CMMC Compliance for Nevada Defense Contractors
CMMC (Cybersecurity Maturity Model Certification) is the Department of War's program for verifying that defense contractors protect Federal Contract Information and Controlled Unclassified Information. Third-party Phase II certification is suspended, but self-assessments, SPRS affirmations and NIST SP 800-171 still apply. Our managed security plans support many of the technical controls involved for Northern Nevada defense suppliers.
Phase II is suspended, but core requirements still apply.
On July 13, 2026, the Department of War (formerly the Department of Defense) suspended CMMC Phase II, which would have required third-party (C3PAO) Level 2 certifications as a condition of award starting November 10, 2026. It also put later phases on hold and launched a CMMC Reform Task Force. The task force delivered its report around September 11, 2026, but it has not been published, and no end date for the suspension has been announced.1
Still required today:
- CMMC Level 1 and Level 2 self-assessments where contracts require them
- Current status and affirmations in the Supplier Performance Risk System (SPRS)
- DFARS 252.204-7012, including cyber incident reporting and cloud security requirements
- NIST SP 800-171 Rev. 2 for contractors handling CUI
- Selected government-led assessments, which the department says will continue
CMMC Level 1 vs Level 2 vs Level 3.
| Level | Protects | Requirements | Assessment |
|---|---|---|---|
| Level 1 | Federal Contract Information (FCI) | 15 basic safeguarding requirements | Annual self-assessment and affirmation |
| Level 2 | Controlled Unclassified Information (CUI) | 110 requirements of NIST SP 800-171 Rev. 2 | Self-assessment, or C3PAO assessment (C3PAO requirement suspended with Phase II) |
| Level 3 | CUI in the highest-priority programs | Level 2 plus selected NIST SP 800-172 requirements | Government-led assessment |
FCI vs CUI
Federal Contract Information is non-public information provided by or generated for the government under a contract. Controlled Unclassified Information is a narrower, more sensitive category that requires specific safeguarding, such as technical drawings and specifications. Which one you handle decides whether Level 1 or Level 2 applies.
Your SPRS score
Contractors handling CUI score themselves against the 110 NIST SP 800-171 requirements using the DoD assessment methodology. A perfect score is 110, and missing controls subtract points, so scores can go well below zero. Under CMMC, a Level 2 self-assessment needs a score of at least 88 to reach conditional status with a plan of action. Contracting officers check SPRS, primes often ask suppliers to confirm a current assessment, and an inaccurate affirmation creates legal risk.
A real issue for the local supply chain.
Northern Nevada's defense supply chain includes manufacturers and service companies in Reno, at the Tahoe-Reno Industrial Center and in Sparks, along with suppliers to larger aerospace and defense primes. CMMC clauses flow down from primes to their subcontractors, so even a small machine shop can find a CMMC requirement in a purchase order.
See how this fits with plant floor and OT security on our cybersecurity for manufacturers page.
Where our plans support CMMC.
Our plans support some NIST SP 800-171 requirement families:
- Access control and identification: zero trust architecture with MFA and least privilege
- Audit and accountability: managed SIEM
- System and information integrity: EDR with 24/7/365 MDR
- Awareness and training: security awareness training
- Incident response: incident response
- Vulnerability scanning: vulnerability management (SecurityPlus)
Other families, such as physical protection, media protection, personnel security and configuration management, depend on your own policies, facilities and IT practices. Our vCISO guidance can advise on priorities. We are not a C3PAO and do not issue certifications.
This page is general information about a program that is changing, not legal or contracting advice.
CMMC FAQ
Find out where your business is exposed.
Book a free, comprehensive cybersecurity risk assessment. See where your business is exposed and what to fix first. No cost, no contract.