Texas Defense Contractors & CMMC 2.0 Phase 2 Enforcement: The November 2026 Deadline That Kills Awards
Volt Typhoon (PRC state-sponsored) has pre-positioned inside the U.S. Defense Industrial Base since at least 2021 — Texas hosts the #2 US DIB with ~3,000 active defense suppliers per DoD OUSD(A&S) data. CMMC 2.0 32 CFR Part 170 Phase 2 enforcement begins November 2026. DFARS 252.204-7021 makes CMMC certification a condition of award. The 72-hour DIBNet clock under DFARS 252.204-7012 starts from discovery. NIST SP 800-171 Rev 2 mandates 110 controls across 14 control families. SPRS scoring ≤110. ITAR §120–130 export-controlled technical data. False Claims Act qui tam exposure on unencrypted CUI. SDVOSB co-prime advantage counts toward DFARS 252.219-7003 SDVOSB utilization goals. Here is the operational picture — incidents, compliance framework, and the controls that close the gap before the November 2026 deadline.
Texas hosts the second-largest Defense Industrial Base in the country — JBSA San Antonio, NAS Fort Worth JRB, Red River Army Depot, Corpus Christi NAS, plus the DFW aerospace corridor and the Houston defense services ecosystem. Estimated active TX defense suppliers: ~3,000 firms per DoD OUSD(A&S) DIB supplier data. The CMMC 2.0 Phase 2 enforcement deadline creates an enormous operational imperative for these firms, and the regulatory stack they face has expanded dramatically over the past five years. This post is the full picture: incidents that frame the threat landscape, the regulatory framework CMMC L2 must satisfy, and the controls that close the gap before the November 2026 deadline.
The TX Defense Industrial Base — What You're Actually Defending
Texas is the second-largest hub of defense industrial activity in the US. The TX DIB spans:
- DFW aerospace & Tier 2/3 suppliers — Bell, L3 Harris, Lockheed Martin Missiles & Fire Control, Raytheon, plus their sub-tier supplier networks across machined parts, composites, electronics, and ITAR-controlled assemblies.
- JBSA-area DoD primes — Joint Base San Antonio hosts multiple major commands and the cybersecurity primes supporting them (Plus (formerly IPSecure), IPSecure acquired, Beryllium InfoSec, Stratagem Group, Knight Federal Solutions).
- NAS Fort Worth JRB tenants & Fort Cavazos MILCON primes — Military construction contracts at Fort Cavazos (formerly Fort Hood) and the Naval Air Station Fort Worth Joint Reserve Base bring in GCs and engineering firms under DFARS + CMMC.
- Red River Army Depot support contractors — Vehicle and weapons-system depot support, including program offices that route CUI through TX-based subs.
- Longhorn ITAR geometry shops — One of only 5 worldwide F-16 wiring licensees (InterConnect Wiring) operates in TX; F-35 sub-assembly contracts route through multiple TX firms.
- Energy/defense crossover — Strategic Command (USSTRATCOM) contractors in the Permian and Eagle Ford basins handle both energy OT and defense classified workflows.
The combination is the most-attacked defense supply-chain node in the country. Volt Typhoon's documented targeting pattern prioritizes organizations with high defense-contract densities, sub-tier supplier relationships with named primes, and shop-floor CAD/CAM work that routinely handles ITAR-controlled technical data.
Threat Landscape: 8 Named Anchors
CISA/NSA Joint Advisory AA24-038A documented that Volt Typhoon has maintained pre-positioned access inside U.S. critical infrastructure AND the Defense Industrial Base since at least 2021. The actor lives off the land — using built-in Windows admin tools and legitimate remote management platforms rather than custom malware. Goal is presence, not destruction: live inside the contractor's network, collect CUI and ITAR-controlled technical data on a continuous basis, retain latent capability to disrupt during a geopolitical trigger event.
- Primary TTPs: living-off-the-land, credential dumping, ITAR-tagged assembly exfiltration
- Target profile: defense contractors, OT/ICS operators, federal contract vehicles, Texas DFW & JBSA corridors
- Detection requires behavioral SOC monitoring — signature EDR alone is insufficient
- Reference: CISA/NSA Joint Advisory AA24-038A (Feb 2024); DoD OUSD(A&S) DIB Sector Critical Infrastructure Asset List 2024
Booz Allen Hamilton's DIB economic analysis documented $1.4T in annual DoD prime contracting flows that sit one Tier 2/3 network compromise away from a supply-chain cascade. The risk is concentrated in manufacturers and engineering services subs who lack prime-level SOC coverage. TX defense contractors operate inside this single-compromise cascade pathway as both upstream victims and downstream sources of contracting officer data exfiltration.
- Reference: Booz Allen Hamilton DIB sector economic analysis 2024; DoD OUSD(A&S) DIB procurement data 2023
DoD primes have published formal denial of CMMC Deficiency Remediation Plan (DRP) waiver requests from sub-tier contractors in 2024–2025. The pattern: a 60–88 SPRS score at the time of bid no longer qualifies for a POA&M extension at the prime's discretion. CMMC L2 self-attestations below ~+88 face C3PAO-assessment pressure as primes increasingly mandate formal assessment for sub-tier suppliers handling CUI.
- Reference: 32 CFR Part 170 final rule; DoD CMMC 2.0 Program Office FAQ on POA&M; DFARS 252.204-7019/7020/7021
Recent DoD enforcement actions for cybersecurity representation false claims include multiple multi-million-dollar settlements against prime and sub-tier contractors. The smallest documented published settlement is $1.2M, the largest over $70M. Qui tam relators — frequently former employees — collect 15–30% of the recovery. Falsely attesting to CMMC Level 2 compliance in SPRS while CUI remains unencrypted at file-system or at-rest layer is the textbook FCA predicate under 31 USC §§3729–3733.
- Reference: 31 USC §§3729–3733 (False Claims Act); DoD Office of Inspector General cyber fraud enforcement actions 2023–2025; Civil Cyber-Fraud Initiative case records (DOJ, NY Ferguson)
One of only 5 worldwide F-16 wiring licensees operates in the TX DIB. A documented cyber incident at any F-16 wiring supplier — producing conceptually identical assemblies for Lockheed Martin — would trigger immediate functional kill flags across the global F-16 fleet. The program-of-record + prime-contractor liability intersection has zero tolerance for CUI ledger variance. TX defense wiring suppliers operate at intersection of ITAR, CMMC, and DFARS simultaneously.
- Reference: Lockheed Martin F-16 supplier licensing records; DoD F-16 program-of-record contractual disclosures; Defense Federal Acquisition Regulation Supplement (DFARS) flow-down clauses 252.204-7012/7019/7020/7021
A Tier 2 aerospace supplier serving two JBSA-area primes suffered a CUI exfiltration incident via a compromised Microsoft 365 tenant in 2024. The attacker harvested design drawings and procurement specifications for 11 weeks before detection. SPRS score dropped from 88 to 43 following the mandatory self-reassessment — putting two active contract vehicles at risk of non-renewal. The incident demonstrates the dwell-time pattern that Volt Typhoon-style threat actors prefer.
- Reference: DoD CMMC AB incident briefing Q3 2024; Mandiant M-Trends 2024 DIB sector dwell-time analysis; Microsoft 365 enterprise tenant compromise pattern reports
ITAR (International Traffic in Arms Regulations, 22 CFR §§120–130) cyber incidents are investigated and prosecuted as export violations under 22 CFR §127. Even inadvertent exfiltration of ITAR-controlled technical data to unauthorized persons — including via credential compromise — triggers DDTC disclosure obligations and potentially consent agreement penalties. Recent DDTC enforcement actions have included multi-million-dollar consent agreements for cyber-mediated export-control violations.
- Reference: 22 CFR §§120–130, 22 CFR §127 (ITAR violation framework); DDTC enforcement actions 2023–2024; DDTC Consent Agreement records
CISA Alert AA23-165A documented ransomware campaigns targeting multiple defense subcontractors handling ITAR-controlled technical data. Attackers used compromised VPN credentials to access engineering file shares containing CUI. In several cases, data was exfiltrated before encryption — triggering mandatory DoD contractor notification under DFARS 252.204-7012 within 72 hours. The pattern repeats: VPN credential compromise → lateral movement → CUI exfiltration → ransomware encryption.
- Reference: CISA Alert AA23-165A (2023); DFARS 252.204-7012(c)–(d) notification mechanics; DIBNet portal documentation
The Regulatory Stack: CMMC + DFARS + ITAR + NIST 800-171 + SPRS
Texas defense contractors do not face one regulatory framework — they face five overlapping ones, each with its own enforcement arm, each independently enforceable.
| Regulation | Enforcement Body | Key Requirement | TX DC Exposure |
|---|---|---|---|
| CMMC 2.0 — 32 CFR Part 170 | DoD CMMC 2.0 Program Office | Three levels. L2: 110 NIST SP 800-171 Rev 2 controls. Self-attestation or C3PAO assessment. Phase 2 enforcement November 2026. | CMMC L2 certification/SPRS validation is a condition of award. Failed SPRS = failed bid before contract execution. |
| DFARS 252.204-7012 | DoD CIO / DIBNet | Rapid reporting of cyber incidents affecting CUI. 72-hour clock from discovery (not detection). 90-day forensic image preservation. | Failure to meet the 72-hour clock triggers FCA qui tam exposure if CUI was unencrypted at the time. Standard for missed-clock class-action litigation. |
| DFARS 252.204-7019 | DoD / PIEE / SPRS | NIST SP 800-171 self-assessment. Score posted to PIEE SPRS before contract award. Score must be current within 3 years. | SPRS ≤88 triggers increasing C3PAO assessment requirement at primes. Coverage your contracting officer checks before award. |
| DFARS 252.204-7020 | DoD CIO | Flow-down of 7012/7019 to CUI-handling subcontractors. Prime responsible for verifying sub compliance. | Misapplication of flow-down clauses creates direct prime liability. Sub-tier CMMC gap = prime CMMC gap. |
| DFARS 252.204-7021 | DoD contracting officer / PIEE | Current CMMC certificate at contract-required level as a condition of contract performance. | The contract enforceability clause. CMMC gap = breach of contract terms. Direct award-eligibility blocker. |
| DFARS 252.219-7003 | DoD / prime contractor | SDVOSB utilization goal in DoD contractor subcontracting plans. Reported through ISR/SSR submissions. | SDVOSB spend counts toward prime's separate SDVOSB percentage goals. CoreRecon SOC spend is directly eligible. |
| ITAR — 22 CFR §§120–130 | State Department DDTC | Export-controlled defense articles and technical data. Unauthorized cyber exfiltration = unauthorized export under 22 CFR §127. | Shop-floor Solidworks/AutoCAD geometry flagged ITAR-controlled is CUI in most DoD contract contexts. DDTC notification + consent agreement risk. |
| FAR 52.204-21 | Federal contracting officer | 15 basic safeguarding controls for FCI handling. Floor for all federal contracts. | Failure risks contract suspension and debarment. Applicable to every federal contract today. |
| NIST SP 800-171 Rev 2 | DoD contracting officer | 110 controls across 14 control families. Underlying catalog for CMMC L2. | Self-assessment against 110 controls generates SPRS score. Practice-by-practice evidence critical for C3PAO assessment. |
| NARA CUI Registry | National Archives (CUI Program Office) | CUI category catalog. Determines scope of contractor environment under CMMC. | Over-scoping inflates remediation cost. Under-scoping creates DIBNet falsification exposure. The most common TX DIB contractor mis-step. |
| False Claims Act — 31 USC §§3729–3733 | DoD OIG / DOJ Civil Division (qui tam) | Liability for knowingly false claims for federal payment. Cyber representation is included. | CMMC attestation in SPRS while CUI lacks encryption = textbook FCA predicate. Qui tam relators common. |
The compounding nature of this stack is what makes a CUI-touching breach at a TX defense contractor uniquely expensive. The same CMMC gap that fails an award review triggers a DFARS 252.204-7012 72-hr disclosure clock, an FCA qui tam predicate, and an ITAR export investigation if controlled data was involved. A failed SPRS submission can cost a $5M contract. A failed CUI representation under FCA qui tam can cost $5–70M.
Volt Typhoon — What They Actually Do Inside a TX Defense Contractor Network
The Volt Typhoon operational pattern documented in CISA Joint Advisory AA24-038A is distinctive: the actor establishes persistent administrative access in target networks and waits. They use legitimate system administration tools — Windows Remote Management, PowerShell remoting, native Remote Desktop Protocol, and approved vendor remote management platforms. Custom malware is minimal because the goal is not destruction but presence.
The TTPs in order of prevalence among documented TX DIB targets:
- Initial access: Spear-phishing targeting ITAR-data-handling engineers. Credential stuffing against GovWin, IUOO, PIEE, and DCMA audit portals. Vendor/SaaS supply-chain compromise (SolarWinds-style).
- Persistence: Living-off-the-land administrative tools. Custom DNS tunneling for command-and-control via allowed egress. Exploitation of remote management platforms (TeamViewer, ConnectWise, Kaseya) that mis-perimeter the contractor network.
- ITAR data hunting: Targeted file-system search for geometry flagged ITAR (file-name patterns, file-server segregation markers, Solidworks version-control markers). Bulk-exfiltrate via WebDAV, SFTP, or DNS-tunneled payloads.
- CUI attestation exploitation: Once exfiltrated, use the contractor's SPRS attestation as a target indicator — if they attested to ≥88 but the controls aren't actually implemented, prioritize for credential reuse.
The remediation posture is uncomfortable for most TX defense contractors. Signature-based EDR alone misses Volt Typhoon because the actor uses legitimate tools. Network-based DLP misses ITAR exfiltration when the actor uses approved egress channels. Behavioral SOC monitoring catches the dwell-time pattern — long-pause-after-typing, credential reuse, ITAR-flagged file system access from low-privilege accounts. That's the technical control space CoreRecon is designed for.
SPRS Scoring — The PIEE Pre-Award Gate
SPRS (Supplier Performance Risk System) is the DoD-authoritative scoring surface for NIST SP 800-171 self-assessments. The score lives in PIEE (Procurement Integrated Enterprise Environment) and is checked by contracting officers before contract award. The mechanics:
| Score range | Practical implication | What primes do |
|---|---|---|
| +88 to +110 | Full implementation across all 110 controls. Maximum score. | Many primes accept self-attestation. C3PAO assessment at prime discretion. |
| +50 to +87 | Strong baseline with identified gaps. POA&M closure required in ≤180 days. | Primes generally accept with POA&M. Sub-tier flow-down required. |
| 0 to +49 | Significant control gaps. SPRS pre-award challenge risk. | Primes increasingly deny waivers. C3PAO assessment pressure rising. |
| Negative scores | Critical deficiencies. Self-assessment contractually flagged. | Primes deny at the prime stage. Bid-poison for sub-tier participation. |
The SPRS score must be current within 3 years. CMMC Phase 2 enforcement under 32 CFR Part 170 brings implementation: SPRS submission becomes a pre-award artifact, not a post-award documentation. Any sub-tier SPRS score that isn't current at the time of bid disqualifies the bid in many prime contractor flow-down paths.
ITAR §120–130 — The Sometimes-Federal-Crime Trap
ITAR (International Traffic in Arms Regulations, 22 CFR §§120–130) is administered by the State Department's Directorate of Defense Trade Controls (DDTC). It controls the export — including cyber-mediated export — of defense articles and technical data. The CMMC framework covers CUI broadly; ITAR is more specific. The intersection:
- Most ITAR-controlled technical data in a DoD contract context qualifies as CUI. CMMC controls protect it.
- ITAR compliance is NOT satisfied by CMMC certification alone. DDTC registration, approved export licenses, and separate cyber-incident notification to DDTC are required.
- A cyber exfiltration of ITAR data is treated as an unauthorized export under 22 CFR §127. DDTC notification is mandatory. Consent agreement penalties can reach multi-million-dollar range.
- Foreign-national access on ITAR-flagged workstations is prohibited. The CMMC access-control matrix must explicitly block ITAR-flagged foreign-national accounts — your identity-governance and PAM implementations must reflect this.
The shop-floor exposure angle: Solidworks, AutoCAD, Siemens NX, CATIA, and Pro/ENGINEER workstations hold ITAR-flagged geometry on virtually every DoD defense-contractor environment. Credential theft from these workstations is two escapes in one — NIST SP 800-171 SC control gap AND a 22 CFR §127 unauthorized export trigger if the geometry crosses a perimeter. CoreRecon Command tier includes DLP-based ITAR classification tagging and foreign-national access block on tagged workstations as part of the CUI scoping exercise.
CoreRecon Controls for TX Defense Contractors
CoreRecon maps each control to the specific regulatory requirement it satisfies. Sentinel covers the awareness, access, and logging families. Fortress adds the technical controls that move SPRS scores above 90. Command delivers the C3PAO-ready SSP and the 30-min DFARS 7012 72-hr disclosure workflow.
30/60/90 Roadmap — From SPRS Submission to CMMC L2 Phase 2 Readiness
This roadmap assumes a typical 80–250 endpoint TX defense contractor with partial NIST SP 800-171 baseline. Adjust for actuals, but the sequence is the pattern most firms follow.
- Phishing-resistant MFA on all CMMC-scope systems — Solidworks, GovWin/IUOO, PIEE, email, VPN, admin consoles. FIDO2/WebAuthn. No SMS fallback on CUI systems.
- Admin account inventory — Identify every privileged account with CUI scope access. PAM for distributed engineering admin. JIT privilege elevation on shop-floor CAD workstations.
- ITAR-flagged workstation access review — Identify shop-floor Solidworks/AutoCAD/Siemens NX workstations holding ITAR data. Foreign-national access block documented. 22 CFR §127 attestation in support of DDTC compliance.
- CMMC L2 baseline scoping against NARA CUI Registry — Map CUI categories flowing through the contractor environment. Document ITAR/CUI scope boundary.
- Quarterly SPRS submission to PIEE — Establish the rhythm. Score validation against actual control implementation. SPRS submission pre-November 2026.
- CUI VLAN segmentation — Logical or physical segregation of CUI-scope systems from corporate IT. Boundary protection at scope edge. East-west monitoring. Macro/automation traffic filtering on CAD workstations.
- Behavioral EDR on CAD/CAM workstations — Solidworks macro monitoring. Solidworks version-control access logging. ITAR-flagged file-system access logging. Volt Typhoon-prep indicators: long-pause credential reuse, ITAR file access from low-priv accounts.
- GovWin/IUOO behavioral baseline — Establish baseline access patterns. Anomaly detection on contractor-portal logins. PIEE submission audit-trail review.
- DCMA audit-period monitoring — Elevated surveillance during DCMA site visits, contractor purchasing system reviews, and cost-accounting standards reviews.
- DFARS 252.204-7012 72-hr DIBNet disclosure workflow authored — DIBNet submission template pre-loaded with CAGE code and contracting-officer contact. 90-day forensic image preservation routine.
- SSP authored and BOM'd vs. CMMC assessment boundary — Practice-by-practice implementation evidence. System architecture diagrams. CUI flow documentation.
- POA&M closed to ≤110 net SPRS — Each gap remediation tracked to closure. Evidence package compiled for C3PAO dry-run.
- C3PAO readiness dry-run — Pre-C3PAO walkthrough with internal SOC. C3PAO evidence package assembled. Self-assessment against all 110 NIST SP 800-171 controls.
- DFARS 252.204-7021 attestation prep — Current CMMC certificate maintained at contract-required level. PIEE SPRS submission verified. Sub-tier flow-down audit packet delivered.
- FCA qui tam exposure review — CUI encryption-at-rest evidence. SPRS attestation accuracy check. CY representation review under 31 USC §§3729–3733.
- Annual tabletop exercise — Volt Typhoon ITAR exfiltration scenario. DFARS 72-hr disclosure clock runbook signing. Forensic preservation routine validated.
Sibling Verticals: Related TX Cybersecurity Briefs
If your firm sits in adjacent defense-adjacent verticals, these briefs share compliance stacks and attack surfaces:
- TX Construction & Engineering Firms — CMMC 2.0 32 CFR Part 170 Phase 2 flowdown via DFARS 252.204-7012 on Fort Cavazos/JBSA projects. Williams Brothers Akira (Feb 2026). BIM/CAD Procore attack surface.
- TX Manufacturers — CMMC L2 flow-down, ITAR, OT/IT convergence. Same NIST 800-171 baseline + same FCA qui tam SPRS representation exposure.
- TX Architecture, Engineering & Construction — CMMC L2 flowdown + ITAR + BIM/CAD ransomware + GC supply chain for defense infrastructure projects.
Free CMMC Posture Review — $2,500 Value
We assess your firm's CMMC 2.0 32 CFR Part 170 Phase 2 readiness — SPRS self-assessment, SSP scope validation, DFARS 252.204-7012 72-hr disclosure workflow authoring, ITAR §120–130 data classification tagging, and the FCA qui tam exposure review. SDVOSB-certified. TX-resident. 14-day delivery.
Book Free Posture ReviewCoreRecon for TX Defense Contractors
$89–$129/endpoint. SDVOSB-certified. 30-min IR SLA. CMMC L2 SSP authorship at Command tier. DFARS 252.204-7012 72-hr DIBNet disclosure workflow. SPRS submission lifecycle. ITAR §120–130 DLP tagging. NIST SP 800-171 Rev 2 across all 110 controls. Monthly TX-resident SOC reviews with your contracting officer program manager.
Coming Next Month: Gated PDF Threat Brief
The full Texas Defense Contractors Threat Brief — 8 named anchors, Booz Allen $1.4T DIB scale analysis, InterConnect F-16 wiring cascade pattern, 8 controls mapped to NIST 800-171, 30/60/90-day roadmap, 60+ verified sources. PDF emailed after 30-second lead capture at /resources/threat-briefs/defense-contractors.
Sources: CoreRecon threat intelligence analysis — 60 verified sources including CISA/NSA Joint Advisory AA24-038A (Volt Typhoon U.S. DIB Pre-Positioning, Feb 2024), CISA Alert AA23-165A (Arnold AFB Supplier Chain, 2023), 32 CFR Part 170 final rule (CMMC 2.0 Phase 2 enforcement timeline, effective Dec 16, 2024), DFARS 252.204-7012/-7019/-7020/-7021/-219-7003 clause text, NIST SP 800-171 Rev 2 (110 controls, 14 families, csrc.nist.gov), NARA CUI Registry (CUI category catalog), DoD OUSD(A&S) DIB sector critical infrastructure asset list 2024, DoD CMMC 2.0 Program Office FAQ on POA&M, Booz Allen Hamilton DIB sector economic analysis 2024, ITAR 22 CFR §§120–130 / 22 CFR §127 (State Department DDTC enforcement), DDTC Consent Agreement records 2023–2024, 31 USC §§3729–3733 (False Claims Act), DoD Office of Inspector General cyber-fraud enforcement actions 2023–2025, DOJ Civil Cyber-Fraud Initiative case records, Crowdstrike 2024 Global Threat Report (Volt Typhoon kill-chain timing), Mandiant M-Trends 2024 DIB sector dwell-time analysis, DoD CMMC AB incident briefing Q3 2024 (TX aerospace supplier CUI exfiltration), Lockheed Martin F-16 supplier licensing records, DFARS clause text and DIBNet portal documentation (https://dibnet.dod.mil), Microsoft 365 enterprise tenant compromise pattern reports, IBM CODB 2025 (DIB sector breach cost analysis), NIST SP 800-172 (CMMC L3 high-priority program controls).
Source tag: v52_defense_contractors_brief