CMMC / California
CMMC Level 2 for California defense suppliers.
This is for the small California suppliers behind aerospace and shipbuilding work. Machine shops in Orange County and the San Fernando Valley. Composites and fabrication firms near Long Beach. Ship repair and marine electrical firms on San Diego harbor. Test and sensor suppliers around the Bay Area. Under 25 people, with one person covering IT alongside quality.
Where the obligation actually stands
Third party certification is paused
The Phase 2 mechanism that was due from 10 November 2026 is on hold while the Department reviews it. That is the only thing that moved.
Your self assessment is not
Level 1 and Level 2 self assessment under DFARS 252.204-7021 has applied to covered solicitations since 10 November 2025, and a passing score remains a condition of award.
DFARS 252.204-7012 still applies
Safeguarding covered defense information and reporting cyber incidents did not change.
NIST SP 800-171 Rev 2 is still the standard
All 110 controls, assessed against the 800-171A objectives.
Flow down is unchanged
Primes remain responsible for the cybersecurity requirements that apply to subcontracted work.
The affirmation is still signed
Your Affirming Official affirms the score in SPRS annually. Signing an inflated score is a False Claims Act matter and it stays with you.
Where California suppliers actually are
Here is where the obligation stands. Third party certification is paused. It is not canceled. The self assessment obligation under DFARS 252.204-7021 never moved. DFARS 252.204-7012 still applies, and NIST SP 800-171 Revision 2 is still the control set. Your SPRS score is still expected to be current and accurate.
What to do first, and why the gap assessment is the gate
Start by drawing the boundary. Know where federal contract information and CUI actually live, then measure that boundary against all 110 controls. The gap assessment is the gate. Without it, your SPRS score is a guess, your System Security Plan describes a system you do not have, and your plan of action carries no real dates. With it, you know your true score, what to fix first, and what it costs.
What we will not do
We will say what we will not do. We will not take custody of your CUI. Your data stays in your environment. We are a compliance firm, not a C3PAO, and we will not certify anyone. We will not inflate a score. We will not sell you tools you do not need. We will not tell you the rule went away.
Find out where you stand in California.
No sales sequence, and no number put in front of you that we cannot defend.
If you are a defense supplier under 25 people, start with the grant. Cyber Grants Alliance, a nonprofit, awards a fully funded gap assessment. It costs you nothing and you are under no obligation to buy anything afterwards, from us or from anyone.