Trust & credentials

Status, not badges.

Every credential we claim, with what it actually means today, the evidence behind it, and what happens next. Where a status is “self-assessed” or “in progress”, it says so in the table, not in a tooltip.

Last verified 2026-09-16. Statuses change by pull request to this page.

CredentialStatusWhat it meansEvidenceNext
SDVOSB (Service-Disabled Veteran-Owned Small Business)HeldVerified through SBA VetCert. Eligible to prime SDVOSB set-asides under FAR Part 19.SAM.gov entity record; SBA SDVOSB database.Annual recertification.
CMMC 2.0 Level 2Self-assessedAll 110 NIST SP 800-171 Rev 2 controls implemented on our own CUI enclave and scored on evidence that flows automatically each week. SPRS score posted. No C3PAO assessment has been performed.SPRS entry; Trust Codex objective-coverage export (320 objectives); weekly signed ISSO reviews since 2026-08-19.Third-party assessment when Phase II resumes. The Department suspended C3PAO and DIBCAC designations on 13 Jul 2026 and made the suspension binding on contracting officers by class deviation on 3 Sep 2026. Until then no vendor can hold a new third-party CMMC certification.
CMMC 2.0 Level 2 third-party certification (C3PAO)Not availableCannot be obtained by any organization while the Phase II suspension stands.Class deviation, 3 Sep 2026; CMMC Reform Task Force review.Assessment scheduled within one quarter of designations reopening.
FIPS 140-3 validated cryptography (Deployable CUI Vault)HeldUbuntu 22.04 OpenSSL Cryptographic Module, NIST CMVP Certificate #4794, Level 1. The managed vault runs Windows Server 2025 with FIPS mode; see the limits note below.CMVP certificate #4794 on the NIST module list.Track the certificate sunset date on the CMVP list; the Windows Server 2025 build has no CMVP certificate of its own yet (control 3.13.11 is on our own POA&M for that reason).
ISO/IEC 27001:2022In progressReadiness underway. The ISMS documents are the same 64-document canon our CMMC program runs on; the Annex A gap list is being built as a crosswalk in Trust Codex.Controlled documents in the Quality system; crosswalk (in build).Stage 1 audit targeted Q1 2027.
SOC 2 Type IIn progressInternal readiness completed for control design. No independent examination yet. Scope: Trust Codex and Proofline as the systems.Internal readiness workpapers.Auditor engaged Q4 2026; report targeted Q1 2027.
Cyber AB Registered Provider Organization (RPO)ApplyingRegistration puts MacTech in the Cyber AB marketplace as a provider that has agreed to its code of professional conduct.-Application Q4 2026.
Microsoft partner competency (Security)ApplyingThe managed vault is Azure and Entra ID; a designation makes that a verifiable claim rather than a description.-Application Q4 2026.
FedRAMP ModerateNot availableOur control design is aligned to the Moderate baseline. MacTech holds no FedRAMP authorization and none is implied.Design documentation on request.Not pursued; the managed vault inherits from Azure, not from a MacTech authorization.

Credibility roadmap

  1. Q4 2026SOC 2 Type I auditor engaged. Cyber AB RPO and Microsoft Security partner applications filed. ISO 27001 Annex A gap list published from the Trust Codex crosswalk.
  2. Q1 2027SOC 2 Type I report. ISO 27001 Stage 1 audit.
  3. Q2 2027ISO 27001 Stage 2 and certificate. GSA MAS / HACS onboarding.
  4. When openCMMC Level 2 C3PAO assessment within one quarter of Phase II designations reopening.

Boundary statements

  • Trust Codex stores no CUI. It holds control state, objective verdicts, POA&Ms, the SSP and evidence metadata (run id, path, SHA-256). Evidence routes refuse file uploads.
  • EnclaveWatch exports no raw logs. Metadata, counts and hashes leave the vault; two validators reject anything else before a bundle is sent. The full list of what does leave is on the EnclaveWatch page.
  • The managed vault runs on Azure. Controls it inherits from Microsoft and controls it carries for you are published per control in the responsibility matrix.
  • We publish our own posture. Our enclave's measured SPRS trajectory and remediation record are on the proof page.

Questions buyers ask

Is MacTech CMMC certified?
MacTech is CMMC Level 2 self-assessed against all 110 NIST SP 800-171 Rev 2 controls, with an SPRS score posted and weekly signed evidence reviews. No C3PAO assessment has been performed. Since 13 July 2026 the Department has suspended new Level 2 third-party and Level 3 government assessments, so no vendor can newly obtain one until Phase II resumes.
What is still required while CMMC Phase II is suspended?
DFARS 252.204-7012, NIST SP 800-171 Rev 2 implementation, a current SPRS score, CMMC Level 1 and Level 2 self-assessments where a contract calls for them, and the annual affirmation. Only the third-party assessment requirement is paused.
Does Trust Codex store CUI?
No. Trust Codex holds compliance state - control status, assessment-objective verdicts, POA&Ms, the SSP and evidence metadata (run id, path, SHA-256). Evidence files stay inside the customer enclave. The API refuses file uploads on evidence routes.