# Gigit Security > Gigit Security provides penetration testing, compliance readiness, AI security, cloud engineering, and fractional security leadership for defense, space, and commercial organizations. Gigit Security provides readiness services only and is not an authorized C3PAO. Engagements are led by Certified CMMC Professionals and Certified CMMC Assessors. ## Current regulatory position CMMC Phase 2 is suspended as of July 13, 2026. The Department of War suspended CMMC Phase 2, the third-party certification requirement scheduled for November 10, 2026, along with pending and future implementation milestones, and opened a 60-day program review. Still in force: Phase 1 Level 1 and Level 2 self-assessment requirements remain in force. DFARS 252.204-7012 safeguarding obligations are unchanged. NIST SP 800-171 Revision 2 remains the contractual baseline for protecting CUI. SPRS score submission and annual affirmations continue. False Claims Act exposure for misrepresenting compliance is unaffected. CMMC Level 2 is assessed against NIST SP 800-171 Revision 2: 110 controls and 320 objectives. ## Government - [CMMC Readiness](https://gigitsecurity.com/cmmc) - [FedRAMP](https://gigitsecurity.com/fedramp) - [NIST SP 800-53](https://gigitsecurity.com/nist-800-53) - [Latest Updates](https://gigitsecurity.com/updates) ## Commercial - [Compliance Readiness](https://gigitsecurity.com/compliance) - [ISO 27001](https://gigitsecurity.com/iso-27001) - [SOC 2](https://gigitsecurity.com/soc-2) - [PCI DSS](https://gigitsecurity.com/pci-dss) - [HIPAA & HITRUST](https://gigitsecurity.com/hipaa-hitrust) - [NIST CSF](https://gigitsecurity.com/nist-csf) ## Cybersecurity - [Penetration Testing](https://gigitsecurity.com/penetration-testing) - [Application Security](https://gigitsecurity.com/application-security) - [Vulnerability Assessment](https://gigitsecurity.com/vulnerability-assessment) - [Risk Management](https://gigitsecurity.com/risk-management) - [Security Architecture Review](https://gigitsecurity.com/security-architecture-review) - [Agentic & MCP AI](https://gigitsecurity.com/ai-security) ## Cloud & IT - [Microsoft 365](https://gigitsecurity.com/microsoft-365) - [AWS](https://gigitsecurity.com/aws) - [Cloud Architecture Assessment](https://gigitsecurity.com/cloud-architecture-assessment) - [vCISO & Embedded Experts](https://gigitsecurity.com/vciso) - [Managed Services](https://gigitsecurity.com/managed-services) - [IT Services](https://gigitsecurity.com/it-services) ## Company - [About](https://gigitsecurity.com/about) - [Contact](https://gigitsecurity.com/contact) - [Privacy Policy](https://gigitsecurity.com/privacy) ## Latest updates - [CMMC Phase 2 suspended: what still applies](https://gigitsecurity.com/updates/cmmc-phase-2-suspended), 2026-07-14: The Department of War suspended CMMC Phase 2 on July 13, 2026. Phase 1 self-assessments, DFARS 7012, and SPRS obligations remain in force. ## Contact - Phone: (707) 350-9900 - Email: hello@gigitsecurity.com - Address: 4770 Baseline Rd. Suite 200, Boulder, CO 80303