Trust & credentials
Status, not badges.
Every credential we claim, with what it actually means today, the evidence behind it, and what happens next. Where a status is “self-assessed” or “in progress”, it says so in the table, not in a tooltip.
Last verified 2026-09-16. Statuses change by pull request to this page.
| Credential | Status | What it means | Evidence | Next |
|---|---|---|---|---|
| SDVOSB (Service-Disabled Veteran-Owned Small Business) | Held | Verified through SBA VetCert. Eligible to prime SDVOSB set-asides under FAR Part 19. | SAM.gov entity record; SBA SDVOSB database. | Annual recertification. |
| CMMC 2.0 Level 2 | Self-assessed | All 110 NIST SP 800-171 Rev 2 controls implemented on our own CUI enclave and scored on evidence that flows automatically each week. SPRS score posted. No C3PAO assessment has been performed. | SPRS entry; Trust Codex objective-coverage export (320 objectives); weekly signed ISSO reviews since 2026-08-19. | Third-party assessment when Phase II resumes. The Department suspended C3PAO and DIBCAC designations on 13 Jul 2026 and made the suspension binding on contracting officers by class deviation on 3 Sep 2026. Until then no vendor can hold a new third-party CMMC certification. |
| CMMC 2.0 Level 2 third-party certification (C3PAO) | Not available | Cannot be obtained by any organization while the Phase II suspension stands. | Class deviation, 3 Sep 2026; CMMC Reform Task Force review. | Assessment scheduled within one quarter of designations reopening. |
| FIPS 140-3 validated cryptography (Deployable CUI Vault) | Held | Ubuntu 22.04 OpenSSL Cryptographic Module, NIST CMVP Certificate #4794, Level 1. The managed vault runs Windows Server 2025 with FIPS mode; see the limits note below. | CMVP certificate #4794 on the NIST module list. | Track the certificate sunset date on the CMVP list; the Windows Server 2025 build has no CMVP certificate of its own yet (control 3.13.11 is on our own POA&M for that reason). |
| ISO/IEC 27001:2022 | In progress | Readiness underway. The ISMS documents are the same 64-document canon our CMMC program runs on; the Annex A gap list is being built as a crosswalk in Trust Codex. | Controlled documents in the Quality system; crosswalk (in build). | Stage 1 audit targeted Q1 2027. |
| SOC 2 Type I | In progress | Internal readiness completed for control design. No independent examination yet. Scope: Trust Codex and Proofline as the systems. | Internal readiness workpapers. | Auditor engaged Q4 2026; report targeted Q1 2027. |
| Cyber AB Registered Provider Organization (RPO) | Applying | Registration puts MacTech in the Cyber AB marketplace as a provider that has agreed to its code of professional conduct. | - | Application Q4 2026. |
| Microsoft partner competency (Security) | Applying | The managed vault is Azure and Entra ID; a designation makes that a verifiable claim rather than a description. | - | Application Q4 2026. |
| FedRAMP Moderate | Not available | Our control design is aligned to the Moderate baseline. MacTech holds no FedRAMP authorization and none is implied. | Design documentation on request. | Not pursued; the managed vault inherits from Azure, not from a MacTech authorization. |
Credibility roadmap
- Q4 2026SOC 2 Type I auditor engaged. Cyber AB RPO and Microsoft Security partner applications filed. ISO 27001 Annex A gap list published from the Trust Codex crosswalk.
- Q1 2027SOC 2 Type I report. ISO 27001 Stage 1 audit.
- Q2 2027ISO 27001 Stage 2 and certificate. GSA MAS / HACS onboarding.
- When openCMMC Level 2 C3PAO assessment within one quarter of Phase II designations reopening.
Boundary statements
- Trust Codex stores no CUI. It holds control state, objective verdicts, POA&Ms, the SSP and evidence metadata (run id, path, SHA-256). Evidence routes refuse file uploads.
- EnclaveWatch exports no raw logs. Metadata, counts and hashes leave the vault; two validators reject anything else before a bundle is sent. The full list of what does leave is on the EnclaveWatch page.
- The managed vault runs on Azure. Controls it inherits from Microsoft and controls it carries for you are published per control in the responsibility matrix.
- We publish our own posture. Our enclave's measured SPRS trajectory and remediation record are on the proof page.
Questions buyers ask
- Is MacTech CMMC certified?
- MacTech is CMMC Level 2 self-assessed against all 110 NIST SP 800-171 Rev 2 controls, with an SPRS score posted and weekly signed evidence reviews. No C3PAO assessment has been performed. Since 13 July 2026 the Department has suspended new Level 2 third-party and Level 3 government assessments, so no vendor can newly obtain one until Phase II resumes.
- What is still required while CMMC Phase II is suspended?
- DFARS 252.204-7012, NIST SP 800-171 Rev 2 implementation, a current SPRS score, CMMC Level 1 and Level 2 self-assessments where a contract calls for them, and the annual affirmation. Only the third-party assessment requirement is paused.
- Does Trust Codex store CUI?
- No. Trust Codex holds compliance state - control status, assessment-objective verdicts, POA&Ms, the SSP and evidence metadata (run id, path, SHA-256). Evidence files stay inside the customer enclave. The API refuses file uploads on evidence routes.