CybertronIT Blog

Cybertron Blog

Cybertron has been serving the Wichita area since 1997, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

10 Questions Every Defense Contractor Should Ask Before Buying a CMMC Solution

Before you read

You hold a defense contract, or you're a subcontractor to a prime that does. Somewhere in your contract is a clause about protecting government information, and now your inbox is full of vendors promising to make CMMC painless. Every one of them sounds confident. Every proposal has a number on it. And you're nodding along to words like "enclave," "GCC High," "C3PAO," and "SPRS," hoping the person across the table actually understands what they mean for a contractor that has to keep bidding, keep delivering, and keep primes happy.

Two things just shifted, and both matter. On July 13, 2026, the Department of War (DoW) suspended CMMC Phase II, the mandatory third-party certification that was set to become a condition of award on November 10, 2026, pending a review aimed at cutting cost and burden. And earlier, effective February 1, 2026, the older self-assessment clauses were restructured: DFARS 252.204-7019 was removed and 252.204-7020 was renumbered, with assessment obligations meant to route through CMMC under DFARS 252.204-7021, which is the piece now paused. In plain terms, the paperwork path keeps changing, but the duty to protect the data has not moved an inch.

Here's the part no vendor should let you forget: DFARS 252.204-7012 is unchanged and has applied since 2017. It still requires you to safeguard Covered Defense Information and report cyber incidents to DoD within 72 hours. NIST SP 800-171 and its 110 controls still stand. So does your obligation to have a real System Security Plan and a defensible score. The suspension paused the certification gate, not the security.

So we wrote this down. Not a teaser, the real thing. First we decode the jargon and lay out what CMMC Level 2 asks for, in plain English. Then we give you a ten-minute exercise to map your own CUI and your flow-down. Then the ten questions we'd ask if we were sitting in your chair, each with what a strong answer sounds like, what a weak one sounds like, and a real number or requirement to hold the vendor to.

Ask these of every vendor you're talking to, including us. The right partner welcomes them and answers straight. The wrong one gets vague. How a vendor handles these ten tells you more than any proposal ever will.

One note on us. We're a CyberAB-authorized Registered Practitioner Organization, so we do CMMC readiness work: a gap analysis, a roadmap, standing up the controls, building the documentation, and getting your self-assessment to a place you can defend. We deliver that as an add-on to our managed IT, on one agreement, with the readiness labor included rather than billed by the hour. We've built our own PCs and servers on our own line in Wichita since 1997.


CMMC Level 2 in plain English

What CMMC is. CMMC stands for Cybersecurity Maturity Model Certification. It's the DoW's way of checking that the companies in its supply chain actually protect the sensitive information they handle. It's a verification layer on top of rules that have existed for years, chiefly DFARS 252.204-7012 and NIST SP 800-171.

The three levels. Level 1 covers Federal Contract Information (FCI) and is a yearly self-assessment against 15 basic safeguards. Level 2 covers Controlled Unclassified Information (CUI) and is where most defense contractors handling technical data land. Level 3 is for the highest-sensitivity programs. This guide is about Level 2, because that's where the cost and the work live.

What Level 2 requires. Level 2 is built on NIST SP 800-171, which has 110 controls across 14 families. To meet it you need three things: the 110 controls in place in your actual environment, a System Security Plan (SSP) describing how each control is met, and a Plan of Action and Milestones (POA&M) for anything not fully done yet.

How you're scored. You self-score against NIST 800-171 on a scale that tops out at 110. That score is posted in a DoW system called SPRS, along with a senior official's affirmation that it's accurate. Until the July 2026 suspension, contracts involving CUI were headed toward a mandatory check of that score by an accredited third-party assessor called a C3PAO. That third-party step is the part now paused.

Where things stand now. On July 13, 2026, the DoW suspended CMMC Phase II pending a review meant to lower cost and burden. It's suspended, not cancelled. Separately, effective February 1, 2026, DFARS 252.204-7019 was removed and 7020 renumbered, with assessment routed through 7021/CMMC, which is the suspended piece. Two things did not change: DFARS 252.204-7012 still requires you to safeguard CUI and report incidents within 72 hours, and Level 2 still stands with all 110 controls. For now you demonstrate Level 2 by self-assessing and affirming your score in SPRS. That affirmation is legally binding, so a score you can't back up carries real exposure, including under the False Claims Act.

Where CybertronIT sits. We're an RPO, a Registered Practitioner Organization. We do the readiness work that gets you to the point where you'd meet the controls and could defend your score. We are not the C3PAO, and by design the same firm can't both prepare you and run the third-party assessment on the same engagement.


The jargon, decoded

  • CUI (Controlled Unclassified Information). Government information that isn't classified but still has to be protected. If your contract involves CUI, you're in Level 2 territory.
  • DFARS 252.204-7012. The clause, in force since 2017, that requires safeguarding covered defense information and 72-hour incident reporting. Unchanged by the CMMC suspension.
  • NIST SP 800-171. The security standard Level 2 is built on: 110 controls across 14 families.
  • SPRS (Supplier Performance Risk System). The DoW system where your self-assessment score is posted with a legally binding senior-official affirmation.
  • Flow-down. The requirement that primes push cybersecurity obligations to their subcontractors.
  • Enclave. A walled-off, secured part of your network where CUI is allowed to live, kept apart from the rest of your systems.
  • GCC High. Microsoft 365 Government Community Cloud High, built to store CUI. Roughly $60 per user per month all-in for a Level 2-capable seat as of 2026.
  • C3PAO. The accredited firm that runs an official Level 2 assessment. Not your IT provider. As of July 13, 2026, the mandatory third-party assessment is suspended.
  • RPO. Registered Practitioner Organization: a firm authorized to do CMMC readiness work. CybertronIT is an RPO.
  • SSP / POA&M. The written master document describing how each control is met, and the plan for closing remaining gaps.

The 10 questions

Here are the ten questions, with why each one matters for a real defense contractor. Ask all ten, and watch the reactions as closely as the answers.

1. Which of my contract clauses actually apply to me, and what do they require right now?

DFARS 252.204-7012 has applied since 2017 and is unchanged. The 7019/7020/7021 framework shifted on February 1, 2026, and CMMC Phase II was suspended on July 13, 2026. A vendor who can't tell you which clauses are in your contracts today is selling you a product, not a plan.

2. What counts as CUI in my environment, and where does it actually live?

The moment CUI enters, whatever it touches can get pulled into scope: the workstation, the file server, the laptop the estimator takes home, the shared printer. Scope drives cost, so a vendor who oversizes your scope oversizes your bill.

3. How do you handle flow-down to and from my subcontractors and my prime?

If you're a prime, you're responsible for confirming your subs meet the requirements before you hand them CUI. If you're a sub, your prime will ask for your SPRS score and your SSP. A vendor who treats your company as an island has left out half the problem.

4. My IT provider touches this data. How does that provider fit into my compliance?

If your MSP administers the systems that hold CUI, that provider is in scope. You can't outsource the obligation. Ask how the vendor's own handling of your CUI is documented and controlled.

5. Can you walk my whole workflow, portal to delivery, and show me it stays compliant end to end?

Your CUI doesn't sit still. Compliance has to hold at every handoff, not just where the data rests. A vendor confident about storage but blank on the workflow has a hole in their plan.

6. What will compliant infrastructure actually cost me, per seat, in writing?

A Level 2-capable GCC High seat runs roughly $60 per user per month all-in as of 2026. Guessing 10 CUI users when the real number is 25 isn't a rounding error. Make the vendor price your seats, your way.

7. How are you handling the controls that aren't technical, the people and building side?

A large share of the 110 controls have nothing to do with software: physical protection, personnel security, training, media handling. A good partner tells you which they implement, and which physical safeguards stay with you as the building owner.

8. Who builds and maintains my SSP, POA&M, and evidence, and keeps them matching reality?

Doing a control isn't enough; you have to prove it. Your score runs on evidence. A vendor who hands you templates to fill out alone is handing you the hardest part.

9. Is the System Security Plan built for my company, or a template with my name pasted in?

The SSP is the backbone of Level 2. NIST 800-171 requires it (control 3.12.4). A real SSP names your systems, your network, your data flow. A template SSP describes a generic company that doesn't exist.

10. How do you make sure I can stand behind my SPRS score, whoever ends up checking it?

With Phase II suspended, you demonstrate Level 2 by self-assessing and affirming your score in SPRS. But self-certifying is not a free pass. The affirmation is legally binding, and the DOJ's Civil Cyber-Fraud Initiative has pursued contractors under the False Claims Act for misrepresenting their cybersecurity.


Red flags to listen for

  • Manufactured urgency. A vendor still pounding the November 2026 deadline. That third-party deadline is suspended as of July 13, 2026.
  • Clause confusion. They can't tell you which DFARS clauses are in your contracts today.
  • Ignoring flow-down. No plan for your subcontractors or your prime relationship.
  • The MSP blind spot. They never address that your IT provider touches your CUI and is in scope.
  • Hidden infrastructure cost. No straight, per-seat number for compliant infrastructure.
  • "We handle all 110 controls." Nobody installs your locks or guards your building.
  • Template documentation. An SSP that describes a generic company instead of yours.
  • The RPO and C3PAO blur. A vendor implying they can both prepare you and run your third-party assessment.

Get the full checklist (free)

Everything above is the map. The full checklist is the tool you bring into the room. The free PDF is built to print and carry. It adds a ten-minute exercise to map your own exposure before you take a single sales call, plus where CybertronIT fits and how to score every vendor you talk to. Give us an email and it is yours.

  • Company Name *
  • First Name *
  • Last Name *
  • Comments:
  • Yes, I'd like to subscribe to:
      10 Questions Every CPA Firm Should Ask Before Buyi...
      10 Questions Every Machine Shop Should Ask Before ...
      Comment for this post has been locked by admin.
       

      Comments

      Already Registered? Login Here
      No comments made yet. Be the first to submit a comment