The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

Managed security review · primary-sourced · last reviewed August 2026

BlueVoyant CMMC Review (2026): What They Can Actually Do for Your Level 2

Last updated:

Last verified: against CMMC rules, DFARS, NIST publications, Cyber AB records, FedRAMP materials, and BlueVoyant public company, service, government, and historical CMMC materials.

BlueVoyant CMMC review illustration showing a managed security operations center, Microsoft-heavy contractor network, data-flow boundary, and compliance evidence

By The Defense Compliance Report Editorial Team Last reviewed: August 2026 · Last verified: August 28, 2026 Evaluation depth: Independent documentary review of published sources. We did not deploy the product, interview BlueVoyant, review a proposal, or receive anything from the company. Compensation relationship with BlueVoyant: none.

If you came here looking for a BlueVoyant CMMC review, here is the short version.

Independent-use note: Educational documentary review; not legal, contractual, export-control, cybersecurity, or compliance advice. Verify the clause, CMMC status, provider listing, and legal entity that apply to your solicitation and contract.


Verdict: BlueVoyant belongs on the shortlist when your real problem is Microsoft-heavy managed detection and response, 24/7 security operations, or supply-chain risk. Do not treat a May 5, 2022 RPO announcement as proof of current Cyber AB status. Do not treat the word assessment as authority to conduct a Level 2 certification assessment. And do not sign until the statement of work resolves scope, CUI and Security Protection Data handling, the Customer Responsibility Matrix, incident reporting, assigned personnel, exit rights, and the full three-year cost.

BlueVoyant is a managed security company that announced CMMC Registered Provider Organization accreditation on May 5, 2022. We could not independently confirm a current BlueVoyant listing in the live Cyber AB Marketplace as of August 28, 2026, so this review treats the designation as a verified historical status, not a verified current one.

An RPO advises. It does not issue a CMMC Level 2 certification. Level 2 may be a self-assessment or a C3PAO certification assessment depending on the contractual requirement. When a Level 2 certification assessment is required, 32 CFR Part 170 requires an authorized or accredited C3PAO to perform it. The same rule prohibits a CMMC ecosystem member from participating in a Level 2 certification assessment when that member served as a consultant preparing the organization for a CMMC assessment within the prior three years.

BlueVoyant's monitoring service does not receive one automatic scope label in every deployment. The treatment turns on architecture and data flow. A provider service that processes Security Protection Data without CUI is assessed as a Security Protection Asset. A provider that processes, stores, or transmits CUI faces the broader ESP or CSP conditions in the rule. A provider that handles neither CUI nor Security Protection Data may not meet the rule's definition of an external service provider at all. The local agents, SIEM, EDR, and other tools protecting the environment may still be Security Protection Assets.

That distinction is the one most buyers get wrong, and it is the reason this page exists. When the service touches CUI or Security Protection Data, hiring a security vendor does not move the compliance work off your plate. It moves another relationship into your System Security Plan.

There is a second thing you should know before you read another word, and we will document it below: the six named CMMC consulting services BlueVoyant published in 2022 do not appear today as the same six named line items. Some underlying concepts remain. The catalog changed. We will show you the before and after, and then we will show you exactly how to make the proposal say what the website no longer does.


BlueVoyant CMMC review: the 30-second verdict

Decision point — What the record supports
Decision pointWhat the record supports
Provider categoryMSSP / MDR provider with a current CMMC readiness page and a historical RPO announcement dated May 5, 2022
Current RPO statusNot independently confirmed from the live Cyber AB Marketplace as of August 28, 2026
Can BlueVoyant certify you?We found no verified C3PAO authorization. During the current Phase I pause, Department guidance says program offices may require Level 1 or Level 2 self-assessment. When a Level 2 certification assessment is required, an authorized or accredited C3PAO must perform it
Does the service enter your assessment scope?Often, but not automatically. CUI, Security Protection Data, local security assets, and the delivery architecture determine the treatment under 32 CFR § 170.19
Best fitContractors that need real 24/7 security operations, run a Microsoft-heavy environment, or need supplier-risk visibility alongside CMMC readiness
Weakest fitA contractor whose immediate need is a tightly defined SSP, POA&M, boundary diagram, evidence package, and hands-on control implementation rather than a recurring SOC service
Published priceNone on the public pages reviewed. Do not accept a verbal number
Published CMMC customer outcomesNone found in the public sources reviewed
Bottom lineCredible security company. Thin public CMMC buying record. Shortlist only after the SOW names the deliverables, control ownership, software, data flow, total cost, and who performs any formal assessment

Which category fits, and which doesn't. If your problem is “nobody is watching our network at 2 a.m.,” this is the right category and BlueVoyant is a serious name in it. If your problem is “we have no SSP, no POA&M, no scoping diagram, and an assessment on the horizon,” you need a readiness or managed-compliance provider first, and you should compare the SOW against CMMC-focused RPOs and MSPs. If your problem is “we need someone to conduct the formal Level 2 certification assessment,” you need an authorized C3PAO — and the ecosystem conflict rule limits participation by a consultant who prepared your organization for a CMMC assessment within the prior three years.

What we actually verified

We read BlueVoyant's live CMMC readiness page, its government-side CMMC materials, its 2022 RPO announcement, its 2023 Conquest Cyber acquisition announcement, its older CMMC articles, its company pages, its Microsoft MDR page, and its government contracts page — all fetched August 27–28, 2026.

We compared those claims against:

We did not: deploy or operate the product, interview BlueVoyant, complete a provider questionnaire, review a customer proposal, interview a customer, or independently confirm a current Cyber AB Marketplace listing.

We have no compensation relationship with BlueVoyant. There are no BlueVoyant sales links or BlueVoyant CTAs on this page. Every recommendation here points to our own free tools or to a provider category.

The Defense Compliance Report is the independent CMMC decision layer for defense contractors — mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category before the contractor spends six figures in the wrong lane.

Before you compare vendors, confirm the category

The right CMMC provider is not the same for every contractor. The category you need — C3PAO, readiness consultant, RPO, MSP/MSSP, GRC platform, or CUI enclave provider — depends on the clause, required level, FCI/CUI flow, assessment type, environment, and contract timeline. The solicitation and contract set the required status. A checklist does not.

Use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right provider category before you request quotes. Do not submit CUI, drawings, vulnerability details, or contract documents.

Commercial disclosure: Some provider matches may involve a referral or paid partner relationship. BlueVoyant is not a commercial partner of The Defense Compliance Report as of August 28, 2026. Commercial relationships do not change the category result or the standards applied in this review.

Map your situation to a provider category — no CUI, no drawings, no sensitive contract details.


What is BlueVoyant, and why do defense contractors keep running into them?

Answer capsule: BlueVoyant is a New York-headquartered cyber defense company founded in 2017 that sells managed detection and response, third-party risk management, digital risk protection, and professional services. It entered the CMMC conversation through a 2022 RPO announcement and the 2023 acquisition of Conquest Cyber, a defense-focused cyber-risk company, alongside a Series E round the company said exceeded $140 million.

Three facts shape everything else on this page.

First, BlueVoyant is large, and its center of gravity is Microsoft security operations. Its current company page says it was founded in 2017, is headquartered in New York City, and has more than 600 employees across offices in College Park, Washington, D.C., London, Leeds, Cork, Toronto, Tel Aviv, Bogotá, Manila, and Singapore — eleven listed cities including headquarters across five continents. Its current site says it has won ten Microsoft security awards, operates 24/7 regional SOC monitoring across Europe and the United States, and has completed more than 1,200 Microsoft Sentinel deployments. Its Microsoft MDR page lists the 2024 Worldwide Security Partner of the Year award and a 2026 Data Security and Compliance Trailblazer award.

Company-stated, but internally consistent. If you run Microsoft Sentinel and Defender and want somebody to operate them around the clock, you are in their fairway.

Second, the DIB-specific software story came through an acquisition. On November 29, 2023, BlueVoyant announced the acquisition of Conquest Cyber, the maker of ARMED ATK, and said it raised more than $140 million in Series E funding alongside the deal. The release said both companies held RPO accreditation at that time and described ARMED ATK as being on the FedRAMP Marketplace.

BlueVoyant's current company page still names Conquest Cyber in its family of companies. We could not find ARMED ATK as a named product in the current commercial navigation. That does not mean the capability vanished — acquired products get renamed and absorbed constantly. The current government contracts page also lists Conquest Technology Services LLC as a wholly owned BlueVoyant subsidiary serving the DIB and government market. If a Conquest-era module is what the rep is demoing, ask for its current product name, owner, roadmap, authorization status, support team, and data-export terms.

Third, the legal entity on your paper matters. BlueVoyant's government contracts page says BlueVoyant Government Solutions is the trade name of 202 Group LLC, an independent BlueVoyant subsidiary, and publishes UEI FPQ6XDL31YX5 and CAGE 8ARP0. The same page separately lists Conquest Technology Services LLC as a wholly owned subsidiary.

That does not mean one entity is better. It means the proposal must identify the entity performing the work, the entity touching your data, the entity carrying insurance, the entity making any compliance representation, and every subcontractor standing behind the service. “BlueVoyant” is a brand. Your contract is with a legal entity.


Is BlueVoyant a C3PAO? No verified authority — and here is exactly what an RPO can and cannot do

Answer capsule: BlueVoyant announced RPO accreditation in 2022, but we could not independently confirm its current Marketplace status or verify C3PAO authorization as of August 28, 2026. An RPO may provide consulting and implementation support. It does not issue a Level 2 certification. A formal Level 2 certification assessment must be performed by an authorized or accredited C3PAO, and the three-year conflict rule follows the ecosystem members who prepared the organization for a CMMC assessment.

The label problem in this market is not cosmetic. It determines whether you are buying advice, implementation, self-assessment support, or an assessment that can produce a CMMC status.

Label — What it can mean — What it does not mean
LabelWhat it can meanWhat it does not mean
RPOA Cyber AB consulting and implementation organization that may provide advice, readiness, and implementation support, subject to its current listing and personnelAuthority to issue a Level 2 certification
Individual Cyber AB credentialsCredentials such as CCP and CCA identify different individual roles; verify each assigned person's current listing and roleThat every person assigned to your engagement has every credential named on a company page
C3PAOAn organization authorized or accredited to conduct Level 2 certification assessments under 32 CFR Part 170A guarantee that the customer will pass
DCMA DIBCACThe government assessment organization that conducts Level 3 certification assessments and may conduct NIST SP 800-171 government assessmentsA readiness consultant hired to build your program

The original draft collapsed all Level 2 paths into one sentence. The current rule does not. Level 2 has a self-assessment path and a C3PAO certification path. During the current Phase I pause, Department guidance says the program may require Level 1 and Level 2 self-assessments. When a Level 2 certification assessment is required, the rule requires an authorized or accredited C3PAO.

The conflict rule also needs exact language. 32 CFR § 170.8 prohibits a CMMC ecosystem member from participating in a Level 2 certification assessment when that member previously served as a consultant preparing the organization for any CMMC assessment within the prior three years. That is not a blanket rule saying every company sharing a parent brand is permanently disqualified from every assessment. It is a real independence restriction that has to be resolved at the legal-entity, assessment-team, referral, and engagement-history level.

Ask for the answer in writing:

  1. Is the entity proposing readiness work currently listed in the Cyber AB Marketplace, and under what exact name?
  2. Is any entity in the proposed delivery chain an authorized or accredited C3PAO?
  3. Which named individuals will prepare us, and will any of them participate in a later Level 2 certification assessment?
  4. Which C3PAO, if any, is being referred, and is any referral compensation paid?
  5. Who signs the assessment agreement, and who signs the readiness SOW?

An honest provider will answer these cleanly. A provider that uses assessment as a fog machine is telling you exactly how the rest of the engagement will go.


The BlueVoyant CMMC evidence matrix

Answer capsule: The strongest verified evidence is corporate scale, Microsoft depth, a live CMMC readiness page, a dated 2022 RPO announcement, the 2023 Conquest acquisition, and a current government contracting presence. The weak spots are the ones a Level 2 buyer must document: current Marketplace status, certification authority, service-specific data flow, CRM, FedRAMP status, pricing, assigned personnel, customer outcomes, and exit terms.

Claim or buying question — Current state as of August 28, 2026 — Evidence boundary — What it means before you sign
Claim or buying questionCurrent state as of August 28, 2026Evidence boundaryWhat it means before you sign
BlueVoyant announced RPO accreditationVerified historical claimBlueVoyant press release dated May 5, 2022Do not convert a 2022 announcement into a current Marketplace status without a live listing
BlueVoyant is currently an RPONot independently confirmedLive Cyber AB Marketplace did not expose a verifiable result through the public pages available to this reviewAsk for the current listing link and verify the exact legal name
BlueVoyant is an authorized C3PAONot verifiedNo C3PAO authority was found in the official BlueVoyant pages reviewed; current Marketplace result was not independently confirmedDo not buy a formal Level 2 certification assessment on implication
BlueVoyant publishes a current CMMC readiness offeringVerifiedCurrent CMMC Readiness pageThe category exists; the public page is not a complete SOW
The 2022 page named six CMMC consulting servicesVerified historical claim2022 RPO announcementTreat as the 2022 catalog, not a promise that every line item still exists
The current page discusses FCI/CUI flow, templates, dashboards, gap validation, roadmaps, and external analysesVerified current claimCurrent CMMC Readiness pageConvert every term into a deliverable, owner, evidence standard, and acceptance criterion
Conquest Cyber and ARMED ATK joined BlueVoyantVerified historical claimNovember 29, 2023 acquisition announcementAsk for current product name, roadmap, support, and data portability
A Conquest government entity still exists in the groupVerified current claimGovernment contracts page lists Conquest Technology Services LLCConfirm which entity performs the work and touches the data
ARMED ATK currently holds a FedRAMP designation or authorizationNot verifiedThe 2023 release said it was on the Marketplace; current status was not confirmedHistorical marketplace language is not current authorization evidence
BlueVoyant publishes standardized CMMC pricingNot foundPublic pages reviewedRequire a three-year, itemized total and change-order schedule
BlueVoyant publishes a CMMC customer outcomeNot foundPublic case studies and CMMC pages reviewedAsk for matched references and redacted deliverables
BlueVoyant publishes a service-specific CRMNot foundPublic pages reviewedMake a completed CRM a pre-signature deliverable
BlueVoyant publishes CUI/SPD residency, subprocessors, and assigned SOC locations for this serviceNot foundPublic pages reviewedResolve by architecture and contract, not by office list
BlueVoyant has substantial Microsoft security operations evidenceVerified company-stated evidenceCurrent company, homepage, and Microsoft MDR pagesStrong reason to take the meeting when Microsoft operations are the actual need

This matrix is intentionally uneven. A strong company can have thin public buying documentation. A thin public record does not prove weak delivery. It proves that the proposal has to carry more weight.

The part of this review that does not flatter anybody

We did not test the product. We did not interview a customer. We did not review a proposal. We could not independently confirm a current Cyber AB listing. We could not verify a current FedRAMP listing for ARMED ATK. We found no public CMMC price, no service-specific CRM, no public data-residency commitment for this service, and no named CMMC outcome.

That is not a reason to reject BlueVoyant. It is a reason to stop pretending a logo wall is due diligence.

BlueVoyant may have excellent answers behind the sales gate. Enterprise security companies often do. But the answers behind the gate are the answers that matter: exact legal entity, architecture, people, deliverables, responsibility split, retention, authorization basis, references, and exit rights.

The website is not the contract. The proposal is.


What CMMC services does BlueVoyant actually advertise in 2026?

Answer capsule: BlueVoyant's 2022 announcement named six CMMC consulting services. Its current CMMC page uses a broader catalog: FCI/CUI flow understanding, templates and dashboards, regular gap validation, organizational footprinting, strategic roadmaps, and digital hygiene or external vulnerability assessments. Several 2022 line items are no longer named. One current term — “comprehensive assessments” — is expressly described as digital hygiene assessments and external vulnerability analyses, not a formal CMMC certification assessment.

Here is the source-to-source comparison.

2022 named CMMC consulting service — What the current page says — Current buying conclusion
2022 named CMMC consulting serviceWhat the current page saysCurrent buying conclusion
CMMC 2.0 Executive Training — half dayNot namedConfirm whether executive training is available, its audience, and its deliverable
Assessment Readiness Engagement for CUI scoping, data-flow diagramming, and project managementCurrent page says it helps determine how FCI and CUI flow through the organizationRelated concept remains; require the actual boundary, data-flow diagram, inventory, and project plan
CMMC 2.0 Mock AssessmentNot namedDo not infer a mock assessment from the word assessment
CMMC 2.0 Post Assessment Annual ReviewNot namedConfirm whether recurring review is advisory, self-assessment support, or evidence operations
NIST 800-53 Compliance ReviewNot namedDo not assume NIST 800-53 work is part of CMMC Level 2 readiness
Professional Consulting ServicesProfessional Services remains in current navigation, but not as the same CMMC-specific line itemName the exact service and engineering work in the SOW
Current-page additions or emphasisTemplates and dashboards; regular compliance-gap validation; organizational footprinting and analysis; strategic roadmaps and charters; digital hygiene assessments; external vulnerability analysesUseful capabilities, but none substitutes for a complete statement of work

Read that last row again. “Comprehensive assessments” is defined on the live page as digital hygiene assessments and external vulnerability analyses. That could be valuable security work. It is not the same purchase as a NIST SP 800-171 gap assessment against all 110 Revision 2 requirements and the applicable NIST SP 800-171A assessment objectives. It is not the same purchase as a mock CMMC assessment. It is not a formal Level 2 certification assessment.

Those are different purchases at different prices with different evidence.

That ambiguity is not unique to BlueVoyant — it is endemic to this market. But it is your problem to solve, and you solve it with definitions.

Translate every marketing term into a contract term

What the marketing says — What your SOW must define
What the marketing saysWhat your SOW must define
“CUI scoping”The written boundary, data-flow map, asset inventory, people/facility scope, and format delivered
“Templates”Which documents: SSP, POA&M, policies, procedures, inventories, diagrams, evidence index; who owns and can export them
“Dashboard”Included or separately licensed; data source; export format; access after termination
“Gap validation”Which Rev. 2 requirements and assessment objectives; evidence standard; frequency; owner; remediation workflow
“Assessment”Digital hygiene, vulnerability analysis, gap assessment, mock assessment, self-assessment support, government assessment support, or formal C3PAO certification assessment — pick one
“Roadmap”Owners, dependencies, budget, milestones, acceptance criteria, and the assumptions that can change the price
“Remediation”Advisory recommendations or hands-on engineering and configuration
“Monitoring”Log sources, retention, alert thresholds, response authority, escalation, evidence exports, and who acts at 3 a.m.
“Maintain compliance”Recurring evidence operations, annual affirmation support where applicable, control testing, configuration management, or merely continued monitoring

If a vendor — any vendor — resists putting these in writing, that is your answer. If they put them in writing, you now have a comparable quote instead of a brochure.

Use the CMMC readiness checklist before the next call — mark what exists, what is missing, and which gaps require documentation, engineering, monitoring, or independent assessment.


Does hiring BlueVoyant expand your CMMC assessment scope?

Answer capsule: It can add scoped assets, services, and documentation, but the answer is not automatically “yes” in the same way for every deployment. Under 32 CFR § 170.19, the treatment turns on what the BlueVoyant service and every underlying platform process: CUI, Security Protection Data, both, or neither. The security tools protecting your environment may already be in scope even before you outsource their operation.

Most contractors assume outsourcing security shrinks their assessment. It can shrink the operational work. It does not erase the assets, data, responsibilities, or evidence.

Here is the rule boundary in plain terms.

What the BlueVoyant service or connected layer handles — Likely rule treatment — What you need in the record
What the BlueVoyant service or connected layer handlesLikely rule treatmentWhat you need in the record
CUIThe service is in the CMMC assessment scope under the applicable CSP or non-CSP ESP provisions; a CSP handling CUI must meet the rule's FedRAMP conditionSSP entry, service description, CRM, data-flow diagram, authorization evidence where applicable, full responsibility and evidence split
Security Protection Data without CUIThe provider service is in scope and assessed as a Security Protection AssetSSP entry, service description, CRM, asset inventory/network diagram treatment, evidence for requirements relevant to the capability
Neither CUI nor Security Protection DataThe provider may not meet the CMMC definition of an ESPWritten architecture proving the boundary; local security assets may still be in scope
Local agent, SIEM, EDR, scanner, identity tool, or other asset protecting the CUI environmentSecurity Protection Asset even if the external provider itself does not receive the dataAsset inventory, SSP treatment, network diagram, relevant requirement evidence

A Security Protection Asset provides security functions or capabilities for the CMMC assessment scope. Security Protection Data includes the logs, configurations, vulnerability data, and credentials used to protect that environment. 32 CFR § 170.19 puts Security Protection Assets in the Level 2 scope and requires them to be documented in the asset inventory, SSP, and network diagram. For an ESP, the rule also requires the relationship and service to be described in the SSP, service description, and Customer Responsibility Matrix.

The cleanest question is not “Is BlueVoyant in scope?” It is:

“Draw every path by which BlueVoyant, its people, its systems, its subprocessors, and the underlying platforms can receive CUI or Security Protection Data.”

Then apply the rule to the drawing.

We cover the general rule in our CMMC external service provider assessment guide and the boundary work in our CMMC scoping guide.

The stacked ESP problem nobody warns you about

BlueVoyant's public materials emphasize Microsoft security operations and say its MDR strengthens existing EDR, SIEM, and cloud-security tools. A real deployment can therefore create more than one scoped layer. The number is architecture-specific, not brand-specific.

Layer — Typical party — Scope question — What to request
LayerTypical partyScope questionWhat to request
Monitoring and analyst serviceBlueVoyant or the legal entity named in the SOWDoes the service or analyst receive CUI or Security Protection Data?Service description, CRM, personnel/access statement, incident workflow
Security platformMicrosoft or another platform identified in the proposalDoes the platform process CUI or Security Protection Data, and in which environment?Product-specific authorization, region, tenant, retention, and responsibility documentation
Your tenant and local toolsYour companyWhich assets protect the CUI environment?Asset inventory, network/data-flow diagrams, configuration evidence
Subprocessors and supportNamed third partiesCan they access telemetry, tickets, evidence, or backups?Current subprocessor list, access locations, purpose, contract flow-downs
Readiness consultantBlueVoyant or another providerWho creates the SSP, policies, POA&M, and evidence?Named deliverables, ownership, acceptance criteria
Formal assessorAuthorized C3PAO when a certification assessment is requiredIs the assessor independent from prior preparation work?Marketplace listing, assessment agreement, conflict disclosure

Two vendors can create two sets of paperwork, but one assessment scope. The practical takeaway is simple: ask for a delivery-architecture diagram, not just a service description. You cannot document what you cannot draw.


Where does your data go, and who is allowed to see it?

Answer capsule: BlueVoyant publishes more than 600 employees across offices in eleven cities on five continents and says it provides 24/7 regional SOC monitoring across Europe and the United States. That does not establish which personnel, locations, tenants, or subprocessors will touch your account. NIST SP 800-171 Revision 2 does not impose a U.S.-citizenship requirement, but export controls, contract terms, program restrictions, and the contents of the telemetry can create separate limits on foreign-person access.

This is the question DIB buyers ask last and should ask first.

BlueVoyant's current company page lists New York City headquarters plus offices in College Park, Washington, D.C., London, Leeds, Cork, Toronto, Tel Aviv, Bogotá, Manila, and Singapore. Its site says it provides 24/7 regional SOC monitoring across Europe and the United States. The company opened a Cork security operations center in March 2025.

That is evidence of scale and follow-the-sun operations. It is not evidence that your DIB account will use every location, any foreign location, or only U.S. personnel. The contract must answer that.

Separate the frameworks instead of blending them:

Framework — What it says — What you must resolve
FrameworkWhat it saysWhat you must resolve
CMMC / NIST SP 800-171 Rev. 2The 110 requirements across 14 families govern access, protection, monitoring, and evidence. They do not create a general U.S.-citizenship ruleWho can access CUI or Security Protection Data, through which system, under which controls
DFARS 252.204-7012If an external cloud service provider stores, processes, or transmits covered defense information, the contractor must require FedRAMP Moderate-equivalent security and the clause's incident, malware, preservation, forensic-access, and damage-assessment dutiesWhether the service is a CSP for your use case and whether covered defense information enters it
ITAR / EARRelease of controlled technical data or technology to a foreign person can be an export or deemed exportWhether logs, tickets, attachments, screenshots, commands, or evidence contain export-controlled content and who can view decrypted data
Contract, program, and customer restrictionsA solicitation, DD254, security classification guide, data-rights term, prime flow-down, or program direction may impose additional restrictionsThe exact language in your documents, not the vendor's generic position

The export-control nuance is narrow and important. 22 CFR §§ 120.50 and 120.56 treat release of controlled technical data to a foreign person as an export. 22 CFR § 120.54 provides conditions under which encrypted transmission or storage is not treated as an export, including control of cryptographic keys. The EAR has separate deemed-export and encrypted-transmission rules. None of those encrypted-storage concepts solves the case where an analyst is authorized to decrypt and read controlled content.

A SOC analyst whose job is to read the data is not “nobody looked at the data.”

We could not find a service-specific public BlueVoyant commitment that CMMC delivery is U.S.-persons-only, that every DIB account is restricted to U.S. facilities, that a particular GCC High or Azure Government integration set is supported, or that a particular telemetry region applies. Absence of a public statement is not evidence that the option does not exist. It means the option must be written into the proposal if you need it.

Ask five questions:

  1. Which legal entity and specific SOC locations will handle our account?
  2. Can access be limited to U.S. persons in U.S. facilities, and what definition of U.S. person will the contract use?
  3. Which Microsoft GCC High, Microsoft 365 Government, Azure Government, Sentinel, Defender, and other integrations are supported in our exact tenant?
  4. Where are telemetry, tickets, evidence, backups, and support records stored; for how long; and which subprocessors can access them?
  5. Will any BlueVoyant or subprocessor system receive, store, process, or transmit CUI or export-controlled technical data — and what written authorization or contractual basis supports that design?

Resolve export-controlled access with qualified export counsel before onboarding. “CMMC-ready” is not an export license.


If BlueVoyant is watching your network, who files the 72-hour report?

Answer capsule: Your company retains the contractual duty. DFARS 252.204-7012 requires the contractor to rapidly report a covered cyber incident to DoD within 72 hours of discovery, preserve affected-system images and relevant monitoring or packet-capture data for at least 90 days from submission of the report, submit isolated malicious software, and support forensic and damage-assessment requests. A provider may assist or act under an agreed workflow, but the SOW does not erase the contractor's responsibility.

This is the highest-value paragraph on this page and it takes thirty seconds to act on.

Ask your rep this question:

“If we have a reportable incident at 2 a.m. on a Saturday, who determines whether DFARS 252.204-7012 is triggered, who files the DIBNet report, who preserves the images and monitoring data, who submits the malware sample, who supports a government request, and where in the contract does it say so?”

DFARS 252.204-7012 places the duties on the contractor and flows the clause to covered subcontracts. A managed detection and response provider can perform real technical work — discovery, triage, containment, evidence collection, malware isolation, timeline reconstruction, and reporting support. That does not silently transfer the contractual obligation.

Four lines belong in the SOW or incident-response exhibit:

  • Decision authority: Who decides that the facts meet the clause's reporting threshold, and who is on call to make that decision?
  • Submission workflow: Who prepares and submits the DIBNet report, under whose certificate and approval, with what escalation if the customer is unreachable?
  • Preservation: Which data and system images are preserved, where, in what format, and for at least the required period from report submission?
  • Government support: Who supplies additional information or equipment for forensic analysis and damage assessment, and what costs are included?

Also ask for the configured retention number, not the marketing number. A ninety-day contractual preservation duty is not satisfied by a dashboard that silently rolls data off on day thirty.


Is BlueVoyant FedRAMP authorized — and does it even matter?

Answer capsule: BlueVoyant's November 2023 acquisition announcement said Conquest Cyber's ARMED ATK solution was on the FedRAMP Marketplace. We could not verify a current ARMED ATK, Conquest Cyber, or BlueVoyant cloud-service listing or authorization as of August 28, 2026. A historical statement that a product was “on the Marketplace” does not establish its current designation, authorization, sponsoring agency, service boundary, or relevance to the service in your proposal.

Two things to understand here, and the second one saves most readers a lot of wasted energy.

One: use the current marketplace, not an acquisition press release. FedRAMP calls its Marketplace the federal government's authoritative catalog for confirming whether a cloud service offering has a designation, is working toward certification, or is connected to agency reuse. Verify the exact product name, package, service boundary, status, date, agency relationship, and whether the offering in your SOW is the same offering in the record. The source of truth is the current FedRAMP Marketplace, not a 2023 sentence.

Two: for many Level 2 monitoring arrangements, the first question is data flow, not the badge. If the provider's cloud service processes, stores, or transmits CUI, DFARS 252.204-7012 and the applicable CMMC CSP provisions control the authorization discussion. If the provider handles Security Protection Data without CUI, 32 CFR § 170.19 puts the service in the assessment scope as a Security Protection Asset. If the provider handles neither, the provider may not be an ESP under the CMMC definition, although local security assets can remain in scope.

So the real question is not:

“Are you FedRAMP authorized?”

It is:

“Will the exact service in this proposal receive, store, process, or transmit our CUI — yes or no — and what current primary-source evidence supports the answer?”

If the answer is no, put the architecture and prohibition in the contract and verify that logs, alerts, tickets, screenshots, attachments, and support workflows honor it. If the answer is yes, demand the exact authorization or equivalency package that applies to the exact service boundary before signing.


What does BlueVoyant CMMC work cost?

Answer capsule: BlueVoyant does not publish standardized CMMC pricing on the public pages reviewed, so any specific public dollar figure attributed to the company should be treated as unverified. A defensible comparison normalizes the same nine cost buckets across every proposal, because two vendors can both say “CMMC readiness” while pricing different work.

We are not going to invent a number. We have seen other pages publish “typical BlueVoyant pricing” with no source, and that is exactly the kind of confident nonsense that gets a buyer's budget blown up in month four.

What we can give you is the structure that makes any two quotes comparable.

Cost bucket — What the quote must answer
Cost bucketWhat the quote must answer
1. Discovery and scopingAre asset discovery, FCI/CUI flow mapping, boundary documentation, facility/people scope, and subcontractor flow-down analysis included?
2. Gap or baseline assessmentAgainst all 110 NIST SP 800-171 Rev. 2 requirements and the applicable assessment objectives? With a written finding and evidence standard?
3. DocumentationWhich artifacts: SSP, POA&M, policies, procedures, diagrams, inventories, evidence index, CRM? Who drafts and who approves?
4. Technical remediationHands-on implementation by engineers or recommendations for your team? This is one of the biggest price and outcome differences in the market
5. Software and licensingWhich Microsoft, SIEM, EDR, GRC, scanning, identity, cloud, or backup licenses are required? Included, resold, marked up, or separately contracted?
6. Ongoing managed serviceWhat starts after implementation, at what monthly rate, for what term, with what minimums and renewal increase?
7. Evidence operationsWho collects, tests, refreshes, maps, exports, and retains evidence for self-assessment, affirmation, or later certification?
8. Formal assessmentIs any C3PAO fee included? Who selects and contracts with the assessor? What travel, re-evaluation, or POA&M closeout costs are excluded?
9. Exit and changeData export, configuration handoff, transition help, early termination, scope growth, user/endpoint growth, change orders, and post-termination access

Two cost traps specific to this category. First, recurring monitoring and project-based readiness work are different purchases. Mixing them into one “CMMC program” number makes the deal hard to compare against a specialist. Ask for them separately. Second, a monitoring subscription can outlive the readiness project by years. Model three years, not three months.

Then ask for one number:

Total three-year cost, including implementation, every required license, recurring service, expected growth, travel, change orders, independent assessment, POA&M closeout, and exit.

Do not accept a verbal number.

Compare the cost structure before you compare the logos — use the same scope and exclusions for every quote.


How current is BlueVoyant's published CMMC guidance?

Answer capsule: BlueVoyant maintains a current CMMC readiness page, but older articles based on superseded versions of the program remain live. Its April 5, 2020 CMMC article describes the original five-level model, recommends aiming for Level 4 or 5, and describes third-party verification “like BlueVoyant.” The current CMMC Program Rule has three levels and separates self-assessment, C3PAO certification assessment, and DIBCAC assessment.

We are not singling anyone out here. Almost every vendor in this market has stale CMMC content somewhere. But you are making an expensive decision, so you need to know which pages to trust.

BlueVoyant content — What it says — How to treat it in 2026
BlueVoyant contentWhat it saysHow to treat it in 2026
April 5, 2020 CMMC articleFive maturity levels; suggests Level 4 or 5; describes third-party verification “like BlueVoyant”Historical only. Do not use it to determine level, assessment type, or assessor authority
May 5, 2022 RPO announcementNames six services and uses pre-Final-Rule assessment languageVerified historical service catalog; reconfirm every service and rule reference
November 29, 2023 Conquest acquisition announcementPre-Final-Rule CMMC framing, historical RPO claims, historical ARMED ATK Marketplace claimUseful acquisition record; not current regulatory or authorization evidence
Current CMMC readiness pageCurrent offering described through FCI/CUI flow, templates, dashboards, gap validation, roadmaps, and external analysesCurrent marketing record; still not specific enough to buy from without a defined SOW

The rule hierarchy that overrides all vendor content:

  1. 32 CFR Part 170 — the CMMC Program Rule. Level 1 uses the 15 safeguards in FAR 52.204-21. Level 2 uses the 110 requirements in NIST SP 800-171 Revision 2. Level 3 adds 24 selected requirements from NIST SP 800-172 on top of Level 2.
  2. Your solicitation and contract clauses — including DFARS 252.204-7012, 252.204-7019, 252.204-7020, and 252.204-7021 when included or applicable.
  3. NIST SP 800-171 Revision 2 — 110 requirements across 14 families. NIST has superseded Revision 2 with Revision 3 as a NIST publication, but the current CMMC rule still expressly incorporates Revision 2. Revision 3 is not the CMMC-controlling version unless and until the Department amends the rule or the contract independently requires it.
  4. NIST SP 800-172 — the source for the 24 selected enhanced requirements incorporated at CMMC Level 3.
  5. Current Department implementation notices — including the July 13, 2026 suspension of Phase II and the continuation of Phase I self-assessment requirements.

If a vendor page and the rule disagree, the rule wins. Every time.


What proof exists that BlueVoyant delivers CMMC outcomes?

Answer capsule: We found no named CMMC customer outcome, no public assessment-success record tied to BlueVoyant's exact role, and no directly attributable CMMC customer reference in the public sources reviewed as of August 28, 2026. BlueVoyant publishes substantial evidence of Microsoft security operations, government-market presence, and cyber-risk work. That is useful evidence about the company. It is not direct evidence that a specific contractor reached a specific CMMC result because of a specific BlueVoyant engagement.

This gap is not unique to BlueVoyant. Assessment results, boundaries, scores, and remediation records are sensitive. Very few providers publish the evidence a buyer actually wants.

But do not accept a category substitution. A strong MDR record is evidence about MDR. A government contract vehicle is evidence about procurement access. A Microsoft award is evidence about Microsoft partnership. None proves that the team assigned to you will write the SSP, close the POA&M, configure the controls, build the evidence, or prepare the boundary you need.

Evidence that is useful but indirect:

  • corporate operating history and scale;
  • Microsoft security awards and deployment claims;
  • a government contracting presence through 202 Group LLC and Conquest Technology Services LLC;
  • published DIB and supply-chain work;
  • current CMMC readiness and government-side CMMC pages.

Evidence that would directly answer the buying question:

  • a named or credibly anonymized CMMC customer case study showing starting maturity, scope, environment, target status, BlueVoyant's exact role, and result;
  • two customer references matched to your CUI footprint, environment, and required assessment type;
  • a completed provider questionnaire;
  • redacted sample deliverables: SSP table of contents, POA&M, boundary diagram, evidence index, CRM, and remediation roadmap;
  • names, locations, employment status, and current credentials of the people assigned to your account;
  • a current Cyber AB Marketplace listing under the exact legal name relied on in the proposal;
  • a current authorization or equivalency package for any cloud service that will process CUI.

The five questions to ask any reference they give you. These separate a real engagement from a logo on a slide:

  1. What was your starting maturity and CUI boundary when you began?
  2. Which deliverables did BlueVoyant personally produce, and which did your team produce?
  3. What work required another MSP, consultant, cloud provider, or C3PAO?
  4. What material costs landed outside the original quote?
  5. What documentation, evidence, configurations, and access did you keep after the engagement ended?

Question four is the one that gets you an honest answer.


How BlueVoyant compares to the other security vendors DIB buyers are weighing

Answer capsule: The useful comparison is not a feature-count contest. It is whether the provider gives you enough pre-signature evidence to document the service, allocate every responsibility, model the real cost, and survive an assessment without depending on a salesperson's memory. BlueVoyant's public strength is operational scale and Microsoft depth. Its public weakness is service-specific CMMC buying documentation.

This is the comparison lens we use across provider reviews: what can a contractor verify before committing?

Pre-signature evidence — BlueVoyant public record reviewed — What a defensible proposal must add
Pre-signature evidenceBlueVoyant public record reviewedWhat a defensible proposal must add
Corporate identity and scaleStrong — founding year, 600+ employees, offices, Microsoft recognition, service categoriesThe exact delivery entity and team for your account
Government legal entityStrong — 202 Group LLC, UEI, CAGE, contract vehicles, Conquest Technology Services LLC disclosedWhich entity signs, performs, subcontracts, and touches data
Current CMMC service pageAvailable but broadNamed deliverables, methods, evidence standards, dates, owners, acceptance criteria
Current Cyber AB statusNot independently confirmedLive Marketplace link under the exact name relied on
Formal-assessment authorityNot verifiedC3PAO listing and separate assessment agreement if certification is required
Service-specific architecture and data flowNot found publiclyDiagram showing every CUI/SPD path, platform, region, support path, and subprocessor
Customer Responsibility MatrixNot found publiclyCompleted CRM tied to your architecture and all inherited responsibilities
Service terms, retention, exit, and evidence portabilityNot found in a CMMC-specific public packageContract terms, retention schedule, export format, transition assistance, deletion certification
Standardized CMMC pricingNot publishedItemized three-year total and change-order schedule
Named CMMC outcomesNot foundMatched references and redacted deliverables
Microsoft security-operations evidenceStrong company-stated recordConfirmation that the exact government tenant, licenses, and integrations are supported

The second comparison is category fit. These providers can all appear in the same search result while solving different problems.

Provider category — The job it should own — Where BlueVoyant is stronger or weaker
Provider categoryThe job it should ownWhere BlueVoyant is stronger or weaker
MSSP / MDR provider24/7 monitoring, detection, investigation, response support, security-platform operationsThis is BlueVoyant's strongest public lane, especially in Microsoft environments
CMMC readiness consultant or RPOScope, SSP, POA&M, policies, evidence planning, remediation roadmap, self-assessment supportBlueVoyant advertises readiness, but the public record does not define a complete artifact-and-remediation package
Managed-compliance MSPOngoing IT administration, control implementation, documentation maintenance, and evidence operationsMay fit a smaller contractor better when hands-on implementation is the main need; verify actual MDR depth
C3PAOFormal Level 2 certification assessment when contractually requiredDifferent authority and agreement; BlueVoyant C3PAO status was not verified
CUI enclave providerReduce and isolate the CUI boundary through architecture, migration, and managed environment servicesDifferent primary purchase; an enclave may still need MDR and readiness support
GRC platformMap requirements, evidence, tasks, risks, and reportingSoftware supports the program but does not replace implementation, monitoring, or assessment

What this table is telling you. BlueVoyant's strength is operational scale and Microsoft depth. Its weakness, for a compliance buyer specifically, is that almost everything you need to document the external service and compare the purchase lives behind a sales conversation.

That is survivable — plenty of enterprise vendors work this way — but it means your diligence has to be more active, not less. You cannot complete this evaluation from a brand name and a three-bullet service page.

One more consideration unique to this buying pattern. If the same provider performs readiness work and runs the monitoring service, it can be both your advisor and part of the scoped service architecture. That combination is not prohibited. It is a concentration you should enter deliberately, with a clear CRM, usable exit rights, and a separate authorized C3PAO when a Level 2 certification assessment is required. The prior-consulting conflict rule still has to be resolved for every ecosystem member proposed for the assessment team.


Who BlueVoyant is right for — and who should look somewhere else

Answer capsule: BlueVoyant fits best when CMMC readiness is one part of a broader security-operations problem — especially a Microsoft-centric environment, a need for 24/7 MDR, or supplier-risk visibility. It fits worst when the immediate purchase is a narrow fixed-scope documentation and implementation project, an enclave design, evidence-workflow software by itself, or an independent formal assessment.

Your actual problem — Likely fit — Why — What to verify first
Your actual problemLikely fitWhyWhat to verify first
Microsoft-heavy environment with no mature internal SOCStrong category fitMDR and Microsoft security operations are central to the public recordExact tenant support, delivery locations, architecture, CRM, retention
Prime contractor managing subcontractor cyber riskStrong category fitThird-party and supply-chain risk are genuine BlueVoyant linesWhether CMMC flow-down, supplier evidence, and remediation support are in the SOW
Existing BlueVoyant customer adding CMMC readinessWorth exploringExisting tooling and delivery relationships may reduce integration workCurrent service catalog, scope change, conflicts, evidence ownership
Need hands-on SSP, POA&M, policies, diagrams, and control implementationDepends entirely on the SOWThe current page names readiness concepts but not a complete artifact-and-remediation packageEvery deliverable, engineer task, owner, acceptance criterion, and excluded control
Need a fixed-scope small-business readiness project more than a recurring SOCUsually a weak category fit unless the proposal proves otherwiseYou may be paying for operational scale while still needing a documentation and implementation specialistCompare CMMC-focused readiness providers and managed-compliance MSPs
Need to reduce scope through a CUI enclaveWrong category for the primary decisionEnclave architecture and migration are separate disciplinesStart with the provider categories guide
Need evidence-workflow software onlyWrong category for the primary decisionSoftware organizes work; it does not perform every control or create every artifactSeparate the GRC software decision from readiness and MDR
Assessment-ready and need a formal Level 2 certification assessmentWrong category unless a separately verified C3PAO is contracting with youReadiness and certification authority are differentVerify the assessor in the Cyber AB Marketplace and keep the agreements separate
Not sure whether the contract requires Level 1, Level 2 self, or a later certification pathStopLevel and assessment type determine everything downstreamRead the CMMC levels guide and use Find My CMMC Path

We would rather lose you to the right category than win you into the wrong one. A wrong-category hire can burn a six-figure budget and a year, and the year hurts more than the money.

Use Who to Hire First before you compare company names. Then use the CMMC provider directory to compare providers inside the right category.

Request source-checked provider options

Commercial disclosure: A match may include providers with whom The Defense Compliance Report has a referral or paid partner relationship. BlueVoyant is not a commercial partner as of August 28, 2026. Do not submit CUI, drawings, vulnerabilities, export-controlled data, or contract documents.


Does the CMMC Phase II suspension change any of this?

Answer capsule: Yes for timing and current procurement mechanics; no for the underlying duty to protect covered information. Phase I began November 10, 2025 and was originally scheduled to run through November 9, 2026. On July 13, 2026, the Department suspended the transition to Phase II, which had been scheduled for November 10, 2026. The program remains paused in Phase I, where Department guidance says only Level 1 and Level 2 self-assessments may be required. DFARS safeguarding and SPRS duties continue where the corresponding clauses apply.

Let's kill the two bad reactions to this news before they cost you money.

Bad reaction one: “We can stop.” No. The Department's July 13, 2026 announcement says all Phase I self-assessment requirements remain in place, the Department will enforce NIST SP 800-171 Revision 2 through self-assessments and selected government-led assessments, and contractors remain obligated to safeguard covered defense information under DFARS 252.204-7012.

The applicability split matters:

Requirement — What continues during the Phase II suspension
RequirementWhat continues during the Phase II suspension
DFARS 252.204-7012Safeguarding and incident duties continue on contracts containing the clause
DFARS 252.204-7019Offerors subject to the provision must verify that a current score — not more than three years old unless the solicitation sets a shorter period — is posted in SPRS for each relevant covered contractor information system; if none is current, the offeror may conduct and submit a Basic Assessment
DFARS 252.204-7020Contractors must provide access needed for a Medium or High government assessment; summary scores are posted in SPRS, and covered subcontract award is conditioned on a current assessment where the clause applies
DFARS 252.204-7021 / CMMC affirmationCMMC status and affirmation duties continue where the CMMC clause and required status apply; they are not a universal duty detached from the clause
Phase II certification rolloutSuspended; Department guidance says the program is paused in Phase I and may require only Level 1 and Level 2 self-assessments

Your SPRS entry is not marketing copy. It is a representation the government can test. On June 18, 2026, the Department of Justice announced a $507,144 settlement resolving allegations that a defense contractor misrepresented cybersecurity compliance; the release says a DCMA DIBCAC Medium Assessment produced a score of -170 after the contractor had represented 110 in SPRS. The settlement was not an admission of liability. It is still a brutal reminder that the evidence behind a self-assessment matters.

When third-party rollout is paused, the self-assessment record is the evidence you own.

Bad reaction two: buying against a deadline that no longer exists. If a vendor is still pitching a November 10, 2026 Phase II countdown as though the suspension never happened, its materials are stale. That is a data point about the vendor.

What we are watching. The Department created a CMMC Reform Task Force and said it would deliver a report to the CIO within 60 days of July 13. The public RFI closed August 14, 2026 and sought industry input on compliance burdens and the use of commercial cybersecurity capabilities, platforms, and managed services. That territory overlaps directly with what an MDR provider sells. We are not going to predict the outcome. We are going to tell you that a 36-month monitoring contract signed today will outlive the answer, so build a regulatory-change and exit mechanism into it.

One attributable voice from inside the company, worth reading. On August 20, 2026, DefenseScoop published an op-ed by Lonny Anderson, president of BlueVoyant Government Solutions and former NSA chief technology officer. He describes himself as a former CMMC skeptic who argued that defenses had been “optimized for audits, not threats.” He argues for a model combining independent assessment, continuous external monitoring, and shared remediation support, and says the Senate version of the FY2027 NDAA would authorize $50 million in CMMC assessment grants.

Read it as what it is: a named executive's public position, not a Department policy. It is honest, it is on the record, and it aligns with BlueVoyant's public operational focus. If continuous monitoring is what you need, that alignment is a reason to take the meeting. If you need somebody to finish the SSP next month, it is a reason to make the deliverable list do the talking.


The 12 questions to ask BlueVoyant before you sign

Answer capsule: A defensible BlueVoyant evaluation ends with written answers on legal entity, current Cyber AB status, assessment type, deliverables, control ownership, remediation scope, licensing, CUI and Security Protection Data handling, assigned personnel, references, three-year cost, and assessment independence. A proposal that leaves any of those ambiguous is not comparable to another proposal.

Take this list into the discovery call. Ask for written answers. If a vendor answers all twelve clearly, you have found a serious partner — whether or not it is this one.

  1. Which legal entity signs the agreement, performs the work, and touches our data? Confirm BlueVoyant, 202 Group LLC, Conquest Technology Services LLC, another affiliate, or a subcontractor. Record the exact legal name, UEI, CAGE code where relevant, address, and role.
  2. What is your current Cyber AB Marketplace status, under which exact listed name? Ask for the live listing link and status. Verify it yourself on the date you rely on it.
  3. Precisely what kind of assessment is included? Digital hygiene, external vulnerability analysis, NIST SP 800-171 gap assessment, mock assessment, Level 2 self-assessment support, government-assessment support, or formal C3PAO certification assessment. Put one exact description in the SOW.
  4. What specific artifacts will you deliver? SSP, POA&M, policies, procedures, boundary and data-flow diagrams, asset inventory, evidence index, CRM, remediation roadmap, incident playbook, and executive affirmation package. Name each one, the format, owner, due date, and acceptance criterion.
  5. Who owns each of the 110 NIST SP 800-171 Revision 2 requirements and the applicable NIST SP 800-171A assessment objectives? Require a Customer Responsibility Matrix tied to the actual architecture — not a generic shared-responsibility graphic.
  6. What technical remediation is included? Separate we will identify from we will configure, we will test, and we will produce evidence.
  7. Which software, cloud, tenant, and security licenses are required, and who pays? Identify what is included, resold, marked up, customer-provided, or separately contracted.
  8. Will any BlueVoyant system, person, support channel, subprocessor, or connected platform receive, store, process, or transmit CUI or Security Protection Data? Require the exact data, path, environment, region, retention period, access locations, encryption model, and authorization basis.
  9. Who is assigned to our account, where do they work, and what are their current credentials? Ask for roles, locations, employee or subcontractor status, U.S.-person restrictions available, security-clearance assumptions, and replacement rules.
  10. Can you provide two references matched to our size, environment, CUI boundary, and target assessment type? Not the biggest logo. The closest analog.
  11. What is the total three-year cost? Itemize discovery, readiness, documentation, remediation, licenses, managed service, evidence operations, travel, change orders, formal assessment, renewals, transition assistance, and termination.
  12. How are readiness and formal assessment kept independent? Identify the proposed C3PAO, prior consulting relationships, referral compensation, assessment agreement, and conflict review. A readiness review does not become a formal assessment because a proposal uses the word assessment.

Formal Level 2 certification assessments are controlled by 32 CFR Part 170. The Cyber AB's CMMC Assessment Process (CAP v2.0), dated December 2024, supplies procedures for C3PAOs conducting Level 2 certification assessments. The Final Rule's preamble is explicit that CAP is Accreditation Body guidance, is not codified in the CFR, and cannot override Part 170. That is why question three must force the proposal to distinguish a readiness service from a formal certification assessment.

Take the readiness checklist into the discovery call

When you have a written scope, use the CMMC Level 2 cost guide to normalize the quote before you compare providers.


BlueVoyant CMMC review: frequently asked questions

Is BlueVoyant currently a Registered Provider Organization?

BlueVoyant announced RPO accreditation on May 5, 2022. That establishes a historical status on that date. We did not independently confirm a current BlueVoyant listing in the live Cyber AB Marketplace as of August 28, 2026. Verify the exact legal name and current listing before relying on the designation.

Is BlueVoyant a C3PAO?

We found no verified C3PAO authorization for BlueVoyant in the public sources reviewed. Do not treat readiness services, a mock assessment, or the word assessment as authority to conduct a Level 2 certification assessment. When certification is required, verify the authorized or accredited C3PAO in the Cyber AB Marketplace and contract with the assessment organization separately.

Can BlueVoyant certify my company for CMMC?

Not based on the public record we could verify. Level 2 certification assessments must be performed by an authorized or accredited C3PAO, and Level 3 assessments are performed by DCMA DIBCAC. During the current Phase I pause, Department guidance says program offices may require Level 1 or Level 2 self-assessments; do not let a vendor blur a self-assessment, readiness engagement, government assessment, and C3PAO certification assessment.

What CMMC services does BlueVoyant advertise in 2026?

Its live CMMC readiness page describes understanding FCI and CUI flow, pre-built templates and dashboards, regular gap validation, organizational footprinting and analysis, strategic roadmaps and charters, digital hygiene assessments, and external vulnerability analyses. Its 2022 announcement named six CMMC consulting services that are not repeated today as the same six line items. Confirm every service you need by name in the SOW.

Does using BlueVoyant put more of my company in CMMC scope?

The answer depends on data flow and architecture. A BlueVoyant service that handles Security Protection Data without CUI is assessed as a Security Protection Asset. A service that processes, stores, or transmits CUI faces the applicable ESP or CSP conditions. A provider that handles neither may not meet the rule's ESP definition, although the security tools protecting the CUI environment can still be Security Protection Assets. Draw the architecture before assigning the scope label.

Is BlueVoyant FedRAMP authorized?

We did not verify a current FedRAMP authorization for BlueVoyant, Conquest Cyber, or ARMED ATK. BlueVoyant's November 2023 acquisition release said ARMED ATK was on the FedRAMP Marketplace at that time. That historical wording does not establish a current authorization. Search the current FedRAMP Marketplace and require the exact package, service name, status, boundary, agency, and date when any service will process CUI.

Does BlueVoyant support Microsoft GCC High or Azure Government?

We found no public BlueVoyant statement that established support for those exact government environments as of August 28, 2026. If your CUI lives there, make tenant and feature support a written condition: integrations, log sources, response actions, API limitations, data region, identity model, and support-person access.

Who files the 72-hour incident report if BlueVoyant monitors our network?

The contractor has the DFARS 252.204-7012 reporting duty. The clause requires the contractor to report a covered cyber incident within 72 hours of discovery, submit isolated malicious software when applicable, preserve affected system images and relevant monitoring data for at least 90 days, and support government damage assessment. A provider can perform contractually assigned tasks, but you remain accountable for a workflow that satisfies the clause.

Does BlueVoyant publish CMMC pricing?

Not on the public pages reviewed. Treat any specific BlueVoyant CMMC price published without a proposal or first-party source as unverified. Compare quotes only after separating project work from recurring MDR and normalizing discovery, documentation, remediation, licenses, evidence operations, formal assessment, change orders, and exit costs.

Is BlueVoyant a good fit for a small defense contractor?

Sometimes, but the SOW has to prove it. A small contractor that primarily needs an SSP, POA&M, scoping package, policies, and hands-on remediation may be better served first by a CMMC-focused readiness or managed-compliance provider. A small contractor with a genuine 24/7 monitoring need and a compatible Microsoft environment may still fit BlueVoyant's operational category.

Does the CMMC Phase II suspension mean we can stop preparing?

No. The July 13, 2026 suspension stopped the transition to Phase II, not the underlying DFARS safeguarding obligation. The program remains in Phase I. Level 1 and Level 2 self-assessment requirements, SPRS duties, government assessment provisions, CMMC status or affirmation duties where the relevant clauses apply, and incident-reporting duties continue according to the solicitation and contract.

Does CMMC Level 2 use NIST SP 800-171 Revision 2 or Revision 3?

The current CMMC Program Rule uses NIST SP 800-171 Revision 2 for Level 2: 110 security requirements across 14 requirement families. NIST has published Revision 3 and withdrawn Revision 2 as its current publication, but Revision 3 does not become the controlling CMMC Level 2 requirement set unless the Department changes the rule or applicable contract framework. Do not let a provider convert a Revision 3 modernization project into a current CMMC rule requirement.

How does NIST SP 800-172 relate to CMMC Level 3?

Level 3 adds 24 selected requirements from NIST SP 800-172 on top of a final Level 2 certification status. DCMA DIBCAC performs the Level 3 assessment. A provider's generic reference to SP 800-172 does not establish that the contractor needs Level 3; the solicitation or contract identifies the required CMMC status.


Our methodology, source hierarchy, and evidence boundaries

This is a documentary provider review, not a hands-on product test and not a CMMC assessment.

Source hierarchy

We used sources in this order:

  1. Regulation and contract text: 32 CFR Part 170, the CMMC acquisition rule and current DFARS clauses, and the Federal Register preamble.
  2. Official technical and implementation sources: NIST CSRC publications, Department CMMC pages and notices, FedRAMP Marketplace records, and Cyber AB Marketplace or ecosystem materials.
  3. BlueVoyant first-party sources: current service pages, historical announcements and articles, company pages, Microsoft materials, and the government contracts page.
  4. Third-party reporting: used only for clearly attributed context, not to establish regulatory requirements or current accreditation.

How claims are labeled

  • Regulation-stated means the conclusion is tied to the current rule, clause, or official implementation notice.
  • Company-stated means BlueVoyant published the claim. It is evidence of what the company represented, not independent operational verification.
  • Historically verified means a dated source establishes the claim on that date but not necessarily today.
  • Not independently confirmed means the public record we could access did not establish the claim. It does not prove the capability or status does not exist privately.
  • Editorial fit judgment means our conclusion about the provider category, SOW, or buying sequence. It is not a government determination.

What we reviewed

BlueVoyant's current CMMC readiness page; government-side CMMC materials; May 5, 2022 RPO announcement; November 29, 2023 Conquest Cyber acquisition announcement; April 5, 2020 CMMC introduction article; current company, Microsoft MDR, and government contracts pages; the current Cyber AB Marketplace interface; and the August 20, 2026 DefenseScoop op-ed by the president of BlueVoyant Government Solutions. Provider sources were fetched August 27–28, 2026.

We compared those materials against 32 CFR Part 170; DFARS 252.204-7012, -7019, -7020, and -7021; NIST SP 800-171 Revision 2; NIST SP 800-171A June 2018; NIST SP 800-172; Department CMMC scoping and Phase I materials; the July 13, 2026 Phase II suspension announcement; and the Federal Register discussion of the Cyber AB CMMC Assessment Process.

CAP boundary: The Cyber AB's CAP v2.0 is a procedural guide for formal Level 2 certification assessments. The CMMC Final Rule preamble says CAP is an Accreditation Body product, is not codified in the CFR, and does not supersede Part 170. We therefore used Part 170 and the incorporated NIST sources as controlling.

What we could not verify

  • a current Cyber AB Marketplace listing for BlueVoyant under the names reviewed;
  • a current C3PAO authorization for BlueVoyant;
  • a current FedRAMP authorization for BlueVoyant, Conquest Cyber, or ARMED ATK;
  • whether BlueVoyant holds a CMMC status for the exact external-service scope a customer would use;
  • a public CMMC-specific SOW, CRM, SLA, retention schedule, subprocessor list, or data-residency commitment;
  • a public U.S.-persons-only delivery commitment;
  • public support documentation for GCC High or Azure Government;
  • standardized public CMMC pricing;
  • a named CMMC customer outcome attributable to the current service;
  • the current commercial name, availability, or roadmap of ARMED ATK;
  • the exact team, locations, architecture, and subcontractors a buyer would receive.

Every unknown above appears in the twelve-question list because the gaps in the public record are the agenda for the discovery call.

Read our research methodology and editorial standards. If BlueVoyant or a reader can document a correction, use our corrections policy. We will update the evidence state and verification date when the underlying check is repeated.


Disclosure

The Defense Compliance Report is an independent trade publication and decision resource for CMMC and Defense Industrial Base compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when the relationship is disclosed. Compensation does not control our regulatory analysis, provider-category recommendation, Cyber AB status check, or correction decisions.

BlueVoyant relationship status: no commercial relationship as of August 28, 2026. There are no BlueVoyant referral links or BlueVoyant sales CTAs on this page.

We are not affiliated with BlueVoyant, the Cyber AB, the Department of War, the Department of Defense, DCMA DIBCAC, NIST, FedRAMP, or any U.S. government agency. This article is educational research, not legal, contractual, export-control, cybersecurity, or compliance advice. The solicitation, contract clauses, information flow, and government determination control your required CMMC status and obligations. Resolve export-control and contract-specific questions with qualified counsel and resolve formal assessment status through the official Marketplace and contracting documents.

No person or credentialed reviewer is represented as having reviewed this article. The byline is The Defense Compliance Report Editorial Team.

What we verified about this provider

Review field — Current state as of August 28, 2026
Review fieldCurrent state as of August 28, 2026
Provider categoryMSSP / MDR and professional-services company with a current CMMC readiness page
Historical ecosystem claimBlueVoyant announced RPO accreditation on May 5, 2022
Current Cyber AB statusNot independently confirmed through the live Marketplace interface
Formal assessment authorityNo current BlueVoyant C3PAO authorization verified in the sources reviewed
Current CMMC service languageFCI/CUI flow understanding, templates and dashboards, gap validation, footprinting, roadmaps, digital hygiene assessments, and external vulnerability analyses
Government legal entity disclosedBlueVoyant Government Solutions is a trade name of 202 Group LLC; its page publishes a UEI and CAGE code and identifies Conquest Technology Services LLC as a wholly owned subsidiary
Published standardized CMMC priceNone found
Published named CMMC outcomeNone found
Compensation relationshipNone with BlueVoyant
Evaluation depthIndependent documentary review; no deployment, interview, provider questionnaire, proposal, or customer-reference call
Last verifiedAugust 28, 2026
Primary unknownsCurrent Marketplace and FedRAMP status, exact SOW, architecture, CUI/SPD handling, subprocessors, locations, GCC High/Azure Government support, assigned team, pricing, outcomes, and Conquest platform status

Still not sure which kind of CMMC provider you need?

Most contractors who land on a vendor review are one step ahead of themselves. The expensive mistake is not picking the wrong company. It is picking the wrong category — buying monitoring when you needed documentation, buying documentation when you needed hands-on engineering, or paying a readiness provider when the immediate purchase is an independent assessment.

Start with Who to Hire First, confirm the required level in the CMMC levels guide, and use Find My CMMC Path to map the next decision.

Need provider options after that? Tell us your level, scope, environment, and timeline, and we will route the inquiry to source-checked providers in the right category.

Get matched with source-checked CMMC provider options

Commercial disclosure: A match may include providers with whom The Defense Compliance Report has a referral, sponsorship, or paid partner relationship. BlueVoyant is not a commercial partner as of August 28, 2026. Do not submit CUI, drawings, export-controlled data, contract documents, credentials, vulnerability details, or sensitive system information through this or any website form.


The Defense Compliance Report is the independent CMMC decision layer for defense contractors. Choose the right CMMC path before you hire.