CAPITALCYBER

CMMC / Georgia

CMMC Level 2 for Georgia defense suppliers.

This page is for the small shops that keep aircraft flying in middle Georgia. Machine shops and sheet metal suppliers near Warner Robins that hold sustainment work for the C-130 and the F-15. Second and third tier suppliers feeding the Marietta line. Repair stations, avionics testers, tooling houses, and the two person engineering firms that send drawings back and forth with a prime. If you have fewer than 25 employees, one person handling IT on top of another job, and a DFARS clause sitting in your contract, you are the reader we wrote this for.

Where the obligation actually stands

Third party certification is paused

The Phase 2 mechanism that was due from 10 November 2026 is on hold while the Department reviews it. That is the only thing that moved.

Your self assessment is not

Level 1 and Level 2 self assessment under DFARS 252.204-7021 has applied to covered solicitations since 10 November 2025, and a passing score remains a condition of award.

DFARS 252.204-7012 still applies

Safeguarding covered defense information and reporting cyber incidents did not change.

NIST SP 800-171 Rev 2 is still the standard

All 110 controls, assessed against the 800-171A objectives.

Flow down is unchanged

Primes remain responsible for the cybersecurity requirements that apply to subcontracted work.

The affirmation is still signed

Your Affirming Official affirms the score in SPRS annually. Signing an inflated score is a False Claims Act matter and it stays with you.

Where Georgia suppliers actually are

Third party certification is paused. That is the only thing that changed. Your self assessment obligation under DFARS 252.204-7021 never moved. DFARS 252.204-7012 never moved. NIST SP 800-171 Rev 2 is still the control set, and your score in the Supplier Performance Risk System is still a number your prime and your contracting officer can read. A stale or invented score is the exposure, not the pause.

What to do first, and why the gap assessment is the gate

Start with a gap assessment against all 110 controls. It is the gate because everything downstream depends on it. Your System Security Plan, your plan of action, your score, and your affirmation all trace back to what the assessment found. Guessing at a score before you have measured is how small suppliers end up defending a number they cannot support.

What we will not do

We will not take custody of your CUI. We will not sit inside your network. We will not sell you tooling you do not need, and we will not tell you that you passed. We are a compliance firm, not a C3PAO and not an assessor.

Find out where you stand in Georgia.

No sales sequence, and no number put in front of you that we cannot defend.

If you are a defense supplier under 25 people, start with the grant. Cyber Grants Alliance, a nonprofit, awards a fully funded gap assessment. It costs you nothing and you are under no obligation to buy anything afterwards, from us or from anyone.