CMMC Compliance for Nevada Defense Contractors

CMMC (Cybersecurity Maturity Model Certification) is the Department of War's program for verifying that defense contractors protect Federal Contract Information and Controlled Unclassified Information. Third-party Phase II certification is suspended, but self-assessments, SPRS affirmations and NIST SP 800-171 still apply. Our managed security plans support many of the technical controls involved for Northern Nevada defense suppliers.

Phase II is suspended, but core requirements still apply.

On July 13, 2026, the Department of War (formerly the Department of Defense) suspended CMMC Phase II, which would have required third-party (C3PAO) Level 2 certifications as a condition of award starting November 10, 2026. It also put later phases on hold and launched a CMMC Reform Task Force. The task force delivered its report around September 11, 2026, but it has not been published, and no end date for the suspension has been announced.1

Still required today:

  • CMMC Level 1 and Level 2 self-assessments where contracts require them
  • Current status and affirmations in the Supplier Performance Risk System (SPRS)
  • DFARS 252.204-7012, including cyber incident reporting and cloud security requirements
  • NIST SP 800-171 Rev. 2 for contractors handling CUI
  • Selected government-led assessments, which the department says will continue

CMMC Level 1 vs Level 2 vs Level 3.

CMMC levels under 32 CFR Part 170
LevelProtectsRequirementsAssessment
Level 1Federal Contract Information (FCI)15 basic safeguarding requirementsAnnual self-assessment and affirmation
Level 2Controlled Unclassified Information (CUI)110 requirements of NIST SP 800-171 Rev. 2Self-assessment, or C3PAO assessment (C3PAO requirement suspended with Phase II)
Level 3CUI in the highest-priority programsLevel 2 plus selected NIST SP 800-172 requirementsGovernment-led assessment

FCI vs CUI

Federal Contract Information is non-public information provided by or generated for the government under a contract. Controlled Unclassified Information is a narrower, more sensitive category that requires specific safeguarding, such as technical drawings and specifications. Which one you handle decides whether Level 1 or Level 2 applies.

Your SPRS score

Contractors handling CUI score themselves against the 110 NIST SP 800-171 requirements using the DoD assessment methodology. A perfect score is 110, and missing controls subtract points, so scores can go well below zero. Under CMMC, a Level 2 self-assessment needs a score of at least 88 to reach conditional status with a plan of action. Contracting officers check SPRS, primes often ask suppliers to confirm a current assessment, and an inaccurate affirmation creates legal risk.

A real issue for the local supply chain.

Northern Nevada's defense supply chain includes manufacturers and service companies in Reno, at the Tahoe-Reno Industrial Center and in Sparks, along with suppliers to larger aerospace and defense primes. CMMC clauses flow down from primes to their subcontractors, so even a small machine shop can find a CMMC requirement in a purchase order.

See how this fits with plant floor and OT security on our cybersecurity for manufacturers page.

Where our plans support CMMC.

Our plans support some NIST SP 800-171 requirement families:

Other families, such as physical protection, media protection, personnel security and configuration management, depend on your own policies, facilities and IT practices. Our vCISO guidance can advise on priorities. We are not a C3PAO and do not issue certifications.

This page is general information about a program that is changing, not legal or contracting advice.

CMMC FAQ

CMMC has three levels. Level 1 covers the 15 basic safeguarding requirements for Federal Contract Information and is met through an annual self-assessment. Level 2 covers the 110 requirements of NIST SP 800-171 Rev. 2 for Controlled Unclassified Information and is met through a self-assessment or, for many contracts, a third-party (C3PAO) assessment. Level 3 adds requirements from NIST SP 800-172 and is assessed by the government.
Level 1 is met by self-assessment rather than certification, so the question is really who needs CMMC. The answer is defense contractors and subcontractors whose contracts include a CMMC requirement, which covers companies that handle Federal Contract Information or Controlled Unclassified Information for the Department of War. CMMC requirements flow down from prime contractors to their suppliers, so a machine shop or software vendor several tiers down can be affected.
Yes. On July 13, 2026 the Department of War suspended Phase II, which would have required third-party Level 2 certifications starting November 10, 2026. As of October 2026 the suspension remains in place. Contractors must still complete CMMC self-assessments, keep current status and affirmations in SPRS, and comply with DFARS 252.204-7012 and NIST SP 800-171 Rev. 2. The department has said it will keep enforcing those requirements through self-assessments and selected government-led assessments.
NIST SP 800-171 Rev. 2 is the set of 110 security requirements behind CMMC Level 2. DFARS 252.204-7012 already required contractors handling CUI to implement it before CMMC existed. Your SPRS score measures how many of those requirements you meet.
Controlled Unclassified Information is government information that is not classified but still requires safeguarding, such as technical drawings, specifications and certain export-controlled data. Federal Contract Information (FCI) is a broader, lower-sensitivity category covering information provided by or generated for the government under a contract that is not intended for public release.
For Northern Nevada manufacturers and service companies, CMMC readiness keeps the door open to defense work and the supply chains of larger primes. The same controls also reduce the risk of ransomware and data theft, whatever the regulatory timeline does.

Find out where your business is exposed.

Book a free, comprehensive cybersecurity risk assessment. See where your business is exposed and what to fix first. No cost, no contract.