CAPITALCYBER

CMMC / Pennsylvania

CMMC Level 2 for Pennsylvania defense suppliers.

This page is for the Pennsylvania shops that already hold defense work. Precision machining suppliers in Erie, Lancaster County, and the Pittsburgh corridor. Shipbuilding and repair suppliers feeding the Philadelphia yards and the Delaware River trade. Firms under 25 people, often with no full time IT person, where the owner or the quality manager also owns the contract clauses.

Where the obligation actually stands

Third party certification is paused

The Phase 2 mechanism that was due from 10 November 2026 is on hold while the Department reviews it. That is the only thing that moved.

Your self assessment is not

Level 1 and Level 2 self assessment under DFARS 252.204-7021 has applied to covered solicitations since 10 November 2025, and a passing score remains a condition of award.

DFARS 252.204-7012 still applies

Safeguarding covered defense information and reporting cyber incidents did not change.

NIST SP 800-171 Rev 2 is still the standard

All 110 controls, assessed against the 800-171A objectives.

Flow down is unchanged

Primes remain responsible for the cybersecurity requirements that apply to subcontracted work.

The affirmation is still signed

Your Affirming Official affirms the score in SPRS annually. Signing an inflated score is a False Claims Act matter and it stays with you.

Where Pennsylvania suppliers actually are

Here is where the obligation stands. Third party certification is paused. That pause does not touch you. The self assessment obligation under DFARS 252.204-7021 never moved. Neither did DFARS 252.204-7012 or NIST SP 800-171 Rev 2. If you hold covered defense information, you still owe a current score in SPRS, a System Security Plan, and a plan for open items.

What to do first, and why the gap assessment is the gate

Start with a gap assessment, not with tools. First define what CUI you actually receive and where it lives. Drawings from a prime, technical data packages, marked files sitting in email. Then score the 110 controls against evidence you can show. The gap assessment is the gate because the SPRS score is a representation to the government. A number with no evidence behind it is the real exposure, not a low score.

What we will not do

Here is what we will not do. We will not take custody of your CUI, and we do not want it. We will not call ourselves a C3PAO or an accredited assessor, because we are a compliance firm. We will not write a score we cannot evidence, and we will not sell you a platform you do not need.

Find out where you stand in Pennsylvania.

No sales sequence, and no number put in front of you that we cannot defend.

If you are a defense supplier under 25 people, start with the grant. Cyber Grants Alliance, a nonprofit, awards a fully funded gap assessment. It costs you nothing and you are under no obligation to buy anything afterwards, from us or from anyone.