Serving North Texas since 2017 817 · 366 · 5829 Contact
Guide · North Texas IT

A CMMC 2.0 Roadmap for Texas Defense Suppliers

If you sell into the defense supply chain from North Texas, CMMC will eventually shape your contracts. This is a plain-language roadmap from where you are to where you need to be.

North Texas has a deep defense and aerospace base, from the primes around Fort Worth down to the machine shops, software vendors, and logistics firms that supply them. If your business touches Department of Defense work, the Cybersecurity Maturity Model Certification (CMMC) program affects your ability to win and keep contracts. This roadmap explains the model in plain language and lays out the path to readiness. Treat it as education rather than legal or assessment advice, since your specific obligations come down to what your contracts say.

What CMMC 2.0 covers

CMMC is the DoD’s framework for verifying that contractors protect sensitive government information. Version 2.0 trimmed the program down to three levels and tied each one to a type of information you already handle.

  • Level 1 (Foundational): for businesses handling Federal Contract Information (FCI). Built on 15 basic safeguarding requirements, with annual self-assessment.
  • Level 2 (Advanced): for businesses handling Controlled Unclassified Information (CUI). Aligned to the 110 controls of NIST SP 800-171. Many contracts require a third-party assessment.
  • Level 3 (Expert): for the highest-priority programs, building on Level 2 with additional requirements from NIST SP 800-172.
Two terms decide almost everything: FCI and CUI. FCI is contract information not meant for public release. CUI is more sensitive government information that carries specific protection requirements. Which of them you handle drives which level applies, so scoping comes first.

The roadmap

  1. Determine your level. Look at your contracts and DFARS clauses to identify whether you handle FCI, CUI, or both. This sets your target.
  2. Scope your environment. Map where that information lives, moves, and is stored, across systems, people, and facilities. Tightening that scope, for example by isolating CUI in a defined enclave, can cut the work down sharply.
  3. Run a gap assessment. Compare your current controls against the applicable requirements (the 15 for Level 1, the 110 of NIST 800-171 for Level 2). The output is a clear list of what’s in place and what’s missing.
  4. Remediate the gaps. Close the findings through policy, configuration, and technology: access control, multifactor authentication, logging, encryption, incident response, and the rest.
  5. Document everything. Produce a System Security Plan (SSP) describing how each requirement is met, and a Plan of Action & Milestones (POA&M) for anything not yet complete.
  6. Assess. Self-assess for Level 1; for most Level 2 work, engage an authorized C3PAO for a third-party assessment.
  7. Maintain. CMMC is ongoing. Controls drift, staff turn over, and reassessment comes back around on a cycle. Run compliance as a standing program with an owner and a budget.

Where Texas suppliers commonly get stuck

  • Scoping too broadly. Pulling the whole company into scope when CUI could be confined to a smaller, well-defined environment multiplies the cost.
  • Treating the SSP as paperwork. The documentation has to reflect reality. Assessors check what you do on the ground, not what the binder claims.
  • Underestimating timelines. Remediation, especially for Level 2, takes months. Starting when a contract already requires certification is starting too late.

How a partner fits in

CMMC sits where IT, security, and documentation meet, which is exactly where a combined MSP and MSSP earns its keep: scoping the environment, putting the technical controls in place, building the SSP and POA&M, and keeping them current through reassessment. The aim is a defensible, audit-ready posture you can stand behind when the assessor arrives.

Frequently asked questions

Does my small North Texas shop really need CMMC if we're a subcontractor?
If you handle Federal Contract Information or Controlled Unclassified Information as part of DoD work, certification requirements can flow down to you through your contracts regardless of size. The level depends on the information you handle, not your headcount. Reviewing your contract clauses is the first step.
What's the difference between CMMC Level 1 and Level 2?
Level 1 covers businesses handling Federal Contract Information and is built on 15 basic safeguarding requirements with annual self-assessment. Level 2 covers Controlled Unclassified Information, aligns to the 110 controls of NIST SP 800-171, and frequently requires a third-party assessment.
How long does CMMC readiness take?
It varies widely with your starting posture and scope, but Level 2 remediation commonly takes several months once gaps are identified. Starting only after a contract demands certification is usually too late, which is why scoping and a gap assessment come early.
Can't we just self-assess and be done?
Level 1 allows annual self-assessment. Many Level 2 contracts require an assessment by an authorized third party (a C3PAO). And in all cases CMMC is ongoing, controls have to be maintained, documentation kept current, and posture reassessed over time.
What is a POA&M?
A Plan of Action and Milestones is a documented list of requirements not yet fully met, with the steps and dates to close them. Combined with a System Security Plan, it shows assessors both your current state and your committed path to full compliance.

Related

Start your CMMC roadmap

Book a free 30-minute conversation. We'll help you figure out which level applies, scope your environment, and sketch a realistic path to readiness, ideally before a contract sets the timeline for you.