CMMC / Connecticut
CMMC Level 2 for Connecticut defense suppliers.
This page is for the small shops that feed Connecticut's submarine and jet engine work. You machine housings, valve bodies, or turbine hardware for Electric Boat or Pratt and Whitney, or you sit two tiers down from them in Groton, New London, Middletown, or the Naugatuck Valley. You have fewer than 25 people, no security staff, and a prime that keeps asking about your score. You handle drawings and specifications that count as controlled unclassified information, and you already signed the clauses that govern them.
Where the obligation actually stands
Third party certification is paused
The Phase 2 mechanism that was due from 10 November 2026 is on hold while the Department reviews it. That is the only thing that moved.
Your self assessment is not
Level 1 and Level 2 self assessment under DFARS 252.204-7021 has applied to covered solicitations since 10 November 2025, and a passing score remains a condition of award.
DFARS 252.204-7012 still applies
Safeguarding covered defense information and reporting cyber incidents did not change.
NIST SP 800-171 Rev 2 is still the standard
All 110 controls, assessed against the 800-171A objectives.
Flow down is unchanged
Primes remain responsible for the cybersecurity requirements that apply to subcontracted work.
The affirmation is still signed
Your Affirming Official affirms the score in SPRS annually. Signing an inflated score is a False Claims Act matter and it stays with you.
Where Connecticut suppliers actually are
Here is where the obligation stands. Third party certification is paused. The self assessment obligation under DFARS 252.204-7021 never moved. DFARS 252.204-7012 and NIST SP 800-171 Rev 2 did not move either. If you hold a contract with those clauses, you owe a current self assessment score in the Supplier Performance Risk System and a plan for what is not yet in place. That is a gate you pass or fail on the record, and the pause changed none of it.
What to do first, and why the gap assessment is the gate
Start with a gap assessment against the 110 controls. Without it you cannot post a defensible score, and a wrong score in SPRS is a false statement risk. The assessment tells you what you already meet, what is cheap to fix, and what belongs in a plan with a date.
What we will not do
We will not take custody of your CUI. We will not act as a C3PAO or an accredited assessor, because we are a compliance firm and not an assessment body. We will not sell you tooling you do not need.
Find out where you stand in Connecticut.
No sales sequence, and no number put in front of you that we cannot defend.
If you are a defense supplier under 25 people, start with the grant. Cyber Grants Alliance, a nonprofit, awards a fully funded gap assessment. It costs you nothing and you are under no obligation to buy anything afterwards, from us or from anyone.