CMMC Partner Information
NSTXL’s CMMC Partners
Help You Get Certified
NSTXL has partnered with trusted vendors to support organizations in achieving the Cybersecurity Maturity Model Certification (CMMC) level that aligns with their specific requirements.
Whether you are just beginning your CMMC journey or preparing for a higher-level certification, NSTXL connects you with the right partner to help you navigate requirements efficiently and with confidence.
NSTXL has eliminated the November 10, 2026, deadline following the DOW’s announcement of a temporary CMMC requirements suspension. NSTXL will continue to monitor the situation and keep members informed of any updates related to CMMC requirements.

Our Partners
NSTXL offers two different vendors for CMMC compliance, depending on your specific needs. Read more about each partner below to determine which path best fits your compliance level needs. If you’d like more information, or aren’t sure which to choose, reach out to us at membership@nstxl.org.
Beskar
NSTXL’s partnership with Beskar Inc enhances support for organizations pursuing CMMC compliance by providing secure, CMMC Level 1 and 2–aligned infrastructure and expert cybersecurity services, helping streamline the path to audit readiness.
Beskar is a great option if you need:
- CMMC Gap and Readiness Assessments, Documentation and Training Development, and Mock C3PAO Assessments.
- CMMC Level 1 or 2–compliant secure virtual desktop environments designed to support protected workloads.
- All-in-One CUI Protection: Work within a secure, zero-trust desktop with protection managed behind the scenes, plus built-in templates and training to maintain compliance.
- 96% Compliance on Day One: Beskar handles nearly all CMMC requirements, so you can focus on running your business while they secure your information.
Flexible and Scalable: From one employee to hundreds, Beskar can scale as your information protection needs grow. Your per-user cost stays the same, keeping your costs predictable. Your success is our success, and they’re here to help you achieve your best.
Penacity
NSTXL has partnered with Penacity, an authorized Third-Party Assessment Organization (C3PAO) accredited by the CyberAB, offering both assessment services and a purpose-built solution to simplify CMMC Level 2 compliance.
Penacity is a great option if you need:
- A more streamlined and predictable path to CMMC compliance including:
- GAP Analysis
- Implementation
- CMMC L1 Attestation
- Full C3PAO CMMC L2 Assessment Services to obtain your Certification
- A secure, isolated environment addressing up to 95 of the 110 CMMC L2 controls for handling Controlled Unclassified Information (CUI), already implemented and managed in (Penacity High-Assessed Secure Environment (PHASE)).
Their enclave significantly reduces the cost, complexity, and internal effort typically associated with achieving certification, especially for niche industries with special requirements like manufacturing, logistics, high end development, and construction.
Certification Levels and Requirements
Certification requirements vary by level, but all come directly from the Department of War and will be phased into contracts over the next several years.

Level 1 Requirements (Foundational)
Requires organizations to implement 17 basic cyber hygiene practices derived from FAR 52.204-21. Certification can be achieved through a self-assessment submitted annually through the Supplier Performance Risk System (SPRS).
Level 2 Requirements (Advanced)
Aligned with the 110 security controls within NIST SP 800-171 Revision 2. Some contracts will allow for Level 2 self-assessments, but most will require an independent evaluation conducted by a Certified Third-Party Assessment Organization (C3PAO).
Level 3 Requirements (Expert)
Aligned with the 110 security controls in NIST SP 800-171 Revision 2, along with an additional 24 controls outlined in NIST SP 800-172. Requires a government-led assessment every three years by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).



