Woman with curly hair using laptop in modern server room hallway with reflective glass wall at night.

CMMC Compliance for Kansas City Defense Contractors: What You Need to Know in 2026

October 06, 2026

Your DoD prime just sent a contract modification referencing DFARS 252.204-7012 — and your SPRS score is sitting at zero. If you supply to Whiteman AFB, Honeywell FM&T, or any other defense prime in the Kansas City metro, CMMC compliance for defense contractors is no longer a future planning item — it's a current contract condition.

Where CMMC Stands Right Now (August 2026)

CMMC Phase I became a live contract requirement on November 10, 2025. Level 1 and Level 2 self-assessments are now a condition of contract award. Phase II — which mandates third-party audits by a C3PAO (Certified Third-Party Assessment Organization) — is indefinitely paused per DoD's ongoing reform task force. Paused is not the same as canceled.

What the Phase II Pause Actually Means

DFARS 252.204-7012, the clause requiring contractors to implement adequate security on systems processing covered defense information, remains fully enforceable today. NIST SP 800-171 Rev. 2 — the 110-control security framework that underpins Level 2 — is still the compliance baseline your contract references. The pause only delays the mandatory C3PAO audit requirement; it does not pause your obligation to meet those controls.

The SPRS Score Requirement Is Already Live

  • DFARS is still enforceable. The Phase II pause creates a preparation window, not permission to stand down. Contracts issued during Phase I already require a current SPRS score — the Supplier Performance Risk System score a senior company official must submit affirming your self-assessment results.
  • A missing or zero score disqualifies your bid. If that score is absent or zero, your bid is disqualified before it's evaluated on price or capability. Building compliance posture now — while C3PAO audit pressure is temporarily off — is the lowest-cost window you will have.

Which CMMC Level Applies to Your Kansas City Contract

Your CMMC level is determined by the type of government information you handle. If you handle only FCI — Federal Contract Information, meaning data generated under a federal contract — you fall under Level 1. If you handle CUI — Controlled Unclassified Information, such as technical specifications or export-controlled data — you fall under Level 2 or Level 3.

CUI (Controlled Unclassified Information):Government-created or government-controlled information that requires safeguarding per law, regulation, or policy, but is not classified — examples include technical drawings, export-controlled specs, and contract performance data.
Data Type CMMC Level Controls Required Assessment Type
FCI only Level 1 17 practices (FAR 52.204-21) Annual self-assessment
CUI present Level 2 110 NIST SP 800-171 Rev. 2 controls Self-assessment now; C3PAO audit when Phase II resumes
CUI + critical programs Level 3 110+ NIST controls plus NIST SP 800-172 requirements Government-led assessment

Why Kansas City Suppliers Often Underestimate Their Level

Suppliers to Whiteman AFB B-21 Raider sustainment contracts almost certainly touch CUI — technical specifications, maintenance data, and engineering files for a classified weapons system do not qualify as simple FCI. Honeywell FM&T in Kansas City, MO produces nuclear weapons components; any sub receiving fabrication specs or design data from Honeywell FM&T is handling CUI and must treat Level 2 as their floor.

CMMC compliance for defense contractors sitting in the Level 2 tier requires a posted SPRS score, a documented System Security Plan, and full implementation of the 110 NIST 800-171 controls — all of which sit within the broader IT compliance services framework TS Conard builds for regional defense subs.

The Subcontractor Flowdown Problem Every Kansas City Prime Ignores

CMMC requirements flow down from prime contractors to every subcontractor that handles FCI or CUI. The prime is contractually responsible for verifying each sub's SPRS score before awarding a subcontract. A sub with a missing or zero SPRS score exposes the prime to contract default — which means your score problem becomes your customer's problem fast.

Why "CMMC Is a Big-Company Problem" Is the Wrong Assumption

CMMC subcontractor flowdown is not optional or advisory. The DFARS clause a prime accepts flows to every tier of the supply chain that touches covered information. For Kansas City defense manufacturers and fabricators who assumed their 15-person shop was too small to matter, the enforcement record says otherwise.

DIBCAC — DoD's enforcement arm — has conducted unannounced assessments of small defense suppliers, including single-digit-headcount fabricators, and found significant NIST 800-171 gaps. The cybersecurity controls required by NIST 800-171 apply regardless of headcount or revenue.

Primes verifying sub SPRS scores before award is now standard practice. If your SPRS score is absent or reflects a score near zero, you will not receive subcontract awards from compliant primes — regardless of your price or delivery history.

Your 2026 Phase I Readiness Checklist

Under Phase I, five actions determine whether your business can compete for DoD contracts right now. None of these wait for Phase II. Each step below is something a Kansas City contractor can begin this week — and each is an area where a gap assessment from TS Conard will surface the specific remediation your environment requires.

Five Steps to Phase I Compliance

  1. Post a current SPRS score. A senior company official must affirm your self-assessment score annually in the Supplier Performance Risk System. A score of zero means you completed no assessment — it does not mean you passed. Primes read a zero score as a disqualifying gap.
  2. Document your System Security Plan (SSP). An SSP is a written description of how your organization implements each NIST SP 800-171 control. SSP documentation is required under DFARS 252.204-7012 regardless of the Phase II pause — it is what a C3PAO auditor will review when Phase II resumes.
  3. Map every CUI data flow in your environment. Identify every location where CUI exists or transits: email, shared drives, ERP systems, engineering file servers, and laptops used off-site. You cannot protect data you have not located.
  4. Audit your Microsoft 365 configuration. Standard commercial Microsoft 365 does not meet CUI handling requirements. Microsoft 365 GCC or GCC High configuration is required — GCC High specifically for ITAR-controlled or highly sensitive CUI. Many Kansas City contractors are using standard M365 and incorrectly assuming they are covered.
  5. Identify and remediate gaps before your next RFP drops. A structured gap assessment against the 110 NIST 800-171 controls — paired with a Plan of Action and Milestones (POA&M) — is the deliverable that demonstrates good-faith compliance progress. TS Conard's CMMC compliance services in Kansas City are built specifically for this process: gap identification, SPRS score documentation, and a prioritized remediation roadmap.

Frequently Asked Questions

Is CMMC Phase II really on hold, or do I still need to prepare?

Phase II — mandatory C3PAO audits — is indefinitely paused per DoD's reform task force. Phase I is live: Level 1 and Level 2 self-assessments are a current condition of contract award. NIST SP 800-171 compliance and DFARS 252.204-7012 obligations remain fully in force. The pause is a preparation window, not a waiver.

What is the difference between CMMC Level 1 and Level 2, and what does my SPRS score need to show?

Level 1 applies when you handle only FCI and requires 17 basic practices with an annual self-assessment. Level 2 applies when you handle CUI and requires all 110 NIST SP 800-171 Rev. 2 controls, a posted SPRS score affirmed by a senior official, and a C3PAO audit when Phase II resumes. Most Whiteman AFB and Honeywell FM&T suppliers fall under Level 2. A zero or missing SPRS score disqualifies your bid before price or performance is evaluated.

Do I need a C3PAO audit right now, or is self-assessment enough?

Under Phase I, self-assessment is sufficient for Level 1 and Level 2 contracts. C3PAO audits — conducted by a Certified Third-Party Assessment Organization — will become mandatory for Level 2 when Phase II resumes. Use the current window to complete your SSP, post your SPRS score, and remediate gaps so a future C3PAO audit does not catch you unprepared.

Can a local Kansas City IT company help me with CMMC, or do I need a specialized national firm?

A Kansas City-based managed IT provider with CMMC expertise can deliver gap assessments, SPRS score documentation, SSP preparation, and ongoing NIST 800-171 control maintenance — with direct knowledge of regional supply chain context that national firms lack. TS Conard serves defense contractors across the KC metro, Northwest Missouri, and Northeast Kansas.

Written by

TS Conard Team

TS Conard Editorial Team

TS Conard is a managed IT services provider based in Saint Joseph, MO, serving Northwest Missouri businesses since 2003 with expertise in cybersecurity, IT compliance, data backup, and proactive technology support for industries including manufacturing, construction, and local government.

Get a CMMC Gap Assessment Before Your Next DoD Contract Drops

Click through to TS Conard's CMMC Compliance Services page to see exactly how our Kansas City team assesses your current posture, prepares your SPRS score documentation, and builds a remediation plan so your contract award isn't at risk.

Schedule Your CMMC Gap Assessment