CAPITALCYBER

CMMC / Arizona

CMMC Level 2 for Arizona defense suppliers.

You build parts for missile programs and defense electronics in Tucson or Phoenix. You are a machine shop, a cable and harness builder, or a test fixture maker sitting two or three tiers below a prime. You have fewer than 25 people, no full time IT staff, and a contract clause that says you already handle controlled unclassified information.

Where the obligation actually stands

Third party certification is paused

The Phase 2 mechanism that was due from 10 November 2026 is on hold while the Department reviews it. That is the only thing that moved.

Your self assessment is not

Level 1 and Level 2 self assessment under DFARS 252.204-7021 has applied to covered solicitations since 10 November 2025, and a passing score remains a condition of award.

DFARS 252.204-7012 still applies

Safeguarding covered defense information and reporting cyber incidents did not change.

NIST SP 800-171 Rev 2 is still the standard

All 110 controls, assessed against the 800-171A objectives.

Flow down is unchanged

Primes remain responsible for the cybersecurity requirements that apply to subcontracted work.

The affirmation is still signed

Your Affirming Official affirms the score in SPRS annually. Signing an inflated score is a False Claims Act matter and it stays with you.

Where Arizona suppliers actually are

Here is where the obligation stands today. Third party certification is paused. It is a pause, not a cancellation. The self assessment obligation under DFARS 252.204-7021 never moved. DFARS 252.204-7012 still applies to your contract. NIST SP 800-171 Rev 2 is still the control set. Your score in SPRS is still an assertion a company officer signs.

What to do first, and why the gap assessment is the gate

Start with a gap assessment against all 110 controls. It is the gate because everything downstream depends on it. Your SPRS score, your System Security Plan, your plan of action, and your budget all come from that one measurement. A shop that guesses at a score carries the guess into a signed representation. Measure first, then fix in order of risk.

What we will not do

Now what we will not do. We will not take custody of your CUI, and we do not need it to do this work. We are not a C3PAO and we do not certify anyone. We will not write a security plan that describes a network you do not own. We will not sell you a tool stack you cannot run.

Find out where you stand in Arizona.

No sales sequence, and no number put in front of you that we cannot defend.

If you are a defense supplier under 25 people, start with the grant. Cyber Grants Alliance, a nonprofit, awards a fully funded gap assessment. It costs you nothing and you are under no obligation to buy anything afterwards, from us or from anyone.