Skip to content

Managed IT and Cybersecurity for Columbus Manufacturers

Your line runs on equipment older than your ERP, and the controller driving it will never take another patch. If you sell into the defense supply chain, a prime is now asking for an SPRS score and a CMMC status you are not sure how to produce. Both problems land on the same small IT budget.

What does CMMC actually require of a Columbus manufacturer right now?

The acquisition rule that puts CMMC into contracts took effect on November 10, 2025.

Since then, a contracting officer can make CMMC status a condition of award, and the required level appears in the solicitation itself under provision DFARS 252.204-7025, Notice of CMMC Level Requirements, before anything is signed. What is in force today is Phase 1.

Level 1 covers contracts that carry the CMMC clause, DFARS 252.204-7021, where the contractor handles Federal Contract Information. It is a self-assessment against 15 basic safeguarding requirements, with the result posted to the Supplier Performance Risk System and an affirmation filed. The CMMC rule defines those 15 by pointing to FAR 52.204-21(b)(1).

Since February 2026, DoD has written solicitations and contracts under the FAR overhaul. That is a rewrite of the Federal Acquisition Regulation, the rulebook for federal contracts, which DoD put in place through formal instructions called class deviations. Where FCI may pass through a contractor’s systems, those contracts carry the same 15, word for word, as FAR 52.240-93.

The self-assessment has to be performed again and reposted every year. Re-signing last year’s affirmation does not satisfy it. No plans of action are allowed at Level 1, so every requirement has to be met.

Separately, those same 15 safeguards reach most contracts where a contractor’s systems may hold FCI, with or without the CMMC clause. Acquisitions of commercially available off-the-shelf items are carved out, which matters to shops selling catalog parts. That rule sits at FAR 4.1902, and at FAR 40.303-1 under the overhaul. Standing alone, the safeguards carry no SPRS or affirmation duty.

Level 2 covers contractors that handle Controlled Unclassified Information. It spans all 110 requirements of NIST SP 800-171 Revision 2, self-assessed every three years, with the result posted to SPRS and an affirmation at completion and annually after that. Level 2 (Self) is the only Level 2 that can be designated for a new requirement today.

The July 13, 2026 memoranda bar program offices from designating Level 2 (C3PAO) or Level 3 (DIBCAC). A C3PAO is an authorized third-party assessor. DIBCAC is the assessment center of the Defense Contract Management Agency (DCMA). No waivers are being granted while the suspension lasts. The suspension stops the designation. The status is unaffected. The rule still provides for third-party assessment, so that discretion can return when the suspension lifts.

A third level, assessed by DCMA’s DIBCAC against 24 added requirements drawn from NIST SP 800-172, is reserved for DoD’s most critical programs and technologies. It was never designatable in Phase 1 and cannot be designated during the suspension. The levels, the 15, 110 and 24 counts, and the assessment types are all defined at 32 CFR 170.4 and 170.14. If a solicitation names a level, those sections are the place to read.

The program is mid-change, and it is worth knowing exactly where. On July 13, 2026, the Chief Information Officer of the Department of War (the Department of Defense, or DoD) suspended Phase 2 in a memo. That is the stage that would have required third-party certification by a C3PAO starting November 10, 2026.

The memo also put all pending and future CMMC implementation milestones on hold until further notice. It set up a CMMC Reform Task Force for a 60-day review, scheduled to end around September 11. The department has said further guidance will follow the review. As of September 12, 2026, none had been issued.

Two other documents carry the suspension into contracts. The first is a same-day memo from the Under Secretary of War for Acquisition and Sustainment. It bars new Level 2 (C3PAO) and Level 3 (DIBCAC) designations. It also directs contracting officers to remove any such requirement already in a contract by modification, before the next option period or at the next scheduled administrative modification. Until then, the contract as awarded still contains it.

The second is DoD’s Class Deviation 2026-O0025, the formal instruction contracting officers follow. It was revised on July 16, 2026 to tell contracting officers to work with requiring activities to remove or revise CMMC requirements. It still allows Level 1 (Self) and Level 2 (Self). A revision dated September 3 repeats that direction word for word.

Phase 1’s self-assessment requirements did not change. DFARS 252.204-7012 and its NIST SP 800-171 Revision 2 requirements still apply. If someone says CMMC went away, the contract is the place to check before believing it.

Working out where a specific contract or subcontract actually stands today, and what that creates as a work list, is where our cybersecurity and virtual CISO engagements with manufacturers start.

How far down the supply chain does CMMC reach?

It reaches suppliers through the customer’s purchase order.

DFARS 252.204-7012 flows down at every tier to subcontracts whose performance will involve covered defense information, and independently to subcontracts for operationally critical support. So a supplier can be caught by the clause without ever receiving a drawing.

What a prime has to check before awarding a subcontract depends on the clauses in its own contract. DFARS 252.204-7020 puts a check on any subcontract that is subject to 252.204-7012’s NIST SP 800-171 requirements. A prime cannot award one unless the subcontractor has completed at least a Basic assessment, the company’s own scored self-assessment, within the previous three years.

Since February 2026, DoD has issued solicitations under the FAR overhaul’s class deviations, formal instructions that replace parts of the standard contracting rules. Those solicitations use a different clause, 252.240-7997. It covers only Medium and High assessments, which the government leads, and has no such check.

Where the CMMC clause, 252.204-7021, is in the contract, the prime has a separate check before award. It has to confirm that the subcontractor has a current CMMC status at the level the flowed-down information calls for, backed by an annual affirmation. The pressure usually shows up as a questionnaire from a customer of many years, with a deadline attached.

The applicable level turns on what actually lands in a contractor’s systems. The marking on a document does not settle it. Federal Contract Information is information the government provided, or that a contractor generated for the government under a contract, that is not intended for public release. Holding Federal Contract Information is what places a contractor at Level 1.

The definition sits at FAR 4.1901, and the FAR overhaul repeats it word for word at FAR 40.301. It carves out a few categories, including information the government has already released publicly and simple transactional data. So it is worth checking the definition against actual records.

Drawings, specs and part data that are Controlled Unclassified Information fall under Level 2. CUI does not stop being CUI because a prime failed to mark it. The question is what the data is.

Which Level 2 applies also depends on the prime: normally Level 2 (Self), but a prime contract that itself carries a Level 2 (C3PAO) or Level 3 (DIBCAC) requirement sets Level 2 (C3PAO) as the flowdown floor. That distinction is on hold while third-party designations are suspended, and it comes back if they resume.

Sorting this out is a scoping exercise: which machines, file shares and mailboxes touch the data. A scope set wrong in either direction is expensive. Too wide and the whole plant gets hardened for no reason. Too narrow and the affirmation that gets signed is inaccurate. An affirmation is a formal statement to the government. Our cybersecurity and virtual CISO work covers the scoping, the control set and the documentation behind it.

What does producing an SPRS score actually take?

The score itself is arithmetic. The work is the 110 determinations underneath it. Someone has to take each requirement in NIST SP 800-171 and decide whether it is implemented in the environment you actually run. The network diagram is not the environment.

The checks are specific: whether multifactor authentication is on every account or on most of them, whether the file share permissions still match who works there now, whether the logs anyone would need after an incident are being kept anywhere at all.

Partial coverage is where the honest answer gets harder. A control running on one server and not on the other three is not the same as a control that is in place across the environment. The determination has to record which it is. Honest first passes usually land lower than the shop expected, and that is the useful outcome. The gap analysis is the deliverable. The number falls out of it.

A determination you cannot show is one you will end up making again from scratch. Evidence for multifactor authentication is the export listing every account and whether it is enforced on each one. A screenshot of the policy saying it should be does not show that. It includes the exceptions, with a reason next to each: the service account nothing logs into interactively, the shared login on a machine PC that has no second factor to give.

That record does double duty. A customer’s security questionnaire and a cyber insurance renewal both ask you to attest that multifactor authentication is enforced. Answering yes takes a second. Proving it, exception list attached, is what takes preparation. Building the record while the work happens is the difference between reconstructing it under someone else’s deadline and pulling a file.

None of it stays done. Equipment gets replaced, people leave, an integrator is given new access, and the self-assessment comes back around. At Level 1 it has to be performed again and reposted every year. Re-signing last year’s affirmation does not satisfy it. Level 2 is self-assessed every three years, with the result posted to SPRS and an affirmation at completion and annually after that.

The requirements not met yet become a work list with an owner and a date on each line. The ones already met have to still be true the next time anyone looks. That is what evidence tracking and control maintenance mean in our virtual CISO and Compliance-as-a-Service work: the record is kept current between reposts. So the next repost is a short review, and a questionnaire from a prime gets answered out of what you already have.

How do you secure machines that cannot be patched?

Most plants have a controller, an HMI or a machine PC running something the vendor stopped supporting years ago, and you cannot replace it without replacing the machine around it. The answer is to make it unreachable from everything that does not need it.

CISA’s Cross-Sector Cybersecurity Performance Goals treat this case as normal: where patching is not possible, or would substantially compromise availability or safety, the goals call for compensating controls such as segmentation and monitoring, and for recording that they were applied.

In practice that means all of these:

  • An accurate inventory of what is really sitting on the production network.
  • A segmented design where the office VLAN and the plant floor are not the same broadcast domain.
  • Tight rules about which traffic crosses between them.
  • Monitoring at that boundary.

The failure we are designing against is an ordinary one: someone in accounting opens an attachment, and nothing in the network stops that from reaching the line. Managed IT and Network Operations Center work cover the ongoing side of this.

None of it starts with a firewall rule. It starts with a list: every controller, HMI and machine PC on the floor, what it runs, and whether anyone still has a login to it. Plants that have been through a few generations of equipment usually find devices nobody remembers configuring, still phoning home to a vendor that no longer exists, or reachable from a laptop that left the building years ago.

Segmentation only works against a list that is actually current, because a boundary drawn around an incomplete inventory protects the blind spots along with everything else. Building that list, and keeping the boundary enforced as equipment gets added, replaced, or handed off between an integrator and your own team, is ongoing work rather than a project with an end date. That ongoing work is what Managed IT and Network Operations Center coverage is built to carry.

Why do attackers keep picking manufacturers?

Because it works. IBM’s 2026 X-Force Threat Index put manufacturing at the top of the most-attacked industry list for the fifth year running, at 27.7% of the incidents it observed, with data theft the most common goal.

The logic is the downtime math you already know. When a line stops, the cost of not producing is large and immediate, so a manufacturer is more likely to pay fast. And a supplier holding drawings and process data on a file server is worth stealing from even when nothing gets encrypted.

That shapes the priorities. Backups have to be tested by restoring them. A green checkmark in the console is not a test. Multifactor authentication belongs on every account, including the ones vendors and integrators use to reach your equipment. And someone has to own the security program as a whole. Worked one control at a time, it has no owner. That is what Virtual CISO and IT Strategy work does for shops with no security leader on staff.

If you do not know where you stand, start with the Security Analysis at https://outreach.ttscyber.com/analysis. It is $349, fully independent, and mapped to 38 compliance frameworks. You get a written picture of your real posture, which is also the input that makes a CMMC scoping conversation worth having in the first place.

Start here

Find out where you actually stand

The Security Analysis is a fixed-scope review of your environment, run independently and mapped to 38 compliance frameworks. It is the fastest way to replace an assumption about your posture with a finding.

Questions we get asked

Does CMMC reach a manufacturer with no DoD work at all?

CMMC follows the contract clause, so where no DoD work exists anywhere in the chain, the clause never lands and no CMMC obligation attaches. The controls still matter for a different reason. Commercial customers now send security questionnaires as a condition of supply. Cyber insurance applications ask whether multifactor authentication, tested backups and endpoint detection are in place, so the answers affect what coverage gets offered. NIST SP 800-171 is a sensible checklist to work from even when nobody is requiring it. TTS Cyber is not a law firm; this is not legal advice.

What is the difference between an SPRS score and a CMMC status?

They are related, but they are not the same thing. The SPRS score comes from the NIST SP 800-171 DoD Assessment Methodology: scoring starts at 110 and subtracts a weighted number of points for each requirement not implemented. So the score can land well below zero. It is a number describing how much of the standard is in place. A CMMC status is a determination at a given level, recorded with an affirmation, and it has three states rather than two.

Final means the requirements were met. Conditional means the assessment passed with a qualifying plan of action, the clock to close it out runs 180 days, and award can still happen meanwhile. The third state is nothing at all. Level 1 has no conditional state, because every requirement must be met. A posted SPRS score and the CMMC status a contract asks for are two separate things, and one can exist without the other. TTS Cyber is not a law firm; this is not legal advice.

Can you actually come out to the plant, or is this remote only?

Remote support covers most of what a manufacturer needs day to day. Our office is in Columbus and most of our onsite work is in Central Ohio, but onsite support can be arranged in any of the 50 states. Plant floor work in particular, walking the production network and tracing what is actually connected to what, usually needs someone there in person at least once.

DoD suspended third-party CMMC assessment in 2026. What happens to a contract that already requires one?

The requirement stays in the contract until a modification removes it. On July 13, 2026, the Chief Information Officer of the Department of War (the Department of Defense, or DoD) suspended Phase 2. The same memo put all pending and future CMMC implementation milestones on hold until further notice and set up a CMMC Reform Task Force to review the program. A same-day memo from the Under Secretary of War for Acquisition and Sustainment directs contracting officers to remove Level 2 (C3PAO) and Level 3 (DIBCAC) requirements from existing contracts by modification.

A C3PAO is an authorized third-party assessor, and DIBCAC is the Defense Contract Management Agency’s assessment center. The modification comes before the next option period or at the next scheduled administrative modification. DoD’s Class Deviation 2026-O0025, the formal instruction contracting officers follow, was revised on July 16 and again on September 3, 2026 to carry out the suspension. Until the modification is made, the contract as awarded still contains the requirement.

Phase 1’s self-assessment requirements did not change: DFARS 252.204-7012 and its NIST SP 800-171 Revision 2 requirements still apply, and Level 2 (Self) remains something a contract can require today. The suspension stops the designation. The underlying status is unaffected. The contracting officer is the one to ask whether a modification is coming before already-scoped work stops. The levels and assessment types are set out at 32 CFR 170.4 and 170.14. TTS Cyber is not a law firm; this is not legal advice.

Does CMMC Level 1 need a fresh self-assessment every year, or will a re-signed affirmation do?

A fresh one. The recurring duty at Level 1 is bigger than most shops expect. The self-assessment covers the 15 safeguarding requirements in FAR 52.204-21(b)(1), which newer DoD contracts involving FCI carry word for word as FAR 52.240-93. It has to be performed again and reposted to the Supplier Performance Risk System every year. Re-signing last year’s result does not satisfy it. No plans of action are allowed at Level 1 either, so every one of the 15 requirements has to actually be met on the day of the affirmation. An affirmation is a formal statement to the government. TTS Cyber is not a law firm; this is not legal advice.

One person clicked something yesterday and now three other computers have it, including the PC out in the warehouse that runs our machines. Those were supposed to be separate. Why did it spread, and how do we stop it while we clean up?

The common reason is that the two networks were only separate on paper. Without looking at what actually crossed, nobody can tell you that is what happened here. If the office VLAN and the plant floor are the same broadcast domain, nothing between them is inspecting that traffic, and the failure is an ordinary one: someone in accounting opens an attachment, and nothing in the network stops that from reaching the line.

While you are cleaning up, containment comes before diagnosis: get affected machines off the network, and treat the boundary between office and production as untrusted until you know what actually crossed it. The durable fix is an accurate inventory of what is really sitting on the production network, a segmented design where the office VLAN and the plant floor are not the same broadcast domain, tight rules about which traffic crosses between them, and monitoring at that boundary.

Further reading

From our blog

TTS Cyber is an IT and cybersecurity company, not a law firm, and nothing on this page is legal advice. This page summarises published rules and cites them so they can be read directly; where this page and the source differ, the source governs. Whether a particular rule reaches a particular business, and what it requires of that business, are legal questions for that business's own attorney.

Page last updated .

Let’s Get in Touch!

Security Analysis

Find out where you actually stand.

Most businesses do not discover a gap until something goes wrong. This is a fixed-scope analysis of your environment, run independently, so you get an answer rather than an opinion.

What the analysis covers