Not sure whether Optiv is the category you need? Use Find My CMMC Path to separate implementation help, managed services, legal/contract interpretation, and the independent certification assessment before you start collecting quotes.
By The Defense Compliance Report Editorial Team
Verified August 28, 2026 — an independent trade publication on CMMC 2.0 and DIB compliance. Last reviewed: August 2026 · Last verified: August 28, 2026 · Next scheduled review: October 2026
Current rollout status (verified August 28, 2026): Phase 1 began November 10, 2025 and runs through November 9, 2026. DoD subsequently suspended the start of Phase 2 and later phased-implementation milestones. That suspension did not erase Phase 1 self-assessment use, the contract-specific requirements already placed in solicitations or awards, or the separate safeguarding and incident-reporting duties in DFARS 252.204-7012. Check the DoD CMMC program page and the actual solicitation before treating any schedule summary as your contract requirement.
Scope and independence: This page provides educational information, not legal, contractual, certification, or compliance advice. The Defense Compliance Report is not affiliated with DoD or The Cyber AB. Provider listings, partnership inquiries, or referral compensation do not change our evidence standards; any compensated destination is labeled at the point of action.
The short version, because you're busy
Optiv is not a C3PAO (CMMC Third-Party Assessment Organization) and cannot certify your company. One Optiv entity does hold a CMMC credential: Optiv + ClearShark — legally Optiv Federal Inc. — announced CMMC Level 2 certification on September 25, 2025. But here is what almost no search for an Optiv CMMC review surfaces, and it's the part that changes your decision: as of today, "Optiv" is three different companies, on three different websites, all publishing CMMC services — and one of them was sold on June 1, 2026.
That's not a gotcha. It's a procurement fact, and it determines which certificate applies to you, which insurance covers you, and whose name belongs in your System Security Plan.
We spent August 28, 2026 reading every public page, press release, and directory we could find, and cross-checking each one against 32 CFR Part 170, the DFARS clauses, and NIST SP 800-171 Revision 2. Below is what holds up, what doesn't, and the exact list of documents to demand before you sign anything.
First-scroll verdict
| The bottom line Where we landed | |
|---|---|
| Can Optiv certify you? | No. Only an authorized or accredited C3PAO performs a CMMC Level 2 certification assessment. No Optiv entity appeared in the Cyber AB Marketplace C3PAO listing when we checked it on August 28, 2026. |
| Is Optiv "CMMC certified"? | Optiv + ClearShark announced CMMC Level 2 certification on September 25, 2025. That is a company statement about its own assessed environment. The announcement names no assessment scope, no assessing C3PAO, and no CMMC Unique Identifier. |
| Best fit for | Mid-size and large DIB contractors with a real security-operations gap, an existing enterprise security stack, and procurement muscle to enforce contract terms. |
| Not the first call for | A 20–50 person shop that needs someone to sit down and write the SSP, close POA&M items, and walk it through a self-assessment. |
| Published price | None found in any Optiv material we reviewed. We're not going to invent one. |
| The single strongest reason to keep talking | Genuine federal depth: a wholly owned federal subsidiary with government contract vehicles, clearances, and its own completed Level 2 assessment. |
| The single biggest thing to resolve first | Which legal entity signs, performs, and warrants the work — and whether the certificate you were told about covers that entity and that service. |
| Our evaluation depth | Public-source profile. We did not test a service, interview Optiv, or review a signed statement of work. |
The one decision this page is built to help you make: do I keep talking to Optiv, and on what terms?
What we actually verified
We put this box on every provider page because the word "review" gets abused in our industry, and because you deserve to know exactly how much weight to put on what follows.
| Provider category | Managed security services provider, security technology reseller and integrator, and — through a wholly owned federal subsidiary — a federal cybersecurity and IT solutions provider. Not an assessment organization. |
| Cyber AB status check | Searched the Cyber AB Marketplace C3PAO listing on August 28, 2026. No Optiv entity surfaced. We were not able to complete an organization-level Registered Provider Organization (RPO) check under every legal and trade name, so we make no claim about RPO status in either direction. |
| Services reviewed | Optiv's live CMMC service page; the Cyber Fusion Center and managed security service pages; the corporate Locations page; Optiv + ClearShark's federal services page; Optiv Consulting's public service and industries pages; the September 2025 CMMC Level 2 announcement; the June 2026 ACT divestiture announcement; the August 2026 Agentic Security Operations launch. |
| Compensation relationship | None. We have no compensation relationship with Optiv Security, Inc., Optiv Federal Inc., Optiv + ClearShark, or Optiv Consulting as of August 28, 2026. We earn nothing if you hire them. There is not a single link on this page that pays us. |
| Evaluation depth | Independent public-source profile and buyer's guide, built from company materials, corporate announcements, three public directories, and primary regulatory sources. We did not run an engagement, interview the company, inspect a customer deployment, or receive anything from any Optiv entity. |
| Last verified | August 28, 2026 |
| What we could not verify | Which legal entity currently delivers CMMC readiness engagements · the assessment scope, assessing C3PAO, unique identifier, Conditional-versus-Final status, or expiry behind the announced Level 2 certificate · whether any Optiv entity holds RPO status · any Optiv price · whether Agentic Security Operations is available in a government cloud · US-persons staffing for any service · whether a Customer Responsibility Matrix exists and is available before signature. Every one of these is question-numbered in the letter near the bottom of this page. |
Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification.
Not advice. This is educational research, not legal, contractual, or compliance advice. The Defense Compliance Report is not affiliated with the Cyber AB, the Department of War or Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency. Confirm scope and applicability with a CMMC Registered Practitioner (RP) or Registered Provider Organization (RPO), and — where legal interpretation is involved — a qualified federal-contracts attorney. The contract clause and your CUI handling set your level, not a checklist.
The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on every claim and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.
Which category fits — and which doesn't
Before we go deep on Optiv, one honest sort. This takes ten seconds and saves some of you an hour.
Optiv may belong on your shortlist if: you run a complex, multi-site or multi-vendor environment; you have an actual 24/7 monitoring gap rather than a documentation gap; you already own enterprise security tooling that needs to be operated well; you have an existing Optiv or Optiv + ClearShark relationship; or you need CMMC folded into a broader security program rather than treated as a standalone project.
Look at a different category first if: you only need a formal Level 2 certification assessment (that's a C3PAO, and it has to be a separate firm from whoever prepared you); you're a small contractor who needs hands-on SSP and POA&M authorship (that's a readiness-focused RPO or a CMMC-specialist MSP); your real problem is shrinking your CUI footprint (that's a CUI enclave); you need evidence workflow and control mapping (that's a GRC platform, and software alone never satisfies CMMC); or you don't yet know whether you handle Federal Contract Information (FCI), Controlled Unclassified Information (CUI), or neither.
The right CMMC provider isn't the same for every contractor — the category you need (a C3PAO, an RPO, an MSSP, a GRC platform, or a CUI enclave) depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline. The contract clause sets your level, not a checklist. Because a general answer can't resolve those for you, use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right provider category before you request quotes — and do not submit CUI, drawings, or sensitive contract details.
Why you're reading an Optiv CMMC review right now
Answer capsule: Most searches for an Optiv CMMC review are triggered by one of five events: a sales conversation, a prime contractor's supply-chain questionnaire, the September 2025 Level 2 announcement, a renewal decision, or the July 13, 2026 suspension of CMMC Phase 2. All five reduce to the same underlying question — which provider category and which legal entity actually solves the problem in front of you.
Let's name them, because you're probably one of these.
A rep used the phrase "we're CMMC certified." It's a real statement about a real thing. It also does not mean what most sales conversations imply it means. We'll take that apart in detail below.
A prime sent a questionnaire. Somewhere on it is a line asking you to list every external service provider that touches your systems and to state each one's CMMC status. If you use an MSSP and your System Security Plan doesn't mention it, that questionnaire is a warning shot.
You read the press release. Optiv + ClearShark announced Level 2 certification on September 25, 2025, and syndicated coverage put it everywhere. It's the most-cited Optiv CMMC fact on the internet and the least-examined.
Renewal is coming. And somewhere in the back of your mind is the news that Optiv sold a chunk of itself in June.
The suspension made you wonder whether to spend at all. Fair. Here's the honest read.
What did not change: DFARS 252.204-7012 (the safeguarding clause that has been in defense contracts since 2017 and requires adequate security for covered defense information), the 110 Level 2 security requirements from NIST SP 800-171 Revision 2 organized into 14 control families, your SPRS (Supplier Performance Risk System) score posting, your annual affirmation, and Phase 1 self-assessment requirements. The CMMC Program Rule at 32 CFR Part 170, effective December 16, 2024, was not repealed. The DFARS clause at 252.204-7021, effective November 10, 2025, was not rescinded. This was a policy pause, not a regulatory rollback.
Here's the part nobody says out loud: with no third-party assessor validating how you documented your external service providers, you assert it and you post it. Your signature carries the risk now. The documentation burden went up, not down.
Which is exactly why "who is my MSSP, legally, and what did they actually get certified for" stopped being a paperwork question.
Is Optiv a C3PAO? No — and here's who can certify you
Answer capsule: Optiv is a managed security services provider and security technology integrator, not a CMMC assessment organization. Under 32 CFR Part 170, only an authorized or accredited C3PAO (CMMC Third-Party Assessment Organization) may conduct a CMMC Level 2 certification assessment, and the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) conducts Level 3 assessments. When we searched the Cyber AB Marketplace C3PAO listing on August 28, 2026, no Optiv entity appeared.
This isn't a criticism. Operators and assessors are supposed to be different companies. That separation is the entire point.
The four facts buyers collapse into one
This table is the single most useful thing on this page for the reader who was just told "Optiv is CMMC certified." Four different statements. Four different meanings. People treat them as interchangeable and it costs them money.
| The claim What it actually proves What it does not prove | ||
|---|---|---|
| "We hold CMMC Level 2 status" | The company's own assessed environment met the applicable requirements, for a specific scope, as of a specific date | That it can assess you, certify you, or that the certified scope includes the service you're buying |
| "We're an RPO" (Registered Provider Organization) | A Cyber AB marketplace designation for readiness and consulting providers | Any authority to issue a certification. RPOs prepare; they cannot certify |
| "We're a leading MSSP" | The company operates security functions for customers | Any CMMC ecosystem role whatsoever. MSSP is a market category, not a credential |
| "We're an authorized C3PAO" | The company may conduct formal Level 2 certification assessments, subject to scope and conflict-of-interest rules | That it's the right readiness partner. In many cases it legally cannot be both |
One more rule that catches people late and expensive: under the CMMC ecosystem's professional conduct requirements, an organization that provided consulting to prepare a company for a CMMC assessment is barred from participating in that company's Level 2 certification assessment process for three years. So if anyone offers you a bundled "we'll get you ready and then certify you," that is your cue to slow the conversation down, not speed it up.
The three-directory check, run on one day
We ran three status checks on August 28, 2026 and we're publishing them as searches, with their limits stated, rather than as verdicts.
| Directory What we checked Result on August 28, 2026 The honest caveat | |||
|---|---|---|---|
| Cyber AB Marketplace — C3PAO listing | Authorized and accredited assessment organizations | No Optiv entity surfaced | A marketplace search is a point-in-time result. Verify it yourself before relying on it |
| MSP Collective ESP Directory — validated Level 2 certified external service providers, each confirmed with the C3PAO that performed the assessment | Whether any Optiv entity appears | 55 listings. No Optiv, Optiv Federal, Optiv + ClearShark, or ClearShark entry. (We counted 49 on this same directory on July 18, 2026) | Listing is voluntary and free. Absence is not proof of no certificate. The directory also excludes cloud service providers that process, store, or transmit CUI, and it requires Final — not Conditional — status |
| FedRAMP Marketplace | Whether an Optiv cloud service offering carries a FedRAMP authorization | None surfaced. Separately, Optiv + ClearShark launched FedRAMP advisory services in April 2025 — helping other companies achieve authorization, which is a different thing entirely | Verify at the FedRAMP Marketplace directly |
Worth noticing about that middle row: of the 55 validated certified external service providers in that directory, the overwhelming majority are regional managed service providers. Only a couple are large national firms. Certified-ESP supply in this market sits with specialists, not integrators. That's a real structural fact about the market you're shopping in, and it reframes the whole buy without insulting anyone.
Not sure whether you need an operator or an assessor?
That's the most expensive question to get wrong, and it takes about two minutes to settle. Compare provider categories with The Defense Compliance Report's Find My CMMC Path tool — tell it your level, whether you handle FCI or CUI, your assessment type, environment, and timeline, and it maps you to the category you need before you take a single sales call. Compare provider categories → No email required. Do not submit CUI, drawings, or sensitive contract details.
The part we have to say first: Optiv's own CMMC page contradicts itself
Answer capsule: Optiv's live CMMC service page, read on August 28, 2026, describes the program as having "five maturity levels" in one FAQ section and three levels in the next, and states that full implementation is not expected until September 2025. Under 32 CFR Part 170, CMMC has three levels. The page is not reachable from Optiv's current Services navigation menu.
We put the uncomfortable finding early, before the case for Optiv, because you should be able to weigh everything that follows knowing we didn't hide the worst thing we found.
Here's the audit. Left column is what the page says. Right column is what the rule says.
| What the live Optiv CMMC page says What the controlling authority says Why it matters to you | ||
|---|---|---|
| Contractors cannot bid without certification at one of "five maturity levels" | 32 CFR 170.4 defines three levels: 15 Level 1 requirements drawn from 48 CFR 52.204-21(b)(1); 110 Level 2 requirements from NIST SP 800-171 Revision 2; and 24 Level 3 requirements selected from NIST SP 800-172 | Five levels ended with CMMC 1.0 in 2021. A page that gets the level count wrong should not be your scoping source |
| The next FAQ section is headed by a question about the three CMMC levels, and describes Levels 1, 2, and 3 correctly | Correct | Both statements are live on the same page. This is worth a screenshot |
| Full implementation "isn't expected to happen until September 2025" | The Program Rule took effect December 16, 2024. The DFARS clause at 252.204-7021 took effect November 10, 2025. Phase 2 was suspended July 13, 2026 | Three separate rule events have happened since that sentence was accurate |
| Contractors "must prove compliance through a C3PAO" | Level 1 is an annual self-assessment. Level 2 may be a self-assessment or a C3PAO certification assessment — the solicitation decides, through the provision at DFARS 252.204-7025 | This would push a Level 1 contractor toward an assessment they don't need and shouldn't buy |
| Some organizations will need "a government audit once every three years" | C3PAOs conduct Level 2 certification assessments. DIBCAC — the government — conducts Level 3 assessments | Conflates two different assessments with very different costs and thresholds |
| More than 60% of Level 2 requirements are documentation-based | No source given | Company-stated. Don't repeat it as fact, and don't let it shape your budget |
| The page's centerpiece quote references pandemic-era business conditions | — | The page has not been substantively refreshed in years |
| The page is not linked from the current Services navigation, and its own "Related Services" list points to URL patterns the site no longer uses | — | This is what an orphaned page looks like |
Now the part that matters more than the finding.
A stale marketing page is not evidence of a weak security operation. Large firms orphan pages all the time, especially when business units move — and a business unit did move here, which we'll get to. We've torn down eight security vendors on this site now and web hygiene has been a poor predictor of operational quality in every single one.
What the audit does entitle you to conclude is narrower and far more useful: do not accept that page — or a rep's summary of it — as your source for what CMMC requires of you. Require the proposal to name the controlling authority behind every requirement it asserts.
And here's the reframe most buyers miss. A vague vendor page is leverage. When the provider hasn't publicly defined deliverables, levels, or scope, you get to define them in the statement of work. That's a better negotiating position than the one you're in with a vendor whose fixed packaging is already printed.
But if you're the wrong buyer, leave now and we'll point you somewhere better. If you're a 25-person machine shop and what you actually need is a human being to write your System Security Plan, build your POA&M, and walk you through a self-assessment, a global integrator is the wrong lane and the price will tell you so. Go look at externally validated certified external service providers built for exactly that job.
If you need a certificate you can hand your assessor
There are 55 external service providers whose CMMC Level 2 certification has been independently validated with the C3PAO that performed the assessment — with certification dates you can read. See the current list, what each one's validation actually covers, and the questions to ask before you shortlist. Check current certified provider status →
Which Optiv would you actually be signing with?
Answer capsule: "Optiv" refers to at least four related organizations. Optiv Security, Inc. is the commercial parent. Optiv Federal Inc., doing business as Optiv + ClearShark, is a wholly owned federal subsidiary in Chantilly, Virginia. ClearShark LLC and ClearShark Services Inc. were acquired in March 2023. And Optiv Consulting — the former advisory, consulting and transformation business — was sold to Vobis Ventures in a deal that closed June 1, 2026 and is now a separate company. Which entity signs your statement of work determines which certificate, which insurance, and which responsibility matrix applies to you.
This is the section that doesn't exist anywhere else, so let's be precise.
The four Optivs
| Entity or brand What it is Public evidence we read CMMC-relevant status (August 28, 2026) What it means for you | ||||
|---|---|---|---|---|
| Optiv Security, Inc. | The commercial parent. Managed security services, staff augmentation, security technology resale and integration. KKR has been majority owner since 2017 | Corporate headquarters listed as Leawood, Kansas on Optiv's own Locations page; site copyright reads "© 2020–2026 Optiv Security Inc."; the August 2026 product launch was datelined Kansas City | No public CMMC certificate found. Did not appear in the Cyber AB Marketplace C3PAO listing | If you're buying managed detection, the Cyber Fusion Center, or co-managed SIEM, this is most likely your counterparty. Confirm it on the paperwork |
| Optiv Federal Inc., d/b/a Optiv + ClearShark | The federal arm, Chantilly, Virginia. Its own site describes it as "a wholly owned subsidiary of Optiv." Named as prime on NASA SEWP VI Category A in July 2026; also holds a GSA Schedule, DoD ESI, and Army ITES-SW2 vehicles | Optiv + ClearShark services and contracts pages; corporate announcements; Optiv's Locations page lists it as a second headquarters | This is the brand that announced CMMC Level 2 certification on September 25, 2025. Its services page lists CMMC under Advisory and Compliance | A certificate held by the federal subsidiary, for a scope that has never been published, does not automatically travel to services another entity delivers to you |
| ClearShark LLC and ClearShark Services Inc. | Hanover, Maryland value-added reseller and services firm, acquisition announced March 14, 2023 | Optiv's acquisition announcement, which named both legal entities | Absorbed into the Optiv + ClearShark brand | The brand on the slide deck is not the entity on the signature page |
| Optiv Consulting | The Advisory, Consulting and Transformation (ACT) project-based services business. Sold to Vobis Ventures; deal closed June 1, 2026. Roughly 500 consultants, roughly 800 enterprise clients, its own CEO. Describes itself as an "independent advisory firm backed by Vobis Ventures" | Optiv's June 2026 announcement; Optiv Consulting's own public site, which as of August 28, 2026 runs on the domain cysecureservices.com | Its Risk & Compliance practice names CMMC directly, and its manufacturing and defense industrial base page lists CMMC compliance as a focus | A separate company. Not covered by Optiv + ClearShark's certificate. Not covered by Optiv's insurance |
Two more delivery facts from Optiv's own Locations page, because they matter later: Optiv lists offices in Mississauga, Ontario and Bangalore, India, and its page description also names.
Three websites, three CMMC service claims, one brand name
This is the finding. Right now, on August 28, 2026, three separate corporate web properties publish CMMC service claims under some version of the Optiv name:
- optiv.com — the commercial parent's CMMC page, unmaintained and self-contradicting, offering readiness support delivered by what it calls its Strategy and Transformation team.
- optivclearshark.com — the federal subsidiary, listing CMMC under Advisory and Compliance alongside FedRAMP and Zero Trust, and holding the announced Level 2 certificate.
- cysecureservices.com — Optiv Consulting, no longer part of Optiv, naming CMMC in its Risk & Compliance practice and on its defense industrial base page.
Now hold that next to the transaction. Optiv sold its project-based advisory, consulting and transformation services business. CMMC readiness work — gap assessments, scoping, SSP authorship, POA&M development, mock assessments — is, by any normal definition, project-based advisory work. Optiv's commercial CMMC page still markets exactly that work as delivered by "our Strategy and Transformation team," and never mentions the divestiture.
We want to be careful here, because the careful version is the useful version. We do not know, and are not asserting, that CMMC readiness engagements moved to Optiv Consulting. Optiv retained managed services and staff augmentation. Optiv Consulting is Optiv's stated priority services partner for a year, so work can flow between them by design. Optiv CEO Kevin Lynch framed the sale as a deliberate search — the company, he said, "went to great lengths to find the ideal partner." Barclays advised on the deal. This was strategy, not distress.
What we do know is that no public document maps CMMC engagements to a legal entity after June 1, 2026. Which is precisely why question one on your list is no longer "what's your methodology."
It's "who signs?"
The eight entity questions that belong in writing
Put these in an email. Any competent enterprise seller can answer all eight in a day. How fast and how completely they come back tells you almost as much as the answers.
- What exact legal entity signs this agreement?
- Which entity employs the named delivery team?
- Will any work be subcontracted to another Optiv-related company or an outside firm?
- Which entity carries the professional liability, cyber, and errors-and-omissions insurance for this engagement?
- Which entity's personnel will have access to CUI, security protection data, evidence, or system configurations?
- Which entity is the External Service Provider we must document in our System Security Plan?
- Who owns the deliverables and evidence at termination, and in what format?
- Which entity is accountable if an implementation fails to meet the agreed acceptance criteria?
One practical tell you can use today: if a proposal or email arrives from a cysecureservices.com address, you are talking to Optiv Consulting — the Vobis Ventures-backed company — not to Optiv Security, Inc.
What the Public Record Proves—and What It Does Not
| Evidence checked | What it supports | What it does not settle |
|---|---|---|
| Optiv’s live CMMC page | Optiv publicly markets CMMC advisory and readiness services. | The page’s stale five-level language and obsolete rollout timing cannot be used as current rule guidance. |
| Optiv + ClearShark’s September 25, 2025 Level 2 announcement | The companies publicly represented that a Level 2 result was achieved. | The release does not identify the exact certificate-holding legal entity, assessment scope, C3PAO, unique identifier, or Conditional-versus-Final status. |
| Cyber AB Marketplace | Entity-specific ecosystem roles and authorization status can be checked at quote time. | An RPO, RP, or consulting listing is not the same as being the independent C3PAO that may issue your assessment result. |
| Optiv’s June 1, 2026 consulting-business separation materials (company source) | The provider name on an older page may not identify the entity that will contract and perform the work now. | Marketing continuity does not answer which legal entity, personnel, insurance, flow-downs, and deliverables will appear in your SOW. |
The buyer move: Ask for the certificate/status details and the proposed contracting entity in the same email. If the answers refer to different entities, require the SOW to explain the relationship and who is accountable for each deliverable.
The current Cyber AB CMMC Assessment Process recognizes both Conditional and Final Level 2 Certificates of CMMC Status. A public announcement that an organization “achieved Level 2” is meaningful evidence, but it does not by itself disclose the exact legal entity, assessment scope, identifier, assessment date, C3PAO, or whether the status was Conditional or Final. Those are quote-stage verification questions—not accusations.
What does the Optiv + ClearShark CMMC Level 2 certificate actually prove?
Answer capsule: On September 25, 2025, Optiv + ClearShark announced it had achieved CMMC Level 2 certification, stating that it demonstrated implementation of NIST SP 800-171 controls for CUI. A CMMC certificate applies to a defined assessment scope, not to a corporate family. The announcement does not state the assessment scope, the assessing C3PAO, the CMMC Unique Identifier, whether the status is Conditional or Final, or the expiration date.
Let's give credit where it's due first, because this matters.
Under 32 CFR Part 170, an external service provider that is not a cloud service provider is not required to hold its own CMMC certification. Any provider that went through a Level 2 assessment did it voluntarily, spent real money, and put its own environment under a microscope. That's a genuine signal about institutional seriousness, and it means their people have lived through evidence collection, control operation, and the organizational friction of an assessment. It is a legitimate point in their favor.
Now the part your assessor cares about.
Everything a certificate has to tell a buyer — and what this announcement says
| What you need What the September 2025 announcement provides Why it decides your outcome How to get it | |||
|---|---|---|---|
| The legal entity holding the certificate | "Optiv + ClearShark" — a brand, not a legal entity | Certificates attach to an assessed organization, not a brand family or a parent company | Request the Certificate of CMMC Status showing the legal entity name |
| The CMMC Assessment Scope | Not stated | A certificate covering a corporate IT enclave tells you nothing about the platform that would monitor your network | Request the scope statement and the asset categories it included |
| Conditional or Final Level 2 | Not stated | A Conditional status runs on a 180-day POA&M closeout clock. If it isn't closed out in time, it expires | Ask which one, and if Conditional, the closeout date |
| The assessing C3PAO | Not stated | It's how you confirm the certificate is real and current | Ask for the name, then confirm that firm's authorization on the Cyber AB Marketplace |
| The CMMC Unique Identifier | Not stated | It's the identifier your prime will eventually ask you for | Ask for it |
| Assessment date and expiration | Announced September 25, 2025; assessment date not stated | Level 2 certification runs three years | Ask for both |
| Does the certified scope include the service I'm buying? | Not stated | This is the only question that changes your assessment burden by one minute of work | Request the service description and the Customer Responsibility Matrix |
| Independent verification | Not available publicly | CMMC status is recorded in SPRS, which is not a public directory. There is no website where you can look this up | Ask the provider directly; confirm through your prime's SPRS access if you have that path |
Two things in that announcement deserve a note. It describes Level 2 as meeting the Department's "highest security expectations," which isn't quite right — Level 3, assessed by DIBCAC against requirements selected from NIST SP 800-172, sits above it. And an Optiv + ClearShark executive described the company as "among the few CMMC 2.0 technology providers" — accurate enough in September 2025, when far fewer certificates had been issued, and worth re-checking against today's market before you treat it as a differentiator.
Compare that with the alternative standard of proof. In the MSP Collective ESP Directory, every one of the 55 listings has had its Level 2 certification cross-checked with the assessing C3PAO, requires Final status specifically, and requires that the assessment scope include the managed services being sold. That's the bar a published, third-party-validated certificate clears.
Neither approach is wrong. They just prove different amounts. A certificate you can't see the scope of is a marketing asset. A certificate with a published scope and a Customer Responsibility Matrix is a compliance asset. Ask which one you're being offered — of Optiv and of everybody else.
If you hire Optiv, what lands in your CMMC assessment scope?
Answer capsule: Under 32 CFR 170.19, an external service provider that handles Security Protection Data — logs, alerts, configurations, or credentials — is treated as a Security Protection Asset within the customer's CMMC assessment scope. The relationship must be documented in the customer's System Security Plan, along with the provider's service description and a Customer Responsibility Matrix. The provider's certificate does not remove that obligation.
Read that again with the emphasis in the right place: your scope, your SSP, your certificate on the line.
This is the mechanic that catches enterprises hardest, because at enterprise scale the MSSP contract is often owned by IT and the CMMC program is owned by compliance, and the two documents never meet.
We maintain a full explainer on external service provider scoping — how Security Protection Assets differ from CUI Assets, how the scoping tables work, and what an assessor will actually ask for. We won't rebuild it here. Read the ESP scoping guide →
What you need on this page is the mapping.
Optiv services and where they land
| The service What it typically touches Likely scoping consequence The artifact to demand | |||
|---|---|---|---|
| Agentic Security Operations (formerly Optiv MDR) | Endpoint, cloud, and network telemetry; alerts; investigation data | Security Protection Data → Security Protection Asset in your scope | Service description + Customer Responsibility Matrix + data location statement |
| Cyber Fusion Center | Same, plus documented remote access into your environment | In scope, and engages your access control and identification/authentication controls | Same, plus the remote-access model and approval gates |
| Co-managed SIEM | Log aggregation and retention | In scope. Log retention terms interact with your DFARS 252.204-7012(e) obligation to preserve images and monitoring data for 90 days | Retention terms in writing, plus evidence portability |
| Vulnerability management | Scan data, asset inventory, findings | In scope as Security Protection Data | Service description + CRM |
| Identity services | Credentials, directory, privileged access | In scope, and touching some of the highest-value controls in the 110 | Service description + CRM + privileged-access model |
| Penetration testing | Point-in-time engagement, findings report | Usually not an ongoing scoping item, but the findings become assessment evidence | Report handling, retention, and destruction terms |
| Security technology resale | Products you own and operate | Generally not an ESP relationship on its own | Confirm who administers what after purchase |
| Advisory, gap assessment, SSP, POA&M | Your compliance documentation and evidence | Not an ESP relationship, but a work-product ownership question — and an entity question after June 1, 2026 | Named entity, deliverable list, acceptance criteria, ownership on termination |
The paragraph that pays for this entire page
Under DFARS 252.204-7012(c), when a cyber incident affects covered defense information or the contractor's ability to perform operationally critical support, the contractor files the report to the Department within 72 hours. Not the SOC. Not the MSSP. You.
We have watched buyers assume, in good faith, that a 24/7 managed detection service means somebody else handles the regulatory notification. It doesn't. Fast containment is an operational service. A 72-hour report to the Department is a contractual obligation with your name on it.
Get it in writing: who drafts the report, who reviews it, who submits it, and what your provider owes you within the first six hours of an incident. If the answer is a shrug, price the gap.
One more scoping wrinkle: stacked providers
Optiv's newest managed offering is built on other companies' platforms. If Optiv operates a security platform on your behalf, and that platform is itself a third-party service, you may have two external service providers in one relationship — each needing its own entry, service description, and responsibility matrix in your SSP. That's not a reason to avoid it. It's a reason to draw the diagram before you sign, not after your assessor asks.
A System Security Plan paragraph you can adapt today
[Company] uses [exact legal entity name] to provide [service name], under agreement dated [date]. The service [does / does not] process, store, or transmit CUI. The service [does / does not] handle Security Protection Data, including [log data / alert data / configuration data / credentials]. The provider is documented as an External Service Provider under 32 CFR 170.19. The provider's service description dated [date] and Customer Responsibility Matrix dated [date] are maintained at [location] and are incorporated by reference. Responsibilities not assigned to the provider in that matrix remain with [Company]. Provider access is [remote / on-site], authenticated via [method], and reviewed [frequency].
Fill in the brackets. If you cannot fill in a bracket, you have found your next question.
Where your data goes: offices, delivery, and the export-control question
Answer capsule: Optiv's own Locations page lists offices in the United States, Canada (Mississauga, Ontario) and India (Bangalore), and its page description also names. NIST SP 800-171 Revision 2 contains no citizenship or nationality requirement. However, if CUI in security telemetry is export-controlled technical data, disclosure to a foreign person can constitute a deemed export under U.S. export control law regardless of what CMMC requires.
We include this section on every managed-security review because it's the question buyers most often forget to ask and most often regret.
| The fact (from Optiv's own materials) What NIST SP 800-171 Rev. 2 says What DFARS 252.204-7012 says What export control says | |||
|---|---|---|---|
| Offices and delivery locations include Leawood, Denver, Newport Beach, Salt Lake City, Chantilly, Mississauga (Canada) and Bangalore (India); the page description also names | There is no citizenship or nationality requirement in the 110 requirements. Don't let anyone tell you there is | If a cloud service stores, processes, or transmits CUI, the FedRAMP Moderate baseline (or an equivalency determination) requirement attaches | If the CUI in your logs is controlled technical data, disclosure to a foreign person — including a non-U.S. analyst — can be a deemed export under the ITAR (22 CFR Part 120) or the EAR. This is a question for export counsel, not for your MSSP's account team |
| The Cyber Fusion Center page describes 24/7 operations that "remotely work within your environment" | Remote access into a CUI environment engages your access control and identification/authentication families and pulls the provider's tooling into the scoping conversation | The 72-hour report remains yours | Remote access by a foreign person is the textbook deemed-export fact pattern |
| No published US-persons statement for any Optiv managed service that we could find | — | — | The absence of a statement is itself the finding. It goes in the letter |
To be fair about it: a global delivery footprint is standard for enterprise managed security, it is not a compliance defect, and plenty of DIB contractors run perfectly clean programs with global providers. What is not optional is knowing the answer in writing before your data starts flowing, and having the ITAR conversation with counsel rather than with a salesperson.
Before the sales call: Run the 32-point CMMC readiness checklist and mark each answer as known, assumed, or unknown. The unknowns become your agenda—and make a vague proposal much easier to spot.
Agentic Security Operations: the new stack and the three questions it creates
Answer capsule: On August 5, 2026, Optiv renamed and rebuilt its managed detection service as Optiv Agentic Security Operations, integrating Google Security Operations, Google Threat Intelligence, and Wiz cloud security, with AI agents performing parts of alert triage and investigation while practitioners validate findings. For DIB buyers with CUI in scope, an AI-assisted managed service raises data-location, subprocessor, and change-control questions that belong in the contract.
For a commercial CISO, this is a capability story. For you, it's three questions.
One: which cloud does my telemetry land in, and is there a government-cloud version of this service? We found no published statement either way. Whether the underlying platforms are being consumed in a commercial or government environment is a scoping fact, not a detail. Ask, and get the answer in the service description.
Two: does the automated processing touch anything that could be CUI, and where does the model run? If CUI reaches a cloud service that stores, processes, or transmits it, the FedRAMP Moderate baseline-or-equivalency requirement in DFARS 252.204-7012 is in play. "It's just alert metadata" is a claim that needs testing against your actual data flows, not an assumption.
Three: who are the subprocessors, and can the list change without notice? At least two major third-party platforms are already named in the stack. Get the current list, and get contractual notice before it changes.
There's a fourth question that comes free with any automated-response capability: what can an agent do inside my environment without a human approving it? Automated remediation that reaches your endpoints has to fit inside your configuration management controls. Ask what approval gates exist, who can override them, and what gets logged.
And one piece of real timing, not manufactured urgency. The CMMC Reform Task Force's public request for information explicitly asked how the Department might recognize commercial cybersecurity tools and managed services in lieu of separate assessments. That RFI closed August 14, 2026. The Task Force report is due to the CIO in mid-September 2026. A platform-plus-managed-service model is precisely what that question touches. We're not going to predict the outcome — nobody credible can — but if you're signing a multi-year managed services agreement in the next 60 days, a short review-and-adjust clause tied to a change in federal requirements costs you nothing to ask for.
What does Optiv CMMC work cost?
Answer capsule: No Optiv-specific CMMC price or package rate appeared in any Optiv material reviewed as of August 28, 2026. Enterprise cybersecurity engagements are typically custom-scoped and quote-based. The practical protection for a buyer is line-item separation of discovery, documentation, remediation, technology licensing, managed operations, and any formal assessment.
We're not printing a number. Not from an aggregator, not from a "typical range," not from a competitor's price list. If we did, you'd anchor on it, and it would be wrong.
What we can give you is more useful anyway: the structure that makes any two quotes comparable.
The 14-line quote normalization table
Make every proposal answer these separately. When a vendor resists breaking a line out, that's information.
| Cost line What the proposal must state | |
|---|---|
| Discovery and scoping | Hours, systems, sites, interviews, boundary assumptions, and the deliverable it produces |
| Gap or readiness assessment | Which of the 110 requirements are tested, evidence depth, and the findings format |
| SSP and documentation | Which documents, who authors them, how many revision cycles, what you must supply |
| POA&M and remediation planning | Prioritization method, effort estimates, owners, dependencies |
| Technical remediation | Labor assumptions, systems touched, configuration responsibility, acceptance testing |
| Technology licenses | Product, quantity, term, implementation, renewal, and any markup |
| Cloud or enclave work | Migration, licensing, administration, support, and exit |
| Managed operations | Coverage hours, SLA, alerting, investigation depth, log retention, evidence production |
| Training | Audience, format, frequency, and who owns the materials |
| Reassessment support | Mock review, evidence refresh, interview preparation |
| Formal C3PAO assessment | Separate provider, separate agreement, travel, retest, POA&M closeout — never bundled |
| Change orders | Trigger, rate, approval process, and cap |
| Ongoing annual work | Annual affirmation support, evidence maintenance, SSP updates |
| Exit and transition | Data export, documentation transfer, credential revocation, migration assistance |
Ten quote red flags
If you see three or more of these, slow down.
- A single "CMMC compliance" line with no enumerated deliverables.
- Technology purchases presented as equivalent to control implementation.
- No Customer Responsibility Matrix, or one promised "after kickoff."
- No stated boundary assumptions and no list of excluded systems or sites.
- Any form of guaranteed-pass language. Nobody cannot guarantee a certification outcome.
- A formal assessment included in the same agreement as the readiness work.
- Discovery with no capped fee and no concrete output.
- No price for what happens after implementation ends.
- No exit, data-export, or evidence-portability provision.
- Reluctance to name the contracting legal entity.
The buyer question underneath all of this — and we hear a version of it constantly from DIB contractors weighing managed security packages — is whether you actually need 24/7 outsourced operations to satisfy CMMC at all. The honest answer: the 110 requirements in NIST SP 800-171 Revision 2 describe outcomes, not staffing models. Several of them push hard toward continuous monitoring, and some organizations genuinely cannot meet them with the people they have. Others can. Buy the operating model your risk and your staffing require, not the one that maps most neatly onto a subscription.
Before you take another quote, know which category you're buying from
Comparing an integrator's proposal against a specialist's proposal is comparing two different products. Tell us your level, scope, and timeline, and we'll match you with source-checked CMMC provider options in the category that actually fits — readiness, managed security, enclave, GRC platform, or assessment. Get matched with source-checked provider options → Two minutes. No sales pitch. Do not submit CUI, drawings, or sensitive contract details.
Optiv versus a certified ESP, an RPO, and a C3PAO
Answer capsule: These four provider categories perform different functions and are not interchangeable. A large MSSP provides scale and continuous operations. A certified external service provider offers a validated CMMC Level 2 certificate and a responsibility matrix. An RPO provides readiness and documentation work. A C3PAO performs the certification assessment and, under conflict-of-interest rules, generally cannot also have prepared you.
This is a category comparison, not a ranking. We don't publish provider rankings, scores, or "best provider" awards, and we're not starting here.
| Large MSSP / integrator (Optiv's category) Certified ESP (validated Level 2 MSP/MSSP) RPO / RP (readiness) C3PAO (assessment) | ||||
|---|---|---|---|---|
| Runs 24/7 security operations | Yes | Often | Rarely | No |
| Holds its own validated Level 2 certificate | Sometimes; verify scope | Yes, by definition of the validation | Sometimes | Required as a condition of C3PAO authorization |
| Publishes a Customer Responsibility Matrix | Ask | Expected as part of validation | Varies | N/A |
| Writes your SSP and POA&M | Sometimes; entity question after June 2026 | Often | Core service | Never for a client it will assess |
| Can perform your certification assessment | No | No | No | Yes |
| Typical fit | Multi-site enterprise with a real operations gap | Small to mid DIB contractor wanting inherited assurance | Documentation-heavy readiness work | Assessment-ready organizations only |
| Where we cover it | This page | Provider directory | Provider directory | Cyber AB Marketplace guide |
The rule that keeps you out of trouble: keep readiness and formal assessment in separate lanes, with separate firms and separate agreements. The three-year conflict bar exists to protect the integrity of your certificate. Violating it doesn't save you money; it costs you a restart.
What belongs in an Optiv statement of work
Answer capsule: A defensible enterprise CMMC engagement identifies the contracting legal entity, the named delivery team, the controlling authority set, the CUI and assessment boundary, control-level responsibility allocation, deliverables with acceptance criteria, technology assumptions, the operating handoff, and assessment independence. Items left to "discovery" without a defined output and a capped fee are not yet a comparable scope.
Twenty points. Print it. Walk it line by line with the seller.
Entity and accountability
- Exact contracting legal entity
- Names and employers of the key delivery personnel
- Any Cyber AB roles claimed — by the entity and by named individuals
- Insurance carrier and coverage for this engagement
- Subcontracting disclosure
Regulatory grounding 6\. The controlling authority set the work is mapped to — for CMMC Level 2 purposes, NIST SP 800-171 Revision 2 unless and until the rule is amended 7\. Your required level and assessment type, taken from your contract, not assumed 8\. Whether the engagement assumes Phase 1 conditions or something else
Scope 9\. In-scope systems, sites, users, and service providers 10\. CUI and Security Protection Data handling 11\. External Service Provider and cloud service provider treatment 12\. The Customer Responsibility Matrix, control by control
Deliverables 13\. Complete deliverable list with formats 14\. Evidence and artifact acceptance criteria 15\. SSP ownership and revision obligations 16\. POA&M assumptions and closure responsibility 17\. Implementation validation method
Operations and exit 18\. Managed service SLA, coverage hours, log retention, and evidence production 19\. Assessment independence and the handoff plan to a separate C3PAO 20\. Exit, data return, sanitization, and evidence portability
The continuity clauses, and why we're recommending them
Here's a set of facts we'd want you to have, stated plainly and without drama.
In August 2025, Bloomberg Law reported that Optiv was exploring a divestiture of its managed-services business to address near-term debt maturities, reporting roughly $1 billion in long-term debt with more than half maturing in 2026. In March 2026, Optiv announced a comprehensive amendment and extension of its credit facilities. On June 1, 2026, the ACT sale closed.
None of that says anything about Optiv's future, and we're not going to speculate. Companies restructure. This one appears to have done it deliberately and with top-tier advisors.
What it does say is that any multi-year external service provider relationship should be papered for change — and here's the CMMC-specific reason nobody tells you: an ESP change is an SSP change. If your provider is sold, novated, or reorganized mid-contract, your service description, your responsibility matrix, your subprocessor list, and potentially your data location all change, and your System Security Plan has to change with them. If that happens two months before an assessment, you have a problem.
So, nine clauses. They work on any vendor, which is why we're giving them away.
- Change-of-control and assignment notice, measured in days.
- ESP-change notification with a re-issued service description and Customer Responsibility Matrix.
- Named subprocessors, with notice before any addition.
- Data location commitment, and any US-persons commitment, in the contract rather than the deck.
- AI and automated-processing disclosure: what agents see, where inference runs, what is retained.
- Exit and transition assistance, priced up front rather than negotiated under pressure.
- Data return and sanitization on termination.
- Evidence portability — you keep the logs and artifacts your assessor will ask for.
- Incident reporting responsibilities, including who drafts and who files the 72-hour report.
What we could not verify — and the 12 questions that close it
Answer capsule: This profile is built from public sources, and several decision-relevant facts about Optiv's CMMC offering are not publicly available. The unresolved items include the delivering legal entity, the certificate's scope and status details, RPO status, pricing, government-cloud availability, and the existence of a pre-signature Customer Responsibility Matrix.
An honest review says what it doesn't know. Here's the list, and here's the letter that closes it.
Copy this, fill in the brackets, send it. Every question maps to something on this page.
Subject: CMMC and scoping questions before we proceed — [Your Company]
We're evaluating [service name] and need the following documented before we can move to pricing. Several of these affect our CMMC assessment scope directly, so they're not optional for us.
- Entity. What exact legal entity will sign this agreement, and which entity employs the delivery team?
- Certificate. Please provide the Certificate of CMMC Status for the entity we would contract with, including the CMMC Unique Identifier, level, assessment date, expiration, and whether the status is Conditional or Final.
- Assessing C3PAO. Which C3PAO performed that assessment?
- Scope. Does the certified CMMC Assessment Scope include the services proposed to us? Please provide the scope statement.
- Service description. Please provide the written service description for the proposed services.
- Customer Responsibility Matrix. Please provide the CRM, control by control, before signature.
- Ecosystem status. Does your organization hold any current Cyber AB role — RPO, or any other — and under which legal name?
- Data location. Where will our data be stored, processed, and accessed from? Please identify all countries. Do you make any US-persons commitment for personnel with access to our environment?
- Subprocessors. Please provide the current subprocessor list and your notice obligation before changes.
- Automated processing. What data do AI or automated components process, where does that processing occur, what is retained, and what actions can be taken in our environment without human approval?
- Incident reporting. Under DFARS 252.204-7012, who drafts, reviews, and files the 72-hour report to the Department? What do you commit to in the first six hours?
- Change and exit. What are your change-of-control notice terms, exit and transition assistance terms, and data return and sanitization commitments?
Please note we will not transmit CUI, drawings, or contract-sensitive details through this thread.
If a provider answers all twelve, you've learned something real. If they answer four and offer a call, you've also learned something real.
One more thing worth doing before that call
Most CMMC money is lost in the first decision, not the last one — buying the wrong category, then discovering it during an assessment. Map your level, FCI or CUI scope, assessment type, environment, and timeline to the provider category you actually need, then take that clarity into every vendor conversation. Find my CMMC provider category → Do not submit CUI, drawings, export-controlled information, contract numbers, or network diagrams.
Frequently asked questions
Is Optiv a C3PAO? No Optiv entity appeared in the Cyber AB Marketplace C3PAO listing when we searched it on August 28, 2026. Only an authorized or accredited C3PAO may conduct a CMMC Level 2 certification assessment under 32 CFR Part 170. Confirm current status yourself at the Cyber AB Marketplace before relying on any provider's role claim.
Is Optiv CMMC certified? Optiv + ClearShark — the federal arm, legally Optiv Federal Inc. — announced on September 25, 2025 that it achieved CMMC Level 2 certification. That is a company statement about its own assessed environment. The announcement does not identify the assessment scope, the assessing C3PAO, the CMMC Unique Identifier, or whether the status is Conditional or Final.
Does Optiv's Level 2 certificate cover my company? No provider's certificate covers your company. CMMC certification applies to the assessed organization's own defined scope. What a provider's certificate can do is reduce the evidence burden for the services inside that scope — which is why the scope statement and the Customer Responsibility Matrix matter far more than the certificate itself.
Can Optiv perform my CMMC assessment? No. Level 2 certification assessments are performed by authorized or accredited C3PAOs, and Level 3 assessments are performed by DIBCAC. Under CMMC ecosystem conduct rules, an organization that consulted to prepare you for an assessment is barred from participating in that assessment for three years.
Is Optiv an RPO? We were not able to complete an organization-level Registered Provider Organization check across every Optiv legal and trade name, so we make no claim in either direction. Search the exact legal entity name in the Cyber AB Marketplace and ask the provider directly.
Did Optiv sell its consulting business? Yes. Optiv announced the sale of its Advisory, Consulting and Transformation project-based services business to Vobis Ventures, closing June 1, 2026. That business now operates as Optiv Consulting — approximately 500 consultants and 800 enterprise clients — as a separate company with its own CEO. Optiv retained managed services and staff augmentation.
Which Optiv entity would perform CMMC work? It depends on the engagement, and no public document resolves it. Three separate web properties currently publish CMMC service claims under an Optiv-related name: optiv.com, optivclearshark.com, and Optiv Consulting's site. Require the proposal to name the contracting legal entity and the delivery team.
Does hiring Optiv put them in my CMMC scope? If the service handles Security Protection Data — logs, alerts, configurations, credentials — then under 32 CFR 170.19 it is treated as a Security Protection Asset within your assessment scope, must be documented in your System Security Plan, and requires the provider's service description and a Customer Responsibility Matrix.
Under DFARS 252.204-7012, the contractor retains the rapid-reporting duty and must report a covered cyber incident within 72 hours of discovery. The clause’s 90-day preservation rule is narrower than “keep every log for 90 days”: after a reported incident, the contractor must preserve and protect images of known affected information systems and relevant monitoring or packet-capture data for at least 90 days from submission of the report so DoD can request them. A consultant can support the process; it does not inherit the contractor’s contractual duty.
Does Optiv support GCC High or AWS GovCloud? We found no published statement either way for any Optiv managed service as of August 28, 2026. Treat it as an open question and get the answer in the service description before signing.
What does Optiv CMMC work cost? No Optiv-specific CMMC price appeared in any material we reviewed. Enterprise engagements are custom-scoped. Require line-item separation of discovery, documentation, remediation, technology, managed operations, and any separate formal assessment so you can compare proposals meaningfully.
Do I still need any of this after the July 13, 2026 Phase 2 suspension? Yes. Phase 2 and future implementation milestones were suspended, but Phase 1 self-assessment requirements, DFARS 252.204-7012, the 110 requirements in NIST SP 800-171 Revision 2, SPRS score posting, and annual affirmations all remain in force. With no third-party assessor validating your documentation, the accuracy of your own attestation carries more weight, not less.
How we produced this Optiv CMMC review
Who. The Defense Compliance Report Editorial Team. We are an independent trade publication on CMMC 2.0 and DIB compliance. No named individual reviewer is claimed for this page because none reviewed it.
How. On August 28, 2026 we read Optiv's live CMMC service page, Cyber Fusion Center and managed security services pages, corporate Locations page, and product announcements; Optiv + ClearShark's federal services page and corporate announcements including the September 25, 2025 CMMC Level 2 release and the July 2026 SEWP VI release; Optiv Consulting's public service and industries pages; the June 2, 2026 ACT divestiture announcement; the MSP Collective ESP Directory, which we counted line by line; the Cyber AB Marketplace C3PAO listing; and the FedRAMP Marketplace. We cross-checked every regulatory statement against 32 CFR Part 170, DFARS 252.204-7012, 252.204-7021 and 252.204-7025, NIST SP 800-171 Revision 2, NIST SP 800-172, and the Department of War's July 13, 2026 announcements suspending CMMC Phase 2.
What we did not do. We did not run an engagement, interview Optiv, review a signed statement of work, obtain a quote, test any service, or receive anything of value from any Optiv entity. Company claims are attributed as company statements and identified as such throughout.
Why. Because a defense contractor about to spend six figures on cybersecurity should be able to find out, in ten minutes, which company they'd be contracting with and what the certificate they were told about actually covers. That page didn't exist. Now it does.
Corrections. If you represent Optiv, Optiv + ClearShark, or Optiv Consulting and any fact here is wrong or out of date, we will correct it promptly and note the correction. If you can provide the certificate scope, the Customer Responsibility Matrix, or an entity-to-service map, we will publish an updated profile and say so at the top.
Primary and company sources reviewed, August 28, 2026
- 32 CFR Part 170 (CMMC Program Rule, effective December 16, 2024) — §§ 170.4, 170.9, 170.17, 170.19
- DFARS 252.204-7012, 252.204-7021, and 252.204-7025 (Acquisition.gov)
- NIST SP 800-171 Revision 2 and NIST SP 800-172 (NIST CSRC)
- Department of War announcements and CIO memoranda suspending CMMC Phase 2, July 13, 2026
- Optiv CMMC service page, Cyber Fusion Center page, Locations page, and Agentic Security Operations announcement (August 5, 2026)
- Optiv + ClearShark services page, CMMC Level 2 certification announcement (September 25, 2025), and SEWP VI announcement (July 7, 2026)
- Optiv ACT divestiture announcement (June 2, 2026) and Optiv Consulting public service and industries pages
- MSP Collective ESP Directory (counted August 28, 2026); Cyber AB Marketplace; FedRAMP Marketplace
- Trade reporting on Optiv's 2025 divestiture exploration and March 2026 credit facility amendment
Need help deciding what type of CMMC provider you need?
Tell us your level, scope, and timeline, and we'll match you with source-checked CMMC provider options.
Find My CMMC Provider Category →
Do not submit CUI, drawings, export-controlled information, contract numbers, or network diagrams.
The Defense Compliance Report — the independent CMMC decision layer for defense contractors. Choose the right CMMC path before you hire.
Regulatory Facts Your Optiv SOW Still Has to Match
CMMC Level 2 is still tied by 32 CFR Part 170 to the 110 security requirements in 14 requirement families from NIST SP 800-171 Revision 2. NIST has published Revision 3, but Revision 3 is not the CMMC-controlling version unless DoD amends the governing rule and contract framework. The incorporated publication remains NIST SP 800-171 Rev. 2.
DFARS 252.204-7019 and DFARS 252.204-7020 remain active parts of the DoD Assessment framework. They were not eliminated by the CMMC clauses. The current clause set also includes 252.204-7021 for CMMC requirements and 252.204-7025 for notice of the required CMMC level. Which clauses control you depends on the solicitation and contract, not on a provider summary.
A provider does not “certify you in SPRS.” Under the CMMC program, the authorized assessment actor records assessment results through the designated CMMC system, and the resulting status is made available to DoD in SPRS. The organization’s designated Affirming Official remains responsible for the required affirmation. Separately, DFARS 252.204-7019 and 252.204-7020 govern NIST SP 800-171 DoD Assessment results in SPRS. Put the exact owner, submission path, and due date for each item in the SOW.
A DIBCAC assessment performed as part of a prospective C3PAO’s authorization path is not the same thing as a CMMC certification assessment of that C3PAO, and it does not by itself produce a Certificate of CMMC Status. Treat C3PAO authorization, an organization’s own CMMC status, and the authority to assess your organization as three separate facts.
Ready to compare scoped proposals? Request a CMMC quote. We may receive compensation from a matched provider, but no provider can pay to change our editorial findings or its placement in this review.
Related Decision Guides
- Confirm the contract target: CMMC Levels explained
- Build a budget range: What CMMC certification costs
- Sequence the work: Who to hire first for CMMC
- Separate provider roles: CMMC provider categories
- See how we verify claims: Methodology and Editorial Standards
- Report a source or factual problem: Corrections Policy
Primary-Source Verification Ledger
Regulatory and technical sources checked August 28, 2026:
- 32 CFR Part 170, CMMC Program and the October 15, 2024 final rule
- NIST SP 800-171 Rev. 2 and NIST SP 800-172
- DFARS 252.204-7012, 252.204-7019, 252.204-7020, 252.204-7021, and 252.204-7025
- Cyber AB CMMC Assessment Process and CMMC Marketplace
- Optiv CMMC services page, Optiv + ClearShark Level 2 announcement, and Optiv company transaction materials
Company marketing and directory status can change between verification and contracting. Re-check the named legal entity and current Marketplace role when you request a proposal.
