CMMC / Michigan
CMMC Level 2 for Michigan defense suppliers.
This page is for the small suppliers in Macomb County who build and finish parts for ground vehicles and armor. Machine shops in Warren and Sterling Heights. Weld and plate fabricators feeding TACOM and the primes. Ten people, sometimes fewer, one office manager, and a contract that now carries flowdown language nobody explained.
Where the obligation actually stands
Third party certification is paused
The Phase 2 mechanism that was due from 10 November 2026 is on hold while the Department reviews it. That is the only thing that moved.
Your self assessment is not
Level 1 and Level 2 self assessment under DFARS 252.204-7021 has applied to covered solicitations since 10 November 2025, and a passing score remains a condition of award.
DFARS 252.204-7012 still applies
Safeguarding covered defense information and reporting cyber incidents did not change.
NIST SP 800-171 Rev 2 is still the standard
All 110 controls, assessed against the 800-171A objectives.
Flow down is unchanged
Primes remain responsible for the cybersecurity requirements that apply to subcontracted work.
The affirmation is still signed
Your Affirming Official affirms the score in SPRS annually. Signing an inflated score is a False Claims Act matter and it stays with you.
Where Michigan suppliers actually are
Here is where the obligation stands. Third party certification is paused, not cancelled. The self assessment obligation under DFARS 252.204-7021 never moved. DFARS 252.204-7012 still applies to every contract that carries it, and NIST SP 800-171 Rev 2 is still the control set you are scored against. Your SPRS score is still an affirmation signed by an Affirming Official.
What to do first, and why the gap assessment is the gate
With fewer than 25 people, start by drawing the boundary. Find where controlled unclassified information actually lives: the quoting inbox, the drawing folder, the laptop that goes home. Then run a gap assessment against all 110 controls. That is the gate. Until you know your real score and can evidence each control, every plan you write is a guess, and the affirmation you sign carries legal weight.
What we will not do
We will not take custody of your CUI. Your drawings stay on your systems, and that is deliberate. We will not write a System Security Plan that describes a network you do not run. We will not sell you managed IT on the back of an assessment. We are a compliance firm, not a C3PAO and not an accredited assessor, and we will not tell you a score is guaranteed.
Find out where you stand in Michigan.
No sales sequence, and no number put in front of you that we cannot defend.
If you are a defense supplier under 25 people, start with the grant. Cyber Grants Alliance, a nonprofit, awards a fully funded gap assessment. It costs you nothing and you are under no obligation to buy anything afterwards, from us or from anyone.