Vigilant Cybersecurity

Anchorage, Alaska · CMMC Level 1 and Level 2

CMMC Readiness for Alaska's Defense Contractors

Built for small and mid-sized defense contractors. Led personally, not delegated.

Vigilant Cybersecurity guides Level 1 and Level 2 defense contractors from gap assessment through assessment-ready.

Photo: E-3 Sentry and F-35As over the Bering Sea during a U.S. and Canadian maritime strike scenario, September 2026 (DVIDS)

CMMC status · Updated September 27, 2026

Phase 2 is on hold. Your safeguarding obligations are not.

The Department of War suspended the November 2026 Phase 2 transition, and contracting officers are to "remove or revise the CMMC requirements" in solicitations and contracts. Contracts may still require Level 1 (Self) or Level 2 (Self). NIST SP 800-171 Rev. 2 under DFARS 252.204-7012 and the FAR basic safeguarding requirements still apply.

Read what this means for your contracts

How We Work

Practitioner Led

Every engagement is led personally by a CISSP and Lead CMMC Certified Assessor. No bench staff billing for "discovery" calls, no handoffs to a team you've never met, no junior consultants learning on your dime.

Right-Sized

We don't oversell tooling, padded artifacts, or controls beyond what your CMMC level requires. Just the work that closes your real gaps — no more, no less.

Sustainable

The controls and documentation we help you implement are ones your team can keep up after we're gone. Compliance shouldn't depend on a consultant on permanent retainer.

Hutch White, founder and principal consultant of Vigilant Cybersecurity

Your practitioner

Hutch White, LCCA, CISSP

Every Vigilant engagement is led by Hutch personally, from the first scoping call to the final evidence review. He is a Lead CMMC Certified Assessor with over 15 years in information security, based in Anchorage.

More about Hutch and his credentials

Latest weekly briefing · Sep 21–25, 2026

Task force report still pending as the Rev. 3 deviation sinks in

No new CMMC actions surfaced September 21–25, but the Rev. 3 class deviation signed September 3 reaches well beyond CMMC. The task force report is still pending.

All briefings

What We Focus On

2–4 weeks

Gap Assessment

A focused engagement that tells you exactly where you stand and what it will take to close the distance.

Gap Assessment details

3–6 months

CMMC Readiness

Full-engagement Level 1 and Level 2 readiness for defense contractors and subcontractors moving from current state to assessment-ready.

CMMC Readiness details

Monthly retainer

vCISO Services

Fractional security leadership for organizations that need a CISO's judgment but not a CISO's salary.

vCISO details

Annual or quarterly

Compliance Sustainment

Ongoing support for organizations that have already achieved readiness and need to maintain it year-over-year.

Sustainment details

Not ready for a call?

Start with the free CMMC Resource Starter Kit

Level 1 readiness resources, funding options, and where Alaska contractors can get free help, including APEX Accelerators and Project Spectrum.

Send me the Starter Kit

Secure the Mission. Protect the Supply Chain.

A free scoping call is the fastest way to find out which CMMC level applies to you and what it will take to get there. Bring your contract requirements, your timeline, or just your questions.

Schedule a Complimentary Scoping Call

Or reach a practitioner directly: (907) 229-5222 · [email protected]