MAD Security CMMC Review? What Its Level 2 Status Really Covers
By The Defense Compliance Report Editorial Team — an independent trade publication on CMMC 2.0 and DIB compliance · Last verified September 2026
MAD Security is a Huntsville, Alabama managed security provider with a Cyber AB Marketplace page at RPO-10172. It sells CMMC readiness and 24/7 monitoring. MAD says it chose not to perform C3PAO assessments, so it presents its role as readiness and operations — not conducting your formal Level 2 certification assessment. The Level 2 certificate MAD reports holding doesn't transfer to you; it can reduce duplicate review only if its level and assessment type fit your requirement and its scope covers the exact services and assets you buy.
Status as of September 24, 2026: The Cybersecurity Maturity Model Certification (CMMC) program remains paused in Phase 1. During the suspension, Department program managers may designate only Level 1 (Self) or Level 2 (Self) in new requirement documents. Affected active solicitations were directed to be amended, and affected existing contracts were directed to be modified before the next option or scheduled administrative modification. Until a written change reaches the instrument in front of you, that instrument still controls. We found no replacement Phase II date or public Reform Task Force outcome on the official program pages checked today. See what the pause changed.
This page is for you if you have a MAD Security proposal, a call on the calendar, or you went looking for a MAD Security CMMC review before signing — and your work involves Controlled Unclassified Information (CUI), or you're not sure yet.
It's not for you if:
- You only need someone to formally assess you. MAD says it doesn't perform C3PAO assessments. Start with our list of authorized C3PAOs.
- You handle only Federal Contract Information (FCI) and your contract points to Level 1. Its 15 requirements don't mandate a 24/7 security operations center. Start with the Level 1 self-assessment checklist.
Below: what each MAD badge actually proves, which MAD services end up inside your assessment, and the 12 things to get in writing before you sign.
MAD Security at a glance: what each claim proves
MAD Security is two things at once: a company that runs security monitoring for defense contractors, and a company that presents itself as a registered CMMC readiness consultant. Think of it as a builder and building manager, not the building inspector. It can help design your setup, run parts of it, and prepare your paperwork. A separate, authorized assessor grades the result when a contract requires that.
Here's what each of MAD's main claims means for you. "Company-stated" means MAD says it and we couldn't check it independently.
| Question | Short answer | Basis checked September 24, 2026 |
|---|---|---|
| What is MAD Security? | A managed security service provider (MSSP) in Huntsville, Alabama, that also sells CMMC readiness consulting. It says it was founded in 2010 and is service-disabled veteran-owned. | Company-stated; SBA VetCert status was not checked |
| Is it registered with the Cyber AB? | A Cyber AB Marketplace page resolves at RPO-10172 and is titled “MAD Security.” The current status fields require JavaScript, so verify the legal entity, active status, and associated Registered Practitioner in a browser on signing day. The Cyber AB describes an RPO as an implementation-consulting role that can also be held by an MSP. | Cyber AB Marketplace page and role page |
| Can it certify your company? | Not under the role MAD publicly offers. MAD says it chose not to perform C3PAO assessments. A CMMC Third-Party Assessment Organization (C3PAO) conducts Level 2 certification assessments and issues Certificates of CMMC Status under 32 CFR 170.9(a). | Rule text; company-stated role choice |
| Does MAD hold CMMC Level 2 itself? | MAD says its own environment achieved Level 2 after a C3PAO assessment on March 28, 2025, and says its own security operations and managed services were covered. CMMC results aren't public (FAQ C-A4), so ask MAD for its certificate or SPRS status printout, current affirmation, and scope. | Company-stated; proof and scope not public |
| Does that make your company compliant? | No. Your organization remains responsible for defining its CMMC assessment scope and obtaining or posting the assessment record, CMMC Status, CMMC UID, and affirmation its written requirement calls for. MAD's status can reduce duplicated review only for covered MAD services and assets when its level and assessment type fit your requirement. | 32 CFR 170.19(c)(2)(ii); DoW FAQ E-A3 |
| What about the “perfect SPRS score of 110”? | MAD says every Level 2 requirement in its own assessment was scored MET. 110 is the maximum Level 2 score under 32 CFR 170.24. It says nothing about your score. | Company-stated score; rule-stated maximum |
| And “Top 250 MSSP”? | MAD reports ranking #95 on MSSP Alert's 2025 list. That's a trade-media ranking, not a CMMC credential. | Company-stated |
| Does MAD guarantee you'll pass? | Its RPO page answers “What happens if I fail my CMMC assessment?” with “If you work with MAD Security, you won't.” No readiness provider controls an independent assessor's findings. MAD's own C3PAO guide warns buyers to beware of “guaranteed” certifications. Hold MAD to that same standard. | MAD RPO page; MAD C3PAO page |
| Does it publish prices? | We found no complete public MAD CMMC price list in the pages and searches reviewed. Every real engagement still needs a scoped quote. | MAD website and searches run September 24, 2026 |
| Are there independent client reviews? | We found no independent client-review profile or community thread focused on MAD's CMMC delivery in the searches we ran. Employee reviews measure the workplace, not client outcomes. | Searches run September 24, 2026 |
The right CMMC path isn't the same for every contractor. Whether you need a managed security provider like MAD, a readiness consultant (RPO), a CUI enclave, a governance, risk, and compliance (GRC) software platform, or — when your written requirement and readiness support it — a C3PAO depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT setup, and your contract timeline. The contract clause sets your level, not a checklist. Because a general profile can't settle those facts for you, use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right kind of help before you request quotes — and do not submit CUI, drawings, or sensitive contract details.
Does MAD Security's Level 2 certificate cover your company?
No. MAD's certificate covers MAD's assessed environment, not yours. Under the CMMC rule, a MAD service becomes an external service provider (ESP) when CUI or Security Protection Data is processed, stored, or transmitted on MAD assets. A service that handles CUI faces different scoping rules from one that holds only logs, alerts, or security configuration data. MAD's certificate can reduce what an assessor or self-assessing contractor must re-check about MAD, but only if it matches your required level and assessment type and covers the exact services and assets you use.
Three terms make this click:
- An external service provider (ESP) is an outside provider of information-technology or cybersecurity services whose assets process, store, or transmit your CUI or Security Protection Data (32 CFR 170.4). A monitoring provider like MAD usually becomes one when its platform holds your logs or alerts.
- Security Protection Data is information used to protect your systems: logs, alerts, security configurations, and similar security records.
- A customer responsibility matrix (CRM) is a table showing which requirement the provider handles, which you handle, and which you share. MAD says it provides one and calls it a Shared Responsibility Matrix. Same idea.
The rule in one table
| If a MAD service… | …and it runs as | What the rule says |
|---|---|---|
| stores, processes, or transmits your CUI | a cloud service provider | The contractor must require and ensure that the cloud service meets FedRAMP Moderate or DoW-recognized equivalent requirements under DFARS 252.204-7012(b)(2)(ii)(D). |
| stores, processes, or transmits your CUI | a non-cloud ESP | The ESP service is inside your assessment scope. For Level 2 (Self), it is assessed against all Level 2 requirements under 32 CFR 170.16(a)(3). |
| holds only Security Protection Data such as logs, alerts, or settings | a CSP or non-CSP ESP | The relevant provider assets are treated as Security Protection Assets and assessed against the requirements that apply to what they do under 32 CFR 170.19(c)(2)(i), Table 4. |
| holds neither CUI nor Security Protection Data on its assets | any service model | It is not an ESP for CMMC under the rule's definition. |
When MAD is an ESP, the relationship belongs in your system security plan (SSP), MAD's service description, and the customer responsibility matrix under 32 CFR 170.19(c)(2)(ii).
What MAD's own certificate can and can't do for you
The rule lets an ESP earn its own CMMC status so there's less to check about it during your assessment (32 CFR 170.19(c)(2)(ii)). The Department's FAQ adds two conditions. The provider's assessment must be the same level and type your contract requires, or higher. And it must cover the assets in your scope (FAQ E-A3).
An MSSP that holds only your Security Protection Data doesn't need a certificate of its own. Its relevant assets and services are assessed as part of your assessment against the applicable requirements (FAQ E-A4). So MAD's certificate is a head start, not a requirement — and not a pass for you.
MAD says its Level 2 covers its own security operations and managed services. That's the right territory. The open question is detail: which tools, platforms, people, facilities, and locations were inside that assessment, and whether they're the ones in your quote.
Think of it like the company that monitors your building's alarm. The monitoring center isn't your building. But when an inspector checks your building's security, they look at how the monitoring works. If the monitoring company already passed its own inspection, the inspector may have less to check — as long as that inspection covered the same monitoring center and the same kind of inspection your building needs.
No web page — including this one — can tell you whether MAD's certificate covers the services in your quote. Only MAD's scope evidence can. The checklist below tells you exactly what to ask for.
How each MAD service lands in your scope
| MAD service, as MAD describes it | What it usually touches* | Rule row that likely applies | Ask MAD |
|---|---|---|---|
| Security operations center (SOC) monitoring, managed detection and response (MDR), network detection and response | Your logs, alerts, and network-security data | Security Protection Data → Security Protection Assets, unless CUI appears in the data | Where are our logs stored — which platform and whose cloud? Could CUI appear in log or alert content? How long do you retain logs and network captures? |
| Incident-response support | Affected systems and files during an incident | CUI row if responders process, store, or transmit CUI on MAD assets | Will your team ever copy our CUI? If so, where does it go, who can access it, and what cloud or non-cloud evidence covers it? |
| Vulnerability management; technical and penetration testing | Scan results; testers may reach systems that hold CUI | Security Protection Data row; CUI row if provider assets capture or retain CUI | Do scan or test results ever capture file contents? Where are results kept, and for how long? |
| Email security and awareness training | Email-security tools that inspect messages may see their contents | CUI row if the provider tool processes, stores, or transmits CUI; an external CSP then needs FedRAMP Moderate authorization or DoW-recognized equivalency | Does your email-security service inspect message content or attachments? Which service handles it, and what authorization or equivalency evidence covers that cloud offering? |
| Virtual Compliance Management (VCM, MAD's ongoing compliance service) and CMMC consulting | Your SSP, diagrams, evidence, tickets, and sometimes documents marked CUI | Depends on what you share and where the provider stores it | Where will our SSP and evidence live? Will this work ever require us to send you CUI? What information is prohibited from your ticketing and document systems? |
*Our reading of MAD's public service descriptions, checked September 24, 2026. Your statement of work, actual data flows, and responsibility matrix decide.
A worked example
Say you run a 40-person machine shop. Your CUI drawings live in a Microsoft 365 GCC High tenant, and you hire MAD to watch it. MAD's tools pull your audit logs into MAD's platform, and MAD's analysts watch alerts around the clock. Assume those logs contain Security Protection Data but no CUI.
MAD now holds your Security Protection Data. Its relevant service and provider assets belong in your Level 2 (Self) assessment scope as an ESP and are treated as Security Protection Assets. You document MAD in your SSP and service description, include its responsibility matrix, and show how requirements such as audit logging (3.3.1) and system monitoring (3.14.6) are met. Some of that is MAD's job. Some is yours — like making sure each in-scope system produces and forwards the logs your SSP and monitoring design say it does. If MAD's own status covered the same platform and assets at the same or a higher assessment level and type than your requirement, you can use that evidence for MAD's share.
Now say a MAD responder, mid-incident, downloads a drawing to a MAD-controlled system to check whether it was altered. At that moment MAD has processed or stored CUI on its own asset, and the CUI-handling row applies. That's why the question gets answered before you sign, not during an incident.
Is MAD Security the right kind of help for you?
MAD's model — readiness consulting plus 24/7 monitoring from one company — fits a contractor that handles CUI and doesn't have its own security team. For CMMC alone, it's more than an FCI-only shop usually needs. It's only partly useful if you already run your own security operations. MAD does not present itself as your formal assessor.
| Your situation | Does MAD's category fit? | Why | Look here instead or also |
|---|---|---|---|
| FCI only; contract points to Level 1 | Usually more than CMMC alone requires | Level 1 is 15 requirements with an annual self-assessment and affirmation (DoW) | Level 1 checklist |
| CUI; Level 2 (Self); thin IT and security staff | Yes — the category's core buyer | You need operating controls, monitoring, evidence, and help documenting the environment | MDR for CMMC and the CMMC provider directory |
| CUI; you already have an MSP running IT | Can fit as the security layer | Any provider whose assets hold CUI or Security Protection Data may enter your scope, so the providers' responsibility matrices must line up | RPO vs. MSP and the responsibility matrix guide |
| You already run your own SOC | Partial fit | You may need only consulting or VCM — ask for a scoped quote without monitoring | Readiness consultants |
| CUI is scattered across email and file shares; no boundary yet | Scoping comes first | MAD says it does scoping, but the enclave or cloud decision drives much of the work and cost | Scoping guide and enclave vs. GCC High |
| You need a formal Level 2 (C3PAO) assessment | No | MAD says it doesn't perform C3PAO assessments | Authorized C3PAOs |
| You want to run compliance yourself with software | Different category | A GRC platform organizes your evidence; it doesn't watch your network or implement every requirement | CMMC provider directory |
| You want a guaranteed pass | No honest provider fits | Nobody controls an independent assessor's findings | — |
Not sure which row is yours? Two quick checks reveal whether you need a closer CUI review:
- Does your contract or subcontract include DFARS 252.204-7012 or say NIST SP 800-171 applies to a covered contractor information system?
- Do you receive files marked CUI, or technical information that the contract or data owner says is controlled and subject to distribution statements B through F?
A “yes” is a reason to trace the written requirement and the actual data — not permission to label every drawing, system, or vendor CUI by assumption. DFARS 252.204-7012 applies its NIST SP 800-171 safeguarding duty to covered contractor information systems that process, store, or transmit covered defense information. Confirm the data owner, markings, contract language, distribution statement, and CUI category or authority before you set scope. Our FCI vs. CUI guide walks through it.
Still not sure which row is yours — or whether a managed security provider is the right first hire at all? That turns on your contract, your data, and your setup, which no vendor profile can see.
What to get from MAD Security in writing before you sign
Ask for 12 things before you sign. A provider that's confident in its work should be able to answer them clearly, and slow or vague answers tell you something too. Don't send CUI while you ask.
As answers come in, mark each row Pass, Clarify, or Stop. Leave a row Unknown until you have proof. Unknown never means yes.
Start your email like this:
Subject: Before we sign — documents and answers we need
We're evaluating MAD Security for CMMC readiness, monitoring, or a combined engagement. Please send the items below. Don't include CUI, drawings, credentials, vulnerability details, or sensitive contract information; if an item requires protected material, tell us what protected channel and handling terms you propose. If something isn't available or isn't included, please say so.
Don't send CUI, drawings, credentials, vulnerability details, or sensitive contract information to a vendor you haven't engaged.
| # | Ask MAD for | A good answer | Push back if | Put it in the contract? |
|---|---|---|---|---|
| 1 | Your Cyber AB Marketplace listing: legal name, current role/status, listing ID, and associated Registered Practitioner | The live listing matches the company named on your contract | You get a logo instead of a live listing, or the legal names don't match | Yes — the role and entity MAD represents |
| 2 | Your Certificate of CMMC Status or an SPRS status printout, including CMMC UID, CMMC Status Date, Final or Conditional status, and latest annual affirmation date | A Final status with a current affirmation; the dates and entity match the proposal | Refusal, a lapsed affirmation, or Conditional described as Final | Yes — accuracy and notification of status claims |
| 3 | A non-sensitive description of what that assessment covered: which SOC, tools, platforms, facilities, and locations | The services and assets in your quote were inside it, or exclusions are explicit | The certificate covers a different environment from the one you'd use | Yes — name the covered services and require notice before they change |
| 4 | A responsibility matrix for the services you'd buy, built on the current CMMC Level 2 baseline of NIST SP 800-171 Revision 2 | Every applicable requirement marked MAD, you, or shared, with an evidence owner | Blank rows, vague “shared” labels, or “we handle compliance” | Yes — as an accepted deliverable |
| 5 | A map of where your data goes: each tool, whose cloud, retention, subproviders, and whether CUI could land there through logs, email scanning, incident response, testing, tickets, or documents | A clear map. Any external CSP that stores, processes, or transmits CUI is FedRAMP Moderate authorized or DoW-recognized equivalent; any non-CSP ESP handling CUI is explicitly included in your assessment scope | They can't say where your logs, evidence, tickets, or copied files live | Yes — data locations, permitted content, retention, and subproviders |
| 6 | Response terms: severity levels, acknowledgment and response times, escalation, and which actions MAD may take without asking you | Written times and a specific authorization matrix. MAD says response actions run according to client authorization — get the list | “24/7” means only alerts forwarded to you, with no response times or authorized actions | Yes — service levels and escalation |
| 7 | Your cyber-incident workflow: who prepares and submits the DIBNet report, who holds the DoD-approved medium assurance certificate, and how affected-system images and relevant monitoring data are preserved for at least 90 days after report submission | A written runbook, tested in a tabletop. The contractor or subcontractor remains accountable, while MAD's investigation, evidence-preservation, and any delegated filing mechanics are explicit under DFARS 252.204-7012(c) and (e) | “We handle 7012,” with no split of duties, account ownership, contacts, or retention process | Yes — runbook, contacts, authority, and retention |
| 8 | The deliverables you'll own: editable SSP, eligible POA&M or remediation tracker, policies, diagrams, evidence index, VCM calendar, and assessment-support hours | You keep editable source files and receive a calendar with named outputs, owners, and acceptance criteria | PDFs only, or “continuous compliance” with no recurring work product | Yes — deliverables, ownership, cadence, and acceptance |
| 9 | Named tools and licenses, who owns each tenant and admin account, and a price split into one-time, monthly, usage-based, and optional costs, totaled over 24 months | Every cost counted once, with assumptions and growth triggers written down | A low monthly fee with mandatory tools, remediation, or usage charges appearing after signature | Yes — price schedule, assumptions, and change triggers |
| 10 | Exit terms: return/export of logs, evidence, tickets, documents, and configurations; tenant/admin access; deletion; transition help; and fees | You retain usable source files, evidence, and necessary access, with a timed transition plan | A tenant or evidence vault only MAD controls, with no practical export | Yes — exit plan, data return/deletion, and rates |
| 11 | Any referral fees, commercial alliances, or assessor/product relationships that could affect a recommendation, plus the names and roles of the people assigned to you | Relationships and individual roles disclosed in writing; assessor independence preserved | “One-stop certification,” undisclosed economics, or evasive answers about who may later assess you | Yes — disclosure and conflict notification |
| 12 | Two references comparable to your size, stack, CUI footprint, and assessment type whose work included MAD's services, plus written confirmation that MAD promises deliverables rather than a pass | References you can call; precise work described; outcome-free contract language | Pass guarantees, a “100% pass rate,” or references that don't match your situation | Outcome language: yes |
End your email like this:
Thank you. We'll review everything before we schedule a proposal walkthrough.
Here's what the difference looks like on row 5. Fictional example — not MAD's answer.
- Vague: “Our SOC is CMMC Level 2 certified, so you're covered.”
- Useful: “Your Windows and firewall logs go to ExampleLog, a fictional log-analysis platform, and are kept for 12 months. We strip file names from log content by default. Our responders don't copy files; if we need to examine one, we do it inside your environment with your admin present.”
For more questions worth asking any consultant, see questions to ask a CMMC consultant.
What will MAD Security cost?
MAD Security doesn't publish a complete public CMMC price list, so every engagement needs a quote. What moves a quote like this is how many devices and users are watched, how much log data is retained and for how long, whether incident response is included, which licenses are required, and how much readiness or VCM work is bundled. Ask MAD to split the quote into the layers below so you can compare it with anyone else's.
| Cost layer | One-time or recurring? | Ask MAD |
|---|---|---|
| Discovery and scoping | One-time | Is it credited toward the project if we go ahead? What written boundary is the deliverable? |
| Readiness project: gap assessment, SSP, eligible POA&M/remediation tracker, policies | One-time | How many revision rounds are included, and which source files become ours? |
| Fixing gaps: configuration work, new tools, hardware | One-time, then as needed | Who buys, owns, administers, and renews what gets installed? |
| SOC and MDR monitoring | Recurring | What drives the price — devices, users, log volume, retention, sites, or response hours? What happens if we grow? |
| Virtual Compliance Management | Recurring | Bundled with monitoring or billed separately? Which monthly, quarterly, and annual outputs are included? |
| Licenses and cloud services | Recurring | In MAD's name or ours? Included in the headline fee or passed through? |
| Incident response beyond monitoring | Retainer, hourly, or event-based | What's included before extra billing starts? Are travel, forensics, legal coordination, or recovery separate? |
| Your own staff time | Recurring internal effort | How many hours a month does MAD expect from us, by role? |
| Formal assessment, if a written requirement calls for one | Separate firm and event | Not MAD's assessment role. Budget it separately and don't count it again inside readiness or SOC fees. |
| Exit and transition | At termination | What does leaving cost, how long does transition support last, and what data and configurations are returned? |
To compare two quotes fairly, total each one over the same stretch — 24 months works well. Count one-time costs once, add each recurring cost for the months it applies, then add only the optional or usage-based extras you reasonably expect to use. Don't count a license, tool, or service again if the quote already includes it. That keeps a low monthly fee from hiding a large setup bill or a separate mandatory stack.
For sourced market figures on managed security and compliance pricing, see our MSSP and managed compliance cost guide.
Are there independent MAD Security CMMC reviews?
Not many that answer a CMMC buyer's question. Our searches on September 24, 2026 found no independent client-review profile, named-client assessment case, or community thread focused on MAD's CMMC delivery. What exists is mostly MAD's own material and press releases, a third-party MDR directory profile built from public company information, trade-list coverage, and employee reviews on sites such as Indeed or Glassdoor. Employee reviews rate the workplace, not client outcomes.
That leaves references more useful than stars for this decision. Row 12 of the checklist asks for two clients comparable to your size, technology, CUI footprint, and assessment type whose work included MAD's services.
How MAD's public CMMC pages hold up
MAD's July 15, 2026 article on the pause correctly reports the main live status: Phase II was suspended while Phase I self-assessments and the underlying safeguarding work continue. Several older pages haven't caught up. Here's what we found on September 24, 2026.
| MAD page | What it says | What the rule and Department say |
|---|---|---|
| “What is CMMC?” (June 3, 2025) | Level 1 has 17 controls and a third-party audit every three years | Level 1 is 15 FAR 52.204-21 requirements with an annual self-assessment and annual affirmation; no C3PAO is used and POA&Ms aren't allowed (DoW). |
| “CMMC Consulting” | Level 3 adds 35 NIST SP 800-172 controls; its “CMMC compliance requirements” link goes to NIST SP 800-171 Revision 3 | Level 3 uses 24 selected SP 800-172 requirements, and the current CMMC Level 2 baseline remains NIST SP 800-171 Revision 2 (FAQ B-A3 and B-A5). NIST has published Rev. 3, but CMMC doesn't switch automatically. |
| “What is a C3PAO?” | A contract requiring Level 2 means a C3PAO assessment | Level 2 can be Self or C3PAO under the rule. During the current suspension, Department requirement documents may designate only Level 2 (Self), while existing written instruments must be checked for an issued amendment or modification (DoW). |
| “CMMC Requirements” (marked updated December 1, 2025) | Phase II starts November 10, 2026, with no mention of the suspension | Phase II was suspended July 13, 2026, and no replacement date appeared on the official program pages checked September 24, 2026 (DoW). |
Out-of-date web copy isn't proof of poor service. It is a reason to check every number and deadline against the controlling source, and it's why row 4 of the checklist asks for a responsibility matrix built on NIST SP 800-171 Revision 2.
Does the CMMC pause change whether you need MAD?
It changes the assessment designation and deadline pressure, not the underlying safeguarding duty. If DFARS 252.204-7012 is incorporated and applies to a covered contractor information system that processes, stores, or transmits covered defense information, NIST SP 800-171 Revision 2 and the clause's 72-hour incident-reporting duty still apply. Level 2 (Self) assessments continue where the live solicitation, contract, or subcontract requires them. What's paused is the expansion of new Level 2 (C3PAO) and Level 3 designations — so buy monitoring because your controls and risk call for it, not to beat a November 10, 2026 date that's no longer live.
During the pause, the Department says it will enforce NIST SP 800-171 Revision 2 through self-assessments and select government-led assessments (DoW). Where Level 2 (Self) applies, your own assessment and annual affirmation carry the live status burden.
If an active solicitation still names Level 2 (C3PAO) or Level 3, the July implementation procedures directed the Department to issue an amendment. If an existing contract contains one of those requirements, contracting personnel were directed to remove it by modification before the next option exercise or during the next scheduled administrative modification. Until the amendment or modification reaches the document governing your work, don't assume a news release rewrote it. For a subcontract, get the prime's position in writing. Our program status page shows what to search for in your paperwork.
If a MAD quote leans on the suspended November 10, 2026 transition for urgency, ask MAD to separate the security work from the rush premium and reprice the timeline. Our guide on what CMMC spending survives the pause helps sort the difference.
Edge cases worth settling before you commit
Keeping your current IT provider
You can use MAD for security and keep another company for IT. A provider becomes an ESP when CUI or Security Protection Data is processed, stored, or transmitted on that provider's assets. When both the MSP and MSSP meet that test, the Department's FAQ treats both as ESPs inside your assessment scope (FAQ E-A4). The risk is a requirement that falls between them. Line up both responsibility matrices before you sign.
Who reports a cyber incident
The contractor or subcontractor remains accountable for the rapid report required by DFARS 252.204-7012. The clause defines “rapidly report” as within 72 hours of discovery, uses DIBNet, and requires a DoD-approved medium assurance certificate for reporting. MAD can investigate, preserve evidence, draft information, and support the process, but the contract should name who owns the DIBNet account, who authorizes submission, who preserves the required data, and who is on call (DFARS 252.204-7012(c) and (e)).
Who signs your annual affirmation
Your own senior company representative — the Affirming Official — not MAD. The Department's FAQ says that person is responsible for deciding whether a significant change affects continuing compliance and bears the legal and contractual risk of that decision (FAQ C-A12). MAD's reports can inform the decision. They can't make or sign it for you. See our annual affirmation guide.
Consultant-to-assessor conflicts
A CMMC Ecosystem member that served as a consultant to prepare your organization for a CMMC assessment may not participate in your Level 2 certification assessment within the prior three years (32 CFR 170.8(b)(17)(ii)(G)). The Cyber AB separately says people who hold both practitioner and assessor credentials cannot assess a company they previously helped implement. MAD's pages say members of its consulting team hold assessor credentials. If a MAD person helps prepare you, record that person's name and role and provide the list to any future C3PAO.
Leaving MAD later
Plan the exit before you start. After a report under DFARS 252.204-7012, the contractor must preserve images of affected systems and relevant monitoring or packet-capture data for at least 90 days after submission (7012(e)). Your exit terms need to preserve access to anything required for that duty, an assessment, or your evidence history. Make sure you get your logs, evidence, configurations, and editable documents back. Our guide to switching CMMC providers covers the transition.
What if MAD's own status lapses?
Final Level 2 statuses use a three-year assessment cycle, with an affirmation after the assessment and annually thereafter. Failure to affirm annually causes the assessment to lapse (DoW). If March 28, 2025 is MAD's actual CMMC Status Date and its status remains Final, the next triennial assessment would be due no later than about March 28, 2028. Ask for a contract clause requiring prompt notice if its status, affirmation, assessed scope, or covered service changes.
Alternatives, by category
If MAD's category is right for you, compare it with other managed security providers. If the category is wrong, the table points to the right one. These links aren't rankings or endorsements.
| If you want… | Category | Read |
|---|---|---|
| 24/7 monitoring with CMMC evidence support | MSSP / MDR | MDR for CMMC and the provider directory |
| Readiness help without managed services | RPO / consultant | Readiness consultants and RPO vs. MSP |
| A smaller CUI footprint | CUI enclave or government cloud | Enclave vs. GCC High and the scoping guide |
| Your own evidence system | GRC platform | CMMC provider directory |
| The formal assessment | C3PAO | Authorized C3PAOs |
Weighing MAD against other kinds of help, not just other MSSPs? Match the category to your contract first, then compare companies inside it.
How we checked this profile
This is a public-source profile, not a hands-on test. We didn't hire MAD, visit its SOC, inspect its private CMMC records, or interview MAD or its clients. Every consequential claim above is tied to a rule or official source, attributed to MAD, or labeled as a scoped finding from the searches we ran.
What we verified on September 24, 2026
- Read: 32 CFR 170.4, 170.8(b)(17), 170.9(a), 170.16(a), 170.19(c)(2), 170.22, and 170.24; DFARS 252.204-7012 on Acquisition.gov; FAR 52.204-21; NIST SP 800-171 Revision 2; the Department of War CIO CMMC FAQ v2.4 (July 13, 2026); the CIO's “About CMMC” page; the July 13 implementation procedures; and the Cyber AB's consulting-role page.
- Checked: the official DARS class-deviation index; the Cyber AB URL and title for MAD's RPO-10172 page; MAD's public pages on CMMC consulting, SOC-as-a-Service, RPO and C3PAO roles, CMMC requirements, Level 2 announcement, and the July 2026 pause; the site's internal destinations used on this page; and search results for public pricing and independent client reviews.
- Couldn't verify from public evidence: the current JavaScript-rendered status fields on MAD's Marketplace record; MAD's certificate, CMMC UID, current Final or Conditional status, annual affirmation, or assessment scope; its SPRS score; client outcomes; complete pricing or service-level agreement; which tools, subproviders, or assets sit behind a buyer's proposed SOC service; or whether a particular MAD service would receive CUI.
- Current-status limitation: the official DARS index identifies Class Deviation 2026-O0025 Revision 3 dated September 3, 2026, but the direct Revision 3 PDF was not retrievable in this audit. This profile makes no clause-detail claim that depends on that inaccessible text; the live CMMC status and July suspension instructions were verified independently from the DoW CIO pages and signed implementation procedures.
Our methodology explains how we build provider profiles.
Frequently asked questions
Does CMMC require a 24/7 SOC or MDR service?
No rule names one. NIST SP 800-171 Revision 2 does require creating and retaining audit logs to support monitoring and investigation (3.3.1), an operational incident-handling capability (3.6.1), and monitoring systems and communications traffic to detect attacks and indicators of potential attacks (3.14.6). A managed SOC is one way to meet and prove those outcomes; in-house tools and staff are another.
Can we use MAD for monitoring and a different firm for consulting?
Yes. A provider enters your CMMC scope as an ESP only when CUI or Security Protection Data is processed, stored, or transmitted on its assets. If both firms meet that test, document both in the SSP and line up their responsibility matrices. The three-year conflict rule limits who can participate in a future Level 2 certification assessment after consulting; it doesn't limit the number of providers that can help you prepare or operate controls.
Does MAD Security work with GCC High or PreVeil?
MAD says it's technology-neutral and advises on Microsoft GCC High, PreVeil, virtual-desktop enclaves, and hybrid setups. Ask who performs the implementation, who owns the tenant and licenses, which provider assets enter scope, and where CUI and Security Protection Data go. For the architecture trade-offs, see enclave vs. GCC High.
Does MAD Security help with Level 1?
MAD says it supports all CMMC levels. Level 1 is 15 FAR 52.204-21 requirements with an annual self-assessment and annual affirmation, and it doesn't require a C3PAO or name a 24/7 SOC. Work the Level 1 checklist first, then buy help only for a gap you can name.
Can we see MAD's certificate ourselves?
Not in a public certified-company directory. The Department doesn't publish a list of companies that completed CMMC assessments or received certificates, but a supplier can print its own status from SPRS and share it (FAQ C-A4). Ask MAD for the certificate or status printout, CMMC UID, status date, current affirmation, and non-sensitive scope evidence.
Still not sure which CMMC path fits your company? Use The Defense Compliance Report's Find My CMMC Path tool to see which path and kind of help fit your contract, CUI, environment, and timeline — before you hire anyone.
Sources
All checked September 24, 2026.
Rules, standards, and official guidance
- 32 CFR Part 170, CMMC Program — especially §§ 170.4, 170.8, 170.9, 170.16, 170.19, 170.22, and 170.24
- Federal Register, Cybersecurity Maturity Model Certification Program Final Rule
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
- FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems
- NIST SP 800-171 Revision 2 and NIST SP 800-171A, June 2018
- Department of War CIO, CMMC FAQ v2.4 (July 13, 2026)
- Department of War CIO, About CMMC and CMMC program page
- Department of War, “Department of War Suspends CMMC Phase II Requirements,” July 13, 2026
- July 13, 2026 CMMC suspension implementation procedures
- DARS, DFARS Revolutionary FAR Overhaul Class Deviations — lists Class Deviation 2026-O0025 Revision 3 dated September 3, 2026; the direct attachment was not retrievable during this audit
- Cyber AB, Consulting and Implementation roles and MAD Security Marketplace page
Company sources — MAD Security
- CMMC Level 2 announcement
- What is a CMMC RPO? · What is a C3PAO? · CMMC Consulting · CMMC Requirements
- SOC-as-a-Service and Managed Security Services
- What is CMMC? (June 3, 2025) · CMMC Phase II Is Suspended (July 15, 2026)
- MSSP Alert Top 250 announcement
Third-party context
- MDR Providers, MAD Security profile — public-data profile; not a client-outcome review
About The Defense Compliance Report
The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on every claim and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures. We're not affiliated with the Cyber AB, DoD, DCMA DIBCAC, NIST, or any U.S. government agency. This page is educational research, not legal, contractual, or compliance advice — confirm scope and applicability with a CMMC Registered Practitioner (RP) or a qualified federal-contracts attorney. See our Editorial & Advertising Policy.