Interweave Technologies
Sep 25

When Will CMMC 2.0 Be Required for DoD Contracts and Why It Matters

CMMC 2.0 is already required for Department of Defense contracts through self-assessment. Since November 10, 2025, contracting officers have been able to make CMMC Level 1 and Level 2 self-assessments a condition of award, and many solicitations now carry that requirement.

Third-party certification is a different story. The Department suspended CMMC Phase II on July 13, 2026, which removed the requirement for an accredited assessor to certify most contractors handling controlled unclassified information. Under current regulation, the date the CMMC clause attaches automatically to any applicable contract is November 10, 2028.

That date comes from DARS Class Deviation 2026-O0025, Revision 3, issued September 3, 2026, which wrote the suspension directly into the DFARS text. Below we cover the full timeline with each milestone's current status, what the self-assessment path requires, who falls in scope, how the requirement is enforced today, the cloud and encryption questions that determine your evidence, what preparation costs in time and money, where the industry actually stands, and what to do between now and the next date.

When Will CMMC 2.0 Be Required for DoD Contracts?

CMMC 2.0 is required for DoD contracts now at Level 1 and Level 2 through self-assessment, and it becomes an automatic requirement on every applicable contract on November 10, 2028. Between those two points sits a review that could change the middle of the schedule but has not changed either end of it.

Three separate questions get collapsed into one when people ask about timing, and separating them removes most of the confusion. Whether CMMC applies to you is settled and has been since Phase 1. How your compliance gets verified is what changed in July 2026. When the clause attaches without a program office specifically asking for it is the November 2028 date. Contractors tracking the current CMMC requirements need all three answers, because a plan built on only one of them will be wrong.

Is CMMC Required for DoD Contracts?

Yes, CMMC is required for DoD contracts where the solicitation includes a CMMC level and the contractor processes, stores, or transmits Federal Contract Information or Controlled Unclassified Information. Contracts exclusively for commercially available off-the-shelf items are exempt.

The requirement reaches you through the solicitation rather than through a general deadline. A program office decides the contract involves covered information, the clause goes in, and meeting the stated level becomes a condition of award. That mechanism has been operating since November 10, 2025 and continues to operate today.

Is CMMC Level 2 Still Suspended?

CMMC Level 2 is not suspended. What is suspended is the third-party certification requirement for Level 2, which would have made an assessment by an accredited CMMC Third-Party Assessment Organization a condition of award starting November 10, 2026.

Level 2 itself, meaning the 110 security requirements drawn from NIST SP 800-171 Rev 2, applies exactly as it did before. Contracting officers can still designate Level 2 in a solicitation, and contractors still have to meet it. The difference is that they now demonstrate it themselves rather than through an outside assessor.

Is CMMC Cancelled?

No, CMMC is not cancelled. The program rule at 32 CFR Part 170 was not repealed, the DFARS acquisition rule was not withdrawn, and the clause remains in the regulation with a date attached to it. A suspension pauses one mechanism; it does not remove a program.

Department officials have been direct about the distinction. The stated purpose of the review is reducing compliance cost and administrative burden for small, medium, and nontraditional businesses while holding the security baseline in place. Removing a verification gate is not the same as lowering a standard, and the underlying obligations confirm that reading.

The Current CMMC Implementation Timeline

The CMMC implementation timeline now has three live milestones and three suspended ones. The table below draws its dates from the program rule at 32 CFR Part 170, the DFARS acquisition rule under DFARS Case 2019-D041, the Department of War CIO memoranda of July 13, 2026, and DARS Class Deviation 2026-O0025, Revision 3.

DateWhat It Did or Would Have DoneCurrent StatusOctober 15, 2024CMMC program rule published at 32 CFR Part 170, defining levels, scoring, and assessment proceduresIn force, effective December 16, 2024September 10, 2025DFARS acquisition rule published, putting CMMC into contract languageIn forceNovember 10, 2025Phase 1 began; Level 1 and Level 2 self-assessments became a condition of award on applicable new contractsIn forceJuly 13, 2026Two CIO memoranda suspended Phase II and established the CMMC Reform Task ForceIn effectSeptember 3, 2026Class Deviation Revision 3 wrote the suspension into DFARS Part 240 and set the automatic-application dateIn effectNovember 10, 2026Phase 2 would have made third-party certification a condition of award for most CUI contractsSuspendedNovember 10, 2027Phase 3 would have extended certification to existing contracts and added Level 3SuspendedNovember 10, 2028The CMMC clause applies automatically to any applicable contract involving FCI or CUIIn the deviation text

The last row is the one that answers the question in the title, and it is also the row most published guidance still gets wrong. Articles written before September 3, 2026 do not have it, and articles written before July 13, 2026 still present November 10, 2026 as a live deadline. Anyone reviewing a CMMC certification plan built on an older timeline should date-check every milestone in it.

What Is DARS Class Deviation 2026-O0025?

DARS Class Deviation 2026-O0025 is the instrument the Department of War uses to implement the CMMC Phase II suspension inside contract regulation, and Revision 3 of it was issued September 3, 2026, superseding Revision 2. A class deviation directs contracting officers to depart from standard DFARS text in a defined way, which is how a policy decision becomes something a contracting officer must actually do.

Revision 3 does three things. It directs contracting officers to work with requiring activities to remove or revise CMMC requirements in new and existing solicitations and contracts, in line with the July 13 CIO memorandum. It permits CMMC Level 1 and Level 2 to be satisfied as self-assessments in procurement documents while requiring baseline compliance with NIST SP 800-171 Rev 2 under DFARS clause 252.204-7012. And it sets two separate bases for when the CMMC clause gets inserted into a contract at all.

Those two bases matter more than the headline. Until November 9, 2028, the clause goes in only when a program office or requiring activity specifically decides a contractor needs a stated CMMC level. From November 10, 2028, it applies to any applicable contract involving FCI or CUI on a contractor information system, without anyone having to ask for it. The first basis is selective and the second is universal, and planning against the wrong one produces a very different budget.

What Did the CMMC Reform Task Force Recommend?

The CMMC Reform Task Force has not published its recommendations as of this writing. The task force was given 60 days from the July 13, 2026 memorandum, which placed the close of its review around September 11, 2026, with recommendations reaching the Chief Information Officer shortly after and a public report expected between late September and early October.

Whatever the report says, it changes nothing by itself. A task force report is advice. Three instruments change what a contract actually requires: a new class deviation, a DFARS rule change, or an amendment to 32 CFR Part 170. Watching for one of those three is a more reliable signal than watching the headlines that accompany the report. Industry responses to the public request for information, which closed August 14, 2026, asked for clearer definition of covered information categories, flowdown limited to contracts genuinely involving it, and a graduated path between Level 1 and Level 2.

Can You Self Assess CMMC Level 2?

Yes, you can self assess CMMC Level 2, and under the current class deviation it is the path contracting officers are directed to use. Level 2 has always had two routes, a self-assessment and a certification assessment, and the suspension leaves only the first available for new solicitations.

Self-assessment is the same work with a different auditor. You evaluate your environment against all 110 requirements, score each one as met or not met using the scoring methodology in the program rule, post the result to the government's Supplier Performance Risk System, and have a senior official affirm compliance annually. Nothing about the standard changes because you are the one applying it. Building government contract compliance on a self-assessment means holding yourself to the evidence standard an outside assessor would have applied.

The document that carries the most weight in that exercise is the one people leave until last. A current system security plan describing your actual environment is a prerequisite, and it is one of the requirements that cannot sit on a plan of action under any circumstances.

What Is a Passing Score for CMMC Level 2?

A passing score for CMMC Level 2 is 110 of 110 for a final status, and at least 88 of 110 for a conditional status with a plan of action. The threshold appears at 32 CFR 170.21(a)(2)(i), which requires the assessment score divided by the total number of Level 2 requirements to be 0.8 or higher.

The number counts points rather than requirements met. Each of the 110 requirements carries a weight of 1, 3, or 5 points, and you subtract the weight of every requirement scored not met from a starting total of 110. Missing a few heavily weighted requirements drops you below 88 while the majority of the list still reads as met, which is why a count of checkboxes gives false comfort.

How Often Is a CMMC Level 2 Assessment Required?

A CMMC Level 2 assessment is required every three years, with an annual affirmation of continuous compliance filed in the intervening years. Level 1 is different and requires a fresh self-assessment plus affirmation every year.

Three years is the maximum age, not a guarantee of validity. A self-assessment stops reflecting reality the moment the environment changes materially, and the affirmation you sign in year two states that the posture still holds. Treating the assessment as a triennial event rather than an ongoing obligation is how a score drifts away from the environment it describes.

Who Needs CMMC Level 2 Compliance?

Any contractor or subcontractor that processes, stores, or transmits Controlled Unclassified Information on its information system under a Department of Defense contract needs CMMC Level 2 compliance. Company size does not matter, and there is no small business exemption.

Data type determines the level, not organizational scale. A two-person engineering firm holding a controlled technical drawing sits at Level 2. A large distributor handling only purchase orders and delivery schedules sits at Level 1, because that material is Federal Contract Information rather than CUI. Common CUI in a defense supply chain includes technical drawings and blueprints, engineering schematics, maintenance manuals, and proprietary data supplied by the government, and older documents marked "For Official Use Only" frequently qualify. Firms pursuing manufacturing compliance alongside defense work usually find the CUI inventory larger than expected once drawings are included.

What Is the Difference Between CMMC 2.0 Level 2 and Level 3?

The difference between CMMC 2.0 Level 2 and Level 3 is 24 additional security requirements and who performs the assessment. Level 2 covers the 110 requirements in NIST SP 800-171 Rev 2. Level 3 requires all of Level 2 plus 24 selected enhanced requirements drawn from NIST SP 800-172, with Department-approved parameters.

Assessment differs as sharply as the requirement count. Level 2 is self-assessed or certified by an accredited third party. Level 3 is assessed by the government directly, through the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center, and a final Level 2 certification is a prerequisite before a Level 3 assessment can even begin.

Who Will Need CMMC Level 3?

Contractors will need CMMC Level 3 when they handle CUI tied to the most sensitive programs, specifically information associated with breakthrough or advanced technology, a significant aggregation of CUI in one environment, or a system where a single compromise would create widespread vulnerability across the Department.

The population is small by design. Most of the defense industrial base sits at Level 1 or Level 2, and Level 3 was built for a narrow tier of programs where an advanced persistent threat is the realistic adversary. Level 3 requirements were suspended alongside Phase 2, so no new contract is currently carrying a Level 3 designation.

Is DoD Enforcing CMMC for Defense Tech Vendors?

Yes, DoD is enforcing CMMC for defense tech vendors, and the suspension changed the verification mechanism rather than the enforcement. Enforcement now runs through the accuracy of what you self-report and through the government's own assessments.

Class Deviation Revision 3 gave contracting officers three specific checkpoints. They must verify your status in the supplier system before award, before exercising an option, and before extending a period of performance, and they must withhold all three where the status has lapsed. A score that goes stale in the middle of a contract can block a renewal as easily as it can block a new bid, which makes currency an operational matter rather than a bidding matter.

The government also retains full authority to conduct its own medium and high NIST SP 800-171 assessments regardless of what a contractor has self-attested. Where a government-led assessment finds a materially different posture from the posted score, the gap between the two becomes the evidence, and a score submitted to the government is a representation carrying False Claims Act exposure. Survey data suggests the gap is widespread: a 2026 Kiteworks study of 273 defense contractors found 96% confident their self-attested score would survive review while only 29% could point to both a current submission and an authorized platform, and 84% reported concern about False Claims Act liability. Around Redstone Arsenal, where a single prime's subcontractor tier can carry dozens of North Alabama suppliers, that confidence gap propagates through the whole chain. Suppliers working out how contractors meet federal cybersecurity rules in practice should start with the accuracy of what is already posted.

What Happens If I Don't Get CMMC Certified?

If you don't get CMMC certified where a contract requires it, you are ineligible for award on that contract. Certification is a condition of award rather than a penalty regime, so the consequence is commercial before it is anything else.

Commercial consequences are already measurable. In the same 2026 survey, 38% of contractors reported losing or being disqualified from a contract over CMMC Level 2 requirements, and the burden fell unevenly: Tier 2 and lower subcontractors reported bid losses at 55% against 31% among primes. Primes enforce ahead of the government because their own eligibility depends on the tiers beneath them.

Does the CMMC Pause Apply to Existing Contracts?

The CMMC pause applies to existing contracts through modification rather than automatically. Revision 3 directs contracting officers to work with requiring activities to remove or revise CMMC requirements in existing contracts as well as new solicitations, and those modifications are being issued.

Until your contracting officer issues the modification, the clause in your contract still governs. A contract already carrying a third-party certification designation continues to carry it on paper, so the practical step is confirming with your contracting officer rather than assuming the suspension reached you.

Cloud, Encryption, and Platform Requirements

Where your data lives determines what evidence you can produce, which makes cloud platform selection one of the earliest CMMC decisions rather than one of the last. Four questions come up constantly and the answers are more specific than the marketing around them suggests.

What Does GCC High Mean?

GCC High means Government Community Cloud High, a Microsoft 365 environment built for organizations handling controlled unclassified information, export-controlled data, and other regulated federal content. It runs in a separate, US-sovereign environment with personnel screening and data residency commitments that the commercial cloud does not carry.

The name describes the tenant type rather than a certification you hold. Moving to GCC High changes where your data sits and which contractual commitments the provider makes about it, and it is a migration rather than a setting. Anyone weighing the move should be clear on the differences between cloud service models first, because the responsibilities that stay with you differ by model.

Do You Need GCC High for CMMC Level 2?

You do not strictly need GCC High for CMMC Level 2, but you do need a cloud environment that meets the requirements DFARS clause 252.204-7012 imposes, and GCC High is the most common way defense contractors meet them for Microsoft workloads. The clause requires a cloud service provider handling covered defense information to meet security requirements equivalent to the FedRAMP Moderate baseline and to satisfy additional commitments covering cyber incident reporting, media preservation, and access for forensic analysis.

Commercial Microsoft 365 is not built to carry that full set for CUI workloads, which is why the migration question arises. Contractors handling only Federal Contract Information at Level 1 face a lighter test and frequently do not need to move. The determining factor is the data, and getting the CUI inventory right before the platform decision saves an expensive reversal.

Does CMMC Level 2 Require FedRAMP?

CMMC Level 2 does not require your own organization to hold a FedRAMP authorization. The FedRAMP requirement applies to cloud service providers handling covered defense information on your behalf, which must meet requirements equivalent to the FedRAMP Moderate baseline under DFARS 252.204-7012.

The distinction trips up contractors regularly. You are not seeking FedRAMP authorization; you are verifying that the providers holding your CUI have it or can demonstrate equivalency, and documenting that verification. Ask each provider for its authorization status and its customer responsibility matrix, because the matrix is what tells an assessor which controls the provider operates and which remain yours.

Is FIPS Required for CMMC Level 2?

Yes, FIPS-validated cryptography is required for CMMC Level 2 where encryption protects the confidentiality of CUI. The requirement sits at SC.L2-3.13.11, which calls for FIPS-validated cryptography specifically rather than encryption generally.

The distinction has a direct scoring consequence and it is the only one of its kind in the rule. Where encryption is employed but the cryptographic module is not FIPS-validated, that requirement may be placed on a plan of action at a value of 3 points, which is a narrow carve-out the regulation grants explicitly. Where no encryption is employed at all, the requirement is fully not met and the carve-out does not apply. Verifying that your file encryption uses validated modules rather than merely strong algorithms is a quick check with an outsized effect on your score.

How Long CMMC Takes and What It Costs

CMMC preparation takes 12 to 18 months for most contractors starting from a partially implemented environment, and the Department's published cost estimates run from roughly $6,000 for a Level 1 self-assessment to roughly $105,000 for a Level 2 certification cycle for a small entity. Both figures need context before they go into a budget.

Duration comes from sequence rather than effort. Scoping precedes remediation, remediation precedes documentation, documentation precedes evidence collection, and evidence collection has to run long enough to show that controls operate continuously rather than on one day. Adding people does not compress that chain. Starting with a gap analysis is what converts a vague eighteen-month worry into a dated plan with owners attached.

How Long Does It Take to Become CMMC Level 2 Certified?

Becoming CMMC Level 2 certified takes 12 to 18 months for full implementation and assessment readiness at most organizations, with mature security programs moving faster and unsegmented environments with no documentation taking longer. Level 1 is considerably shorter, often three to six months where most basic safeguarding requirements are already met.

Waiting for a solicitation to appear before starting is the one approach that reliably fails. A contract carrying a CMMC requirement does not allow eighteen months of remediation between the RFP and the award, which is why the suspension window is worth using rather than waiting out.

How Much Does It Cost to Get CMMC Level 2?

Getting CMMC Level 2 costs approximately $37,000 for a self-assessment cycle and approximately $105,000 for a certification assessment cycle over three years for a small entity, according to the Regulatory Impact Analysis published with the CMMC program final rule. Larger entities were modeled at roughly $49,000 and $118,000 respectively.

Those numbers measure proving compliance, not achieving it. The rule explicitly assumes the underlying security requirements are already implemented, so remediation, tooling, cloud migration, documentation, and training all sit outside the estimate. Treat the published figures as the floor of an assessment budget and scope the implementation work separately. Running the whole program under managed compliance rather than as a series of one-off projects is how most small suppliers keep the total predictable.

How Many Companies Have CMMC Level 2 Certification?

Only a small fraction of the defense industrial base holds a CMMC Level 2 certification, and the constraint has been assessor capacity rather than contractor interest. The Defense Industrial Base consists of over 220,000 companies that process, store, or transmit FCI or CUI, according to the Department's own CMMC Model Overview.

Against that base, roughly 104 authorized third-party assessment organizations and 988 Certified CMMC Assessors served the entire sector as of May 2026, according to Secureframe's federal cybersecurity reporting. Even before the suspension, the arithmetic made a rapid certification wave impossible, and assessor capacity was among the concerns the Department cited when it opened the review.

Self-reported readiness tells a related story. The 2026 State of the Defense Industrial Base report from CyberSheath and Merrill Research, based on 302 contractors, found the average score in the supplier system reached a five-year high of +51 against a maximum of 110, up from +33 the prior year. Scores are improving and remain well short of the 110 a final Level 2 status requires.

Why the CMMC Timeline Matters More Now Than Before the Suspension

The timeline matters more now because a suspended requirement eventually returns into the same thin assessor capacity that helped cause the suspension. Fewer than 1,000 certified assessors cannot process a queue of hundreds of thousands of suppliers on a compressed schedule, and the contractors who wait will be waiting behind the ones who did not.

Position in that queue is the practical stake. A contractor who spends the review period scoping controlled information, implementing NIST SP 800-171 Rev 2, correcting an inflated score, and building an evidence trail is ready to schedule an assessment the week a requirement returns. A contractor who stands down spends that same week starting a gap analysis. The technical work is identical; only the sequence differs, and sequence is what determines who can bid.

Two developments run alongside the pause and neither is affected by it. Prime contractors have continued enforcing expectations down their supply chains ahead of the government, because their own eligibility depends on it. And the governmentwide controlled unclassified information rule folded into the June 23, 2026 Federal Acquisition Regulation overhaul rulemaking proceeds independently, which means contractors selling to both defense and civilian customers gain little from a Department pause if a broader requirement arrives to fill the gap. Suppliers building compliance programs for both markets should plan against the wider requirement rather than the narrower pause.

What to Do Between Now and the Next CMMC Date

Between now and the next CMMC date, do the work that holds its value under every outcome the review could produce. Most of the work qualifies, because the standard did not move and only the verification method did.

These obligations remain fully in force today regardless of the suspension:

  • DFARS clause 252.204-7012, safeguarding covered defense information and 72-hour cyber incident reporting
  • Implementation of the 110 security requirements in NIST SP 800-171 Rev 2
  • A current self-assessment score posted to the supplier system
  • The annual affirmation of continuous compliance signed by a senior official
  • Flow-down of applicable requirements to subcontractors handling covered information

The sequence that makes the most of the window runs as follows:

  1. Finish the scoping. Establish where controlled information lives, how it flows, and which systems and vendors touch it. Every later decision inherits this one.
  2. Re-run the self-assessment against evidence. Score each requirement from what you can demonstrate rather than what you believe is configured.
  3. Correct the posted score if it overstates reality. A corrected score is a manageable commercial problem; an uncorrected overstatement is a legal one.
  4. Close the requirements that can never be deferred. Every 3-point and 5-point requirement, plus the six the regulation bars from a plan of action by name.
  5. Keep the system security plan current and the plan of action dated. A POA&M showing a genuine history of items opened, worked, and closed reads as program maturity.
  6. Collect evidence continuously. Access reviews, log reviews, vulnerability scans with remediation records, and training completions accumulate history that cannot be manufactured later.
  7. Confirm your contract status with your contracting officer. Find out whether a modification has been issued and what your solicitation pipeline now requires.
  8. Watch for the three instruments that actually change obligations. A new class deviation, a DFARS rule change, or an amendment to 32 CFR Part 170.

Small suppliers without internal security staff have free federal help available. The Department's Office of Industrial Base Growth runs Project Spectrum, which provides cybersecurity training, tools, and access to cyber advisors at no cost to small and medium businesses in the defense supply chain. Combining those resources with structured audit readiness work makes the window productive rather than idle.

Can a Contracting Officer Still Require a C3PAO Assessment?

A contracting officer cannot require a third-party certification assessment in a new solicitation during the suspension. Program managers can designate CMMC Level 1 (Self) or Level 2 (Self), and Revision 3 directs officers to remove or revise designations that call for third-party certification.

Voluntary assessments remain available. The assessment infrastructure continues operating, accredited organizations are still performing assessments for contractors who want them, and existing certifications remain valid and still post to the government's systems. A certificate obtained voluntarily is a commercial differentiator with primes even where no clause demands it.

Frequently Asked Questions

What Is DFARS 252.204-7021?

DFARS 252.204-7021 is the contract clause titled Contractor Compliance with the Cybersecurity Maturity Model Certification Level Requirement. It is the clause that obligates a contractor to hold and maintain the CMMC status the contract specifies for the duration of performance. Class Deviation Revision 3 governs when contracting officers insert it, which is selectively until November 9, 2028 and automatically from November 10, 2028.

Does CMMC Apply to Civilian Agency Contracts?

No, CMMC applies only to Department of Defense contracts. No formal rulemaking has extended the program to civilian agencies. A separate governmentwide controlled unclassified information rule is moving through the Federal Acquisition Regulation overhaul rulemaking, and contractors serving civilian agencies should track that rule rather than CMMC.

What Is the Difference Between a Memo, a Class Deviation, and a Rule?

A memo directs how officials exercise discretion, a class deviation directs contracting officers to depart from standard regulation text in a defined way, and a rule changes the regulation itself through formal rulemaking. The July 13, 2026 suspension began as memoranda and became operational through a class deviation. The underlying program rule at 32 CFR Part 170 was not amended, which is why the program remains intact.

Do Existing CMMC Certifications Still Count During the Suspension?

Yes, existing CMMC certifications still count during the suspension. Certifications already issued remain valid for their full three-year term, continue to post to the government's systems, and still require the annual affirmation. Contractors who certified early kept the benefit of that work.

Is There a Small Business Exemption From CMMC?

No, there is no small business exemption from CMMC. The requirement follows the data and the contract rather than headcount or revenue. A two-person firm handling controlled unclassified information faces the same 110 requirements as a large prime, which is precisely the burden the current program review was opened to address.

Where Can Small Contractors Get Free CMMC Help?

Small contractors can get free CMMC help through Project Spectrum, a platform run by the Department's Office of Industrial Base Growth that provides cybersecurity training, tools, and cyber advisor support at no cost. Registration is open to small and medium businesses in the defense supply chain, and the Defense Acquisition University also offers free online CMMC and cybersecurity training.

The Bottom Line

CMMC 2.0 is required for DoD contracts today through self-assessment at Level 1 and Level 2, and it has been since November 10, 2025. Third-party certification was suspended on July 13, 2026 and remains suspended while the Reform Task Force review concludes. Under DARS Class Deviation 2026-O0025, Revision 3, issued September 3, 2026, the CMMC clause is inserted selectively until November 9, 2028 and applies automatically to any applicable contract from November 10, 2028.

None of that changed the underlying obligation. DFARS 252.204-7012, the 110 requirements in NIST SP 800-171 Rev 2, a current posted score, and the annual affirmation all bind you now, and contracting officers must verify your status before award, before exercising an option, and before extending a period of performance. With fewer than a thousand certified assessors serving a base of more than 220,000 companies, the contractors who use this window will be the ones positioned when a verification requirement returns.

We have spent over 20 years helping organizations across Huntsville and North Alabama weave technology into a solid and compliant infrastructure, with Certified CMMC Assessors and Certified CMMC Professionals leading the process from scoping through evidence collection. If you would like a clear read on where your environment stands against the 110 and what your current solicitations actually require, the team at Interweave Technologies is glad to walk through it with you. You can reach us at (256) 837-2300.

‍