CMMC / Washington
CMMC Level 2 for Washington defense suppliers.
This page is for small suppliers around Puget Sound. The machine shop in Kent cutting aerospace structures for a Tier 1. The fabricator in Everett. The marine and ship repair firms working Bremerton and Bangor. Ten people, maybe twenty. One person who handles IT along with everything else, and a prime who has already asked what your score is.
Where the obligation actually stands
Third party certification is paused
The Phase 2 mechanism that was due from 10 November 2026 is on hold while the Department reviews it. That is the only thing that moved.
Your self assessment is not
Level 1 and Level 2 self assessment under DFARS 252.204-7021 has applied to covered solicitations since 10 November 2025, and a passing score remains a condition of award.
DFARS 252.204-7012 still applies
Safeguarding covered defense information and reporting cyber incidents did not change.
NIST SP 800-171 Rev 2 is still the standard
All 110 controls, assessed against the 800-171A objectives.
Flow down is unchanged
Primes remain responsible for the cybersecurity requirements that apply to subcontracted work.
The affirmation is still signed
Your Affirming Official affirms the score in SPRS annually. Signing an inflated score is a False Claims Act matter and it stays with you.
Where Washington suppliers actually are
Here is where the obligation stands. Third party certification is paused. The pause is real, and it is not relief. The self assessment obligation under DFARS 252.204-7021 never moved. Neither did DFARS 252.204-7012 or NIST SP 800-171 Rev 2. If your contract carries those clauses, you owe a current and accurate score in SPRS today.
What to do first, and why the gap assessment is the gate
Start with a gap assessment against all 110 controls. Not a policy pack, not a tool purchase. The gap assessment is the gate because a score you cannot evidence is a false statement risk, and because it tells you exactly which controls you fail, what each fix costs, and what order to do them in. Most shops your size find the work is mainly documentation and a short list of configuration changes.
What we will not do
What we will not do. We will not take custody of your CUI, because your data belongs in your environment and not in ours. We will not post a score on your behalf. We will not sign an assessment as a C3PAO, because we are a compliance firm and not an accredited assessor. We will not sell you tools you do not need.
Find out where you stand in Washington.
No sales sequence, and no number put in front of you that we cannot defend.
If you are a defense supplier under 25 people, start with the grant. Cyber Grants Alliance, a nonprofit, awards a fully funded gap assessment. It costs you nothing and you are under no obligation to buy anything afterwards, from us or from anyone.