Imprimis Introduces "Own Your Assessment" Campaign The Department of War's (DoW) 60-day suspension of CMMC Phase II third-party audits is not deregulation; it is a tactical retreat from the overly complicated and small business resource-straining auditor ecosystem. By halting C3PAO requirements, and initiating a 60-day review process... the DoD has put the burden of proof squarely back on the defense contractor through mandatory Phase I and Phase II self-assessments.

Imprimis Inc. Introduces "Own Your Assessment" Campaign
FOR IMMEDIATE RELEASE
Imprimis, Inc. Launches “Own Your Assessment” Campaign Following DoW CMMC Phase II Suspension, Stabilizing the Defense Industrial Base with Proven Self-Assessment Automation Software Tools and Express Documentation Solutions:
COLORADO SPRINGS, CO — July 20, 2026 — Imprimis, Inc. (i2), a pioneer in federal cybersecurity compliance automation, today announced its "Own Your Assessment" Campaign initiative. The aggressive strategic campaign follows the Department of War’s (DoW) sudden 60-day suspension of CMMC Phase II third-party assessment (C3PAO) requirements. Imprimis aims to protect small and mid-sized defense contractors from market panic by delivering immediate, automated self-assessment, evidence-gathering, and SPRS reporting tools.
While the DoW has paused the heavily bottlenecked third-party audit apparatus, the legal mandates to protect Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) remain fully in force. Contracting officers have been directed to amend active solicitations, but Phase I and Phase II self-assessment requirements remain completely unchanged. Defense Industrial Base (DIB) companies must still prove their compliance baseline via the government’s Supplier Performance Risk System (SPRS).
"The math behind the third-party auditor model was broken from the start, leaving 100,000 small businesses chasing fewer than 100 qualified auditors," said Michael Semmens, Imprimis President and Co-Founder. "But a pause on audits is not a pause on cybersecurity. Contractors don't need an auditor to stay compliant—they need internal control. Imprimis has been automating this exact capability since 2010. Our i2ACT platform gives small defense firms the software to build, document, and defend their own compliance baselines (either CMMC or NIST 800-171) right now, completely independent of the auditor bottleneck."
Introducing Imprimis Solution Offerings: 10 Days, 10 Solution Suggestions...
Over the course of the next several weeks, with 5 social media posts per week (Mon-Friday) on Imprimis LinkedIn Page We will outline our overall CMMC Assessment and Compliance Strategy in Clear Strategically Aligned Segments to outline our Comprehensive NIST|CMMC Assessment and Compliance Process.
Why ?
Because the core challenge in B2B cybersecurity compliance for the Defense Industrial Base (DIB) is overcoming inertia and anxiety. DIB contractors know CMMC rules are rigid, but they often get paralyzed by the complexity of navigating assessment, remediation, and long-term sustainment. Our purpose over this 2-week campaign is to position Imprimis as an "Architect of Clarity". We want to break down our highly structured, proprietary methodology—the Integrated Services Framework, our 6-Logical Procedure Steps, the 3-Phase Model, and the 8 Process Workflows—into bite-sized, high-impact daily insights. By stepping through the logic behind our structure, we want to separate Imprimis from competitors who offer vague, unproven spreadsheets in the sky checklists, or overly broad GRC "note-taking" solutions that leave you high-and dry with topical summaries, and no detailed remediation steps or milestones.
Week 1: The Architecture of Certainty (Framework & Phases)
Week 2: The Engine of Execution (Procedures & Workflows)
The Imprimis suite centers on its proprietary i2ACT Software Tool (Version 4.0), an on-premise framework that automates assessments and data intake, calculates exact SPRS scores, manages evidence artifacts, and assists with content and narratives to create mandatory documentation like System Security Plans (SSPs) and Plans of Action and Milestones (POA&Ms).
Combined with the i2CyberBuild remediation roadmap and the i2Sustain long term compliance program for sustaining cybersecurity IT and network configurations, (vulnerability scanning, networking monitoring, endpoint protection, 2FA multifactor authentication, training and logging), The use of the Imprimis i2ACT software tool supports defense contractors in their efforts to maintain eligibility for active solicitations during the DoW’s 60-day reform window and beyond.
DIB organizations looking to secure their active contracts can learn more about the "Own Your Assessment" program by visiting www.imprimis-inc.com
About Imprimis Inc.
Imprimis Inc. provides the DIB with the tools, training, and expertise necessary to "Turn Technology into Capability." Their flagship i2ACT 4.0 Assessment Compliance Software is utilized by contractors nationwide to manage, maintain, and prove cybersecurity compliance in the most demanding regulatory environments. For More Information about Imprimis: https://www.imprimis-inc.com/home/history
#
Mike Schmidt
Business Development Director
Imprimis, Inc.
Colorado Springs, CO
Email: mike.schmidt@imprimis-inc.com
Phone: 719-463-0333 x 5