMMC UID or other underlying evidence, status type, CMMC Status Date, system boundary, and assessor before relying on the badge.

Is Apptega a C3PAO or a Registered Practitioner Organization?

Apptega's public materials reviewed for this page present it as a software company, not as the formal-assessment or registered-readiness organization performing those roles. Verify any firm claiming an official C3PAO, RPO, or practitioner status in the Cyber AB Marketplace; our Marketplace guide shows how.

Does Apptega submit my score to SPRS?

We found nothing public establishing direct SPRS submission. For Level 1 and Level 2 self-assessments, authorized users from your organization enter or manage the CMMC record in SPRS, and the Affirming Official submits the affirmation. Make the vendor distinguish a dashboard score, an export, the CMMC self-assessment record, and the separate NIST SP 800-171 DoD Assessment record.

Is there a free version of Apptega?

The official pricing page shows no free plan. Apptega currently advertises a 14-day trial without a credit card; paid configurations are quote-based, and service-provider features may depend on the package and add-ons.

Does Apptega's AI read my evidence?

At least one current feature does. Apptega's Assessment Completion Agent says users upload security policies and documentation, and the AI reads and extracts the content to populate an assessment. Keep CUI out, ask which AI features and model providers are enabled, obtain the subprocessor list, and get retention, training-use, deletion, and access terms in writing.

Can Apptega write my SSP for me?

Apptega says it produces SSP reports from assessment information. The resulting SSP still has to describe the real system, scope, service providers, responsibilities, and implementation accurately, and the evidence supporting it must be final. We did not test the current export, so require the representative to generate one from a fictional program before you buy.

Still not sure which CMMC path fits your company? Use The Defense Compliance Report's Find My CMMC Path tool to see which path and kind of help fit your contract, CUI, environment, and timeline — before you hire anyone.

Sources

  1. CMMC Program rule, 32 CFR Part 170, eCFR current through September 22, 2026: § 170.4 definitions, § 170.8 ecosystem conflicts, and Subpart D — levels, assessment, scoping, POA&Ms, affirmations, and scoring — checked September 23–24, 2026.
  2. FAR 52.204-21 and NIST, SP 800-171 Rev. 2, SP 800-171A (June 2018), and SP 800-172 — checked September 24, 2026. Newer NIST revisions do not replace the versions incorporated into CMMC without a controlling rule change.
  3. Acquisition.gov: DFARS 252.204-7012, 252.204-7021, and 252.204-7025 — checked September 24, 2026.
  4. Department of War CIO, CMMC program page, suspension implementation procedures, and DPCAP DARS RFO class-deviation index — checked September 24, 2026.
  5. Supplier Performance Risk System: CMMC materials and tutorials, CMMC/NIST FAQ, and separate NIST SP 800-171 assessment information — checked September 24, 2026.
  6. FedRAMP, official Marketplace, Marketplace designation guidance, and official Marketplace data — checked September 24, 2026.
  7. Apptega, letter of notice on FedRAMP and CMMC certification, CMMC v2.13 release, and March 2025 release notes — checked September 24, 2026.
  8. Apptega, Trust Center, pricing, free trial, CMMC framework page, CMMC guide, integrations, and Assessment Completion Agent — checked September 24, 2026.
  9. Apptega platform announcement via Business Wire, December 8, 2025; current Apptega homepage and company releases — checked September 24, 2026.
  10. G2 Apptega reviews — snapshot checked September 23, 2026; Capterra Apptega listing — snapshot checked September 24, 2026.
  11. Our Editorial & Advertising Policy and methodology.

About The Defense Compliance Report

The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on every claim and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures. We're not affiliated with the Cyber AB, DoD, DCMA DIBCAC, NIST, Apptega, or any U.S. government agency. This page is educational research, not legal, contractual, or compliance advice — confirm scope and applicability with a CMMC Registered Practitioner (RP) or a qualified federal-contracts attorney.

See my CMMC path →