CMMC / Missouri
CMMC Level 2 for Missouri defense suppliers.
This page is for the small shops in the St Louis aviation corridor. Machine shops in St Charles County cutting brackets and fittings for airframe primes. Test and inspection firms near Berkeley and Hazelwood. Tooling suppliers, harness builders, and engineering services outfits in the Boeing supply chain, plus the smaller firms feeding Whiteman and Fort Leonard Wood work. If you have fewer than 25 people, one person handling IT part time, and a prime asking about your score, you are who we built this for.
Where the obligation actually stands
Third party certification is paused
The Phase 2 mechanism that was due from 10 November 2026 is on hold while the Department reviews it. That is the only thing that moved.
Your self assessment is not
Level 1 and Level 2 self assessment under DFARS 252.204-7021 has applied to covered solicitations since 10 November 2025, and a passing score remains a condition of award.
DFARS 252.204-7012 still applies
Safeguarding covered defense information and reporting cyber incidents did not change.
NIST SP 800-171 Rev 2 is still the standard
All 110 controls, assessed against the 800-171A objectives.
Flow down is unchanged
Primes remain responsible for the cybersecurity requirements that apply to subcontracted work.
The affirmation is still signed
Your Affirming Official affirms the score in SPRS annually. Signing an inflated score is a False Claims Act matter and it stays with you.
Where Missouri suppliers actually are
Here is where the obligation stands. Third party certification is paused. The self assessment obligation under DFARS 252.204-7021 never moved. Neither did DFARS 252.204-7012, and neither did NIST SP 800-171 Rev 2. If CUI touches your systems, you owe a current score in SPRS, a system security plan, and a plan of action with real dates. That was true last year and it is true today.
What to do first, and why the gap assessment is the gate
Start with a gap assessment, because the gate is accuracy. A score you cannot defend is worse than a low score you can. The assessment tells you which of the 110 controls you actually meet, what the honest number is, and what belongs in the plan of action. Everything after that is sequencing.
What we will not do
We will not take custody of your CUI. We will not sell you tools you do not need. We will not inflate your score to make a prime happy. We are a compliance firm, not a C3PAO, and we will not pretend otherwise.
Find out where you stand in Missouri.
No sales sequence, and no number put in front of you that we cannot defend.
If you are a defense supplier under 25 people, start with the grant. Cyber Grants Alliance, a nonprofit, awards a fully funded gap assessment. It costs you nothing and you are under no obligation to buy anything afterwards, from us or from anyone.