Is Peraton CMMC and FedRAMP Compliant? How to Verify Any Prime

No public database lists any contractor's CMMC status or NIST SP 800-171 score — DFARS 252.204-7020(f) keeps both between DoD and the assessed company. What to request instead, which clause obliges them to have it, and how the flowdown duty runs back toward you.

Cabrillo Club

Cabrillo Club

Editorial Team · March 21, 2026 · Updated Jul 27, 2026 · 3 min read

Share:LinkedInX
Infographic for Is Peraton CMMC and FedRAMP Compliant? 2026 Status

CMMC program update — July 13, 2026

The Department of War has suspended CMMC Phase 2 requirements pending a 60-day program review. Phase 1 self-assessments, SPRS scores, and DFARS 252.204-7012 safeguarding obligations remain fully in force. Certification dates and third-party assessment requirements referenced in this article may change when the review concludes. Read the DoW release

Is Peraton CMMC and FedRAMP Compliant? How to Verify Any Prime

If you are here, you are probably about to team with, subcontract to, or subcontract under a large defense prime, and someone has asked you to confirm their cybersecurity compliance posture. This page will not give you a verdict on Peraton or any other named company, because no source outside DoD and that company is in a position to issue one. What it gives you is the thing that actually closes your diligence: what the regulations require the other party to have, what you are entitled to ask for, and how to read the answer.

The short answer: there is no public record to check

There is no public register of CMMC statuses, and no public register of NIST SP 800-171 scores. Summary-level assessment scores posted in the Supplier Performance Risk System (SPRS) are available to DoD personnel, and to authorized representatives of the contractor that was assessed — and to nobody else. That rule is printed in the clause itself, at DFARS 252.204-7020(f)(1)-(2). Any page that appears to publish another company's score is inferring it, and an inference is not diligence.

What the clauses actually require of a prime handling CUI

Three obligations are worth knowing before you send a single email, because each one creates an artifact you can ask for. Under DFARS 252.204-7021(d), a contractor must have and maintain a current CMMC status at the level written into the contract for every information system that processes, stores, or transmits FCI or CUI, and must complete an annual affirmation of continuous compliance in SPRS. Under DFARS 252.204-7019(b), an offeror must already have a current assessment — not more than three years old — for each covered system relevant to the offer. And under DFARS 252.204-7012(b)(2)(ii)(D), if covered defense information goes to an external cloud service provider, that provider must meet security requirements equivalent to the FedRAMP Moderate baseline. Note the word: equivalent, not authorized.

Which direction the diligence actually runs

The clause burden sits on whoever awards the subcontract. Before awarding a subcontract that will process, store, or transmit FCI or CUI, the awarding party must ensure the subcontractor holds a current CMMC status at the level appropriate to what is being flowed down (DFARS 252.204-7021(f)(2), applying the flowdown rules at 32 CFR 170.23). Separately, a subcontract subject to NIST SP 800-171 implementation may not be awarded unless the subcontractor has completed at least a Basic Assessment within the last three years (DFARS 252.204-7020(g)(2)). In practice this means the smaller party is the one being assessed. If you are vetting a large prime as a prospective teammate, expect the same questions to come back at you, in writing, before award.

FedRAMP: what a Marketplace listing does and does not mean

FedRAMP authorizes cloud service offerings, not companies. The FedRAMP Marketplace is the authoritative list and it is searchable by product name. A systems integrator that deploys inside a customer's already-authorized boundary will not have a listing of its own, and that absence is not a compliance finding — but it does mean the authorization being relied on belongs to somebody else, and you should find out whose. The question that resolves this is not "are you FedRAMP authorized?" but "which cloud service offering will my data reside in, and is it authorized or asserted as FedRAMP Moderate equivalent?"

What this page will not tell you

It will not tell you whether Peraton — or any other named contractor — is compliant, holds a particular CMMC level, or is better or worse prepared than its peers. Earlier versions of this page did make claims of that kind. They were not traceable to any primary source, they were not knowable from outside the company, and they have been removed. A compliance claim about a third party that you cannot cite is not information; it is a liability you would be forwarding to a contracts officer.

How to verify: 11 steps, each with the clause behind it

The checklist below is the working method. Each step states an obligation printed in a regulation, links the clause or CFR section it comes from, and names the specific artifact to request — a CMMC Unique Identifier, a status date and an affirmation date, the SPRS assessment fields, the cloud service offering your data will actually live in. Work it top to bottom and you will end with answers you can put in a subcontract, which is the only place they are worth anything.

Due-diligence checklist

11 steps to verify a prime or teaming partner

Every step below states an obligation printed in a regulation and links the clause it comes from. Nothing here relies on our opinion of anyone — because outside DoD and the assessed contractor, nobody has a lookup for this.

  1. Start from what is not public — which is almost all of it

    There is no public database of CMMC statuses or NIST SP 800-171 scores. Summary-level assessment scores posted in SPRS are available to DoD personnel, and to authorized representatives of the contractor that was assessed — nobody else. Any site that claims to publish another company’s score is inferring it.

    What to ask for: Nothing yet. This step is the one that saves you a week: stop searching for a lookup that does not exist and move to a written request.

  2. Check which direction the diligence actually runs

    The clause obligation is on the buyer of the subcontract. Before awarding a subcontract or other contractual instrument that will process, store, or transmit FCI or CUI, the prime must ensure the subcontractor holds a current CMMC status at the level appropriate to what is being flowed down. If you are the smaller party, you are the one about to be assessed.

    What to ask for: Ask which CMMC level they intend to flow down to your scope of work, and on what basis they selected it.

  3. Ask for the CMMC UID, level, and whether the status is Conditional or Final

    SPRS issues a CMMC Unique Identifier for each assessed information system. The contractor reports those UIDs to the Contracting Officer — which means the UID exists, is specific, and can be named in writing. "We are CMMC compliant" is not an answer; a UID, a level, and a Conditional-or-Final status is.

    What to ask for: Ask for the CMMC UID(s), the assessment level (Level 1 Self, Level 2 Self, Level 2 C3PAO, or Level 3 DIBCAC), and whether each status is Conditional or Final.

  4. Date-check the status against the clause’s own definition of "current"

    The clause defines "current" by level, and the windows are not the same. Conditional Level 2 statuses go stale at 180 days. Final Level 1 (Self) is one year. Final Level 2 (Self or C3PAO) and Final Level 3 (DIBCAC) run three years — but each also requires an affirmation of continuous compliance no older than one year. A three-year-old certificate with no current affirmation does not meet the clause.

    What to ask for: Ask for the status date and the date of the most recent annual affirmation, separately. Two dates, not one.

  5. Confirm the status covers the systems that will actually touch your data

    CMMC status attaches to information systems, identified per CMMC UID — not to a company as a whole. The requirement is that FCI and CUI are only processed, stored, or transmitted on systems that carry the required status. A corporate enclave that was assessed tells you nothing about the program enclave your data will land in.

    What to ask for: Ask which CMMC UID covers the environment your data will be handled in, and get the boundary described in a sentence you can put in the subcontract.

  6. Ask for the SPRS assessment fields, not a compliance letter

    An offeror must have a current NIST SP 800-171 assessment — not more than three years old — posted in SPRS at the time of offer. The record itself has a known shape: the standard assessed, the organization that conducted it, every CAGE code covered by the system security plan, the date and level, the summary-level score, and the date by which all requirements are expected to be implemented. Ask for those fields by name and a vague answer becomes visible immediately.

    What to ask for: Ask for: standard assessed, assessing organization, CAGE codes covered, assessment date and level, summary-level score, and expected full-implementation date.

  7. If they will be your subcontractor, treat the three-year Basic Assessment as a hard gate

    You may not award a subcontract subject to NIST SP 800-171 implementation unless the subcontractor has completed at least a Basic Assessment within the last three years for the covered systems relevant to its offer. If they have no current score in SPRS, the clause tells them exactly what to do — conduct a Basic Assessment and submit it for posting — so "we are working on it" has a defined next action, and a date.

    What to ask for: Ask for the SPRS posting date. If there is none, ask when the Basic Assessment will be submitted for posting.

  8. If they claim a certification, verify the assessor — not just the certificate

    A Level 2 certification assessment has to be performed by an authorized CMMC Third-Party Assessment Organization. The accreditation body publishes which organizations hold that authorization, so the assessor named on a certificate is checkable even when the certificate itself is not.

    What to ask for: Ask which C3PAO performed the assessment, then confirm that organization is listed as authorized.

  9. Check FedRAMP by exact product name — and know what absence means

    FedRAMP authorizes cloud service offerings, not companies. The Marketplace is the authoritative list and it is searchable by product name. A systems integrator that builds inside a customer’s authorized boundary will not appear there, and that absence is not a deficiency — but it does mean the authorization being relied on belongs to somebody else, so find out whose. Note the actual standard in the clause: where covered defense information goes to an external cloud service provider, that provider must meet security requirements *equivalent to* the FedRAMP Moderate baseline. Equivalency is the bar, not a Marketplace listing — which is exactly why the listing alone neither convicts nor clears anyone.

    What to ask for: Ask which cloud service offering your data will actually reside in, whether it is FedRAMP authorized or asserted as FedRAMP Moderate equivalent, and on what evidence. If it is authorized, get the package ID and look it up yourself.

  10. Run the one check that is genuinely public: SAM.gov

    Entity registration, CAGE code, and active exclusions are public and free. This will not tell you anything about cybersecurity posture, and it is the only step on this list you can complete without asking the company a question — which is precisely why it is worth doing first and why it is not sufficient on its own.

    What to ask for: Confirm active registration, the CAGE code(s) they gave you, and that there are no active exclusions.

  11. Move the answers out of the email thread and into the subcontract

    Both clauses require their substance to be inserted into subcontracts that carry the underlying requirement, and 7021 additionally requires that subcontractors complete an affirmation of continuous compliance prior to subcontract award and annually thereafter. A representation that lives only in a sales email is a representation you cannot enforce and cannot show an auditor.

    What to ask for: Get the CMMC level, the CMMC UID or SPRS score with its date, and the annual affirmation obligation written into the subcontract terms.

The same questions are about to come back at you

Vendor due diligence points back at you the moment you award the work. DFARS 252.204-7020(g)(2) says you may not award a subcontract subject to NIST SP 800-171 unless that subcontractor has a Basic Assessment less than three years old — and it flows the clause down with it. Book a 25-minute flowdown review and leave with your SPRS score, your CMMC scope boundary, and the answers written down before someone asks for them.

Book a 25-min flowdown review

Related: how much CMMC certification costs — DoD’s own priced figures

Cabrillo Club

Cabrillo Club

Editorial Team

Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.

Related Articles