CMMC / Indiana
CMMC Level 2 for Indiana defense suppliers.
This page is for the small shops that supply Naval Surface Warfare Center Crane and the primes around it. Precision machinists in Bloomington and Bedford. Electronics and cable assembly firms in the Westgate corridor. Test equipment and sensor suppliers in Indianapolis and Fort Wayne. Companies with a dozen people, one person handling IT part time, and a DoD contract that already carries DFARS clauses. If you hold controlled unclassified information on a laptop, in email, or on a shared drive, this applies to you.
Where the obligation actually stands
Third party certification is paused
The Phase 2 mechanism that was due from 10 November 2026 is on hold while the Department reviews it. That is the only thing that moved.
Your self assessment is not
Level 1 and Level 2 self assessment under DFARS 252.204-7021 has applied to covered solicitations since 10 November 2025, and a passing score remains a condition of award.
DFARS 252.204-7012 still applies
Safeguarding covered defense information and reporting cyber incidents did not change.
NIST SP 800-171 Rev 2 is still the standard
All 110 controls, assessed against the 800-171A objectives.
Flow down is unchanged
Primes remain responsible for the cybersecurity requirements that apply to subcontracted work.
The affirmation is still signed
Your Affirming Official affirms the score in SPRS annually. Signing an inflated score is a False Claims Act matter and it stays with you.
Where Indiana suppliers actually are
Here is the current state of the obligation. Third party certification assessments are paused. That pause did not remove anything else. DFARS 252.204-7012 still requires you to safeguard covered defense information and report cyber incidents within 72 hours. NIST SP 800-171 Rev 2 still defines the 110 controls. DFARS 252.204-7021 still requires a current self assessment score in SPRS. A score you posted in 2022 and never revisited is a problem today.
What to do first, and why the gap assessment is the gate
Start with a gap assessment against all 110 controls before you buy tools or write policy. The gap assessment is the gate because your SPRS score, your plan of action, and your spending order all depend on it. Guessing produces a score you cannot defend.
What we will not do
We will not take custody of your CUI. We will not certify you, because no consultant can. We will not sell you software you do not need, and we will not inflate your score to make the number look better.
Find out where you stand in Indiana.
No sales sequence, and no number put in front of you that we cannot defend.
If you are a defense supplier under 25 people, start with the grant. Cyber Grants Alliance, a nonprofit, awards a fully funded gap assessment. It costs you nothing and you are under no obligation to buy anything afterwards, from us or from anyone.