CMMC / North Carolina
CMMC Level 2 for North Carolina defense suppliers.
This page is for North Carolina suppliers holding DoD contracts near Fort Bragg and Camp Lejeune. Machine shops around Fayetteville. Electrical and facilities contractors around Jacksonville. Small IT providers, logistics firms, and engineering shops in the Triangle that ship parts or services onto those installations. Usually fewer than 25 people, often with no full time security staff.
Where the obligation actually stands
Third party certification is paused
The Phase 2 mechanism that was due from 10 November 2026 is on hold while the Department reviews it. That is the only thing that moved.
Your self assessment is not
Level 1 and Level 2 self assessment under DFARS 252.204-7021 has applied to covered solicitations since 10 November 2025, and a passing score remains a condition of award.
DFARS 252.204-7012 still applies
Safeguarding covered defense information and reporting cyber incidents did not change.
NIST SP 800-171 Rev 2 is still the standard
All 110 controls, assessed against the 800-171A objectives.
Flow down is unchanged
Primes remain responsible for the cybersecurity requirements that apply to subcontracted work.
The affirmation is still signed
Your Affirming Official affirms the score in SPRS annually. Signing an inflated score is a False Claims Act matter and it stays with you.
Where North Carolina suppliers actually are
Third party certification is paused. That pause did not touch your self assessment obligation under DFARS 252.204-7021, and it did not touch DFARS 252.204-7012 or NIST SP 800-171 Rev 2. If your contract carries those clauses, you owe a current score in SPRS, a system security plan, and a plan of action with real dates. Contracting officers still check, and primes still ask.
What to do first, and why the gap assessment is the gate
If you have fewer than 25 employees, start by drawing the boundary. Write down where federal contract information and controlled unclassified information actually sit, which is usually email, one file share, and a handful of laptops. Then run a gap assessment against all 110 controls. That assessment is the gate. Your SPRS score, your remediation order, and your budget all come out of it. Guessing the score is the most common way a small supplier gets exposed later.
What we will not do
We will not take custody of your CUI. You keep it, and the risk stays inside your own boundary. We are not a C3PAO and we do not perform certification assessments. We will not tell you CMMC went away. We will not sell you tools you do not need, and we will not write a score you cannot defend.
Find out where you stand in North Carolina.
No sales sequence, and no number put in front of you that we cannot defend.
If you are a defense supplier under 25 people, start with the grant. Cyber Grants Alliance, a nonprofit, awards a fully funded gap assessment. It costs you nothing and you are under no obligation to buy anything afterwards, from us or from anyone.