APTSecurity Management

Industries

Defense Industrial Base

If your contract carries DFARS 252.204-7012, you handle Controlled Unclassified Information and owe a NIST SP 800-171 self-assessment, a System Security Plan, a POA&M, an SPRS score and an annual affirmation. The July 2026 CMMC suspension paused the third-party audit. It did not pause any of that.

Where contractors usually are

Just received a flow-down

A prime is asking what you handle

Start with scoping. Which systems touch FCI, which touch CUI, and where the boundary sits. Put the question to your prime in writing if the answer is not in the contract.

Assessed once, then stopped

You have an SSP from two years ago

The affirmation is annual and it is signed by a company official. A plan that no longer describes your systems is worse than no plan, because someone attested that it did.

Suspension confusion

You stopped work in July 2026

Phase 2 pausing did not repeal 7012 or 7021. If you downed tools you are out of compliance now, and picking it back up is cheaper than explaining the gap later.

Subcontracting out

You flow CUI down to others

Your obligations travel. A flow-down letter that names the clauses and the data type is the minimum, and there is a free tool below that writes one.

Eight free tools for this work

No signup, no email capture. Seven of the eight serve obligations that the suspension left untouched.

What we do for DIB contractors

Scoping and gap assessment, remediation and documentation, and the penetration testing that Level 2 practices call for. Details on the CMMC readiness page.

We hold CMMC Registered Practitioner status. We are not a C3PAO and cannot certify you, which is the correct separation: the people who prepare you should not be the people who assess you.

Not sure whether you handle CUI?

That is the question worth answering first, and it usually takes one conversation.