You hold a defense contract, or you're a subcontractor to a prime that does. Somewhere in your contract is a clause about protecting government information, and now your inbox is full of vendors promising to make CMMC painless. Every one of them sounds confident. Every proposal has a number on it. And you're nodding along to words like "enclave," "GCC High," "C3PAO," and "SPRS," hoping the person across the table actually understands what they mean for a contractor that has to keep bidding, keep delivering, and keep primes happy.
Two things just shifted, and both matter. On July 13, 2026, the Department of War (DoW) suspended CMMC Phase II, the mandatory third-party certification that was set to become a condition of award on November 10, 2026, pending a review aimed at cutting cost and burden. And earlier, effective February 1, 2026, the older self-assessment clauses were restructured: DFARS 252.204-7019 was removed and 252.204-7020 was renumbered, with assessment obligations meant to route through CMMC under DFARS 252.204-7021, which is the piece now paused. In plain terms, the paperwork path keeps changing, but the duty to protect the data has not moved an inch.
Here's the part no vendor should let you forget: DFARS 252.204-7012 is unchanged and has applied since 2017. It still requires you to safeguard Covered Defense Information and report cyber incidents to DoD within 72 hours. NIST SP 800-171 and its 110 controls still stand. So does your obligation to have a real System Security Plan and a defensible score. The suspension paused the certification gate, not the security.
So we wrote this down. Not a teaser, the real thing. First we decode the jargon and lay out what CMMC Level 2 asks for, in plain English. Then we give you a ten-minute exercise to map your own CUI and your flow-down. Then the ten questions we'd ask if we were sitting in your chair, each with what a strong answer sounds like, what a weak one sounds like, and a real number or requirement to hold the vendor to.
Ask these of every vendor you're talking to, including us. The right partner welcomes them and answers straight. The wrong one gets vague. How a vendor handles these ten tells you more than any proposal ever will.
One note on us. We're a CyberAB-authorized Registered Practitioner Organization, so we do CMMC readiness work: a gap analysis, a roadmap, standing up the controls, building the documentation, and getting your self-assessment to a place you can defend. We deliver that as an add-on to our managed IT, on one agreement, with the readiness labor included rather than billed by the hour. We've built our own PCs and servers on our own line in Wichita since 1997.
What CMMC is. CMMC stands for Cybersecurity Maturity Model Certification. It's the DoW's way of checking that the companies in its supply chain actually protect the sensitive information they handle. It's a verification layer on top of rules that have existed for years, chiefly DFARS 252.204-7012 and NIST SP 800-171.
The three levels. Level 1 covers Federal Contract Information (FCI) and is a yearly self-assessment against 15 basic safeguards. Level 2 covers Controlled Unclassified Information (CUI) and is where most defense contractors handling technical data land. Level 3 is for the highest-sensitivity programs. This guide is about Level 2, because that's where the cost and the work live.
What Level 2 requires. Level 2 is built on NIST SP 800-171, which has 110 controls across 14 families. To meet it you need three things: the 110 controls in place in your actual environment, a System Security Plan (SSP) describing how each control is met, and a Plan of Action and Milestones (POA&M) for anything not fully done yet.
How you're scored. You self-score against NIST 800-171 on a scale that tops out at 110. That score is posted in a DoW system called SPRS, along with a senior official's affirmation that it's accurate. Until the July 2026 suspension, contracts involving CUI were headed toward a mandatory check of that score by an accredited third-party assessor called a C3PAO. That third-party step is the part now paused.
Where things stand now. On July 13, 2026, the DoW suspended CMMC Phase II pending a review meant to lower cost and burden. It's suspended, not cancelled. Separately, effective February 1, 2026, DFARS 252.204-7019 was removed and 7020 renumbered, with assessment routed through 7021/CMMC, which is the suspended piece. Two things did not change: DFARS 252.204-7012 still requires you to safeguard CUI and report incidents within 72 hours, and Level 2 still stands with all 110 controls. For now you demonstrate Level 2 by self-assessing and affirming your score in SPRS. That affirmation is legally binding, so a score you can't back up carries real exposure, including under the False Claims Act.
Where CybertronIT sits. We're an RPO, a Registered Practitioner Organization. We do the readiness work that gets you to the point where you'd meet the controls and could defend your score. We are not the C3PAO, and by design the same firm can't both prepare you and run the third-party assessment on the same engagement.
Here are the ten questions, with why each one matters for a real defense contractor. Ask all ten, and watch the reactions as closely as the answers.
DFARS 252.204-7012 has applied since 2017 and is unchanged. The 7019/7020/7021 framework shifted on February 1, 2026, and CMMC Phase II was suspended on July 13, 2026. A vendor who can't tell you which clauses are in your contracts today is selling you a product, not a plan.
The moment CUI enters, whatever it touches can get pulled into scope: the workstation, the file server, the laptop the estimator takes home, the shared printer. Scope drives cost, so a vendor who oversizes your scope oversizes your bill.
If you're a prime, you're responsible for confirming your subs meet the requirements before you hand them CUI. If you're a sub, your prime will ask for your SPRS score and your SSP. A vendor who treats your company as an island has left out half the problem.
If your MSP administers the systems that hold CUI, that provider is in scope. You can't outsource the obligation. Ask how the vendor's own handling of your CUI is documented and controlled.
Your CUI doesn't sit still. Compliance has to hold at every handoff, not just where the data rests. A vendor confident about storage but blank on the workflow has a hole in their plan.
A Level 2-capable GCC High seat runs roughly $60 per user per month all-in as of 2026. Guessing 10 CUI users when the real number is 25 isn't a rounding error. Make the vendor price your seats, your way.
A large share of the 110 controls have nothing to do with software: physical protection, personnel security, training, media handling. A good partner tells you which they implement, and which physical safeguards stay with you as the building owner.
Doing a control isn't enough; you have to prove it. Your score runs on evidence. A vendor who hands you templates to fill out alone is handing you the hardest part.
The SSP is the backbone of Level 2. NIST 800-171 requires it (control 3.12.4). A real SSP names your systems, your network, your data flow. A template SSP describes a generic company that doesn't exist.
With Phase II suspended, you demonstrate Level 2 by self-assessing and affirming your score in SPRS. But self-certifying is not a free pass. The affirmation is legally binding, and the DOJ's Civil Cyber-Fraud Initiative has pursued contractors under the False Claims Act for misrepresenting their cybersecurity.
Everything above is the map. The full checklist is the tool you bring into the room. The free PDF is built to print and carry. It adds a ten-minute exercise to map your own exposure before you take a single sales call, plus where CybertronIT fits and how to score every vendor you talk to. Give us an email and it is yours.
Comments