Manufacturing · Defense Industrial Base · CMMC 2.0

Your prime just added CMMC Level 2 to the RFP. You have until the next award to be ready.

300,000+ DIB contractors will need a current CMMC Level 2 certificate to bid on DoD work by 2028. Most aren’t ready. The 110 NIST 800-171 Rev 3 controls, the CUI handling program, the SSP + POA&M, and the C3PAO assessment don’t build themselves. We run the platform mechanics continuously and walk the C3PAO assessment with you.

Not selling to DoD? Non-DoD manufacturers still work with us for OT/ICS security, IEC 62443, and enterprise SOC 2. The CMMC track below is where most manufacturing conversations start. It’s not the only one. Reach out.

§ I · Why This RFP Landed Different

The CMMC 2.0 clock has been ticking since December.

The Final Rule is in effect. The assessment ecosystem is standing up. DoD contracting officers are inserting DFARS 252.204-7021 into new solicitations on a phased schedule. The rollout dates on the left set the calendar. The clauses on the right are what your solicitation will cite, and what each really enforces beneath the surface text.

  1. Dec 16 2024CMMC Program Final Rule effective · 32 CFR Part 170 · self-assessment, C3PAO, and DIBCAC tracks all binding
  2. May 2024NIST SP 800-171 Rev 3 published · 110 controls · ODP-parameter withdrawals reshaped every C3PAO’s assessment procedures
  3. Q1 2026Phase 1 contract flow-down active · CMMC L1/L2 self-assessment requirements begin appearing in new solicitations, phased by NAICS
  4. 2028Phase 4 · full DIB coverage · CMMC required on effectively every new DoD contract at the specified Level; suppliers without cert lose award eligibility
  1. DFARS 252.204-7012 In force since 2017

    Every DoD contractor has been under this since the last administration. Most treated the SPRS self-assessment as vanity; the score didn’t matter because nobody was pulling it. CMMC 2.0 changes the enforcement, not the clause. If your evidence is thin, 7012 is where the audit trail was supposed to live.

  2. DFARS 252.204-7020 The SPRS floor

    Your posted SPRS score is what a prime pulls before award. In 2026, primes are setting minimum SPRS thresholds in RFP language on their own initiative. 88 out of 110 is common, higher on classified adjacencies. That threshold game beats you to the CMMC L2 requirement by six months.

  3. DFARS 252.204-7021 The CMMC clause

    Phased flow-down. Not applied to your backlog; applied to your next new solicitation once your NAICS phases in. Your Program Manager’s phase-in date is the timeline that actually matters, and nobody at your prime knows it either. Getting the answer requires calling the acquisition office.

  4. FAR 52.204-21 The federal floor

    Fifteen controls. Every federal contract, not just DoD. GSA, DHS, DOE flow this down too. Most contractors treat it as CMMC’s little cousin and skip the evidence work. Real risk: an OIG audit under FAR is a faster enforcement vector than a C3PAO assessment.

  5. ITAR §120-130 Parallel regime

    If you touch munitions-list data, ITAR isn’t a layer on top; it’s a separate enforcement regime with criminal penalties. Overlap with 800-171 §3.1 and §3.9 is real, but ITAR pre-shipment reviews are their own beast that CMMC doesn’t cover. Handle both, not one.

§ II · Where CMMC Costs Land

Three moments turn CMMC from a compliance line item into a contract loss.

Every DIB supplier walks through all three. The cost of missing one shows up in lost awards, extended C3PAO cycles, and remediation billing.

PHASE 01 · AWARD

The clause hits your inbox.

Your prime forwards the RFP with DFARS 252.204-7021 flow-down. You have the length of the proposal window to demonstrate readiness or the prime routes the work to a competitor who is.

PHASE 02 · GAP

Your SSP has holes.

Every DIB supplier walks in thinking they’re halfway there. Roughly 4 in 5 discover their SSP and POA&M can’t defend more than 40 of the 110 controls in a real assessment interview.

PHASE 03 · C3PAO

The assessor arrives.

A C3PAO is not a friendly audit. They test the evidence and the personnel who own it. First-pass fail rates on Rev 3 assessments are running above 50%. Every miss adds 90-180 days before the next window.

Platform Track

Continuous evidence collection against every 800-171 Rev 3 control. Auto-generated SSP, POA&M with remediation targets, and CUI-boundary attestation. Ready to hand a C3PAO on Day 1, not built the week before.

Advisory Track (Other20)

Real vCISO in your assessment interviews. Pre-mission briefing for control owners. Post-assessment POA&M triage. Not a partner-network handoff. Our people on your calls, priced by the hour.

§ III · Outcomes on the Line

What a completed run looks like on paper.

Eight to twelve weeks after kickoff, this is the readiness summary you hand your prime, before the C3PAO shows up.

Contractor Cyber Readiness Summary · CMMC L2ITEM 03 · REV A
1. Controls Attested
110
Full 800-171 Rev 3 catalog. Evidence continuous.
2. SSP Freshness
< 30d
Auto-regenerated on control change. Not a static PDF.
3. POA&M Aging
Zero
Every open remediation item within its target window.
4. Time-to-Ready
8-12w
From kickoff to C3PAO scheduling. Typical DIB supplier.
Signed: Yolonda Smith, CISSP · CISM · Principal AdvisorvCISO Lite · Other20

§ IV · When the Prime Sends the Data Call

Your written response gets pasted straight into the prime’s proposal, word for word.

Every prime assembling a major DoD bid sends a CMMC compliance data call to their subcontractors, usually 30 to 60 days before the proposal is due. Whatever you write comes back verbatim in their Technical Volume. If it reads uncertain, the prime lowers their proposed technical rating to absorb your risk, or drops you from the team. If it reads decisive and evidenced, it becomes a strength claim in their writeup and the reason you keep the seat.

The AFTER response → is what the prime pastes into their Technical Volume. The BEFORE is the reason a competing subcontractor gets the seat instead.

Sub-Contractor Compliance Data CallQ. 47 · CMMC MATURITY
Question 47Please provide evidence of your current CMMC Level 2 status. Include CAGE code, C3PAO of record, and cert expiration date. If not yet certified, provide most recent NIST SP 800-171 self-assessment score, POA&M closure timeline, and target C3PAO assessment window.
Before
We are currently pursuing CMMC Level 2 certification. Our target assessment date is TBD pending completion of our internal readiness work. Please advise whether CMMC L2 certification is a gating requirement for this solicitation, and if so, we would appreciate any flexibility on scheduling.
After Other20
CMMC Level 2 Final Certification: In progress with scheduled C3PAO assessment window. CAGE: 1H3X4. C3PAO of record: [Assessor], assessment scheduled 11 weeks from award notification. Current NIST SP 800-171 Rev 3 self-assessment: 110 of 110 controls attested, evidence continuous. SSP + POA&M attached (Encl. C). Zero open findings past target closure date. vCISO of record available for prime-level review call.
Attach. C · SSPAttach. D · POA&M

§ IVa · Program Horizon 2026-2028

The next 24 months of DoD cyber flow-down, on one chart.

The DoD rollout is phased. Different CMMC Levels apply to different contract types across a 24-month window. Below is the sequence, with the rule number driving each phase.

ProgramH2 2026H1 2027H2 2027H1 2028H2 2028
CMMC L1 Self-AssessContract flow-down active
CMMC L2 C3PAOPhased into new solicitations
CMMC L3 DIBCACApplied to highest-value APT-in-scope work
NIST 800-171 Rev 3Default control catalog for all L2+ assessments
FAR Part 40 CUIBroader civilian-agency CUI flow-down expected

Sources: DoD Program Executive Office · 32 CFR Part 170 · FAR Council rulemaking calendar. Dates reflect our current tracked signal; we brief you when they move.

§ V · What Ships

The deliverables list. Every artifact, named and linked.

Each is an artifact your C3PAO will ask for. Some the platform produces continuously; some Other20 authors on the mission clock. Click through to the feature or service page that owns the artifact.

Platform
System Security Plan
Auto-regenerated on every attested control change. Structured to the DoD SSP template. Traceable, defensible in the assessment interview.
See the feature
Platform
POA&M register
Every open item, target closure date, owner, remediation evidence link. Signed change history retained. XLSX and JSON exports for your C3PAO.
See the feature
Platform
CUI boundary attestation
Where CUI enters, where it lives, where it exits. Drawn from actual data flow, not a whiteboard sketch. PDF plus signed source diagram.
See the feature
Platform
Control evidence bundle
One artifact per NIST 800-171 Rev 3 control. Timestamped, cryptographically hashed, portable across assessors. ZIP + manifest.
See the feature
Platform
Subcontractor flow-down register
Every sub in scope, current cert status, contract obligations tracked in one register. Alerts when a sub's SPRS score drifts before your prime notices.
See the feature
Platform
Continuous monitoring cadence
Quarterly re-attestation calendar mapped to Rev 3 assessment procedures. Automated evidence refresh. No lapse between assessment cycles.
See the feature
Other20
Assessment interview kit
Control-owner briefings, sample questions, likely follow-ups. Every named responder walks in prepared. Delivered as PDF + audio briefing.
See the service
Other20
C3PAO briefing packet
Everything your assessor wants delivered on Day 1. Reduces interview time. Removes surprise findings. Assembled by Other20, reviewed by your vCISO.
See the service
Other20
Incident-response playbook
Purpose-built for DIB reporting timelines. DIBNet + DC3 reporting steps encoded. Tabletop exercise scheduled quarterly with an Other20 vCISO on the call.
See the service
Other20
Post-assessment POA&M triage
If any findings land, Other20 triages them by contract-impact and negotiates remediation windows with your assessor. You keep the awards you were about to lose.
See the service

§ VII · Is this you?

The DIB supplier moments we walk through the most.

Six situations we see repeatedly. If you’re inside any of them, the pre-mission briefing is where we start.

Your prime added CMMC Level 2 as a gating clause on your next bid, and your last SPRS score is more than a year old.

You subcontract on a program you can’t afford to lose, and the DFARS 252.204-7021 flow-down memo landed in your inbox this quarter.

Your CUI lives across cloud, on-prem, and a few engineer workstations, and nobody has drawn the actual data-flow diagram in two years.

You have 30+ sub-tier suppliers under you and no register that proves who’s L1 self-assessment ready and who isn’t.

You’re staring down a NIST 800-171 Rev 3 gap analysis and you don’t know whether to hire a consultant, buy software, or do both.

Your CFO wants a fixed number for CMMC readiness and every quote you’ve gotten is either “$X million” or “call for pricing.”

Advisory · Other20

The pre-mission briefing before your C3PAO cycle.

Every serious CMMC engagement starts with a 45-minute working session. No sales cycle, no NDA hoops. The assessment world runs on classified-briefing rhythm, so ours does too.

Briefing · Op-Ready · Cleared for Distribution
Pre-Mission Briefing: CMMC Level 2 Readiness

Fractional CISO, 20+ years in the field, US Air Force background. Yolonda has walked the exact assessment cadence your C3PAO will follow. This is what the 45 minutes covers.

Agenda · 01 · Scope

Your CUI boundary. Contract count in play. Subcontractor tier depth. Where your SSP already covers you, where it doesn’t.

Agenda · 02 · Timeline

C3PAO scheduling reality. What’s achievable in 8-12 weeks vs. 16-20. Where your prime’s award calendar forces the choice.

Agenda · 03 · Package

Platform + Other20 scope. Fixed monthly retainer or hourly. Explicit deliverables list from § V above. No mystery pricing.

§ VIII · Common Questions

What DIB program managers ask us.

  • What's the difference between CMMC Level 1, Level 2, and Level 3?

    Level 1 covers Federal Contract Information (FCI): the 15 controls in FAR 52.204-21, verified by annual self-assessment. Level 2 covers Controlled Unclassified Information (CUI): all 110 NIST 800-171 Rev 3 controls, verified either by self-assessment or by a C3PAO third-party assessment depending on the contract. Level 3 covers the most sensitive DoD programs (APT-in-scope): 110 Rev 3 controls plus a subset of NIST 800-172 enhanced requirements, assessed by DIBCAC. Your contracting officer specifies the Level required for each award.

  • Can Other20 attend my C3PAO assessment interviews?

    Yes. Your vCISO participates as a program-team member: briefing control owners in advance, sitting through interviews as a subject-matter resource, and supporting POA&M triage if the C3PAO surfaces findings. We don't role-play as your employee, but we do show up as a named advisor on your program team, which is standard practice and well within CMMC assessment norms.

  • What if we're a subcontractor to a prime? Do we still need Level 2?

    If you process, store, or transmit CUI in performance of the subcontract, yes. DFARS 252.204-7021 flows down. The prime is contractually required to verify your Level before award, and most primes are now using a supplier's SPRS score and CMMC status as a pre-bid gate. If you don't touch CUI, Level 1 (self-assessment) is often sufficient. We help you make that determination in the readiness call.

  • How long does the platform + Other20 combined engagement typically take?

    8-12 weeks from kickoff to C3PAO scheduling for a typical DIB supplier with reasonably mature IT hygiene. Longer (16-20 weeks) for organizations rebuilding an SSP from scratch, running heterogeneous cloud + on-prem environments, or with more than three tiers of subcontractor flow-down to organize. The readiness call gives you a scoped timeline before you commit.

  • Is Other20 an authorized C3PAO?

    No. That's intentional. C3PAOs perform the formal assessment, and Cyber-AB rules prohibit an assessor from also serving as the readiness partner for the same organization. We prepare you for the assessment; a separate authorized C3PAO conducts it. We can recommend C3PAOs whose scheduling and scope match your target window.

  • Do you handle NIST 800-171 for non-DoD federal contracts too?

    Yes. The 800-171 control catalog is used by GSA, DHS, DOE, and other civilian agencies via various contract clauses (and FAR Part 40 rulemaking is expanding this reach). Our platform's evidence collection is 800-171-native, and Other20's readiness process works the same whether the assessor is a C3PAO, a civilian agency IG, or a prime auditor.

Contact · vCISO Lite · Defense Practice

You’re on a bid cycle. Get on the briefing calendar.

CMMC L2 readiness is measured in weeks, not quarters. But only if the clock starts today. Book the briefing, walk into your next prime call with a scoped timeline, and stop watching awards go to competitors who moved first.

01 · Point of Contact
Yolonda Smith
Founder & Principal Advisor · Other20
02 · Response Window
Same-day briefing scheduling
45-min working session
03 · Credentials
CISSP · CISM · GSEC · GCIH
USAF · Carnegie Mellon CISO Cert
04 · Scope
CMMC L1 · L2 · L3 readiness
NIST 800-171 Rev 3 · CUI · ITAR overlap