Skip to content

Managed IT and Cybersecurity for Columbus Manufacturers

Your line runs on equipment older than your ERP, and the controller driving it will never take another patch. If you sell into the defense supply chain, a prime is now asking for an SPRS score and a CMMC status you are not sure how to produce. Both problems land on the same small IT budget.

What does CMMC actually require of a Columbus manufacturer right now?

The acquisition rule that puts CMMC into contracts took effect on November 10, 2025. Since then, a contracting officer can make CMMC status a condition of award, and the required level appears in the solicitation itself under provision DFARS 252.204-7025, Notice of CMMC Level Requirements, before you ever sign anything. What is in force today is Phase 1.

Level 1 applies when your contract carries the CMMC clause, DFARS 252.204-7021, and you handle Federal Contract Information. It is a self-assessment against the 15 safeguarding requirements in FAR 52.204-21(b)(1), with the result posted to the Supplier Performance Risk System and an affirmation filed. The recurring duty is bigger than most shops expect: you have to redo the self-assessment and repost it every year, not just re-sign last year’s affirmation. No plans of action are allowed at Level 1, so every requirement has to be met. Separately, those same FAR 52.204-21 safeguards apply to most contracts where your systems may hold FCI, with or without the CMMC clause. Acquisitions solely for commercially available off-the-shelf items are carved out, which matters if you sell catalog parts; the scope is set at FAR 4.1902. Standing alone, the safeguards carry no SPRS or affirmation duty.

Level 2 applies when you handle Controlled Unclassified Information. It covers all 110 requirements of NIST SP 800-171 Revision 2, self-assessed every three years, with the result posted to SPRS and an affirmation at completion and annually after that. Level 2 (Self) is the only Level 2 a contract can require today, because the July 13, 2026 memoranda bar program offices from designating Level 2 (C3PAO) or Level 3 (DIBCAC) on a requirement, and no waivers are being granted while the suspension lasts. The suspension stops the designation, not the status: the rule still provides for third-party assessment, so that discretion can return when the suspension lifts.

A third level, assessed by DCMA’s DIBCAC against 24 added requirements drawn from NIST SP 800-172, is reserved for DoD’s most critical programs and technologies. It was never designatable in Phase 1 and cannot be designated during the suspension. The levels, the 15, 110 and 24 counts, and the assessment types are all defined at 32 CFR 170.4 and 170.14. If a solicitation puts a level on you, read those sections, or send us the clause and we will read it with you.

The program is mid-change, and it is worth knowing exactly where. On July 13, 2026, the Department of War suspended Phase 2, the stage that would have required third-party certification by a C3PAO starting November 10, 2026, and held later milestones in abeyance while a CMMC Reform Task Force reviews the program. The industry comment window closed on August 14, 2026, the Task Force’s 60-day review runs to roughly September 11, and the department has said further guidance follows at its conclusion. Phase 1 did not change. Contracting officers have been directed to strike suspended Level 2 and Level 3 certification requirements from existing solicitations and contracts by modification, but until that modification actually lands, the terms written into your award still bind you. Your obligations under DFARS 252.204-7012, your implementation of NIST SP 800-171 and your SPRS score all still apply. If someone tells you CMMC went away, read your contract before you believe it.

Our shop is a subcontractor, not a prime. Does CMMC still reach us?

It reaches you through your customer’s purchase order. DFARS 252.204-7012 flows down at every tier to subcontracts whose performance will involve covered defense information, and independently to subcontracts for operationally critical support, so a supplier can be caught by the clause without ever receiving a drawing. Under DFARS 252.204-7020, a prime cannot award a subcontract subject to NIST SP 800-171 unless you have completed at least a Basic assessment within the previous three years and posted the score. The pressure usually shows up as a questionnaire from a customer you have supplied for years, with a deadline attached.

The level you need depends on what actually lands in your systems, not on what a document is stamped. Federal Contract Information is information the government provided, or that you generated for the government under a contract, that is not intended for public release, and holding it puts you at Level 1. The definition at FAR 4.1901 carves out a few categories, including information the government has already released publicly and simple transactional data, so read it against your own records rather than assuming.

Drawings, specs and part data that are Controlled Unclassified Information put you at Level 2. CUI does not stop being CUI because a prime failed to mark it, so ask what the data is rather than what the stamp says. Which Level 2 you need also depends on the prime: normally Level 2 (Self), but a prime contract that itself carries a Level 2 (C3PAO) or Level 3 (DIBCAC) requirement sets Level 2 (C3PAO) as your flowdown floor. That distinction is on hold while third-party designations are suspended, and it comes back if they resume.

Sorting this out is a scoping exercise: which machines, file shares and mailboxes touch the data. Getting the scope wrong in either direction costs you. Too wide and you are hardening the whole plant for no reason. Too narrow and you are signing an affirmation that is inaccurate, and an affirmation is a formal statement to the government, not an internal note. Our cybersecurity and virtual CISO work covers the scoping, the control set and the documentation behind it.

How do you secure machines that cannot be patched?

Most plants have a controller, an HMI or a machine PC running something the vendor stopped supporting years ago, and you cannot replace it without replacing the machine around it. The answer is not to patch it. The answer is to make it unreachable from everything that does not need it. CISA’s Cross-Sector Cybersecurity Performance Goals treat this case as normal: where patching is not possible, or would substantially compromise availability or safety, you apply compensating controls such as segmentation and monitoring, and you record that you did.

In practice that means an accurate inventory of what is really sitting on the production network, a segmented design where the office VLAN and the plant floor are not the same broadcast domain, tight rules about which traffic crosses between them, and monitoring at that boundary. The failure we are designing against is an ordinary one: someone in accounting opens an attachment, and nothing in the network stops that from reaching the line. Managed IT and Network Operations Center work cover the ongoing side of this.

Why do attackers keep picking manufacturers?

Because it works. IBM’s 2026 X-Force Threat Index put manufacturing at the top of the most-attacked industry list for the fifth year running, at 27.7% of the incidents it observed, with data theft the most common goal. The logic is the downtime math you already know. When a line stops, the cost of not producing is large and immediate, so a manufacturer is more likely to pay fast. And a supplier holding drawings and process data on a file server is worth stealing from even when nothing gets encrypted.

That shapes the priorities. Backups have to be tested by restoring them, not just watched for a green checkmark. Multifactor authentication belongs on every account, including the ones vendors and integrators use to reach your equipment. And someone has to own the security program as a whole instead of treating each control as another ticket, which is what Virtual CISO and IT Strategy work does for shops with no security leader on staff.

If you do not know where you stand, start with the Security Analysis at https://outreach.ttscyber.com/analysis. It is $349, fully independent, and mapped to 38 compliance frameworks. You get a written picture of your real posture, which is also the input that makes a CMMC scoping conversation worth having in the first place.

Start here

Find out where you actually stand

The Security Analysis is a fixed-scope review of your environment, run independently and mapped to 38 compliance frameworks. It is the fastest way to replace an assumption about your posture with a finding.

Questions we get asked

We only do commercial work and never touch DoD contracts. Does any of this apply to us?

CMMC follows the contract clause, so with no DoD work anywhere in your chain there is no CMMC obligation. The controls still matter for a different reason. Commercial customers now send security questionnaires as a condition of supply, and cyber insurance applications ask whether you run multifactor authentication, tested backups and endpoint detection, so the answers affect what coverage is offered to you. NIST SP 800-171 is a sensible checklist to work from even when nobody is requiring it of you.

What is the difference between an SPRS score and a CMMC status?

They are related, but they are not the same thing. The SPRS score comes from the NIST SP 800-171 DoD Assessment Methodology: you start at 110 and subtract a weighted number of points for each requirement you have not implemented, so the score can land well below zero. It is a number describing how much of the standard you have in place. A CMMC status is a determination at a given level, recorded with an affirmation, and it has three states rather than two. Final means you met the requirements. Conditional means you passed with a qualifying plan of action, you have 180 days to close it out, and you can still be awarded work meanwhile. The third state is nothing at all. Level 1 has no conditional state, because every requirement must be met. You can have a posted SPRS score and still not hold the CMMC status a contract asks for.

Can you actually come out to the plant, or is this remote only?

Remote support covers most of what a manufacturer needs day to day. Our office is in Columbus and most of our onsite work is in Central Ohio, but onsite support can be arranged in any of the 50 states. Plant floor work in particular, walking the production network and tracing what is actually connected to what, usually needs someone there in person at least once.

Let’s Get in Touch!

Cybersecurity & Risk Analysis

Find out where you actually stand.

Most businesses do not discover a gap until something goes wrong. This is a fixed-scope analysis of your environment, run independently, so you get an answer rather than an opinion.

What the analysis covers