Tech Insights

In the Defense Supply Chain? CMMC Is Here and “We’ll Deal With It Later” Won’t Work

In the Defense Supply Chain? CMMC Is Here and "We'll Deal With It Later" Won't Work

“We just make brackets for a company that sells to the Navy. CMMC is their problem, not ours.” — a Houston machine shop owner, about nine months before a contract he’d held for years quietly went to a competitor who could prove compliance.

That sentence is one of the most expensive misunderstandings in the Houston defense and aerospace supply chain right now. If you make parts, write code, provide engineering, do logistics, or supply anything that ends up inside a Department of Defense program — even three or four tiers down from a prime — the Cybersecurity Maturity Model Certification (CMMC) program is your problem too. And the clock that says you can “deal with it later” ran out a while ago.

What CMMC Actually Is (In Plain English)

CMMC is the Department of Defense’s way of stopping itself from handing sensitive information to companies that can’t protect it. For years, the rule was essentially “promise us you’re secure.” Companies promised. A lot of them weren’t. Sensitive defense data leaked out the bottom of the supply chain for years, and DoD got tired of it.

So CMMC changes the deal: instead of promising you’re secure, you now have to prove it — with documented controls, real technical safeguards, and in many cases an outside assessment.

This is not a future idea. The CMMC Program final rule (32 CFR) became effective December 16, 2024. The companion contracting rule (the 48 CFR / DFARS side) is what puts CMMC requirements directly into DoD contracts, and those requirements are being phased into new contracts now. In practice, that means the language is starting to show up where it matters most: in the deals you actually want to win.

The Three Levels

  • Level 1 (Basic). For companies that handle Federal Contract Information (FCI) — basic, non-public info generated under a federal contract. This is a set of foundational safeguards and is typically self-assessed.
  • Level 2. For companies that handle Controlled Unclassified Information (CUI). This level aligns with NIST SP 800-171 and its 110 security requirements. Depending on the contract, Level 2 may require a third-party assessment by a certified C3PAO, though some cases allow self-assessment.
  • Level 3. The highest tier, for the most sensitive programs, with additional government-led assessment. Most Houston small businesses won’t live here — but plenty live squarely at Level 2.

The two words that decide your fate are FCI and CUI. If CUI touches your systems — drawings, specs, technical data, certain export-controlled information — you are almost certainly looking at Level 2.

“I’m Just a Sub” Is Not an Exemption

Here is the part that catches small shops off guard: CMMC requirements flow down. A prime contractor that must meet a level is required to push the appropriate requirements down to the subcontractors who handle that same information. If a prime hands you CUI to do your job, you inherit the obligation that comes with it.

So the comforting story — “the prime is huge, they’ll handle the compliance, we just deliver our part” — gets it exactly backwards. The prime handling compliance is precisely why they will require you to handle yours. No prime is going to risk their contract by funneling protected data to a sub who can’t demonstrate the controls. The moment they have a compliant alternative, the non-compliant sub becomes a liability they drop.

In a region like Houston — with a deep energy, aerospace, and defense supply chain — that’s not hypothetical. The small specialty shops are often the ones holding sensitive technical data, and often the ones least prepared to protect it.

What Level 2 Really Takes

People hear “110 requirements” and picture a checklist they can knock out in a weekend. It isn’t. NIST SP 800-171 is a comprehensive security posture covering how your whole environment is built, run, and monitored. A real Level 2 effort includes things like:

  • Access control — who can touch CUI, under what conditions, and proving the rest of the company cannot.
  • Multi-factor authentication (MFA) across the systems that matter — not just email, but the places CUI actually lives.
  • Encryption of CUI at rest and in transit, using approved methods.
  • Audit logging — capturing who did what, when, and being able to produce those logs on demand.
  • Configuration management — knowing and controlling how your systems are set up, instead of every machine being its own snowflake.
  • Incident response — a real, written, practiced plan for when something goes wrong.

That’s the technical side. Then there’s the paperwork that makes it official:

  1. A System Security Plan (SSP). A written description of your environment and exactly how you meet each requirement. No SSP, no credible compliance — full stop.
  2. A Plan of Action & Milestones (POA&M). An honest list of the gaps you haven’t closed yet, with dates and owners for closing them.
  3. A SPRS score. Self-assessment scores get reported into the DoD’s Supplier Performance Risk System (SPRS). That score is visible to the government and, effectively, to the primes deciding who to trust.

And in many Level 2 cases, all of that gets verified by a third-party assessment from a certified C3PAO (a CMMC Third-Party Assessment Organization). That’s an important line to be clear about: Aspendora is not your assessor. We implement and document the controls and get you assessment-ready; a certified C3PAO performs the formal Level 2 assessment. Anyone who claims to both build your controls and certify them is someone to walk away from.

Why “We’ll Deal With It Later” Fails

1. It takes months — often a year.

Getting a typical small-business setup — a mix of consumer-grade tools, shared logins, and “it’s always worked fine” habits — up to a passing 800-171 posture is not a quick project. You have to find where CUI actually lives, close real technical gaps, deploy new controls, write the documentation, and then live with those controls long enough to prove they work. That timeline doesn’t compress just because a contract deadline appears.

2. No score means no award.

When CMMC language is in a solicitation, missing or insufficient compliance isn’t a paperwork ding you fix later — it can mean you’re not eligible for the award. For existing work, it can mean you lose your seat at the table when contracts renew. “Later” is exactly when you discover you needed it “already.”

3. Faking your SPRS score is a legal landmine.

Some businesses are tempted to enter an optimistic SPRS number and sort out reality later. Do not. A self-assessment score is a representation to the federal government. An inflated or false score can create serious legal exposure — including under the False Claims Act and whistleblower (qui tam) actions, where insiders can sue on the government’s behalf. This is squarely a legal question, so talk to qualified counsel — Aspendora is not a law firm and does not give legal advice. But the short version is blunt: a fake score is a far bigger risk than an honest POA&M.

What to Do Now

The good news: this is a knowable, finishable project when you start early and do it in the right order.

  1. Scope your environment. Figure out where FCI and CUI actually flow — which machines, which apps, which people, which email threads. You can’t protect what you haven’t mapped.
  2. Gap-assess against NIST SP 800-171. Measure your real environment against all 110 requirements and get an honest score, not a hopeful one.
  3. Build the SSP and POA&M. Document what you have, and lay out a credible, dated plan for the gaps.
  4. Remediate. Deploy the controls — MFA, encryption, access control, logging, configuration management, incident response — and the ongoing monitoring that keeps them honest.
  5. Get assessment-ready. Reach the posture where a C3PAO assessment is something you walk into confident, not dreading.

This is the work Aspendora does. Our compliance services turn 800-171 from an abstract list into implemented, documented, monitored controls — making your compliance real, not just claimed on paper. The technical backbone of that — MFA, encryption, segmentation, logging, monitoring — comes through our network security and managed IT services work, so the controls don’t just exist on assessment day — they keep running. This is professional, ongoing engineering, and we charge professional rates for it. There’s no free setup and no free support — because half-built compliance is worse than none.

The Bottom Line

CMMC is no longer theoretical, and being a small subcontractor doesn’t exempt you — it’s often what puts you directly in scope. The companies that start now will spend the next stretch methodically closing gaps. The ones who “deal with it later” will spend it watching contracts go to competitors who didn’t wait.

If your business is anywhere in the defense or aerospace supply chain — prime, sub, or sub-to-a-sub — start with a free 15-minute discovery call. We’ll talk through where CUI likely lives in your environment, what level you’re probably looking at, and a realistic path to assessment-ready. From there, see exactly what hands-on compliance work involves. The discovery call is the only free thing — the actual work of making you compliant is real engineering, priced accordingly. But it’s a far better conversation to have now than after you’ve lost the contract.

Aspendora Technologies provides cybersecurity, managed IT, and expert on-premise & open-source solutions to Houston-area small businesses since 2010.

Need IT Help?

Talk to a real Houston-based IT pro. 15 minutes, no pressure.

Schedule a Free Consultation