SHOP ONLINE STORE →

Blog · Compliance

CMMC Is Coming for Your Supply Chain

Your drawings are Controlled Unclassified Information. The shop that polishes your lenses will need to prove it can protect them.

CMMC — the DoD's Cybersecurity Maturity Model Certification — stops being an abstraction the day a prime flows it down your supply chain. Level 2, built on the 110 controls of NIST SP 800-171, applies to any supplier that touches Controlled Unclassified Information. A toleranced drawing of a seeker dome is CUI. So is the STEP file of a targeting-pod window. If your optics vendor emails those around like vacation photos, your program inherits the finding.

What flow-down actually looks like

Expect three things in sequence: DFARS 252.204-7012 language in POs (safeguarding + incident reporting), a demand for the vendor's SPRS score against NIST SP 800-171, and finally a requirement for third-party CMMC Level 2 assessment for contracts carrying CUI. Suppliers who start at the third step will lose a year; suppliers who never start will quietly disappear from bidder lists.

StageWhat ArrivesWhat You Must Show
1 · DFARS 252.204-7012PO clauseSafeguarding + 72-hour incident reporting
2 · NIST SP 800-171SPRS score requestSelf-assessment score, SSP, POA&M
3 · CMMC Level 2Contract requirementThird-party (C3PAO) assessment
Controlled Data · Concept Defense platform HUD — the drawings behind systems like this are Controlled Unclassified Information

Questions to ask your optics shop this quarter

Where is my technical data stored, and who can reach it? Are U.S.-person controls in place for ITAR data? Is there an SSP (System Security Plan) and a current self-assessment score? Is a C3PAO assessment scheduled? A supplier who answers in specifics is a supplier whose paperwork will not stall your award.

Where American Photonics stands

Cybersecurity: NIST SP 800-171 implementation in progress under DFARS 252.204-7012. CMMC Level 2 assessment planned within DoD's Phase 2 implementation window (2026). ITAR-registered handling governs controlled technical data. We publish the posture on our compliance page and will share details under NDA with any program that asks.

Program manager's takeaway: audit your optics vendors' data handling with the same energy you audit their scratch-dig. The lens can be perfect and still sink the contract.

Questions About This Article?

Our engineers wrote it — ask them directly.

Ask an Engineer