
CMMC Phase II Suspended: What It Means for NNPP Vendors
The Pentagon suspended CMMC Phase II on July 13, 2026. Protection requirements are unchanged. What the suspension means for contractors handling NNPI, and what it does not.
Read moreWe help nuclear organizations stay ahead of regulatory requirements—catching compliance gaps before inspectors arrive, building security programs that earn regulator confidence, and turning audit findings into operational improvements. Our approach emphasizes prevention over remediation, proactive oversight over reactive firefighting, and management accountability over individual blame.
Identify compliance gaps and vulnerabilities with comprehensive assessments against DOE and NRC requirements.
Independent audits and self-assessments to verify regulatory compliance and readiness for inspections.
Build robust security programs from the ground up for new nuclear facilities, reactors, and technologies.
Investigate incidents, identify systemic issues, and develop effective corrective action plans that prevent recurrence.
From gap analysis assessments to security program development, our former NRC and DOE leadership delivers measurable outcomes that strengthen compliance posture and reduce regulatory risk.
Comprehensive gap analysis and audit programs that identify vulnerabilities before regulators arrive and build defensible compliance documentation.
Physical Security Plans, Cyber Security Plans, and T&Q programs developed for SMR developers and advanced reactor firms navigating first-of-a-kind licensing.
Root cause analysis and corrective action programs that address systemic vulnerabilities across complex nuclear organizations.
Next-generation nuclear developers navigating NRC licensing for the first time, requiring security programs that satisfy 10 CFR Part 73 without over-engineering or unnecessary cost burdens.
Primary AudienceOur team includes former NRC and DOE leadership who understand what regulators scrutinize during inspections and audits.
We partner with your team through execution, ensuring corrective actions withstand regulatory scrutiny.
We transfer knowledge to your team, building the judgment needed to maintain compliance as programs mature.
Expert perspectives on nuclear compliance, regulatory strategy, and security program development.

The Pentagon suspended CMMC Phase II on July 13, 2026. Protection requirements are unchanged. What the suspension means for contractors handling NNPI, and what it does not.
Read more
NN-801 establishes strict cybersecurity requirements for vendors processing NNPI. Learn about protecting NNPI and getting approved to process it on your network.
Read more
Learn what the NNPICO role requires, where its authority comes from, and the common pitfalls that undermine NNPI compliance across the defense vendor base.
Read moreSchedule a consultation with our former NRC and DOE leadership team to discuss gap analysis, regulatory audits, security program development, or root cause analysis.