Defense Industrial Base · CMMC

CMMC compliance for Texas defense contractors

CMMC Phase II third-party certification was suspended in July 2026, but your obligations did not go away, you still must self-assess to NIST SP 800-171 Rev 2 and protect CUI under DFARS 252.204-7012. Tynrose Secure takes Texas defense suppliers from self-assessment to genuinely ready, implementing the controls and assembling the evidence, in one relationship.

In plain English

What is CMMC Level 2?

CMMC Level 2 is the "Advanced" cybersecurity level for defense contractors, built on the 110 controls of NIST SP 800-171. It applies to companies that handle Controlled Unclassified Information (CUI). On July 13, 2026 the Department of War (formerly the DoD) suspended the Phase II third-party (C3PAO) certification mandate pending a 60-day reform review, but self-assessment against NIST 800-171 Rev 2 and DFARS 252.204-7012 obligations remain in force.

  • 110 Level 2 controls
  • NIST 800-171 Rev 2 Basis
  • Suspended · Jul 2026 Phase II certification
  • DFARS 7012 Still required
Who this is for

Does this apply to you?

  • Aerospace components and defense electronics manufacturers
  • Government IT and engineering services firms
  • Subcontractors to primes such as Lockheed, Raytheon, L3Harris, and SAIC
  • Any company that receives documents marked CUI, FOUO, or with distribution restrictions
  • Companies handling Federal Contract Information (FCI) — Level 1 minimum
Key dates

The timeline that matters

  1. Nov 10, 2025 CMMC Phase 1 active — self-assessment requirements appear in new defense solicitations.
  2. Jul 13, 2026 The Department of War suspends CMMC Phase II (the third-party C3PAO certification mandate) and opens a 60-day reform review.
  3. Interim (now) Contractors self-assess to NIST SP 800-171 Rev 2; DFARS 252.204-7012 obligations to safeguard CUI remain in force.
How Tynrose Secure helps

Controls and documentation, handled together

Most firms do the technical work or the compliance paperwork. We do both, in one relationship, so nothing falls between IT and the auditor.

Gap assessment & SPRS score

We benchmark you against all 110 NIST 800-171 controls, define the assessment boundary, and give you an accurate SPRS score before you commit to a path.

SSP, POA&M & control implementation

A System Security Plan that reflects reality, a prioritized Plan of Action & Milestones, and hands-on engineering to implement access control, encryption, logging, and MFA.

Defense-grade platform

CMMC Level 2 environments run on our FedRAMP-aligned platform with GCC High support, so CUI is handled in an enclave built for it.

Self-assessment & staying ready

We stand up your NIST 800-171 Rev 2 self-assessment and keep the evidence current, so you satisfy today’s requirement and are ready the moment the reformed program reinstates a formal assessment.

FAQ

CMMC 2.0 questions, answered

Is CMMC still required in 2026?

On July 13, 2026 the Department of War suspended CMMC Phase II — the third-party (C3PAO) certification requirement that had been set for November 10, 2026 — pending a 60-day reform review. Your obligations remain: you must still self-assess against NIST SP 800-171 Rev 2 and protect covered defense information under DFARS 252.204-7012. The certification mandate is paused; the security requirements are not.

Do I still need to protect CUI?

Yes. If your company handles Controlled Unclassified Information (CUI) for a defense contract, DFARS 252.204-7012 still requires you to safeguard it and implement NIST SP 800-171 Rev 2. A quick check: do you receive documents marked CUI, FOUO, or with distribution restrictions? If yes, the 800-171 controls apply to you now.

Should we pause our CMMC preparation?

No. The underlying NIST 800-171 Rev 2 self-assessment and DFARS 252.204-7012 obligations remain in force, and the 60-day review is expected to return with reformed, likely reinstated requirements. Staying ready now is far cheaper than restarting under pressure later, and it keeps your SPRS score current when primes ask.

Does Tynrose Secure perform the certification?

When third-party certification is in effect it is performed by an independent C3PAO — that mandate is currently suspended. Either way, Tynrose Secure gets you genuinely ready (controls plus documentation), runs your NIST 800-171 Rev 2 self-assessment, and supports any government-led assessment.

No cost, no pitch

See where you stand on CMMC 2.0

Book a complimentary readiness consultation with a senior engineer. We map your gaps and the realistic path to close them.