CMMC — the DoD's Cybersecurity Maturity Model Certification — stops being an abstraction the day a prime flows it down your supply chain. Level 2, built on the 110 controls of NIST SP 800-171, applies to any supplier that touches Controlled Unclassified Information. A toleranced drawing of a seeker dome is CUI. So is the STEP file of a targeting-pod window. If your optics vendor emails those around like vacation photos, your program inherits the finding.
What flow-down actually looks like
Expect three things in sequence: DFARS 252.204-7012 language in POs (safeguarding + incident reporting), a demand for the vendor's SPRS score against NIST SP 800-171, and finally a requirement for third-party CMMC Level 2 assessment for contracts carrying CUI. Suppliers who start at the third step will lose a year; suppliers who never start will quietly disappear from bidder lists.
| Stage | What Arrives | What You Must Show |
|---|---|---|
| 1 · DFARS 252.204-7012 | PO clause | Safeguarding + 72-hour incident reporting |
| 2 · NIST SP 800-171 | SPRS score request | Self-assessment score, SSP, POA&M |
| 3 · CMMC Level 2 | Contract requirement | Third-party (C3PAO) assessment |
Questions to ask your optics shop this quarter
Where is my technical data stored, and who can reach it? Are U.S.-person controls in place for ITAR data? Is there an SSP (System Security Plan) and a current self-assessment score? Is a C3PAO assessment scheduled? A supplier who answers in specifics is a supplier whose paperwork will not stall your award.
Where American Photonics stands
Cybersecurity: NIST SP 800-171 implementation in progress under DFARS 252.204-7012. CMMC Level 2 assessment planned within DoD's Phase 2 implementation window (2026). ITAR-registered handling governs controlled technical data. We publish the posture on our compliance page and will share details under NDA with any program that asks.
