CMMC / Utah
CMMC Level 2 for Utah defense suppliers.
This page is for the small shops in the Hill Air Force Base supply chain. Machine shops in Clearfield and Ogden turning sustainment parts. Electronics and cable builders along the Wasatch Front. Software and engineering support firms holding a few subcontracts through a prime at the base. If you have fewer than 25 employees, no full time IT staff, and a contract that carries DFARS 252.204-7012, you are in scope and you are the reason this page exists.
Where the obligation actually stands
Third party certification is paused
The Phase 2 mechanism that was due from 10 November 2026 is on hold while the Department reviews it. That is the only thing that moved.
Your self assessment is not
Level 1 and Level 2 self assessment under DFARS 252.204-7021 has applied to covered solicitations since 10 November 2025, and a passing score remains a condition of award.
DFARS 252.204-7012 still applies
Safeguarding covered defense information and reporting cyber incidents did not change.
NIST SP 800-171 Rev 2 is still the standard
All 110 controls, assessed against the 800-171A objectives.
Flow down is unchanged
Primes remain responsible for the cybersecurity requirements that apply to subcontracted work.
The affirmation is still signed
Your Affirming Official affirms the score in SPRS annually. Signing an inflated score is a False Claims Act matter and it stays with you.
Where Utah suppliers actually are
Here is where things stand. Third party certification is paused. The self assessment obligation under DFARS 252.204-7021 never moved, and neither did DFARS 252.204-7012 or NIST SP 800-171 Rev 2. Your score in the Supplier Performance Risk System is still expected to be current and accurate. A prime can ask for it, and a contracting officer can act on it. Nothing about the pause changes what you already agreed to when you signed.
What to do first, and why the gap assessment is the gate
Start with a gap assessment against all 110 controls. That is the gate. Until you know your real score and your real system boundary, every dollar you spend on tools is a guess, and every number you post is exposure. The assessment gives you a defensible score, a System Security Plan, and a plan of action with dates.
What we will not do
We will not take custody of your CUI. We will not sell you a tool stack you do not need. We will not post a score for you. We are a compliance firm, not a C3PAO, and we will never certify you.
Find out where you stand in Utah.
No sales sequence, and no number put in front of you that we cannot defend.
If you are a defense supplier under 25 people, start with the grant. Cyber Grants Alliance, a nonprofit, awards a fully funded gap assessment. It costs you nothing and you are under no obligation to buy anything afterwards, from us or from anyone.