What Is CMMC 2.0?
CMMC (Cybersecurity Maturity Model Certification) 2.0 is the Department of Defense’s framework for protecting Controlled Unclassified Information (CUI) across the defense supply chain. For any Houston business that holds DoD contracts — or supports a prime contractor who does — CMMC certification is no longer optional. Phase 2 enforcement goes live in November 2026, meaning any company handling CUI must be certified before bidding on new DoD contracts or risk being locked out entirely.
CMMC 2.0 streamlines the original five-level model down to three levels, aligning requirements with NIST SP 800-171 and NIST SP 800-172. That streamlining does not make compliance easier — it makes enforcement more systematic. Contracting officers can see your SPRS score before awarding a contract. Gaps will cost you work.
Houston’s Defense Industrial Base
Houston is home to one of the most active defense and aerospace supply chains in the nation. NASA Johnson Space Center in Clear Lake, Ellington Field Joint Reserve Base, Boeing Defense & Space, Lockheed Martin, KBR, and L3Harris all operate locally — and hundreds of smaller subcontractors support them. The CMMC requirement cascades down the entire supply chain. A $2M subcontractor supporting a Boeing space systems contract needs Level 2 certification just as much as Boeing does. If your company handles CUI and you haven’t started your gap assessment, you’re behind.
The Clear Lake and Webster aerospace corridor is particularly exposed. Intuitive Machines (Artemis lunar landers), Axiom Space, Jacobs Technology, SAIC, and Leidos — along with their subcontractor networks — all face CMMC requirements flowing down from NASA and DoD prime contracts. If you support JSC missions and handle technical data, your CMMC obligation is already written into your contract.
CMMC Level 1 vs. Level 2
Level 1 (Foundational): 17 basic cybersecurity practices from FAR 52.204-21. Annual self-assessment. Applies to companies that handle Federal Contract Information (FCI) only — not CUI.
Level 2 (Advanced): All 110 security requirements from NIST SP 800-171. Third-party C3PAO assessment required for most contracts involving CUI. This is the level most Houston defense subcontractors must achieve.
Level 3 (Expert): Based on NIST SP 800-172. Government-led assessment. Reserved for a very small number of contractors on the most critical programs.
For the vast majority of Houston’s defense subcontractors — across aerospace, energy support, and professional services — Level 2 is the target. The mandatory C3PAO third-party assessment is what makes Level 2 categorically more demanding than self-attestation. Your documentation, evidence, and security program must all be defensible before the auditor arrives.
xSIT’s CMMC Compliance Process
Step 1 — Gap Assessment: We evaluate your current security posture against all 110 NIST 800-171 controls and produce a System Security Plan (SSP) and Plan of Action & Milestones (POA&M). This baseline shows exactly where you stand and what remediation will cost.
Step 2 — Remediation: We implement the missing controls — endpoint protection, multi-factor authentication, privileged access management, audit logging, incident response procedures, and configuration management. We manage technical implementation and policy documentation together.
Step 3 — SPRS Submission: We calculate your score using the DoD methodology and submit it to the Supplier Performance Risk System (SPRS). Your SPRS score is visible to contracting officers and can affect contract awards even before formal CMMC certification is required.
Step 4 — C3PAO Preparation: We prepare your full documentation package and conduct a pre-assessment readiness review. Our goal is that you pass the formal audit on the first attempt — not discover gaps under pressure from an assessor.
Investment & Timeline
Gap assessments typically run $15,000–$50,000 depending on company size and environment complexity. Full remediation engagements for mid-size Houston contractors run $75,000–$250,000 when you factor in technical controls, documentation, policy development, and project management over a multi-month engagement.
Timeline to Level 2 certification: 4–9 months from initial gap assessment, assuming active remediation throughout. C3PAO audit slots are already booking out months in advance. Companies that delay risk missing the November 2026 enforcement deadline — which means exclusion from new DoD contract bids until certification is achieved.
Ready to Get Started?
The November 2026 Phase 2 deadline is approaching fast. Don’t wait until Q3 to start — remediation takes months, and C3PAO audit slots are filling up. Contact xSIT today for a no-obligation CMMC readiness conversation.