CAPITALCYBER

CMMC / Virginia

CMMC Level 2 for Virginia defense suppliers.

This page is for the small Virginia shops that sit one or two tiers below the primes. Ten people in Chantilly doing systems engineering support. A four person shop in Norfolk machining parts for a shipyard sub. An eight person software team in Arlington with a subcontract that came down through a large integrator. You hold CUI or you are about to, your contract carries DFARS 252.204-7012, and you do not have a compliance department. Virginia has more defense contractors than any other state, which means your prime has more replacements for you than you have contracts.

Where the obligation actually stands

Third party certification is paused

The Phase 2 mechanism that was due from 10 November 2026 is on hold while the Department reviews it. That is the only thing that moved.

Your self assessment is not

Level 1 and Level 2 self assessment under DFARS 252.204-7021 has applied to covered solicitations since 10 November 2025, and a passing score remains a condition of award.

DFARS 252.204-7012 still applies

Safeguarding covered defense information and reporting cyber incidents did not change.

NIST SP 800-171 Rev 2 is still the standard

All 110 controls, assessed against the 800-171A objectives.

Flow down is unchanged

Primes remain responsible for the cybersecurity requirements that apply to subcontracted work.

The affirmation is still signed

Your Affirming Official affirms the score in SPRS annually. Signing an inflated score is a False Claims Act matter and it stays with you.

Where Virginia suppliers actually are

Here is where the obligation stands. Third party certification is paused. The self assessment obligation under DFARS 252.204-7021 did not move. Neither did DFARS 252.204-7012 or NIST SP 800-171 Rev 2. Your score in SPRS is still a representation to the government, and a wrong one carries consequences a pause does not soften.

What to do first, and why the gap assessment is the gate

If you have fewer than 25 people, start with a gap assessment against all 110 controls before you buy anything. That is the gate. Without it you cannot score honestly, you cannot build a defensible System Security Plan, and you cannot write a POA&M that holds up under scrutiny. Tooling bought before the assessment is usually the wrong tooling.

What we will not do

We will not take custody of your CUI. We will not call ourselves a C3PAO or an accredited assessor, because we are not one. We will not sell you a platform you do not need, and we will not tell you a control is met when it is not.

Find out where you stand in Virginia.

No sales sequence, and no number put in front of you that we cannot defend.

If you are a defense supplier under 25 people, start with the grant. Cyber Grants Alliance, a nonprofit, awards a fully funded gap assessment. It costs you nothing and you are under no obligation to buy anything afterwards, from us or from anyone.