Wright-Patterson Air Force Base anchors an aerospace, research, and engineering economy across the Miami Valley, and it supports a supply chain that runs from large primes down to machine shops with a dozen employees. If any part of your work involves Controlled Unclassified Information, the compliance requirement is the same regardless of which end of that chain you occupy.
What changes on November 10, 2026
CMMC Phase 2 makes third-party certification by an accredited C3PAO mandatory for contracts involving CUI. Until now, a great many suppliers have operated on self-attestation. That option is closing for the requirements that matter, and the practical consequence is straightforward: a supplier without certification becomes ineligible for the contract.
The number that surprises people is how long readiness takes. Reaching a defensible Level 2 posture from a cold start realistically takes nine to twelve months — not because the controls are exotic, but because evidence has to accumulate. An assessor examines whether controls have been operating, and a control implemented last week has no operating history to show. That is precisely why starting now rather than next quarter is the entire point.
The work, in the order it should happen
Draw the CUI boundary first
Every dollar you spend on CMMC is priced by your scope. Over-scope and you are hardening laptops that never touch CUI. Under-scope and an assessor finds CUI living somewhere unprotected, which is a far worse outcome. Before touching a single control, establish where CUI enters, lives, moves, and leaves — email, file shares, ERP, engineering workstations, backups, and any subcontractor who handles it.
Classify the assets inside it
CUI assets, Security Protection assets, Contractor Risk Managed assets, and out-of-scope. This inventory is itself an assessment artefact, so build it as a living document rather than a one-time spreadsheet.
Gap-assess against the 110 requirements
NIST SP 800-171 defines the control set. An honest gap assessment tells you where you actually stand, including the uncomfortable parts. Optimistic self-scoring is common and it is the most expensive mistake available, because it is discovered by a C3PAO rather than by you.
Build the SSP and work the POA&M
The System Security Plan has to describe the environment as it really is; assessors compare documentation to reality and expect them to agree. The Plan of Action and Milestones needs to be genuinely worked rather than maintained as a fiction — a POA&M whose dates have all quietly slipped past is worse than no POA&M, because it evidences a programme that is not operating.
Document your external service providers
Your MSP, your cloud tenants, any managed SOC. Their responsibilities have to be written down, and where CUI is involved, backed by the right agreements. If you engage us, this includes us — we expect to be documented as part of your boundary, and we provide what you need for that.
Beyond the defense supply chain
Not every Dayton business is a defense supplier. The region also has healthcare, education, and general commercial activity, and the managed security, managed IT, SOC, and recovery services underneath the compliance work are the same in either case. Compliance is a way of proving your controls exist. The controls themselves are what actually protect the business.
Distance, honestly
Dayton is around ninety minutes to two hours from our office. CMMC work is overwhelmingly documentation, configuration, and evidence collection — all of which is delivered remotely without any loss. Where an on-site day genuinely helps, such as an initial boundary walkthrough, we schedule it.
Have a contract that renews after November 2026 and no certification path yet?
This page is general information about regulatory frameworks and is not legal, compliance, or audit advice. Any engagement is governed by the executed Torchsec service agreement.