CAPITALCYBER

CMMC / Texas

CMMC Level 2 for Texas defense suppliers.

This page is for the small shops that keep Texas aviation and ground systems work moving. Machine shops and harness builders in the Fort Worth corridor. Avionics and sustainment vendors around San Antonio. Firms holding subcontracts on missile and vehicle programs managed out of Huntsville. Fewer than 25 people, one person wearing the IT hat, and a prime asking for a score.

Where the obligation actually stands

Third party certification is paused

The Phase 2 mechanism that was due from 10 November 2026 is on hold while the Department reviews it. That is the only thing that moved.

Your self assessment is not

Level 1 and Level 2 self assessment under DFARS 252.204-7021 has applied to covered solicitations since 10 November 2025, and a passing score remains a condition of award.

DFARS 252.204-7012 still applies

Safeguarding covered defense information and reporting cyber incidents did not change.

NIST SP 800-171 Rev 2 is still the standard

All 110 controls, assessed against the 800-171A objectives.

Flow down is unchanged

Primes remain responsible for the cybersecurity requirements that apply to subcontracted work.

The affirmation is still signed

Your Affirming Official affirms the score in SPRS annually. Signing an inflated score is a False Claims Act matter and it stays with you.

Where Texas suppliers actually are

Here is where the obligation stands. Third party certification is paused. The self assessment obligation under DFARS 252.204-7021 never moved. Neither did DFARS 252.204-7012 or NIST SP 800-171 Rev 2. Your SPRS score is still the number your prime and your contracting officer can see, and it is still dated.

What to do first, and why the gap assessment is the gate

Start with a gap assessment against all 110 controls, scored the way the DoD scores it. That is the gate. Until you know which controls are met, partially met, or not met, every dollar you spend on tools is a guess. The assessment gives you a defensible score, a System Security Plan that matches how you actually operate, and a POA&M with dates you can hold.

What we will not do

We will not take custody of your CUI. Your data stays in your environment, and that keeps your scope small and your risk with you. We will not call ourselves a C3PAO or an accredited assessor, because we are not one. We are a compliance firm. We will not sell you a platform you do not need, and we will not post your score for you. You sign it. You own it.

Find out where you stand in Texas.

No sales sequence, and no number put in front of you that we cannot defend.

If you are a defense supplier under 25 people, start with the grant. Cyber Grants Alliance, a nonprofit, awards a fully funded gap assessment. It costs you nothing and you are under no obligation to buy anything afterwards, from us or from anyone.