CAPITALCYBER

CMMC / New York

CMMC Level 2 for New York defense suppliers.

This page is for the small shops upstate that build the electronics and sensors inside somebody else's program. Circuit board assembly in the Hudson Valley. Optics and imaging work around Rochester. RF and test equipment suppliers near Binghamton and Syracuse. You may hold twelve people and one prime contract, and you may be a third tier supplier who has never spoken to a contracting officer directly. If DFARS 252.204-7012 is in your contract or your purchase order flows it down, this applies to you.

Where the obligation actually stands

Third party certification is paused

The Phase 2 mechanism that was due from 10 November 2026 is on hold while the Department reviews it. That is the only thing that moved.

Your self assessment is not

Level 1 and Level 2 self assessment under DFARS 252.204-7021 has applied to covered solicitations since 10 November 2025, and a passing score remains a condition of award.

DFARS 252.204-7012 still applies

Safeguarding covered defense information and reporting cyber incidents did not change.

NIST SP 800-171 Rev 2 is still the standard

All 110 controls, assessed against the 800-171A objectives.

Flow down is unchanged

Primes remain responsible for the cybersecurity requirements that apply to subcontracted work.

The affirmation is still signed

Your Affirming Official affirms the score in SPRS annually. Signing an inflated score is a False Claims Act matter and it stays with you.

Where New York suppliers actually are

Here is where the obligation stands. Third party certification is paused. The self assessment obligation under DFARS 252.204-7021 never moved. Neither did DFARS 252.204-7012, and neither did NIST SP 800-171 Rev 2. Your score in the Supplier Performance Risk System is still a representation to the government. The pause changed who checks your work. It did not change the work.

What to do first, and why the gap assessment is the gate

If you have fewer than 25 people, do not start buying tools. Start by defining your CUI boundary, because every control after that depends on knowing what is in scope. Then run a gap assessment against all 110 controls. That is the gate. Without it your SPRS score is a guess, and a guessed score submitted as fact is the exposure.

What we will not do

We will not take custody of your CUI. We will not write your System Security Plan and hand it back as finished. We will not certify you, because no compliance firm can.

Find out where you stand in New York.

No sales sequence, and no number put in front of you that we cannot defend.

If you are a defense supplier under 25 people, start with the grant. Cyber Grants Alliance, a nonprofit, awards a fully funded gap assessment. It costs you nothing and you are under no obligation to buy anything afterwards, from us or from anyone.