CMMC supplier verification is the independent check of the claims a supplier makes about its cybersecurity posture (the CMMC level it states, the NIST SP 800-171 controls it says it operates, the flow-down it passes to subcontractors) against evidence, before a prime relies on them. Certisyn verifies each claim and seals the determination, so the prime, its auditor and the contracting officer read the same record.
| Claim | Evidence examined | Determination |
|---|---|---|
| A CMMC level is held | The assessment record and the stated scope | Held, in scope and in date, or the reason it could not be determined |
| NIST SP 800-171 controls are operated | Policy, configuration snapshots, telemetry, logs | Documented, Operational or Adversarial-ready, per control |
| A reported score reflects the environment | The scoring basis and the evidence behind it | Reconciled to the evidence, with differences listed |
| Flow-down reaches subcontractors | Subcontractor attestations and agreements | Established for the examined subcontractors, with the remainder named |
A supply chain verification states what it examined. The coverage statement declares the examined population with explicit denominators, enumerates every unexamined unit with a specific reason, and carries each determination under the policy version in force. A prime reading it knows how much of the supply base the result describes.
Certification decisions sit with the Department of War's assessment ecosystem and its C3PAOs. Certisyn determinations serve the prime's own reliance decision: which supplier claims it can accept, which it must test further, and on which it holds evidence an auditor can replay.
CMMC supplier verification is the independent check of the claims a supplier makes about its cybersecurity posture against evidence, before a prime relies on them.
The CMMC level a supplier states, the NIST SP 800-171 controls it says it operates, the score it reports, and the flow-down it passes to its own subcontractors.
Certification decisions sit with the Department of War's assessment ecosystem and its C3PAOs. Certisyn operates upstream and alongside: it verifies the claims a prime receives and seals the determination, so the prime, its auditor and the contracting officer read the same record.
A sealed determination for each claim, a coverage statement naming what was examined and what was not, and a registry code that resolves publicly.