Skip to content

Managed IT and Cybersecurity for Columbus Manufacturers

Your line runs on equipment older than your ERP, and the controller driving it will never take another patch. If you sell into the defense supply chain, a prime is now asking for an SPRS score and a CMMC status you are not sure how to produce. Both problems land on the same small IT budget.

What does CMMC actually require of a Columbus manufacturer right now?

The acquisition rule that puts CMMC into contracts took effect on November 10, 2025. Since then, a contracting officer can make CMMC status a condition of award, and the required level appears in the solicitation itself under provision DFARS 252.204-7025, Notice of CMMC Level Requirements, before anything is signed. What is in force today is Phase 1.

Level 1 covers contracts that carry the CMMC clause, DFARS 252.204-7021, where the contractor handles Federal Contract Information. It is a self-assessment against the 15 safeguarding requirements in FAR 52.204-21(b)(1), with the result posted to the Supplier Performance Risk System and an affirmation filed. The self-assessment has to be performed again and reposted every year, and re-signing last year’s affirmation does not satisfy it. No plans of action are allowed at Level 1, so every requirement has to be met. Separately, those same FAR 52.204-21 safeguards reach most contracts where a contractor’s systems may hold FCI, with or without the CMMC clause. Acquisitions solely for commercially available off-the-shelf items are carved out, which matters to shops selling catalog parts; the scope is set at FAR 4.1902. Standing alone, the safeguards carry no SPRS or affirmation duty.

Level 2 covers contractors that handle Controlled Unclassified Information. It spans all 110 requirements of NIST SP 800-171 Revision 2, self-assessed every three years, with the result posted to SPRS and an affirmation at completion and annually after that. Level 2 (Self) is the only Level 2 a contract can require today, because the July 13, 2026 memoranda bar program offices from designating Level 2 (C3PAO) or Level 3 (DIBCAC) on a requirement, and no waivers are being granted while the suspension lasts. The suspension stops the designation. The status is unaffected. The rule still provides for third-party assessment, so that discretion can return when the suspension lifts.

A third level, assessed by DCMA’s DIBCAC against 24 added requirements drawn from NIST SP 800-172, is reserved for DoD’s most critical programs and technologies. It was never designatable in Phase 1 and cannot be designated during the suspension. The levels, the 15, 110 and 24 counts, and the assessment types are all defined at 32 CFR 170.4 and 170.14. If a solicitation names a level, those sections are the place to read.

The program is mid-change, and it is worth knowing exactly where. On July 13, 2026, the Department of War suspended Phase 2, the stage that would have required third-party certification by a C3PAO starting November 10, 2026, and held later milestones in abeyance while a CMMC Reform Task Force reviews the program. The industry comment window closed on August 14, 2026, the Task Force’s 60-day review runs to roughly September 11, and the department has said further guidance follows at its conclusion. Phase 1 did not change. Contracting officers have been directed to strike suspended Level 2 and Level 3 certification requirements from existing solicitations and contracts by modification, but until that modification actually lands, the terms written into an award still bind the parties to it. Obligations under DFARS 252.204-7012, implementation of NIST SP 800-171 and the SPRS score all still apply. If someone says CMMC went away, the contract is the place to check before believing it.

Working out where a specific contract or subcontract actually stands today, and what that creates as a work list, is where our cybersecurity and virtual CISO engagements with manufacturers start.

How far down the supply chain does CMMC reach?

It reaches suppliers through the customer’s purchase order. DFARS 252.204-7012 flows down at every tier to subcontracts whose performance will involve covered defense information, and independently to subcontracts for operationally critical support, so a supplier can be caught by the clause without ever receiving a drawing. Under DFARS 252.204-7020, a prime cannot award a subcontract subject to NIST SP 800-171 unless the subcontractor has completed at least a Basic assessment within the previous three years and posted the score. The pressure usually shows up as a questionnaire from a customer of many years, with a deadline attached.

The applicable level turns on what actually lands in a contractor’s systems. The marking on a document does not settle it. Federal Contract Information is information the government provided, or that a contractor generated for the government under a contract, that is not intended for public release, and holding it is what places a contractor at Level 1. The definition at FAR 4.1901 carves out a few categories, including information the government has already released publicly and simple transactional data, so it is worth checking the definition against actual records.

Drawings, specs and part data that are Controlled Unclassified Information fall under Level 2. CUI does not stop being CUI because a prime failed to mark it. The question is what the data is. Which Level 2 applies also depends on the prime: normally Level 2 (Self), but a prime contract that itself carries a Level 2 (C3PAO) or Level 3 (DIBCAC) requirement sets Level 2 (C3PAO) as the flowdown floor. That distinction is on hold while third-party designations are suspended, and it comes back if they resume.

Sorting this out is a scoping exercise: which machines, file shares and mailboxes touch the data. A scope set wrong in either direction is expensive. Too wide and the whole plant gets hardened for no reason. Too narrow and the affirmation that gets signed is inaccurate. An affirmation is a formal statement to the government. Our cybersecurity and virtual CISO work covers the scoping, the control set and the documentation behind it.

What does producing an SPRS score actually take?

The score itself is arithmetic. The work is the 110 determinations underneath it. Someone has to take each requirement in NIST SP 800-171 and decide whether it is implemented in the environment you actually run. The network diagram is not the environment. The checks are specific: whether multifactor authentication is on every account or on most of them, whether the file share permissions still match who works there now, whether the logs anyone would need after an incident are being kept anywhere at all. Partial coverage is where the honest answer gets harder. A control running on one server and not on the other three is not the same as a control that is in place across the environment, and the determination has to record which it is. Honest first passes usually land lower than the shop expected, and that is the useful outcome. The gap analysis is the deliverable. The number falls out of it.

A determination you cannot show is one you will end up making again from scratch. Evidence for multifactor authentication is the export listing every account and whether it is enforced on each one. A screenshot of the policy saying it should be does not show that. It includes the exceptions, with a reason next to each: the service account nothing logs into interactively, the shared login on a machine PC that has no second factor to give. That record does double duty. A customer’s security questionnaire and a cyber insurance renewal both ask you to attest that multifactor authentication is enforced. Answering yes takes a second. Proving it, exception list attached, is what takes preparation. Building the record while the work happens is the difference between reconstructing it under someone else’s deadline and pulling a file.

None of it stays done. Equipment gets replaced, people leave, an integrator is given new access, and the self-assessment comes back around. At Level 1 it has to be performed again and reposted every year. Re-signing last year’s affirmation does not satisfy it. Level 2 is self-assessed every three years, with the result posted to SPRS and an affirmation at completion and annually after that. The requirements not met yet become a work list with an owner and a date on each line. The ones already met have to still be true the next time anyone looks. That is what evidence tracking and control maintenance mean in our virtual CISO and Compliance-as-a-Service work: the record is kept current between reposts, so the next repost is a short review, and a questionnaire from a prime gets answered out of what you already have.

How do you secure machines that cannot be patched?

Most plants have a controller, an HMI or a machine PC running something the vendor stopped supporting years ago, and you cannot replace it without replacing the machine around it. The answer is to make it unreachable from everything that does not need it. CISA’s Cross-Sector Cybersecurity Performance Goals treat this case as normal: where patching is not possible, or would substantially compromise availability or safety, the goals call for compensating controls such as segmentation and monitoring, and for recording that they were applied.

In practice that means an accurate inventory of what is really sitting on the production network, a segmented design where the office VLAN and the plant floor are not the same broadcast domain, tight rules about which traffic crosses between them, and monitoring at that boundary. The failure we are designing against is an ordinary one: someone in accounting opens an attachment, and nothing in the network stops that from reaching the line. Managed IT and Network Operations Center work cover the ongoing side of this.

None of it starts with a firewall rule. It starts with a list: every controller, HMI and machine PC on the floor, what it runs, and whether anyone still has a login to it. Plants that have been through a few generations of equipment usually find devices nobody remembers configuring, still phoning home to a vendor that no longer exists, or reachable from a laptop that left the building years ago. Segmentation only works against a list that is actually current, because a boundary drawn around an incomplete inventory protects the blind spots along with everything else. Building that list, and keeping the boundary enforced as equipment gets added, replaced, or handed off between an integrator and your own team, is ongoing work rather than a project with an end date, which is what Managed IT and Network Operations Center coverage is built to carry.

Why do attackers keep picking manufacturers?

Because it works. IBM’s 2026 X-Force Threat Index put manufacturing at the top of the most-attacked industry list for the fifth year running, at 27.7% of the incidents it observed, with data theft the most common goal. The logic is the downtime math you already know. When a line stops, the cost of not producing is large and immediate, so a manufacturer is more likely to pay fast. And a supplier holding drawings and process data on a file server is worth stealing from even when nothing gets encrypted.

That shapes the priorities. Backups have to be tested by restoring them. A green checkmark in the console is not a test. Multifactor authentication belongs on every account, including the ones vendors and integrators use to reach your equipment. And someone has to own the security program as a whole. Worked one control at a time, it has no owner. That is what Virtual CISO and IT Strategy work does for shops with no security leader on staff.

If you do not know where you stand, start with the Security Analysis at https://outreach.ttscyber.com/analysis. It is $349, fully independent, and mapped to 38 compliance frameworks. You get a written picture of your real posture, which is also the input that makes a CMMC scoping conversation worth having in the first place.

Start here

Find out where you actually stand

The Security Analysis is a fixed-scope review of your environment, run independently and mapped to 38 compliance frameworks. It is the fastest way to replace an assumption about your posture with a finding.

Questions we get asked

Does CMMC reach a manufacturer with no DoD work at all?

CMMC follows the contract clause, so where no DoD work exists anywhere in the chain, the clause never lands and no CMMC obligation attaches. The controls still matter for a different reason. Commercial customers now send security questionnaires as a condition of supply, and cyber insurance applications ask whether multifactor authentication, tested backups and endpoint detection are in place, so the answers affect what coverage gets offered. NIST SP 800-171 is a sensible checklist to work from even when nobody is requiring it. TTS Cyber is not a law firm; this is not legal advice.

What is the difference between an SPRS score and a CMMC status?

They are related, but they are not the same thing. The SPRS score comes from the NIST SP 800-171 DoD Assessment Methodology: scoring starts at 110 and subtracts a weighted number of points for each requirement not implemented, so the score can land well below zero. It is a number describing how much of the standard is in place. A CMMC status is a determination at a given level, recorded with an affirmation, and it has three states rather than two. Final means the requirements were met. Conditional means the assessment passed with a qualifying plan of action, the clock to close it out runs 180 days, and award can still happen meanwhile. The third state is nothing at all. Level 1 has no conditional state, because every requirement must be met. A posted SPRS score and the CMMC status a contract asks for are two separate things, and one can exist without the other. TTS Cyber is not a law firm; this is not legal advice.

Can you actually come out to the plant, or is this remote only?

Remote support covers most of what a manufacturer needs day to day. Our office is in Columbus and most of our onsite work is in Central Ohio, but onsite support can be arranged in any of the 50 states. Plant floor work in particular, walking the production network and tracing what is actually connected to what, usually needs someone there in person at least once.

DoD suspended third-party CMMC assessment in 2026. What happens to a contract that already requires one?

The requirement stays in force until it is removed. On July 13, 2026 the Department of War suspended Phase 2 and held later milestones in abeyance while a CMMC Reform Task Force reviews the program, and contracting officers were directed to strike suspended Level 2 and Level 3 certification requirements from existing solicitations and contracts by modification. Until that modification actually lands on an award, the terms written into it still bind the parties. Phase 1 did not change either: obligations under DFARS 252.204-7012, implementation of NIST SP 800-171 and the posted SPRS score all still apply, and Level 2 (Self) remains something a contract can require today. The suspension stops the designation. The underlying status is unaffected. The contracting officer is the one to ask whether a modification is coming before already-scoped work stops, and the levels and assessment types are set out at 32 CFR 170.4 and 170.14. TTS Cyber is not a law firm; this is not legal advice.

Does CMMC Level 1 need a fresh self-assessment every year, or will a re-signed affirmation do?

A fresh one. The recurring duty at Level 1 is bigger than most shops expect. The self-assessment against the 15 safeguarding requirements in FAR 52.204-21(b)(1) has to be performed again and reposted to the Supplier Performance Risk System every year. Re-signing last year’s result does not satisfy it. No plans of action are allowed at Level 1 either, so every one of the 15 requirements has to actually be met on the day of the affirmation. An affirmation is a formal statement to the government. TTS Cyber is not a law firm; this is not legal advice.

One person clicked something yesterday and now three other computers have it, including the PC out in the warehouse that runs our machines. Those were supposed to be separate. Why did it spread, and how do we stop it while we clean up?

The common reason is that the two networks were only separate on paper. Without looking at what actually crossed, nobody can tell you that is what happened here. If the office VLAN and the plant floor are the same broadcast domain, nothing between them is inspecting that traffic, and the failure is an ordinary one: someone in accounting opens an attachment, and nothing in the network stops that from reaching the line. While you are cleaning up, containment comes before diagnosis: get affected machines off the network, and treat the boundary between office and production as untrusted until you know what actually crossed it. The durable fix is an accurate inventory of what is really sitting on the production network, a segmented design where the office VLAN and the plant floor are not the same broadcast domain, tight rules about which traffic crosses between them, and monitoring at that boundary.

Primary sources

Read the rules yourself

Everything on this page rests on the text below. Where a section is named above, it is worth reading in the instrument rather than taking a summary for it, including this one.

TTS Cyber is an IT and cybersecurity company, not a law firm, and nothing on this page is legal advice. This page summarises published rules and cites them so they can be read directly; where this page and the source differ, the source governs. Whether a particular rule reaches a particular business, and what it requires of that business, are legal questions for that business's own attorney.

Let’s Get in Touch!

Security Analysis

Find out where you actually stand.

Most businesses do not discover a gap until something goes wrong. This is a fixed-scope analysis of your environment, run independently, so you get an answer rather than an opinion.

What the analysis covers