The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

NeoSystems CMMC Review: 2026 Status, Service Continuity, and What to Verify

By The Defense Compliance Report Editorial Team — an independent trade publication on CMMC 2.0 and DIB compliance · Last verified September 2026

NeoSystems LLC told employees in May 2026 that it was winding down, the Washington Business Journal reported through Reston Patch. BlueStreet Solutions acquired its Enterprise Solutions Group. FIT Solutions was named to assume service continuity for Information Services Group customers. NeoSystems LLC's 2025 Final Level 2 announcement does not establish that today's operator or service is covered.

If you came here for a NeoSystems CMMC review, the table below shows who is who today. The sections after it show what each old claim still proves, and what to get in writing before you sign, renew, or move data.

Program status, checked September 23, 2026: CMMC remains paused in Phase 1. The Department's current CIO site uses Department of War (DoW), while the codified rule and DFARS clauses still use Department of Defense (DoD). DoW suspended Phase II on July 13, 2026. Level 1 and Level 2 self-assessments, NIST SP 800-171 Revision 2 for Level 2, applicable SPRS entries, annual affirmations, and DFARS 252.204-7012 duties remain. The 60-day review period has passed, but no public task-force report or replacement Phase II date appeared on the official pages we checked. Where the program stands now →

This page is for you if:

This page is not for you if:

NeoSystems at a glance (checked September 23, 2026)

"NeoSystems" now points to at least three different things. There's legacy NeoSystems LLC, which was reported as winding down and preparing to dissolve in May 2026. There's its back-office unit, now owned by BlueStreet. And there's the IT and CMMC customer base known as NeoSystems ISG, for which FIT Solutions was named to assume service continuity. Which one you're dealing with decides every answer below.

Question — Short answer — Source — What it means for you
QuestionShort answerSourceWhat it means for you
What happened to NeoSystems LLC?About 70 employees received termination notices on May 1, 2026, and a letter said the company was winding down after finding “no viable options exist to avoid dissolution,” the Washington Business Journal reported.Washington Business Journal, as summarized by Reston Patch on May 6, 2026Don't treat a “NeoSystems” logo as proof of the legal company that owes you performance. Find the legal name on the contract.
Who bought the back-office side?BlueStreet Solutions bought the NeoSystems Enterprise Solutions Group (ESG).BlueStreet announcement dated May 1, 2026ESG covers systems implementation and managed accounting, finance, payroll, and HR. The announcement does not say BlueStreet bought the IT, hosting, NeoEnclave, or CMMC business.
Who was named to provide ISG service continuity?FIT Solutions LLC, a San Diego managed IT and cybersecurity firm, was named as “assuming service continuity” for NeoSystems ISG customers.May 14, 2026 notice; FIT Solutions“Service continuity” is not the same as owning the old contracts, systems, brand, or credentials. Get the relationship and contracting authority in writing.
Is “NeoSystems ISG” the same legal company as legacy NeoSystems LLC?We could not confirm that. It is a brand marketed at neosystemsisg.com, and legacy CMMC and NeoEnclave pages point there.Our check of both sitesAsk for the current legal name, IRS Form W-9, formation state, and authorized signer before you sign or renew.
What did NeoSystems announce about CMMC Level 2?NeoSystems LLC announced a 110/110 result and Final Level 2 (C3PAO) status in March 2025. We did not review the certificate itself.NeoSystems announcement, March 26, 2025Meaningful history. Whether it covers today's operator, system, or service is a separate question. Use the test below.
Is its hosting FedRAMP Certified today?NeoSystems described NeoSystems.Cloud as “FedRAMP Ready” in 2024. FedRAMP retired Ready in July 2026 and moved remaining records to “Legacy FedRAMP Ready”; Ready was not FedRAMP Certification. We could not confirm a current Marketplace record for NeoSystems.Cloud.NeoSystems announcement, January 9, 2024; FedRAMP's July 2026 transition noticeAsk for the exact current Marketplace record or current equivalency evidence for the cloud in your proposal. See the hosting section.
Is it on the Cyber AB Marketplace today?A Cyber AB page titled “NeoSystems, LLC” still loaded, but its current details did not render for us. We could not confirm a listing for the present NeoSystems ISG operator or FIT Solutions.Cyber AB member pageCheck the live Marketplace under the exact legal name you'll contract with.
Is there public pricing?We found no fixed public price on the company pages reviewed September 23, 2026.Our review of the current public pagesGet an itemized quote before you compare anyone.
Is it related to NeoSystems Inc. in Calgary?No. The G2 seller page under that name covers ITRAK 365, a separate Calgary risk-management software vendor.G2 profileIgnore those product reviews for this decision.

Whether you should stay with NeoSystems ISG, move your Controlled Unclassified Information (CUI) into a Microsoft tenant your company owns, pick a different CUI enclave, or just bring in readiness help depends on your required CMMC level, whether you handle Federal Contract Information (FCI) or CUI, your assessment type, your cloud setup, and your contract timeline. The contract clause sets your level, not a checklist. A company profile can't settle those facts for you, so use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right kind of help before you request or renew a quote — and do not submit CUI, drawings, or sensitive contract details.

What happened to NeoSystems? A dated timeline

NeoSystems didn't fade out slowly. In roughly two weeks in May 2026, ESG was sold to BlueStreet, termination notices were reported at legacy NeoSystems LLC, and FIT Solutions was named to assume service continuity for ISG customers. Here's each step, where it comes from, and what it does not prove.

Date — What happened — Source — What it does not prove
DateWhat happenedSourceWhat it does not prove
Jan. 11, 2021NeoSystems announced it had been recognized as a Registered Provider Organization by the CMMC accreditation body, now called the Cyber AB. The current Cyber AB term is Registered Practitioner Organization (RPO).NeoSystems releaseA current listing, current status, or a listing for any successor.
Jan. 9, 2024NeoSystems said it renewed the “FedRAMP Ready” designation for NeoSystems.Cloud, which it called a community cloud for government contractors.NeoSystems releaseFedRAMP Certification, present Marketplace status, or the current boundary and operator.
Mar. 26, 2025NeoSystems LLC announced a 110/110 result and Final Level 2 (C3PAO) status.NeoSystems releaseThat the status covers a different legal entity, system, service, or customer today.
May 1, 2026BlueStreet announced it acquired NeoSystems ESG.BlueStreet releaseAny purchase of the IT, hosting, NeoEnclave, or CMMC business.
May 1, 2026 (late Friday)About 70 employees received termination notices. A letter said the company was winding down after a “deteriorating financial condition,” the Washington Business Journal reported.Washington Business Journal, as summarized by Reston PatchThe company's final legal status or what happened to each customer's systems, contracts, data, or evidence.
May 14, 2026BlueStreet said FIT Solutions would assume service continuity for NeoSystems ISG customers as a “strategic operating partner,” and listed separate contacts for ESG and ISG.May 14 noticeThat FIT bought ISG, owns the NeoSystems name, took assignment of contracts, or holds any NeoSystems credential.
May 2026High Street Capital, which says it first invested in NeoSystems in 2021, announced the sale of NeoSystems ESG to BlueStreet.High Street CapitalAnything about the ISG side.
Sept. 23, 2026 (our check)neosystemscorp.com identified as “NeoSystems ESG LLC.” Legacy CMMC, NeoEnclave, and NeoSystems.Cloud pages pointed toward neosystemsisg.com, which marketed CMMC help and “FedRAMP-moderate hosting.”Our direct checks and current search-index extractWho legally operates neosystemsisg.com or what current evidence supports each claim.

You'll also find forum threads and blog commentary about NeoSystems' final months that go beyond these records. We couldn't verify those accounts, so we don't repeat them. Nothing on this page relies on them.

What we checked, and what we couldn't

Checked on September 23, 2026: the company notices and releases above; both NeoSystems websites; FIT Solutions' website; the Cyber AB member page; 32 CFR Part 170, including sections 170.4, 170.8, 170.9, 170.19, 170.21, and 170.22; DFARS 252.204-7012 and 252.204-7021; NIST's Revision 2 and Revision 3 publication records; FedRAMP's 2026 Ready transition and terminology; the official DARS class-deviation index; and the Department of War's current CMMC page.

Could not confirm: the legal company operating neosystemsisg.com; whether FIT Solutions or the current NeoSystems ISG operator holds a current CMMC status or Cyber AB listing; NeoSystems.Cloud's current FedRAMP Marketplace record; the actual 2025 Certificate of CMMC Status or current annual affirmation; any court, bankruptcy, or state dissolution record; any public Reform Task Force report; or the status of any single customer's data. The official DARS index showed Class Deviation 2026-O0025, Revision 3, dated September 3, 2026, but its attachment was not fully readable through our audit tools, so this page does not claim more from it than the current DoW CIO page supports.

NeoSystems CMMC review: does the 2025 status cover today's service?

Not automatically, and not by itself. Under the CMMC rule, a status belongs to a specific organization's information system, and a certificate identifies the organization, the industry CAGE codes associated with the systems in scope, an assessment identifier, a date, and a level. A 2025 status announced by NeoSystems LLC proves that announcement concerned NeoSystems LLC's assessed system in 2025. You need current documents to connect it to the operator, system, and service in front of you now.

No web page — including this one — can tell you whether today's NeoSystems ISG service sits inside a current CMMC certificate. The certificate, current status record, scope, and contract can. Here's how to read them.

The rule defines CMMC Status as the status of an Organization Seeking Assessment's information system, stored in SPRS and shown on a certificate when a C3PAO or DIBCAC performed the assessment (32 CFR 170.4). Each certificate must list, at a minimum, every industry CAGE code associated with the systems in scope, the C3PAO's name, the assessment's unique ID, the Organization Seeking Certification's name, and the status date and level (32 CFR 170.9(b)(18)).

Think of it less like a badge attached to a brand and more like an inspection record for a named organization and a defined system boundary. A new operator, legal entity, or boundary needs a documented match. Continuity cannot be assumed from the logo.

The five-match test

Ask for the certificate, current affirmation, and scope record, then line them up against the proposal or contract. Mark each row Matched, Not matched, or Unknown. Unknown is not a no. It's a document or explanation you haven't received yet.

Match — Compare — Good sign — If it doesn't match
MatchCompareGood signIf it doesn't match
1. Legal entityOrganization name on the certificate vs. the name on your contract, invoice, and W-9Same company, or written evidence that establishes the legal continuity you are being asked to rely onAsk for the transaction and contract-authority documents before you rely on the status.
2. SystemCAGE codes, assessment UID, and CMMC UID or scope identifiers vs. the service in your proposalA written map showing how the proposed service relates to the assessed systemDo not rely on the old status for your service until the mismatch is resolved in writing.
3. Date and upkeepStatus date and proof of the latest annual affirmationCurrent for the period and purpose you're relying onAsk for current status and affirmation evidence.
4. BoundaryThe assessed scope vs. the tools, tenant, people, facilities, and cloud in your proposalEverything you're buying is mapped to the assessed scope or clearly identified as outside itAsk for a scope map and a Customer Responsibility Matrix.
5. RoleWhat the provider does vs. who assesses youThe provider prepares or operates; a separate authorized C3PAO performs a required Level 2 certification assessmentIf you only need an assessment, you need a C3PAO, not this provider category.

Even a perfect match doesn't make you compliant

A provider's own status may reduce the provider's assessment effort during your assessment. It doesn't replace your assessment, your evidence, or your responsibilities. When a provider that is not a cloud service provider processes, stores, or transmits your CUI, its services are in your assessment scope and are assessed as part of your assessment (32 CFR 170.19(c)(2)(i), Table 4). For your assessment, your company is the Organization Seeking Assessment (OSA).

The rule calls a provider's own certification voluntary and says it may reduce the ESP's effort required during the OSA's assessment. It also requires the OSA to document the provider relationship and services in its System Security Plan (SSP), the provider's service description, and the Customer Responsibility Matrix (CRM), the chart showing which requirements the provider handles and which remain with you (32 CFR 170.19(c)(2)(ii)).

NeoSystems' 2025 announcement said clients could rely on it to “greatly simplify and accelerate” their own certification. “Simplify” was the honest word. It never meant done for you. For more on how this works with any provider, see what the CMMC rule requires of MSPs and our guide to the shared responsibility matrix.

RPO, C3PAO, “certified MSP”: what each label proves

Label — What it means — What it doesn't mean — How to check
LabelWhat it meansWhat it doesn't meanHow to check
RPO (Registered Practitioner Organization)A Cyber AB ecosystem organization registered to provide non-certified advisory services. Older NeoSystems material used the former term “Registered Provider Organization.”Authority to conduct or issue a certification assessmentThe live Cyber AB Marketplace, under the exact legal name
C3PAOAn organization authorized or accredited by the Cyber AB to conduct Level 2 certification assessments (32 CFR 170.4)That every service it provides is assessment work, or that it may assess work it preparedThe live Marketplace or our authorized C3PAO list
Final Level 2 (C3PAO) statusA C3PAO assessed one OSA information system and it met the final-status standardCoverage of other legal entities, systems, services, or customersThe certificate fields, current affirmation, scope, and five-match test above
“Certified MSP” or “certified ESP”Marketing shorthand that may refer to an MSP's or external service provider's own assessed systemThat its customers are certified or that every offered service is in that assessed boundaryThe current certificate, scope map, and CRM for the services you buy

C3PAOs must follow Cyber AB conflict-of-interest policies. More specifically, a CMMC ecosystem member that served as a consultant preparing an organization for any CMMC assessment during the preceding three years may not participate in that organization's Level 2 certification assessment (32 CFR 170.8(b)(17)(ii)(G)). Use a separate assessment firm.

Can NeoSystems ISG host your CUI?

Maybe, but a website phrase won't tell you. If an outside cloud stores, processes, or transmits covered defense information, DFARS 252.204-7012 requires security equivalent to the FedRAMP Moderate baseline, plus the clause's incident-reporting and forensic-support terms. NeoSystems' own records described NeoSystems.Cloud as “FedRAMP Ready” in 2024. FedRAMP retired Ready in July 2026 and transitioned remaining records to Legacy FedRAMP Ready; Ready was never FedRAMP Certification.

Here's the rule text in plain terms. If you use an outside cloud service provider (CSP) to store, process, or transmit covered defense information, you must require the CSP to meet security requirements equivalent to the FedRAMP Moderate baseline. The CSP must also comply with paragraphs (c) through (g) of the clause: cyber-incident reporting, malicious-software submission, preserving images of affected systems for at least 90 days, forensic access, and damage assessment (DFARS 252.204-7012(b)(2)(ii)(D)).

In 2024, FedRAMP Ready meant a third-party assessment organization had prepared a Readiness Assessment Report and FedRAMP had accepted the service as ready to pursue authorization. In July 2026, FedRAMP retired that path, renamed surviving records Legacy FedRAMP Ready, and introduced Class A as the entry path toward Certification. A legacy Ready record can still be useful diligence evidence. It is not FedRAMP Certification. (FedRAMP's July 2026 transition notice)

Which rule applies depends on whose cloud it is

DoD's Level 2 scoping guidance draws a useful line. A provider that manages a third-party cloud on your behalf, such as your own Microsoft 365 GCC High (Government Community Cloud High) tenant, is an external service provider rather than the CSP for that cloud. A provider that operates the cloud platform holding your CUI is the CSP for that service. NeoSystems' past marketing described both environments built on NeoSystems.Cloud and CUI work in Microsoft 365. Find out which one holds your data today.

Where your CUI lives — Which rule applies — What to ask for
Where your CUI livesWhich rule appliesWhat to ask for
Your own Microsoft GCC High or Azure Government tenant, managed by the providerThe provider is an ESP for its managed services, not the CSP that operates Microsoft's cloud. Its in-scope services are assessed with your environment.A CRM, proof your company controls the top administrative roles and break-glass account, SSP entries for the provider, and the exact Microsoft service and licensing record
The provider's own cloud, such as the historical NeoSystems.Cloud modelThe provider is a CSP handling CUI, so it must meet the applicable FedRAMP requirements in DFARS 252.204-7012 (32 CFR 170.19, Table 4)The exact current Marketplace record or current equivalency evidence, written paragraph (c)–(g) commitments, the service boundary, and a CRM
You're not sureThe applicable path cannot be determined from the brand nameEverything in both rows until the contract and architecture identify the actual cloud

A note on terms: FedRAMP now calls an authorization a “FedRAMP Certification,” and it is replacing the old Low, Moderate, and High labels with Classes A through D. The Marketplace is scheduled to show the old labels in parentheses through December 31, 2026. Class C replaces the former Moderate path, while the DFARS clause still says “FedRAMP Moderate baseline.” Read the current class, any parenthetical legacy label, lifecycle state, package owner, and exact offering. For how equivalency works when a cloud isn't listed, see our guide to FedRAMP equivalency for CMMC cloud providers.

Question — Good evidence — Not enough by itself
QuestionGood evidenceNot enough by itself
Which cloud holds our CUI?The named service, operator, tenant owner, and boundary written into the contract“Secure cloud” or “FedRAMP-moderate hosting”
Is that cloud FedRAMP listed today?A current Marketplace record for the exact offering, including status and package ownerA 2024 press release
If it claims equivalency, where's the proof?Current evidence that meets DoD's FedRAMP Moderate-equivalency requirements for the exact offeringThe provider's own say-so
Will it meet paragraphs (c)–(g)?A written commitment covering incident reporting, malware submission, 90-day image preservation, forensic access, and damage assessmentSilence in the contract
Who can reach export-controlled data?A written access and location list, followed by an export-control review of whether U.S.-person-only access, a license, or another authorization applies to the data in scope“U.S.-based support”

If export-controlled data under the International Traffic in Arms Regulations (ITAR) or the Export Administration Regulations (EAR) is involved, see our CMMC guide for ITAR companies.

Former NeoSystems clients: stay or switch?

It depends on where your CUI lives and whether your company holds the keys. If your data sits in a Microsoft tenant your company owns, this is mostly an MSP change. If it sat in NeoSystems' own cloud, it's a data-custody and cloud-compliance question first.

Three quick checks before you read the table:

  1. Does your DoD contract include DFARS 252.204-7012? If yes, the clause governs covered contractor information systems and covered defense information when they are present. Then confirm whether NeoSystems stored, processed, or transmitted covered defense information, or provided security protection for systems that did.
  2. Where does your CUI live today: in a tenant your company owns, or in an environment NeoSystems ran?
  3. Does someone authorized by your company hold a working Global Administrator or equivalent top-level administrative account and a tested break-glass account right now?
Your situation — What's at stake — Do this first
Your situationWhat's at stakeDo this first
Your CUI lived in NeoEnclave or NeoSystems.CloudWhere your data is, who can reach it, and whether the actual cloud meets the contract's DFARS 252.204-7012 requirementsGet a written answer on where your data sits, who operates the environment, who can access it, and a dated export plan. Save everything you already have. Stay only if you receive current cloud evidence, paragraph (c)–(g) commitments, a CRM, administrative-control terms, and exit terms. Otherwise plan a controlled move.
Your CUI lives in your own GCC High or Azure Government tenant that NeoSystems managedWho controls your administrative accounts, licenses, logs, and security operations, and whether service had gapsConfirm your company controls Global Admin and a break-glass account. List every outside account with admin or delegated access. Identify the Microsoft partner of record and renewal dates. Stay only with a signed CRM and your company in control; otherwise change providers while keeping the tenant.
You hold Final Level 2 (C3PAO) status and NeoSystems was inside your assessed scopeYour assessed information system may have undergone an architectural, boundary, service, or personnel changeUpdate your SSP, CRM, diagrams, and change record. Determine whether the change is operational or significant to the architecture or boundary, then follow the assessment path your current contract requires. Do not book a new C3PAO assessment until the contract and current acquisition direction call for one.
You hold Level 2 (Self) status, or you're mid-readinessWhether the implementation and evidence behind your current assessment remain accurateReassess the affected NIST SP 800-171 Revision 2 requirements against what is running now. Do not count provider-operated requirements you cannot show are still satisfied. Update the score, POA&M, SSP, and SPRS record when required before affirming.
You used NeoSystems only for accounting, payroll, HR, or Costpoint work through ESGUsually a narrower CMMC issue, unless the service processed CUI, handled Security Protection Data, or provided security protection for an in-scope systemAsk BlueStreet which company now hosts and supports your system, what data it holds, and whether any CUI or security data is involved. The May 14 notice puts hosting continuity on the ISG contact path and lists ESG functions separately.
You don't know what NeoSystems ran, or whether it held CUIEverything above is an assumptionPull your contract, statement of work, invoices, SSP, architecture, asset inventory, and account list. Identify every system and data flow NeoSystems touched. Check your contracts for DFARS 252.204-7012 and your files for CUI markings. Our FCI vs. CUI guide and scoping guide walk through it.

Does your own CMMC status survive the change?

Your CMMC Status is tied to your assessed information system, not to the provider's separate status. A provider change does not automatically erase it. But a significant architectural or boundary change requires a new assessment, while operational changes within the existing boundary that follow the SSP may be addressed through the annual affirmation. Document what changed before choosing the path.

Your change — How the rule frames it — Next step
Your changeHow the rule frames itNext step
New MSP staff run the same tools in your company-owned tenant, with no material boundary or architecture changePotentially an operational change inside the existing boundaryUpdate the SSP, CRM, access list, personnel record, and evidence. Confirm the classification of the change, then affirm on schedule if the current status remains supportable.
Your CUI moved out of NeoEnclave into a new environmentA material environment move is a boundary and architecture change, not merely a staffing changePlan the new assessment required for that changed scope and the level/assessment type your current contract requires. Under the current Phase 1 pause, do not assume the old Phase II certification schedule controls the answer.
Controls NeoSystems ran, such as logging or patching, stopped for a periodThe boundary may be unchanged, but implementation and evidence may no longer support the prior score or affirmationReassess the affected requirements, document the outage, restore the controls, and update the score, POA&M, SSP, or SPRS record when required before affirming.
You can't tell which it isThe facts and contract have not been resolvedDocument the old and new architecture. Get written input from your contracts lead and qualified CMMC adviser; involve the C3PAO when a certification scope is relevant and the contracting officer or prime when contract interpretation is needed. Keep the resolution with your SSP.

Say your drawings moved from NeoEnclave into a new GCC High tenant in June. That's a boundary change, not merely a staffing change, and your SSP, diagram, CRM, evidence, and assessment plan should say so.

What didn't pause when NeoSystems did

  • Incident reporting. DFARS 252.204-7012 requires a cyber incident to be rapidly reported within 72 hours of discovery. A vendor winding down is not an incident by itself. Unknown admin accounts, missing logs, unexplained access, or CUI in an unknown place may require immediate incident-response and legal review. More in our DFARS 252.204-7012 guide.
  • Your assessment record and affirmation. Your Affirming Official affirms continuing compliance, and a Level 2 (Self) status lapses if the required annual affirmation is not maintained. Do not affirm requirements you cannot show are satisfied. See our guides to the annual affirmation and your SPRS score.
  • The first-week basics. For administrative access, backups, logs, and evidence export, use our 72-hour plan for a failed CMMC MSP. For a planned move, see switching CMMC providers mid-engagement.

If your row points toward a move, or you still can't tell whether you need a new MSP, a CUI enclave, or readiness help, sort that out before you call anyone. It takes a few questions about your contract, data, environment, timeline, and budget, and it points you to a category of help, not a company.

Map what your CMMC setup needs next

The NeoSystems verification checklist

Don't ask “Are you CMMC compliant?” and accept a yes. Ask for these twelve items in writing from whoever will sign your contract: the current NeoSystems ISG operator, FIT Solutions, or BlueStreet for ESG work. A missing item isn't proof of a problem. It's an open question you shouldn't sign around.

This worksheet is for procurement notes. Do not enter CUI, drawings, passwords, export-controlled information, vulnerability details, or sensitive contract information.

Interactive worksheet for procurement notes

Track requests in this browser only. This is a to-do list, not a score, grade, pass/fail result, provider ranking, or compliance determination.

12 of 12 items still open.

NeoSystems verification worksheet controls
#Ask forWhy it mattersStatusReasonNotes
1The legal company name, W-9, formation state, authorized signer, and which company will invoice you and perform the workA certificate identifies one organization, and your contract binds a legal entity. See the 32 CFR 170.9(b)(18).Only needed for Not applicable.0/300
2A written explanation of how that company relates to legacy NeoSystems LLC, NeoSystems ESG, NeoSystems ISG, BlueStreet, and FIT Solutions, including who owns or may use the brand, contracts, systems, and service assetsThe May 14 notice describes service continuity, not ownership, acquisition, assignment, or credential transfer. Read the notice.Only needed for Not applicable.0/300
3For existing customers: the document that assigns, assumes, amends, or replaces your contractWithout it, it may be unclear who is bound by your old service, confidentiality, security, data-return, and liability terms.Only needed for Not applicable.0/300
4If the provider relies on a CMMC claim: the current certificate or status record, showing the organization name, CAGE codes, C3PAO, assessment UID, status date, level, and current affirmation — or a plain statement that it has no provider-level statusThese are core identity and status fields required by the rule. See 32 CFR 170.9(b)(18) and 32 CFR 170.22.Only needed for Not applicable.0/300
5A one-page map showing how the assessed scope relates to the services, tenant, tools, people, facilities, and cloud in your proposalCMMC Status attaches to a specific OSA information system, not to every service sold under a brand. See 32 CFR 170.4.Only needed for Not applicable.0/300
6The company's current Cyber AB Marketplace listing under its exact legal name, including role, member/listing ID, and statusRPO, RP, C3PAO, assessor, and provider roles do different jobs. Check the live Cyber AB Marketplace.Only needed for Not applicable.0/300
7The current service description, boundary and data-flow diagrams, asset and subprocessor lists, and Customer Responsibility MatrixThe provider relationship, services, responsibilities, and in-scope assets must be documented in your SSP and assessment evidence. See 32 CFR 170.19(c)(2)(ii).Only needed for Not applicable.0/300
8For any outside cloud that stores, processes, or transmits covered defense information: the exact FedRAMP Marketplace record or current equivalency evidence, plus written commitments to DFARS 252.204-7012 paragraphs (c)–(g)The external-CSP requirement applies to the actual cloud offering handling covered defense information. See DFARS 252.204-7012(b)(2)(ii)(D) and 32 CFR 170.19(c)(2)(i).Only needed for Not applicable.0/300
9A list of every account with administrative or delegated access; proof your company controls the top administrative and break-glass accounts; and your Microsoft partner of record, subscription IDs, and renewal datesAccess credentials that grant access to the in-scope environment can be Security Protection Data. See the definition in 32 CFR 170.4. Never put credentials in this worksheet.Only needed for Not applicable.0/300
10For export-controlled data: the people, citizenship/status where relevant, work locations, support locations, and subprocessors with access, followed by a written export-control determination from qualified counsel22 CFR 120.62 defines “U.S. person,” but applicability and authorization require a data- and transaction-specific determination.Only needed for Not applicable.0/300
11The dates and scope of any interruption in logging, endpoint protection, backups, vulnerability scanning, patching, identity services, or other security functions after May 1, 2026An interruption may change whether affected requirements are met and what an Affirming Official can truthfully affirm. See the NIST SP 800-171 DoD Assessment Methodology and 32 CFR 170.22.Only needed for Not applicable.0/300
12Written exit terms: who owns the tenant, settings, domains, keys, licenses, logs, SSP, POA&M, CRM, diagrams, tickets, and evidence; export timing and format; deletion certification; transition help; change-of-control terms; incident notice; and service levelsThe scoping guidance tells contractors to evaluate provider contracts and service-level agreements. The DFARS 252.204-7012(c)–(g) duties also make transition cooperation important.Only needed for Not applicable.0/300

# — Ask for — Why it matters
#Ask forWhy it matters
1The legal company name, W-9, formation state, authorized signer, and which company will invoice you and perform the workA certificate identifies one organization, and your contract binds a legal entity. You need to know who actually owes you performance.
2A written explanation of how that company relates to legacy NeoSystems LLC, NeoSystems ESG, NeoSystems ISG, BlueStreet, and FIT Solutions, including who owns or may use the brand, contracts, systems, and service assetsThe May 14 notice describes service continuity, not ownership, acquisition, assignment, or credential transfer.
3For existing customers: the document that assigns, assumes, amends, or replaces your contractWithout it, it may be unclear who is bound by your old service, confidentiality, security, data-return, and liability terms.
4If the provider relies on a CMMC claim: the current certificate or status record, showing the organization name, CAGE codes, C3PAO, assessment UID, status date, level, and current affirmation — or a plain statement that it has no provider-level statusThese are core identity and status fields required by the rule. A non-CSP ESP's own status is voluntary, but any status used to win your reliance must match the current entity and service.
5A one-page map showing how the assessed scope relates to the services, tenant, tools, people, facilities, and cloud in your proposalCMMC Status attaches to a specific OSA information system, not to every service sold under a brand.
6The company's current Cyber AB Marketplace listing under its exact legal name, including role, member/listing ID, and statusRPO, RP, C3PAO, assessor, and provider roles do different jobs. A historical announcement does not establish a current listing.
7The current service description, boundary and data-flow diagrams, asset and subprocessor lists, and Customer Responsibility MatrixThe provider relationship, services, responsibilities, and in-scope assets must be documented in your SSP and assessment evidence.
8For any outside cloud that stores, processes, or transmits covered defense information: the exact FedRAMP Marketplace record or current equivalency evidence, plus written commitments to DFARS 252.204-7012 paragraphs (c)–(g)The external-CSP requirement applies to the actual cloud offering handling covered defense information, not to a general marketing phrase.
9A list of every account with administrative or delegated access; proof your company controls the top administrative and break-glass accounts; and your Microsoft partner of record, subscription IDs, and renewal datesAccess credentials that grant access to the in-scope environment can be Security Protection Data. Provider failure should not lock your company out of its tenant, logs, licenses, or evidence.
10For export-controlled data: the people, citizenship/status where relevant, work locations, support locations, and subprocessors with access, followed by a written export-control determination from qualified counselThe ITAR defines “U.S. person,” but whether U.S.-person-only access, a license, or another authorization is required depends on the data and transaction. “U.S.-based support” does not answer that question.
11The dates and scope of any interruption in logging, endpoint protection, backups, vulnerability scanning, patching, identity services, or other security functions after May 1, 2026An interruption may change whether affected NIST SP 800-171 requirements are met, whether the evidence supports your score, and what an Affirming Official can truthfully affirm.
12Written exit terms: who owns the tenant, settings, domains, keys, licenses, logs, SSP, POA&M, CRM, diagrams, tickets, and evidence; export timing and format; deletion certification; transition help; change-of-control terms; incident notice; and service levelsThe scoping guidance tells contractors to evaluate provider contracts and service-level agreements. Your provider's notice and cooperation also need to support your own 72-hour reporting and evidence-preservation duties.

Give each item one of these statuses: Not requested, Requested, Received, Verified, Gap, or Not applicable (with a written reason). “Received” isn't “Verified” until you've checked it against the five-match test. Don't total the list into a score.

A worked example (hypothetical). Say you run a 40-person machine shop. Your prime's drawings, which are CUI, sat in NeoEnclave, and last year you posted a Level 2 self-assessment result in SPRS. In September a NeoSystems ISG renewal lands on your desk. You send the twelve asks. One of three things happens:

  • Everything lines up. The legal company is named, any CMMC claim maps to the current entity and service, the cloud has a current Marketplace record or current equivalency evidence as applicable, and the exit terms are in writing. You move on to price and references.
  • Key items stay unknown. Say the current operator relies on the legacy CMMC announcement but provides no current certificate-to-service match, and there is no current cloud evidence for the environment holding your drawings. You mark those items as gaps, hold the renewal and any data move, and ask for a written answer by a set date. That's not an accusation. It's how you avoid signing around a gap.
  • You learn your real need is different. Your contract calls for Level 2 (Self), and your drawings could live in a GCC High tenant your company owns, run by a capable MSP. The question shifts from “NeoSystems or not” to “which kind of help.”

In all three cases, reassess the affected NIST SP 800-171 Revision 2 requirements against what is running today. Update your assessment result, SSP, POA&M, evidence, and SPRS record when the facts or applicable requirements call for it before your next affirmation.

Who NeoSystems ISG may fit, and who should look elsewhere

We haven't tested NeoSystems ISG's service, so this is about fit and proof, not quality. Legacy NeoSystems LLC's 2025 announcement does not prove post-May 2026 delivery, current scope, or current customer outcomes. Ask for references from customers served under the current operating arrangement since May 2026, at your size and with a comparable environment.

Your situation — Fit today — What must be true first
Your situationFit todayWhat must be true first
Existing NeoSystems ISG customer who needs steady service while you re-check everythingCan make sense short termChecklist items 1–3, 7, 9, 11, and 12 answered in writing, with no unresolved access or data-custody risk
Small or midsize CUI contractor wanting an enclave plus managed security from one firmPossibleAll twelve items, especially 4, 5, 7, 8, and 12
Microsoft-based shop that wants its own GCC High tenant managedPossibleCompany-controlled administration, a signed CRM, exact Microsoft service and partner records, and clear evidence delivery
You need only a formal Level 2 certification assessmentWrong categoryUse an authorized C3PAO.
FCI-only Level 1 contractorOften more than the CMMC requirement alone requiresConfirm the contract clause and whether you have CUI or another business reason for the added environment.
Strong internal IT that needs only SSP, scope, or gap helpPossibly too broadCompare a focused RPO/RP engagement (RPO vs. MSP).
You want posted pricing to compareNot yetGet an itemized quote that separates implementation, migration, recurring service, licenses, third parties, assessment exclusions, increases, and exit costs over the same term.

If the paperwork checks out but you're still unsure whether your real need is an enclave, managed security, readiness help, software, or a formal assessment, choose the category before you compare company names.

See which kind of CMMC help fits

NeoSystems alternatives, by category

Pick the category first, then the company. Each of these does a different job, and swapping one for another can leave the original problem unsolved.

Category — Best for — Can't replace — Our guide
CategoryBest forCan't replaceOur guide
MSP or MSSP (managed security service provider) running a tenant your company ownsDay-to-day IT and security operationsA formal assessmentChoosing a CMMC MSP
CUI enclaveKeeping CUI in one walled-off area, like a locked room inside the building where all the CUI work happensCompany-wide policies, physical security, personnel, training, and every responsibility outside the enclaveCUI enclave providers and enclave vs. GCC High
GCC High migrationMoving eligible email, files, and collaboration workloads into Microsoft's government cloudYour SSP, assessment evidence, identity design, endpoint controls, or every CUI workflowGCC High migration for CMMC
RPO or Registered Practitioner (RP)Rebuilding scope, SSP, POA&M, CRM, and evidenceA formal certification assessmentRPO vs. C3PAO
GRC platform (governance, risk, and compliance software)Tracking requirements, evidence, owners, and remediationOperating controls, deciding contract applicability, or issuing CMMC StatusCMMC provider directory
C3PAOA formal Level 2 certification assessment when a current contract requires one or the contractor chooses a voluntary assessmentRemediation, managed operations, or provider continuityAuthorized C3PAO list

To compare roles and check listings in one place, use our CMMC provider directory. To test any provider's claims, see how to verify your MSP's CMMC status.

Frequently asked questions

How do I get my data back from NeoSystems?

Start with the contacts in BlueStreet's May 14, 2026 notice: BlueStreet for NeoSystems ESG services, and FIT Solutions for NeoSystems ISG service continuity. Put every request in writing, ask for the legal counterparty and a dated export plan, and keep CUI out of ordinary email. If access is delayed, disputed, or tied to conditions, bring in counsel.

Are there real NeoSystems CMMC reviews from customers?

Our September 23, 2026 review found no independent, verifiable customer review specifically evaluating the current post-May 2026 CMMC service arrangement. Glassdoor ratings come from employees, and the G2 listing under “NeoSystems” covers a different Calgary software company. Forum posts are anecdotes. Ask the current operator for recent references using a comparable service, scope, and company size.

Was NeoSystems a C3PAO?

We found no source establishing that legacy NeoSystems LLC was a C3PAO. Its own announcements described an RPO role and its own Final Level 2 status as an external service provider. “Final Level 2 (C3PAO)” describes the assessment type performed on NeoSystems' system; it does not say NeoSystems was the C3PAO that performed assessments for customers. Verify any current role in the live Cyber AB Marketplace.

What about Microsoft GCC High licenses we bought through NeoSystems?

Legacy NeoSystems' website offered Microsoft 365 Government licensing. If you bought licenses through it, identify your Microsoft partner of record, tenant owner, subscription IDs, renewal dates, billing contact, and administrative roles now. An unclear reseller relationship is an avoidable outage, but do not send credentials or CUI in the request.

Do I need to tell my prime contractor about the NeoSystems change?

Possibly, if it changes a contractual representation, flow-down obligation, deliverable, CUI location, external service provider, cloud, assessed boundary, CMMC UID, SPRS record, or ability to meet an incident-reporting deadline. Have your contracts lead or counsel read the actual prime/subcontract terms, then share verified facts through the required channel. See how to prove CMMC compliance to a prime.

Does the Phase II suspension mean I can ignore this?

No. Phase II's third-party rollout was suspended, but Phase I self-assessments remain, Level 2 still uses the 110 NIST SP 800-171 Revision 2 requirements, annual affirmations remain where required, and DFARS 252.204-7012 still applies when included and applicable. A provider change can make the implementation or evidence behind an assessment and affirmation inaccurate even when a C3PAO assessment is not currently required.

Still not sure which CMMC path fits your company? Use The Defense Compliance Report's Find My CMMC Path tool to see which path and kind of help fit your contract, CUI, environment, and timeline — before you hire anyone.

Sources

All checked September 23, 2026.

Rules and official program sources

Company records (company-stated)

News and identity disambiguation

About The Defense Compliance Report

The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on every claim and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.

We are not affiliated with the Cyber AB, the Department of Defense (Department of War), DCMA DIBCAC, NIST, or any U.S. government agency. This page is educational research, not legal, contractual, or compliance advice. Confirm scope and applicability with a CMMC Registered Practitioner (RP) or a qualified federal-contracts attorney. How we handle commercial relationships is explained in our Editorial & Advertising Policy.

Find my CMMC path →