Real security for a Washington defense supplier is the day-to-day operations underneath the certificate — DFARS 252.204-7012 incident reporting in 72 hours, a System Security Plan that matches reality, a Plan of Action and Milestones that is actually being worked, NIST SP 800-171 controls operating continuously, and the discipline to keep the environment audit-ready every day, not just the week before an assessor arrives. A CMMC certificate is a snapshot. Real security is a routine.
Quick Reality Check on Rev 2 vs Rev 3
This is the single most-confused topic in the defense supplier conversation right now, and it matters operationally.
- NIST SP 800-171 Revision 3 was published in May 2024.
- DFARS Class Deviation 2024-O0013 (and follow-on guidance) keeps Revision 2 the operative requirement for CMMC and for DFARS 252.204-7012 contracts.
Translation: your contract today flows down NIST SP 800-171 Rev 2. Build your environment against Rev 2. Plan for an eventual transition to Rev 3 — there are meaningful changes in control families and language — but do not let a vendor sell you a Rev 3 remediation program as if it is mandatory tomorrow. It is not, as of May 2026.
Important second clarification: ROI Technology Inc. is an MSP that prepares clients for assessment. We are not a Certified Third-Party Assessment Organization (C3PAO). Only accredited C3PAOs perform CMMC Level 2 third-party assessments. Any MSP claiming they can certify you is misrepresenting the program.
The CMMC Rollout Timeline, Stated Carefully
The published rule and follow-on guidance give a clear set of milestones that Washington suppliers should plan against:
- 32 CFR Part 170 (the CMMC program rule) became effective December 16, 2024.
- 48 CFR (the contract-clause rule that authorizes DoD contracting officers to include CMMC requirements in solicitations) is effective approximately November 10, 2025.
- Phase 2 of the phased rollout, when CMMC Level 2 requirements begin appearing more broadly in DoD contracts, begins approximately November 10, 2026.
That means a Snohomish County defense supplier today is operating under DFARS 252.204-7012 with the current self-assessment expectation, and is on the runway to formal CMMC Level 2 third-party assessments under Phase 2. For the structural overview of what CMMC requires at each level, see CMMC compliance for Washington defense contractors.
What DFARS 252.204-7012 Actually Requires Today
If you have a DoD contract that flows down the CUI clause, you already have obligations that exist whether or not you are CMMC-certified yet:
- Implement NIST SP 800-171 Rev 2 (110 controls across 14 families) to protect Covered Defense Information / CUI on your information systems.
- Submit a current self-assessment score to the Supplier Performance Risk System (SPRS).
- Report cyber incidents to DoD within 72 hours of discovery via DIBNet.
- Preserve and protect images of affected systems for at least 90 days.
- Flow the clause down to subcontractors that will handle CUI.
If your supplier-security questionnaire to a prime says “we are working toward compliance,” you are already behind the published baseline. Self-assessment and SPRS scoring are current obligations, not future ones.
What “Real Security” Looks Like Underneath the Certificate
A CMMC Level 2 assessment validates a snapshot. Real security shows up between assessments. The operational disciplines that separate a paper-compliant supplier from a defensible one:
A System Security Plan That Matches the Network
An SSP that describes an environment your assessor cannot find when they walk in the door is a failed assessment. Real security means the SSP is a living document — updated when you change firewalls, when you swap EDR vendors, when you add a new SaaS tool that touches CUI, and when you move from on-prem file storage to GCC High. Tie the update process to your change management ticket.
POA&M Discipline
CMMC and DoD guidance allow a limited Plan of Action and Milestones for specific controls at assessment time, but POA&M items must be closed within 180 days — not a year, not “when budget allows.” Real security means you close POA&Ms on schedule, document the evidence, and update the SSP. A POA&M that has been open for 18 months is not a POA&M; it is an admission.
CUI Identification and Scoping
The most common quiet failure in defense suppliers we assess is that nobody knows where CUI actually lives. Engineers email CUI drawings to themselves. Programs save CUI to a shared OneDrive that was never scoped for it. Quality teams print CUI documents and store them in a filing cabinet outside the assessed boundary. Real security means a written, enforced CUI handling policy and recurring spot-checks.
Multi-Factor Authentication, Everywhere It Matters
NIST SP 800-171 Rev 2 requires MFA for privileged accounts and for remote access to non-privileged accounts. Real security pushes that further — MFA on every account, phishing-resistant MFA on every account that can touch CUI, and Conditional Access that blocks legacy authentication paths.
Endpoint Detection and Response
Traditional antivirus is not adequate for a CUI environment. Managed EDR with 24/7 monitoring is the working baseline. The “M” in MDR — having actual humans triaging alerts — is what turns a tool into a defense.
Backup and Incident Response Readiness
Tested, immutable backups. An incident response plan for small business scaled to defense-supplier obligations (72-hour DoD reporting, 90-day image preservation, prime-contractor notification). Tabletop exercises at least annually with the documented playbook on the table.
A Security Assessment Cadence
Real security includes a recurring IT security assessment — not just the pre-assessment readiness review. Internal vulnerability scanning, configuration drift detection, and an annual third-party look from someone other than the MSP who built the environment.
What This Means for a Snohomish County Supplier Right Now
For a Western Washington defense supplier looking at the 2026 calendar, the practical roadmap looks like this:
- Confirm scope. Identify every contract that flows down CUI today, identify every system that touches CUI, and identify which subcontractors you flow CUI to. Many “we don’t really have CUI” claims do not survive five minutes of conversation with engineering.
- Get a clean SPRS score. A current, honest NIST SP 800-171 Rev 2 self-assessment posted to SPRS is table stakes. Score the environment as it actually is — overstating posture in SPRS is a False Claims Act exposure.
- Close gaps against Rev 2. Build to the standard that is currently operative for CMMC, not the one that may be operative in two years.
- Prepare your SSP and POA&M as living documents. Not artifacts for the C3PAO.
- Engage a C3PAO when ready. Schedule early — the assessment pipeline is finite and Phase 2 demand is going to surge.
- Operate the program. Once certified, run the daily, monthly, and annual disciplines that keep the environment audit-ready.
For compliance services that walk this path with a supplier, ROI Technology Inc. partners on the technical and program-management work that sits underneath the C3PAO assessment.
ROI Technology Inc. partners with Washington defense suppliers on the operational work behind CMMC — NIST SP 800-171 Rev 2 control implementation, SSP and POA&M discipline, DFARS 252.204-7012 readiness, and the daily security operations that keep the environment audit-ready between assessments. Contact us or call (888) 707-3652 for a no-cost CUI scoping conversation. (We prepare you; an accredited C3PAO certifies you — we will help you choose one.)