CMMC / Ohio
CMMC Level 2 for Ohio defense suppliers.
This page is for Ohio suppliers who hold a DoD contract or subcontract and handle controlled unclassified information on their own systems. Machine shops in Dayton feeding Wright-Patterson programs. Second and third tier aerospace parts makers around Cincinnati, Columbus, and Cleveland. Job shops that took on a prime flowdown clause and now have DFARS language in a contract they signed two years ago. Most have fewer than 25 people, one person handling IT alongside another job, and no security staff at all.
Where the obligation actually stands
Third party certification is paused
The Phase 2 mechanism that was due from 10 November 2026 is on hold while the Department reviews it. That is the only thing that moved.
Your self assessment is not
Level 1 and Level 2 self assessment under DFARS 252.204-7021 has applied to covered solicitations since 10 November 2025, and a passing score remains a condition of award.
DFARS 252.204-7012 still applies
Safeguarding covered defense information and reporting cyber incidents did not change.
NIST SP 800-171 Rev 2 is still the standard
All 110 controls, assessed against the 800-171A objectives.
Flow down is unchanged
Primes remain responsible for the cybersecurity requirements that apply to subcontracted work.
The affirmation is still signed
Your Affirming Official affirms the score in SPRS annually. Signing an inflated score is a False Claims Act matter and it stays with you.
Where Ohio suppliers actually are
Here is where the obligation stands. Third party certification assessments are paused. The self assessment obligation under DFARS 252.204-7021 never moved. DFARS 252.204-7012 still applies, NIST SP 800-171 Rev 2 still applies, and your score in the Supplier Performance Risk System is still what a contracting officer sees. A paused certification program does not pause a clause already in your contract. If your last score was posted from an estimate, that is the exposure to address now.
What to do first, and why the gap assessment is the gate
Start with a gap assessment against all 110 controls. It is the gate because everything downstream depends on it. Your SPRS score, your System Security Plan, your plan of action, and your budget all come out of that one document. Guessing at the score first and building evidence later is how suppliers end up with a number they cannot defend.
What we will not do
What we will not do. We will not take custody of your CUI. We will not sell you tools you do not need. We are a compliance firm, not a C3PAO, and we will not tell you we can certify you.
Find out where you stand in Ohio.
No sales sequence, and no number put in front of you that we cannot defend.
If you are a defense supplier under 25 people, start with the grant. Cyber Grants Alliance, a nonprofit, awards a fully funded gap assessment. It costs you nothing and you are under no obligation to buy anything afterwards, from us or from anyone.