CAPITALCYBER

CMMC / Maryland

CMMC Level 2 for Maryland defense suppliers.

This page is for the small shops in the Fort Meade corridor. You are a ten person software firm in Columbia, a signals analysis team in Annapolis Junction, a staffing supplier in Linthicum that puts cleared engineers on task orders. You hold a subcontract under a prime, or you sell directly to an agency customer. Your contracts carry DFARS 252.204-7012, and the CUI on your systems is engineering data, contract deliverables, and personnel records rather than classified material. You have no security staff. The compliance work sits with an owner, a program manager, or the person who also runs IT.

Where the obligation actually stands

Third party certification is paused

The Phase 2 mechanism that was due from 10 November 2026 is on hold while the Department reviews it. That is the only thing that moved.

Your self assessment is not

Level 1 and Level 2 self assessment under DFARS 252.204-7021 has applied to covered solicitations since 10 November 2025, and a passing score remains a condition of award.

DFARS 252.204-7012 still applies

Safeguarding covered defense information and reporting cyber incidents did not change.

NIST SP 800-171 Rev 2 is still the standard

All 110 controls, assessed against the 800-171A objectives.

Flow down is unchanged

Primes remain responsible for the cybersecurity requirements that apply to subcontracted work.

The affirmation is still signed

Your Affirming Official affirms the score in SPRS annually. Signing an inflated score is a False Claims Act matter and it stays with you.

Where Maryland suppliers actually are

Here is where things stand. Third party certification assessment is paused. The self assessment obligation is not. DFARS 252.204-7021 still requires a current score in SPRS, and DFARS 252.204-7012 and NIST SP 800-171 Rev 2 never moved. If your score is stale, inflated, or copied from a template, that exposure is live today and it is yours to carry.

What to do first, and why the gap assessment is the gate

Start with a gap assessment. It is the gate because everything downstream depends on it. Your SPRS score, your System Security Plan, your POA&M, and your remediation budget all trace back to an honest reading of where the 110 controls actually sit. Guessing at the gate means rebuilding later.

What we will not do

We will not take custody of your CUI. We will not write a score we cannot defend. We are a compliance firm, not a C3PAO, and we will not assess or certify you.

Find out where you stand in Maryland.

No sales sequence, and no number put in front of you that we cannot defend.

If you are a defense supplier under 25 people, start with the grant. Cyber Grants Alliance, a nonprofit, awards a fully funded gap assessment. It costs you nothing and you are under no obligation to buy anything afterwards, from us or from anyone.