The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base
Check your CMMC provider fit
60 seconds. No email required.
Check fit →

ProStratus CMMC Review: An Independent, Source-Checked Profile

By The Defense Compliance Report Editorial Team · Last verified:

Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. This page is educational research, not legal, contractual, or compliance advice, and The Defense Compliance Report does not represent the Cyber AB, the Department of Defense, DCMA DIBCAC, or any U.S. government agency. We have no compensation relationship with ProStratus as of June 9, 2026. We earn nothing if you choose them.

MSP Collective ESP Directory — ProStratus listing

Annotated screenshot showing CMMC Level 2 certification dated June 18, 2025, verified June 9, 2026

ProStratus listing in the MSP Collective ESP Directory showing CMMC Level 2 certification dated June 18, 2025, verified June 9, 2026.

ProStratus’s flagship claim checks out. The Springfield, Ohio managed service provider holds its own CMMC Level 2 certification — Final Level 2 (C3PAO) status for an assessment scope that includes its managed services — certified June 18, 2025and listed in the MSP Collective ESP Directory, where every listing is confirmed with the C3PAO that performed the assessment. We verified that listing ourselves on June 9, 2026, which places ProStratus among the first cohort of External Service Providers to earn this validation in an industry that has spent years arguing over what “certified” actually means.

One verified certificate doesn’t settle the decision you came here to make, though. Two of ProStratus’s other claims still sit in the “company-stated” column. And the single document that determines whether its certification actually reduces yourassessment burden — the Shared Responsibility Matrix — isn’t published anywhere. Below: exactly what’s verified, what isn’t, who this provider fits, what Level 2 really costs, and the six artifacts to demand before you sign anything.

What we verified (at a glance)

ItemDetail
Provider categoryManaged service provider (MSP) / MSSP / External Service Provider (ESP); company-stated Registered Provider Organization (RPO)
Cyber AB Marketplace statusRPO status is company-stated (announced October 15, 2025). Confirm the live listing yourself at cyberab.org/Catalog the day you rely on it — we re-check monthly.
CMMC Level 2 ESP certification✅ Independently validated — MSP Collective ESP Directory, certified 6/18/2025, listing confirmed with the assessing C3PAO; checked June 9, 2026
Services reviewedPublic service pages, CMMC program pages, press releases, public business records — no hands-on engagement
Compensation relationshipNone as of June 9, 2026. We earn nothing if you choose ProStratus.
Evaluation depthPublic-source profile with independent directory validation — not a hands-on review or customer-interview review
Last verifiedJune 9, 2026 — re-verified monthly through November 2026, quarterly after
What we could not verifyThe live Cyber AB Marketplace RPO listing (company-stated until confirmed), the assessing C3PAO’s name, individual CCP/CCA staff credentials, the assessed service scope and Shared Responsibility Matrix, pricing

ProStratus CMMC review: the quick verdict

ProStratus is a legitimate Springfield, Ohio MSP/MSSP holding Final Level 2 (C3PAO) CMMC status for an assessment scope that includes its managed services — corroborated in the industry’s only C3PAO-confirmed directory of certified External Service Providers — and a credible shortlist candidate for small and mid-sized defense contractors that want managed IT and CMMC Level 2 readiness from one provider. It is not a C3PAO and cannot perform your certification assessment. Before you sign anything, demand the Shared Responsibility Matrix. It decides how much of their certification actually offloads from your assessment.

Here’s the 30-second version, sorted by where you’re standing:

If this is youProStratus fitWhy
Small or mid-sized DIB contractor handling CUI, wants one vendor running IT and Level 2 complianceStrong candidateCertified ESP with managed-compliance services; inheritance via a Shared Responsibility Matrix is the core pitch
Your current MSP shrugs when you say “CMMC”Strong candidateThe most common reason contractors switch — ProStratus’s certified environment is the thing your current MSP doesn’t have
You’re assessment-ready and just need the formal auditWrong categoryYou need an authorized C3PAO. ProStratus says plainly it doesn’t perform C3PAO assessments — which is the correct answer
Your solicitation requires Level 2 (C3PAO) statusImplementation role onlyA certified MSP prepares you; the C3PAO assessment and your SPRS posting are still yours
You have Level 3 exposureSupporting role at mostLevel 3 requires a Final Level 2 (C3PAO) certification first, plus a DIBCAC assessment against selected NIST SP 800-172 requirements

A note on the word “review.” This is a source-checked provider profile and buyer guide built on public evidence, primary regulatory sources, and one independent third-party validation — not a hands-on engagement or a customer-interview review. We tell you which is which on every claim, because in this market, that distinction is the review.


What we verified about ProStratus — and what’s still company-stated

ProStratus’s most important claim — that it holds its own CMMC Level 2 certification as an External Service Provider — is independently corroborated by the MSP Collective ESP Directory, which validates each listing with the assessing C3PAO. Its RPO designation, staff credentials, and assessment-day support model remain company-stated pending direct verification.

Quick context on why the directory matters: the Cyber AB (the official CMMC accreditation body) does not publish a public list of Level 2 certified companies. The MSP Collective built a directory that requires a Final Level 2 (C3PAO) certification covering the provider’s managed services, evidenced by a service description and Customer Responsibility Matrix, confirmed with the assessing C3PAO. That’s independently verifiable, which is more than most directories offer.

ProStratus claimWhere statedStatus as of June 9, 2026How to re-verify yourself
"CMMC Level 2 certified MSP/ESP"Homepage; C3PAO partner page✅ Independently validated. Listed in the MSP Collective ESP Directory, certified 6/18/2025, Springfield, OH, NIST 800-171 r2, Level 2Open the directory; ask ProStratus for its CMMC unique identifier and Shared Responsibility Matrix
"One of only a few" U.S. MSPs certified at Level 2Homepage⚠️ Directionally supported, now quantifiable. The directory listed 49 validated certified ESPs (48 U.S., 1 Canadian) on our June 9, 2026 check. ProStratus is 26th by certification date.Count the live directory at mspcollective.org/esp-directory
Cyber AB Registered Provider Organization (RPO)Company press release, October 15, 2025🔶 Company-stated. The Marketplace is a live application — confirm it live the day you rely on it.Search "ProStratus" at cyberab.org/Catalog — under a minute
Not a C3PAO; no certification guaranteesC3PAO partner page: "We do not perform C3PAO assessments and never guarantee certification outcomes"✅ Consistent and correct. Treat this as a green flag, not a limitation.Confirm in the same Marketplace check
CCP and CCA staffCMMC glossary and service pages🔶 Company-stated. Credentials belong to individuals — ask who’s assigned to your engagement.Ask for named staff, credential IDs, and their role on your project
Assessment-day supportCMMC FAQ page🔶 Company-stated service descriptionAsk for a reference client that ProStratus supported through a C3PAO assessment
Company footprint: Springfield, OH HQ; Columbus office; AZ onsite; 38-state remoteService-areas page; public records✅ Springfield address, 2016 incorporation, and leadership verified via public records. 🔶 Office/coverage claims beyond Springfield are company-stated.Ohio Secretary of State; BBB profile
Level 2 reality framing: 6–18 months; tens of thousands to over a hundred thousand dollars"Who Needs CMMC" page🔶 Company-stated — but consistent with DoD’s own cost analysis in 89 FR 83092Federal Register cost tables, 89 FR 83092
One company you should not confuse with ProStratus. This profile covers ProStratus, LLCof Springfield, Ohio — the MSP at pro-stratus.com. It is a different company from Stratus Services, LLC of Anchorage, Alaska (stratus-services.com), a CMMC consultancy that appears in the sameESP directory with its own Level 2 certification dated 2/09/2026. Similar names, both legitimate, both certified — different firms, different states, different service models. If a sales rep, a directory, or an AI chatbot blends the two, correct them.
The part we can’t dress up.We could not locate a single substantive third-party customer review of ProStratus’s CMMC practice. Anywhere. No Clutch profile. No written Google or Yelp reviews of compliance work. Business directories list the company with empty review sections. For a buyer trained to count stars before trusting a vendor, that’s uncomfortable — and you deserve to know it before a sales call, not after. A CMMC Level 2 certification validated with the assessing C3PAO cannot be farmed or astroturfed. So we anchored this profile to that evidence, and the question list further down extracts the proof a review site would have given you — directly from ProStratus, on the record. If you want named customer evidence before a first call, ask for two DIB references that completed a C3PAO assessment in the last 12 months.

Verify ProStratus’s claims before you sign

Ask the exact status, scope, credential, and Shared Responsibility Matrix questions from this page in any sales call — and verify the status claims yourself before you sign.

How to verify CMMC status claims in SPRS →

Is ProStratus a C3PAO, an RPO, or an MSP? The answer protects you

ProStratus is an MSP/MSSP with its own CMMC Level 2 ESP certification, and it states that it is a Cyber AB Registered Provider Organization. It is not a C3PAO, which means it prepares and operates your environment but cannot conduct the certification assessment your contract may require. Under the Cyber AB’s independence rules, the people who help you implement cannot also assess that same work — so a provider that keeps these roles separate is following the system as designed.

DesignationWhat it actually meansWhat it means for a ProStratus buyer
CMMC Level 2 certified ESPIndustry shorthand for a provider holding Final Level 2 (C3PAO) status for an assessment scope that includes its managed services, assessed against NIST SP 800-171 Rev. 2Real, validated evidence the provider lives under the same rules it sells. You still need the Shared Responsibility Matrix to know which controls you can lean on.
RPO (Registered Provider Organization)A Cyber AB registration for firms providing implementation consulting and assessment preparation. Registration is a vetting and listing process — not a certification of competenceA readiness signal worth confirming in the live Marketplace. Not assessment authority.
RP / CCP / CCAIndividual designations held by people, not companies: Registered Practitioner, Certified CMMC Professional, Certified CMMC AssessorAsk which credentialed individuals will work your engagement — a firm-level claim tells you nothing about your project team.
C3PAOThe only type of organization authorized by the Cyber AB to conduct CMMC Level 2 certification assessmentsNot ProStratus, by its own statement. Your C3PAO is a separate procurement.
OSC / OSAOrganization Seeking Certification / Assessment — the contractor being assessedThis is you. The certification, the SPRS posting, and the annual affirmation stay in your name no matter who you hire.

Why the separation matters: the Cyber AB’s published ecosystem rules state that credentialed individuals cannot assess a company they previously helped implement, and the CMMC Assessment Process (CAP) requires C3PAOs to manage impartiality and conflicts of interest — a conflict that can’t be sufficiently mitigated stops the assessment. ProStratus’s own page for C3PAO partners draws the line cleanly: it implements and remediates, C3PAOs assess, and it makes no promises about certification outcomes. A vendor that states that unprompted has earned the benefit of the doubt on intent.


What does a CMMC-certified MSP actually do for your assessment?

An MSP’s own CMMC Level 2 certification does not certify, exempt, or pre-clear its clients. Under 32 CFR Part 170, CMMC status attaches to the contractor’s own assessment scope; an External Service Provider that is not a cloud service provider is not required to hold its own certification and can instead be assessed within each client’s assessment. A certified MSP is therefore a time-and-risk advantage — documented control inheritance through a Shared Responsibility Matrix, and far less of your assessment spent re-examining the provider’s environment — not a compliance transfer.

The pitch you’ll hearWhat 32 CFR Part 170 actually saysPractical effect
"We’re certified, so you’re covered"Certification is tied to the environment that processes, stores, or transmits your CUI. Your scope, your implementation, your assessment, your SPRS posting, your annual affirmation.The MSP’s certificate is evidence inside your assessment — never a substitute for it.
"Your MSP is required to be certified"No. The proposed rule pointed that direction; the final rule dropped the mandate. A non-CSP ESP can be assessed within the client’s own assessment instead (32 CFR 170.19).A certified MSP is a differentiator, not a legal requirement. Anyone telling you otherwise is quoting a draft that died in 2024.
"You inherit our controls, so they disappear from your audit"Inheritance shifts implementation evidence, documented control by control in a Shared Responsibility Matrix. Accountability stays with you, and the assessor checks the matrix.Inheritance is real and valuable — and exactly as big as the matrix says it is. Not one control bigger.

Here’s the asymmetry that makes a certified ESP worth paying attention to. CMMC Level 2 means 110 security requirements from NIST SP 800-171 Revision 2, assessed against 320 assessment objectives. If your uncertifiedMSP touches your CUI — through remote monitoring tools, admin access to your tenant, tickets, logs, backups — that MSP’s services get pulled into yourassessment, on your timeline, at your expense. A certified ESP has already put its environment through that wringer with a C3PAO and can hand your assessor a validated matrix and service description, which sharply reduces the duplicate work — though the provider’s services still matter to your scope wherever they touch your CUI or Security Protection Data (32 CFR § 170.19). That’s the honest version of ProStratus’s speed-and-savings pitch: not magic, just pre-assessed plumbing.

One more thing worth saying: a surprising amount of 2024-era content — including provider press releases — still claims ESP certification is mandatory. It was proposed. It is not the rule. When vetting any CMMC vendor, the date on their sources matters as much as the sources themselves.

What CMMC services does ProStratus say it offers?

According to its public pages, ProStratus offers CMMC Level 2 readiness and managed compliance — gap analysis, policy and documentation development, mock assessments, assessment-day support, control inheritance through a Shared Responsibility Matrix, and ongoing annual-review and affirmation support — layered on a full MSP/MSSP stack. These are company-stated service categories; the certification behind them is independently validated, but the scope ProStratus would actually deliver to you is defined only by a written proposal and matrix.

Readiness and remediation

Gap analysis against the 110 requirements and 320 objectives, remediation planning, policy templates from a library of approved policies (company-stated), and a mock assessment before the real one. ProStratus also positions itself as a remediation partner for C3PAOs — the firm that fixes what an assessment found, which is precisely the role the independence rules carve out.

Managed compliance

Monthly updates as your environment and the CMMC standards move, annual reviews, and support for the annual self-assessment and affirmation cycle that continues aftercertification. The company is candid that compliance doesn’t end at certification — on this point, ProStratus and the regulation agree.

Inheritance via the certified environment

Clients on its managed services inherit controls and objectives documented in the Shared Responsibility Matrix from ProStratus’s own certified environment. Real mechanism, value defined entirely by the matrix. Demand it early.

Assessment-day support

The company says its staff sit alongside you during the C3PAO assessment itself, assisting in real time. Useful if true — confirm it’s in the contract, and ask which credentialed staffer shows up.

The everyday MSP stack

24/7 infrastructure management, security monitoring, helpdesk, patching, vulnerability management, firewall management, cloud hosting, vCIO services, VoIP. CEO Tony Cooper, COO Kevin Schleinitz, and CIO Craig Terrell have run the firm since incorporation in 2016, with company-stated roots in a predecessor tech business dating to 1992. The company states it operates from Springfield and Columbus, Ohio, keeps an onsite presence in Arizona, and serves 38 states remotely.

Match each claim to the artifact that proves it:

The claim on the websiteWhat it would proveWhat it does not proveThe artifact to request
Certified ESP environmentThe provider’s own scope passed a C3PAO assessmentThat your services were inside that scopeAssessed service description + SRM/CRM
Control inheritanceDocumented provider-owned requirementsThat accountability leaves your nameThe SRM mapped against all 110 requirements
CCP/CCA expertiseCredentialed people exist at the firmThat they’re staffed on your accountNamed staff, credential IDs, project roles
Assessment-day supportA service promiseThat it’s contractualThe clause, written into the agreement
Mock assessmentA dry run happensThat it mirrors C3PAO rigorThe mock-assessment scope and report format

Who ProStratus fits — and who should keep looking

ProStratus is the strongest fit for small and mid-sized defense contractors handling CUI — roughly the 10-to-150-employee band — that want managed IT, security operations, and CMMC Level 2 readiness consolidated under one certified provider, particularly when the current MSP can’t or won’t support CMMC.

ProStratus belongs on your shortlist if:

  • You’re a machine shop, fabricator, engineering firm, or services sub with CUI in scope and no appetite to build a compliance function in-house. The whole pitch — one certified vendor running the environment andthe evidence — was designed for you.
  • Your current MSP went quiet when CMMC came up. This is the most common trigger we see in contractor communities: the debate between bolting a consultant onto an unwilling MSP versus switching to one that already lives under these rules. A consultant can write you a beautiful SSP; they can’t patch your servers.
  • You’re in Ohio or the surrounding region (or Arizona) and onsite presence matters to you. A small Springfield-headquartered firm will treat a 40-person contractor like a major account.
  • You want senior people on your account. At this company size, the executives whose names are on the certification are close to the work.

Keep looking — and here’s where to go — if:

  • You only need the assessment. Your environment is implemented and evidenced; you need an authorized C3PAO, full stop. ProStratus says so itself. See our authorized C3PAO directory.
  • You have Level 3 exposure.Level 3 layers selected NIST SP 800-172 requirements on top of a Final Level 2 (C3PAO) certification and is assessed by DIBCAC. That’s a different planning conversation than hiring a regional MSP.
  • Your real problem is CUI sprawl, not IT operations. If shrinking your assessment scope matters more than outsourcing your helpdesk, compare CUI enclave and secure-collaboration providers first.
  • You need evidence workflow, not an operator.GRC and compliance-operations software organizes your proof; it doesn’t implement controls.
  • You’re a 500-person, multi-site, hybrid-cloud prime sub. Be honest about scale. A small firm can be excellent and still be the wrong size for that engagement — the larger national certified ESPs in the comparison table below exist for a reason.

That last bullet is the trade-off baked into everything good about this provider: the same small-firm structure that gets you senior attention is the thing to pressure-test for depth of bench, after-hours coverage, and what happens when your account manager takes a vacation. Ask. A good small firm answers that question without flinching.

If that fit profile reads like your shop

Go straight to the source — and take the six-artifact checklist from this page with you so the first call runs on your agenda, not theirs.

Reminder from our disclosure: we have no compensation relationship with ProStratus as of June 9, 2026. We earn nothing if you choose them. We just did the homework.

Request ProStratus’s CMMC readiness consultation →

What does ProStratus cost, and how long does Level 2 take?

ProStratus does not publish pricing. The company’s own framing — Level 2 compliance typically takes 6 to 18 months, at a cost running from the tens of thousands into six figures depending on size and maturity — squares with the Department of Defense’s own modeling in the CMMC Program rule (89 FR 83092): DoD estimated a small entity’s Level 2 (C3PAO) certification at $104,670 across the full three-year cycle— the triennial assessment plus two annual affirmations — and roughly $118,000 for other-than-small entities. Those figures cover certification activities only, because DoD assumes the NIST SP 800-171 implementation work was already done under DFARS 252.204-7012. A shop starting cold pays for implementation on top. Treat every quote as scope-dependent and demand line items.

Where you’re starting. A shop with DFARS 252.204-7012 obligations since 2017 that actually did the work has a short remediation list. A shop with an aspirational SPRS score has a long one.

How big your scope is. CUI flowing through the whole company costs more to protect than CUI fenced into an enclave. User count, endpoint count, sites, and cloud architecture all move the number more than any vendor’s rate card.

What “managed compliance” includes. A certified ESP’s value is recurring: monitoring, evidence upkeep, annual affirmation support. That’s a monthly line, not a one-time project — budget for it as the operating cost of holding DoD contracts.

Take this normalization sheet into every quote conversation:

Line itemWhat to confirm is actually included
Onboarding / remediationGap analysis, migration from your current MSP, identity and endpoint rebuilds
Monthly managed servicesMonitoring, patching, helpdesk hours, response-time commitments
Security toolingWho licenses the SIEM, EDR, and backup stack — and who keeps it if you leave
Documentation & evidenceSSP and POA&M ownership vs. templates-plus-guidance; evidence upkeep cadence
Assessment supportHours, named credentialed staff, presence at C3PAO interviews
OffboardingData return, evidence handover, exit cost before assessment

Any bid missing a row isn’t cheaper — it’s incomplete.

See scoped quotes from matched provider categories

The fastest way to catch a scope gap is two or three line-item quotes priced on the same basis. Tell us your level, environment, and timeline, and we’ll match you with source-checked provider options so you’re comparing like with like.

Get matched →

How does ProStratus compare with other certified CMMC MSPs?

As of June 9, 2026, the MSP Collective ESP Directory lists 49 validated CMMC Level 2 certified External Service Providers, and ProStratus sits in the middle of that field by certification date — earlier than nearly half of it. The honest comparison is not “ProStratus versus every CMMC company”; it is ProStratus versus other certified ESPs on focus, geography, and scale.

Every certification date below comes from the same validated source, checked the same day. Cert dates on provider websites are marketing; cert dates in a directory confirmed with the assessing C3PAO are evidence. Focus and fit descriptions are our editorial reads of each provider’s own materials as of June 9, 2026 — orientation, not verified scope.

ProviderL2 ESP certified
(MSP Collective, 6/9/2026)
HQFocusStrongest-fit signalComp. status
ProStratus6/18/2025Springfield, OHFull-stack regional MSP/MSSP + managed Level 2 compliance, SRM inheritance10–150-person DIB shop, one vendor for IT + compliance, Midwest/AZ onsite valueNone as of 6/9/2026
Summit 73/07/2025Huntsville, ALMicrosoft Government Cloud / GCC High specialist with a large DIB practiceM365 GCC High–committed orgs, larger subs, complex migrationsNone as of 6/9/2026
C3 Integrated Solutions3/08/2025Arlington, VAMicrosoft-cloud-focused CMMC MSPGCC High implementations, Beltway-area contractorsNone as of 6/9/2026
CorpInfoTech3/07/2025Charlotte, NCSMB-focused MSP/MSSP with CMMC practiceSmall contractors, Southeast footprintNone as of 6/9/2026
CyberSheath3/19/2025Reston, VACMMC-first managed compliance at scaleMid-tier subs that want a compliance-led (not IT-led) vendorNone as of 6/9/2026
OSIbeyond4/09/2025Rockville, MDMSP + RPO with a DC-metro GovCon client baseDC-area contractors wanting compliance-as-a-serviceNone as of 6/9/2026

No rankings, no stars. All six hold the same validated credential. The differences that should drive your choice are ecosystem, scale match, and geography.

And if the right answer isn’t an MSP at all:

If your real issue is…Compare this category instead
Shrinking CUI scope, not outsourcing ITCUI enclave / secure collaboration providers
Strategy, SSP/POA&M, and documentation onlyRPO / readiness consultants
Organizing evidence and workflowGRC / compliance-operations software (a layer, never the whole solution)
The formal certification assessmentAuthorized C3PAOs — kept separate from whoever implemented
Level 3 exposureLevel 2 (C3PAO) certification first, then DIBCAC-oriented planning

Not sure which category you actually need?

Two minutes, ten questions, and it maps your level, scope, and timeline to the provider category that fits — before you spend an hour on the wrong sales call.

Take the Find My CMMC Path quiz →

Before you sign: six artifacts and sixteen questions

A certificate proves a provider secured its own environment; these six artifacts prove it can secure yours. Before signing with ProStratus — or any CMMC MSP — obtain the Shared Responsibility Matrix, the assessed service description, the CMMC unique identifier and assessing C3PAO, named credentialed staff, a data-flow and subprocessor map, and the exit and incident-response terms. A provider that hesitates on any of the six is telling you something.

1.

The Shared Responsibility Matrix (SRM/CRM), mapped to NIST SP 800-171 Rev. 2

This is the document the entire "inherit our controls" pitch lives or dies on — requirement by requirement: provider-owned, customer-owned, or shared. The ESP directory itself tells buyers to request it.

Ask: Which of the 110 requirements do you own outright? Which stay with us? Can our future C3PAO see this matrix before we sign?

2.

The assessed service description

The C3PAO certified a specific scope of services. Your job is confirming the services you’re buying are the services that were assessed — not a sibling offering that never saw an assessor.

Ask: Which services were inside your Level 2 assessment scope? Are those exactly what’s in our proposal?

3.

The CMMC unique identifier and the assessing C3PAO’s name

Every certification carries an identifier, and the assessing C3PAO is a matter of record. A certified provider produces both in one email.

Ask: What’s your CMMC UID, when does your certificate expire, and which C3PAO assessed you?

4.

Named staff and credentials assigned to your engagement

Firm-level credential claims are decoration. Delivery happens through people.

Ask: Which CCP, CCA, or RP individuals will work our account? Will one of them attend our assessment interviews? What’s your bench if that person leaves?

5.

The data-flow and subprocessor map

The quiet scope-killer: your CUI — and the Security Protection Data around it — leaking into the provider’s ticketing system, log aggregation, backups, or a subcontractor’s tooling.

Ask: Where do our data, logs, tickets, and backups physically live? Do any of your tools or subcontractors process, store, or transmit CUI? Which cloud environments do you implement?

6.

Exit terms and incident-response responsibilities

DFARS 252.204-7012 gives you 72 hours to report a cyber incident to DoD. Know in writing who detects, who reports, and what happens to your data and evidence if you leave mid-engagement.

Ask: Who owns the 72-hour reporting workflow? What are the offboarding terms, data-return procedure, and cost if we exit before assessment?

One warning we’d rather over-state than under-state:do not paste CUI, contract numbers, technical drawings, or anything export-controlled into web forms — ours, ProStratus’s, or anyone’s. Level, scope size, environment, and timeline are all a matching process needs.

The rules and dates behind this review

CMMC is governed by two final rules: 32 CFR Part 170 (89 FR 83092), which defines the program and became effective December 16, 2024, and the DFARS acquisition rule published September 10, 2025, which became effective November 10, 2025 and put CMMC into contracts through clause 252.204-7021 and solicitation provision 252.204-7025. Phase 1 runs through November 9, 2026; Phase 2 begins November 10, 2026, when Level 2 (C3PAO) certification becomes an award condition in applicable solicitations.

Phase 2 — November 10, 2026— is roughly five months out. ProStratus’s own stated readiness range is 6 to 18 months, which means a contractor starting Level 2 from a weak posture today is already negotiating with the calendar, not just with vendors. The contractors who’ll clear Phase 2 comfortably are the ones treating June 2026 as late, not early. Take the two-minute path quiz →

How we evaluated ProStratus — and what would make this a full review

This profile is built on public-source research cross-checked against primary regulatory sources and one independent third-party validation, performed June 9, 2026. It is not a hands-on technical assessment, a customer audit, a certification outcome, or an endorsement, and The Defense Compliance Report does not represent the Cyber AB, the Department of Defense, or any U.S. government agency.

What we did:read ProStratus’s public site, CMMC program pages, and press releases; pulled and archived the MSP Collective ESP Directory listing and its validation criteria; confirmed business records (incorporation, leadership, BBB profile); cross-checked every regulatory claim against the Federal Register, acquisition.gov, the eCFR, and DoD CIO publications; searched for third-party customer evidence across Clutch, Google, Yelp, and business directories (and reported the absence honestly); and computed the directory statistics (49 providers; ProStratus 26th by certification date) ourselves from the June 9, 2026 pull.

Evidence typeUsed?
Public-source profileYes
Primary-source regulatory reviewYes
Independent directory validation (MSP Collective)Yes — June 9, 2026
Cyber AB Marketplace manual screenshotPending — RPO listing treated as company-stated until captured; re-checked monthly
Provider questionnaireNo — invitation open
Interviews / hands-on review / customer references / contract or pricing reviewNo

What would upgrade this to a full review:a completed provider questionnaire (assessed scope, SRM sample, staffing model, pricing structure), two attributable customer references we can interview, and the assessing C3PAO’s confirmation of certificate details. ProStratus — that’s an open invitation.

This page is re-verified monthly through November 2026, quarterly after. The “Last verified” date at the top changes only when we’ve actually re-checked. See our editorial standards and corrections policy. If we got something wrong, tell us — we fix it and log it.


ProStratus CMMC review: frequently asked questions

Is ProStratus legit?

On the available evidence, yes. Its CMMC Level 2 ESP certification (June 18, 2025) is independently validated in the MSP Collective ESP Directory, which confirms listings with the assessing C3PAO, and its Ohio business records since 2016 check out. Publicly available customer reviews are absent, which is why we recommend requesting two DIB references directly.

Is ProStratus CMMC Level 2 certified?

Yes, as an External Service Provider — certified June 18, 2025, per the MSP Collective ESP Directory checked June 9, 2026. Ask ProStratus for its CMMC unique identifier and the Shared Responsibility Matrix to see exactly which services that certification covers.

Is ProStratus a Cyber AB RPO?

ProStratus announced its Registered Provider Organization designation on October 15, 2025. That claim is company-stated; confirm the current listing yourself in the live Cyber AB Marketplace at cyberab.org before relying on it. We re-check it monthly.

Is ProStratus listed in the Cyber AB Marketplace?

Check it live — it takes under a minute: go to cyberab.org/Catalog, search “ProStratus,” and screenshot what you see with the date. The Marketplace is the source of truth for RPO and C3PAO listings, and because it’s a live application, the listing on the day you sign matters more than any snapshot, including ours.

Is ProStratus a C3PAO?

No — by its own statement, ProStratus does not perform C3PAO assessments. Under Cyber AB rules, the credentialed people who help you implement cannot also assess that same work, and C3PAOs must manage conflicts of interest — so readiness help and the formal assessment stay separate.

Does hiring a CMMC-certified MSP make my company certified?

No. Under 32 CFR Part 170, certification attaches to your organization’s own assessment scope. A certified MSP lets you inherit documented controls through a Shared Responsibility Matrix and spares your assessor from re-examining the provider’s environment from scratch — but the provider’s services still count toward your scope wherever they touch CUI or Security Protection Data, and compliance never transfers.

Do I still need a C3PAO if I use ProStratus?

If your solicitation requires Level 2 (C3PAO) status, yes. DFARS 252.204-7025 lets the contracting officer specify Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), or Level 3 (DIBCAC), and the required status must be posted in SPRS before award.

Does CMMC Level 2 use NIST SP 800-171 Revision 2 or Revision 3?

Revision 2 — 110 requirements assessed against 320 objectives — is the controlling version for CMMC Level 2 unless DoD amends the rule. Revision 3 exists but is not the CMMC baseline today.

What changed on November 10, 2025 — and what changes on November 10, 2026?

On November 10, 2025, the DFARS final rule took effect and Phase 1 began: CMMC self-assessment requirements at award. On November 10, 2026, Phase 2 begins: Level 2 (C3PAO) certification becomes an award condition in applicable solicitations.

Where is ProStratus located, and who runs it?

Headquarters in Springfield, Ohio, with a Columbus office and an onsite service presence in Arizona. The leadership team — CEO Tony Cooper, COO Kevin Schleinitz, and CIO Craig Terrell — has run the firm since it incorporated as an LLC in 2016.

Is ProStratus the same company as Stratus Services?

No. ProStratus, LLC (pro-stratus.com) is in Springfield, Ohio, certified 6/18/2025. Stratus Services, LLC (stratus-services.com) is in Anchorage, Alaska, certified 2/09/2026. Both appear in the same ESP directory; they are unrelated firms.

What is a Shared Responsibility Matrix?

The document that maps every applicable NIST SP 800-171 Rev. 2 requirement to who handles it — provider-owned, customer-owned, or shared. Your assessor will check it, which is why no contractor should sign with any ESP without one.

Does ProStratus guarantee CMMC certification?

No — the company states plainly that it does not guarantee certification outcomes, and no legitimate provider can. Treat any vendor’s certification guarantee as a red flag, not a feature.


Related guides

Need help deciding what type of CMMC provider you need?

Tell us your level, scope, and timeline, and we’ll match you with source-checked CMMC provider options.

Get matched with source-checked CMMC provider options →

By The Defense Compliance Report Editorial Team · Last verified: · The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification.