CAPITALCYBER

CMMC / Massachusetts

CMMC Level 2 for Massachusetts defense suppliers.

This page is for the small Massachusetts shops that keep defense programs supplied. Optics houses along Route 128. Electronics and RF board builders in Lowell, Worcester and New Bedford. University spinouts near Cambridge running SBIR and Phase II work for the Air Force and Navy. Machine and coating shops that feed the primes in Andover and Nashua. If you have fewer than 25 people, no full time IT staff, and a DFARS clause in your contract, you are who we built this for.

Where the obligation actually stands

Third party certification is paused

The Phase 2 mechanism that was due from 10 November 2026 is on hold while the Department reviews it. That is the only thing that moved.

Your self assessment is not

Level 1 and Level 2 self assessment under DFARS 252.204-7021 has applied to covered solicitations since 10 November 2025, and a passing score remains a condition of award.

DFARS 252.204-7012 still applies

Safeguarding covered defense information and reporting cyber incidents did not change.

NIST SP 800-171 Rev 2 is still the standard

All 110 controls, assessed against the 800-171A objectives.

Flow down is unchanged

Primes remain responsible for the cybersecurity requirements that apply to subcontracted work.

The affirmation is still signed

Your Affirming Official affirms the score in SPRS annually. Signing an inflated score is a False Claims Act matter and it stays with you.

Where Massachusetts suppliers actually are

Here is where the obligation actually stands. Third party certification is paused. The self assessment obligation under DFARS 252.204-7021 did not move. DFARS 252.204-7012 did not move. NIST SP 800-171 Rev 2 did not move. Your SPRS score is still a representation to the government, and a wrong score is a false statement, not a paperwork error. Nothing has been cancelled. The gate has just moved back a step, to the score you posted yourself.

What to do first, and why the gap assessment is the gate

Start with a gap assessment against all 110 controls. Not a policy pack, not a tool purchase. You cannot price remediation, defend an SPRS score, or write a real System Security Plan until you know which controls you actually meet today. The gap assessment is the gate because everything downstream is guesswork without it.

What we will not do

We will not call ourselves a C3PAO or an accredited assessor. We are not one. We will not take custody of your CUI. We will not sell you software you do not need.

Find out where you stand in Massachusetts.

No sales sequence, and no number put in front of you that we cannot defend.

If you are a defense supplier under 25 people, start with the grant. Cyber Grants Alliance, a nonprofit, awards a fully funded gap assessment. It costs you nothing and you are under no obligation to buy anything afterwards, from us or from anyone.