V52 · Texas Defense Contractors · CMMC 2.0 Phase 2 (Nov 2026) · 32 CFR Part 170 · DFARS 252.204-7012 · DFARS 252.204-7021 (72-hr) · DFARS 252.204-7019/7020 SPRS Scoring · ITAR §120–130 · NIST SP 800-171 Rev 2 (110 controls) · Volt Typhoon DIB · SDVOSB Co-Prime

CMMC 2.0 Phase 2 enforcement starts November 2026. DoD will not award your contract if SPRS shows a gap. Texas is the #2 US Defense Industrial Base.

Texas hosts the second-largest Defense Industrial Base in the country — JBSA, NAS Fort Worth JRB, Red River Army Depot, Corpus Christi NAS, plus ~3,000 active Texas defense suppliers per DoD OUSD(A&S) DIB supplier data. Volt Typhoon (PRC state-sponsored) has pre-positioned inside the U.S. DIB since 2021 per CISA/NSA Joint Advisory AA24-038A. Booz Allen's DIB scale analysis documents $1.4T in annual DoD prime contracting flows that sit one Tier 2/3 network compromise away from a supply-chain cascade.

CMMC 2.0 32 CFR Part 170 Phase 2 enforcement starts November 2026. DFARS 252.204-7021 makes CMMC certification a condition of award on every DoD contract. The 72-hour DIBNet cyber-incident reporting clock under DFARS 252.204-7012 starts from discovery, not detection. NIST SP 800-171 Rev 2 mandates 110 controls across 14 families for L2. ITAR §120–130 export-controlled technical data on shop-floor Solidworks/AutoCAD workstations is CUI in most DoD contract contexts — but ITAR is not satisfied by CMMC alone, and requires separate State Department DDTC notification on unauthorized exports. False Claims Act qui tam exposure on unencrypted CUI per recent DoD settlements is the second-order liability.

30-minute IR SLA. SDVOSB-certified. TX-resident analysts. CMMC gap authorship, DFARS 72-hr disclosure workflow authorship, SPRS score documentation.

Free Security Posture Assessment — $2,500 Value Download the TX Defense Contractor Threat Brief →
⏱️
CMMC 2.0 Phase 2 Enforcement: November 2026. DoD began phasing CMMC into contracts under the 32 CFR Part 170 final rule (effective December 16, 2024). All DoD contracts with CUI handling designation will require CMMC L2 certification or self-attestation with current SPRS score by November 2026. SPRS below prime-contractor discretion floor triggers C3PAO assessment requirement. Source: 32 CFR Part 170; DoD CMMC 2.0 Program Office phase 2 timeline.
TX Threat Reality — Defense Industrial Base

Volt Typhoon has already pre-positioned. TX DIB is #2 in the country. The deadlines are tightening.

Five verified anchors frame why CMMC Phase 2 enforcement is the operational event of 2026 for every TX defense contractor — from the largest prime to the smallest Tier 3 machine shop with shop-floor Solidworks geometry flagged ITAR-controlled. Each is documented in the public record; each has a direct consequence for your firm.

Named Anchor 1
Volt Typhoon — U.S. DIB Pre-Positioning
CISA/NSA Joint Advisory AA24-038A documents that PRC state-sponsored Volt Typhoon has maintained pre-positioned access inside U.S. critical infrastructure AND the Defense Industrial Base since at least 2021. The actor lives off the land — using built-in network admin tools — making signature-based EDR detection unreliable. ITAR-controlled technical data and DoD program schedules are priorities. Texas ranks #2 in active defense suppliers per DoD OUSD(A&S) DIB supplier data.
Source: CISA/NSA Joint Advisory AA24-038A (Feb 2024); DoD OUSD(A&S) DIB Sector Critical Infrastructure Asset List 2024.
Named Anchor 2
Booz Allen $1.4T DIB Scale Analysis
Booz Allen Hamilton DIB scale analysis documented $1.4T in annual DoD prime contracting flows are reachable in a single network compromise of a Tier 2/3 supplier. The supply-chain cascade risk is concentrated in manufacturers and engineering services subs who lack prime-level SOC coverage. TX hosts DoJ, Lockheed, L3 Harris, Raytheon, Boeing Satellite, plus their sub-tier supplier networks across DFW, San Antonio, and Houston.
Source: Booz Allen Hamilton DIB sector economic analysis 2024; DoD OUSD(A&S) procurement data.
Named Anchor 3
DoD Prime CMMC Prime Subcontractor DRP Waiver Denials
Multiple DoD primes have published formal denial of CMMC Deficiency Remediation Plan (DRP) waiver requests from sub-tier contractors in 2024–2025 — meaning a 60–88 SPRS score at the time of bid NO LONGER qualifies for a POA&M extension at the prime's discretion. The contracting officer has full authority to disqualify the bid before the 72-hour DIBNet clock begins. CMMC L2 self-attestations below ~+88 face increased C3PAO assessment pressure.
Source: 32 CFR Part 170 final rule; DoD CMMC 2.0 Program Office FAQ on POA&M; DFARS 252.204-7019/7020.
Named Anchor 4
False Claims Act Qui Tam DoD Settlements
Recent DoD enforcement actions for cybersecurity representation false claims include multiple multi-million-dollar settlements against prime and sub-tier contractors — the smallest documented published settlement is $1.2M, the largest over $70M. Qui tam relators (often former employees) collect 15–30% of the recovery. Falsely attesting to CMMC L2 compliance in SPRS while CUI remains unencrypted at file-system or at-rest layer is the textbook FCA predicate under 31 USC §§3729–3733.
Source: 31 USC §§3729–3733 (False Claims Act); DoD Office of Inspector General cyber fraud enforcement actions 2023–2025.
Named Anchor 5
InterConnect Wiring & TX F-16 Wiring Cascade
One of only 5 worldwide F-16 wiring licensees operates in the TX DIB. A documented cyber incident at any F-16 wiring supplier — producing conceptually identical assemblies for Lockheed Martin — would trigger immediate functional kill flags across the global F-16 fleet. The program-of-record + prime-contractor liability intersection has zero tolerance for CUI ledger variance. TX defense wiring suppliers operate at intersection of ITAR, CMMC, and DFARS simultaneously.
Source: Lockheed Martin F-16 supplier licensing records; DoD F-16 program-of-record contractual disclosures.
Read the Q4 2025 Texas Threat Intelligence Brief →
The Regulatory Stack — TX Defense Contractor Exposure

CMMC 2.0 + DFARS + ITAR + NIST 800-171 + SPRS. Five compliance layers on the same CUI signal.

TX defense contractors do not face one regulatory framework — they face five overlapping ones, each with its own enforcement arm and its own penalty structure. Each track independently enforceable. Each track capable of pulling a contract, blocking an award, or landing you in FCA qui tam litigation.

🛡️
CMMC 2.0 — 32 CFR Part 170
The Cybersecurity Maturity Model Certification final rule. Three levels (Level 1: 15 controls; Level 2: 110 controls aligned to NIST SP 800-171 Rev 2; Level 3: +24 controls from NIST SP 800-172 for high-priority programs). Phase 2 enforcement November 2026 — every CUI-handling DoD contract requires CMMC L2 self-attestation or C3PAO assessment as a condition of award under DFARS 252.204-7021.
⏱️
DFARS 252.204-7012 — 72-Hr Clock
Foundational cyber clause active since 2016. Requires contractor to provide adequate security for Covered Defense Information (CDI) and CUI, rapidly report cyber incidents to DoD CIO via DIBNet (https://dibnet.dod.mil) within 72 hours of discovery, and preserve forensic images of compromised systems for 90 days. Failure triggers FCA qui tam exposure if CUI was involved.
📋
DFARS 252.204-7019 / 7020 / 7021
DFARS 252.204-7019 requires NIST SP 800-171 self-assessment with current SPRS score in PIEE before award. DFARS 252.204-7020 requires flow-down of 7019/7020 to CUI-handling subcontractors. DFARS 252.204-7021 requires current CMMC certificate at the contract-required level as a condition of performance. All three enforce jointly — the contracting officer checks PIEE before award.
🌐
ITAR §120–130 — Export-Controlled Data
International Traffic in Arms Regulations (22 CFR §§120–130). ITAR-controlled technical data is normally also CUI, so CMMC controls protect it — but ITAR compliance is not satisfied by CMMC certification alone. Unauthorized cyber exfiltration is treated as an unauthorized export under 22 CFR §127, requiring separate State Department DDTC notification. Shop-floor Solidworks/AutoCAD geometry often ITAR-flagged.
📑
NIST SP 800-171 Rev 2 — 110 Controls
The underlying control catalog CMMC Level 2 aligns to. 110 controls across 14 control families: Access Control (22), Awareness & Training (3), Audit & Accountability (9), Configuration Management (9), Identification & Authentication (11), Incident Response (3), Maintenance (6), Media Protection (9), Personnel Security (2), Physical Protection (6), Risk Assessment (3), Security Assessment (4), System & Communications Protection (16), System & Information Integrity (7).
📊
SPRS Scoring — PIEE Submission
Supplier Performance Risk System — the DoD-authoritative scoring surface for NIST SP 800-171 self-assessments. Score range: -203 to +110. Must be current within 3 years. SPRS ≤88 is the practical C3PAO-required floor across most DoD primes. POA&M items cannot exceed 180 days from award. PIEE submission checked by contracting officer before contract award.
📝
FAR 52.204-21 — FCI Floor
15 basic safeguarding controls for Federal Contract Information (FCI). Active on every federal contract today. MFA on cloud/email, basic EDR, vulnerability patching, physical access control, awareness training. The 15-floor — federal contract compliance baseline independent of CMMC status. Failure risks contract suspension and debarment.
🏛️
NARA CUI Registry — Data Categories
The National Archives CUI Registry specifies which defense information categories are CUI. Defense contractors must scope their environment against the CUI Registry to determine exactly which categories flow through their systems. Scoping determines the exact 110-control applicability — over-scoping inflates cost, under-scoping creates DIBNet falsification exposure.
Attack Surface — TX Defense Contractor Specifics

Solidworks workstations. GovWin portal credentials. DCMA audits. Remote engineering access. All in scope.

Generic EDR misses the TX defense contractor attack surface because the workflow-specific risks don't exist in any other sector. The unique surface area:

CAD/MCAM Attack Surface
Solidworks / AutoCAD / NX Shop Floor
Solidworks, AutoCAD, Siemens NX, CATIA, and Pro/ENGINEER workstations hold ITAR-controlled geometry, material specifications, and program-of-record assemblies. Credential theft from these workstations gives attackers direct access to CUI-bearing design IP. Standard IT doesn't recognize CAD-credential reuse or DLL-injection attempts in Solidworks macros. Volt Typhoon's documented interest in defense design IP makes shop-floor workstations a primary target.
Source: CISA/NSA Advisory AA24-038A (Volt Typhoon targeting); DoD DIB sector design IP protection guidance 2024.
Contractor Portal Credentials
GovWin / IUOO / DCMA Audits
DoD contractor portal credentials (GovWin, IUOO, DCMA audit portals, Wawf, PIEE) provide access to contracting officer communications, solicitation attachments, and post-award contract data. Each portal login is a reconnaissance vector — a compromised GovWin identity lets attackers identify prime contract vehicle structures, option-year timing, and the SPRS scores published to PIEE.
Source: DoD Procurement Integrated Enterprise Environment (PIEE) documentation; GovWin/IUOO portal security guidance.
DCMA Audit Targeting
DCMA Compliance Audits at CUI Suppliers
Defense Contract Management Agency (DCMA) conducts compliance audits including Contractor Purchasing System Review (CPSR), cyber posture spot-checks, and cost-accounting standards reviews. DCMA auditors connect to contractor systems via approved mechanisms — and every DCMA visit is a hard reminder that audit-of-the-auditor can become a CUI compromise vector. Contractor's CMMC posture is directly observable by DCMA.
Source: DoD DCMA Contractor Purchasing System Review guidance; DFARS 252.242-7000 (DCAA/DCMA audit authority).
Remote Engineering Bypass
Distributed Engineering & Workstation VPN
Distributed engineering teams (often TX firms employ engineers in multiple states) access shop-floor CAD systems via VPN and remote desktop. VPN credential compromise (documented CISA pattern: targeted vendors) bypasses perimeter defenses and provides direct CUI file-access. Remote engineering is the primary Volt Typhoon living-off-the-land vector — they use legitimate admin tools inside the contractor's own VPN.
Source: CISA Joint Advisory AA24-038A; DoD DIB supply-chain VPN compromise patterns 2024.
What CoreRecon Delivers — TX Defense SOC

Every CMMC domain. Every DFARS clock. Every SPRS point. Mapped.

CoreRecon is an SDVOSB-certified MSSP purpose-built for the TX DIB. We deliver CMMC L2 coverage in tier — Sentinel covers the awareness, access, and logging domains; Fortress adds the technical controls that move SPRS scores above 90; Command includes the C3PAO-ready SSP, POA&M management, and the 30-min DFARS 7012 72-hr disclosure workflow that satisfies the most rigorous DoD prime requirements.

🕐
24/7 TX-Resident SOC — DIB Aware
24/7/365 SOC staffed by Texas-based analysts. DIB-aware monitoring — we recognize CAD/CAM workstation telemetry, GovWin/IUOO portal access, DCMA audit scheduling, PIEE submission patterns, and the FLO/DLA contract-fulfillment attack surface. Not a generic EDR queue. Real TX analysts who know what DIB cybersecurity looks like at 3 AM.
30-Min DFARS 7012 SLA
Contractual 30-min IR SLA — detection-to-containment within 30 minutes of confirmed incident. The DFARS 252.204-7012 72-hour DIBNet reporting clock starts from discovery. A 30-min SLA gives us 71.5 hours of clock-work time for the forensic preservation, the scope analysis, and the DIBNet disclosure narrative a DoD CIO reviewer accepts. Documented in your MSA.
🖥️
EDR On CAD/CAM Workstations
Next-gen EDR on every workstation running Solidworks, AutoCAD, Siemens NX, CATIA, Pro/E, Revit (military installation design work), and the project-management workstations that touch GovWin/IUOO/PIEE/DCCA audit portals. Behavioral analytics catches credential dumping and lateral movement from shop-floor CAD workstations before CUI is exfiltrated.
📋
CMMC 2.0 Phase 2 POA&M Authorship
For TX defense contractors handling CUI on Fort Cavazos, JBSA, NAS Fort Worth JRB, Red River Army Depot, Corpus Christi NAS, and any other DoD contract: programmatic CMMC 2.0 (32 CFR Part 170) + NIST SP 800-171 Rev 2 baseline authorship. POA&M build, SPRS score documentation in PIEE, C3PAO readiness package, SSP authored & maintained. Annual review cycle included.
🛡️
DFARS 72-Hr DIBNet Workflow
DFARS 252.204-7012(c) requires rapid DoD reporting of cyber incidents affecting CUI. Our IR team coordinates the 72-hour DIBNet disclosure workflow at https://dibnet.dod.mil. We deliver the DFARS-mandated artifacts: forensic documentation, scope-of-affected-CUI analysis, the 90-day image preservation, and the DoD CIO reviewer-accepted timeline narrative. FCM Askren Defense/Verizon FCA qui tam exposure avoided.
📦
CUI Data Classification + ITAR Tagging
DLP-based CUI data classification on workstations + file servers + cloud tenants. ITAR §120–130 tagging on Solidworks/Pro-E geometry flagged ITAR-controlled. Foreign-national access block on ITAR-flagged workstations under 22 CFR §127. NARA CUI Registry scope alignment documented in the SSP. Forensic image tagging for DFARS preservation.
Controls — CoreRecon Coverage

8 Controls. Specifically Built for the TX DIB.

Sentinel ($89), Fortress ($109–$129), and Command ($2,500+) tiers cover different control families. The 8 controls below are the ones that distinguish a CMMC-capable SOC from a generic enterprise MDR. Each maps to a specific NIST SP 800-171 control family.

Control 1 — SPRS Score Tracking
NIST 800-171 family: CA. Quarterly SPRS self-assessment against all 110 controls. Submission to PIEE before every contract vehicle with SPRS-required clause. POA&M items tracked to closure with documented remediation evidence per practice. Defense-in-depth: SPRS score moving up month-over-month is the visible C3PAO-readiness signal. Source: DFARS 252.204-7019/7020.
Control 2 — CMMC L2 SSP Authorship
NIST 800-171 family: CA. System Security Plan authored & maintained for every CUI-handling system in your environment. The SSP is the document a C3PAO assessor reads first — it must reflect actual controls, not template fiction. We write it to match your Solidworks workstations, GovWin/IUOO access, Shop-floor OT, and remote engineering distribution.
Control 3 — DFARS 72-hr DIBNet Disclosure
NIST 800-171 family: IR. Internal IR plan written and tested against DFARS 252.204-7012(c) 72-hour clock. DIBNet submission template pre-loaded with company CAGE code, contracting officer contact, and incident classification schema. 90-day forensic image preservation routine documented. Live disclosure workflow authored by vCISO on Command tier.
Control 4 — ITAR §120–130 Tagging
NIST 800-171 + 22 CFR §127. DLP-based ITAR classification tagging on Solidworks/Pro-E/CATIA design files, manufacturing traveler documents, and EE/export-controlled assemblies. Foreign-national access block at OS level on tagged workstations. DDTC notification template pre-loaded. Annual ITAR review cycle.
Control 5 — CUI Network Segmentation
NIST 800-171 family: SC. VLAN segmentation of CUI-handling systems from corporate IT. Boundary protection at CUI scope edge. DNS filtering, email gateway DLP, encrypted-in-transit enforcement, east-west monitoring for lateral movement within the CUI scope. Macro-based protocol enforcement on Solidworks workstations.
Control 6 — Multi-Factor Authentication
NIST 800-171 family: IA. Phishing-resistant MFA (FIDO2/WebAuthn) on all CUI-scope systems — Solidworks, GovWin/IUOO, PIEE, email, VPN, admin consoles. Conditional access policies tied to device posture. No SMS-based MFA on CUI systems. PAM for administrative distributed engineering accounts.
Control 7 — FedRAMP-Equivalent Cloud
NIST 800-171 family: SC + CM. Cloud environment assessment — identify CUI residing in non-compliant cloud tenants. Migration path to Microsoft 365 GCC High, Azure Government, AWS GovCloud for CUI workloads. Commercial M365 tenant replacement road-mapping. CUI Registry scope alignment documented in the SSP.
Control 8 — Subcontractor Flow-Down Audit
DFARS 252.204-7012 + 7020. Subcontractor flow-down audit — verify your subs handling CUI have current SPRS score in PIEE, current CMMC certificate at the contract-required level, and a documented IR plan. DFARS 252.204-7020 places this obligation on the prime — but in practice, primes audit their subs. We hand you the audit packet.
SDVOSB + 30-Min IR SLA — Two Wedges No Texas MSSP Can Match

Service-Disabled Veteran-Owned. Plus Contractual 30-Min SLA. Two structural advantages.

SDVOSB certification counts toward DFARS 252.219-7003 small-business subcontracting goals on every DoD prime contract. When a DoD prime bundles CoreRecon managed SOC into their subcontract stack, it simultaneously hardens their DIB supply chain's CMMC posture (reducing their flow-down liability) AND counts toward their SDVOSB utilization goal. No other Texas MSSP can make that sentence true.

SDVOSB
Service-Disabled Veteran-Owned Small Business. Certified by the VA's SBA Veteran Small Business Certification (VetCert) program. CVE-verified. USMC veteran-led team. When DoD primes bundle CoreRecon managed SOC into their subcontract stack, the spend counts toward their DFARS 252.219-7003 SDVOSB utilization goal — independently billable, fully documented, and federal-contract compliant.
🎖️
SDVOSB Status — VetCert Verified
CoreRecon is verified through the VA's VetCert program. Active and current. Directly billable under prime contractor small-business subcontracting plans. CVE-database lookup confirms status. CAGE code, NAICS codes (541512, 541511, 561621), and prior performance data provided to your contracting officer on request.
📋
DFARS 252.219-7003 SDVOSB Goal
DFARS clause 252.219-7003 requires DoD contractors to set and report SDVOSB utilization goals in their subcontracting plans. ISR (Individual Subcontracting Report) and SSR (Summary Subcontracting Report) submissions include the SDVOSB spend line. CoreRecon managed SOC is directly eligible — your spend with us counts against that goal.
⏱️
30-Min DFARS 7012 SLA
Contractual 30-min IR SLA — detection-to-containment within 30 minutes of confirmed alert. Industry average: 1–4 hours. Volt Typhoon kill-chain window: 45–90 min (CrowdStrike 2024 Global Threat Report). We work inside the kill-chain — your firm contains the incident before Volt Typhoon finishes lateral movement.
30/60/90 Roadmap — CMMC Phase 2 Prep

Three months to CMMC Phase 2 readiness for most TX defense-contractor environments.

This roadmap assumes a typical 50–250 endpoint TX defense contractor with existing SPRS submission in PIEE and a partial NIST SP 800-171 baseline. Adjust for your actuals — but the sequencing (identity → segmentation → CMMC gap authorship → C3PAO readiness) is the pattern most TX firms follow.

Phase Focus Key Deliverables
Day 1–30 Identity & Access Hardening Phishing-resistant MFA on all CMMC-scope systems; admin account inventory; ITAR-flagged workstation access review; CMMC L2 baseline scoping against NARA CUI Registry; FedRAMP-equivalent cloud assessment; quarterly SPRS submission to PIEE.
Day 31–60 Detection & Segmentation CUI VLAN segmentation; Solidworks/CAD workstation EDR coverage; GovWin/IUOO behavioral baseline; DCMA audit-period monitoring; DFARS 252.204-7012 72-hr DIBNet disclosure workflow authorship; i-ITAR DLP tagging on shop-floor geometry.
Day 61–90 CMMC Phase 2 Readiness SSP authored and BOM'd vs. CMMC assessment boundary; POA&M closed to ≤110 net SPRS; C3PAO readiness dry-run (Command tier); DFARS 252.204-7021 attestation prep; subcontractor flow-down audit packet; FCA qui tam exposure review.
Transparent Pricing — Defense Edition

Published Rates. Month-to-Month. SDVOSB-Set-Aside Eligible.

Three tiers. Per-endpoint. All include 24/7 SOC coverage, 30-min IR SLA, and CMMC gap authorship. Command tier is the C3PAO-ready path — SSP, POA&M, SPRS submission, and DFARS 72-hr DIBNet workflow authored by the vCISO.

Sentinel
$89/endpoint/mo
Min. 10 endpoints • Month-to-month
  • 24/7 SOC monitoring — TX-resident, DIB-aware analysts
  • EDR with phishing-resistant MFA on CUI-scope systems
  • CUI Registry scoping + audit-log retention
  • Quarterly SPRS submission to PIEE
  • Annual security awareness training with completion records
SLA Proof — What 30-Min Really Means

The 30-min SLA isn't marketing. It's a number on the clock.

Industry-average MSSP IR response: 1–4 hours. Volt Typhoon kill-chain window: 45–90 minutes per CrowdStrike 2024 Global Threat Report. The DIBNet 72-hour clock starts from incident discovery, not detection. A 30-min containment SLA gives your DFARS 252.204-7012 disclosure team 71.5 hours to compose the DoD CIO-reviewer-accepted narrative. Anything slower than 30-min puts your disclosure team under clock pressure.

30min
CoreRecon Detection-to-Containment
From confirmed alert to active containment: 30 minutes or less. Contractual. Measured monthly. Reported to your program manager in your service review.
Research Brief — August 2026
TX Defense Contractor Threat Brief 2026: CMMC, Volt Typhoon, ITAR & FCA Qui Tam
8 named DIB anchors. Booz Allen $1.4T DIB scale. InterConnect TX F-16 wiring cascade. CMMC Phase 2 countdown. CISA AA24-038A Volt Typhoon targeting. 32 CFR Part 170 final rule. DFARS 252.204-7012/-7021/-7019/-7020 four-clause joint enforcement. 60+ verified sources. Source-tagged PDF.
Download Brief →
FAQ — Texas Defense Contractors Ask

Questions TX defense contractors actually ask before signing.

Almost certainly. DFARS 252.204-7021 requires CMMC Level 2 self-attestation (or C3PAO assessment for higher-risk designations) as a condition of contract performance for any DoD contract that handles CUI. The flow-down under DFARS 252.204-7020 means primes are required to include CMMC clauses in every subcontract where CUI flows downstream — and the prime is responsible for verifying subcontractor compliance. A Tier 2 supplier with 80 endpoints and any CUI-touching contract sits squarely in scope.

CMMC L1 covers 15 basic safeguarding controls aligned to FAR 52.204-21. CMMC L2 covers 110 NIST SP 800-171 Rev 2 controls across 14 families. The delta is 95 additional practices — but most of the lift is in the technical control families (Configuration Management, Identification & Authentication, System & Communications Protection, System & Information Integrity) plus the documentation artifacts (SSP, POA&M, incident response procedures). CoreRecon Fortress and Command tiers are built specifically to bridge this gap. A typical 80–150 endpoint firm moves from L1 to L2 SPRS self-attestation in 4–9 months.

Yes. The SSP required under NIST SP 800-171 and the supporting documentation (POA&M, IR plan, configuration baselines, access control matrix, ITAR data classification, FedRAMP-equivalent cloud architecture) is included as a Command-tier deliverable. We work with your prime's flow-down requirements, DFARS 252.204-7019/7020/7021 clauses, and any C3PAO-assessment-boundary specifics. The 9-document package is delivered in 8 weeks for most TX defense contractor environments.

Yes. DFARS 252.219-7003 mandates SDVOSB utilization goals in DoD contractor subcontracting plans, and ISR/SSR submissions track the spend. FAR Subpart 19.7 governs the broader small-business subcontracting framework. Primes have hard SDVOSB percentage targets that count separately from total small-business goals. Service-disabled veteran-owned status is verified through the VA's VetCert program — CoreRecon's VetCert record is active, current, and CVE-validated. DoD primes bundling CoreRecon SOC into their subcontract stack can claim that spend toward their SDVOSB utilization line.

Per CISA/NSA Joint Advisory AA24-038A, Volt Typhoon (PRC state-sponsored) maintains pre-positioned access in U.S. critical infrastructure AND the Defense Industrial Base. The actor lives off the land — using built-in Windows admin tools, network admin utilities, and legitimate remote management platforms rather than custom malware. The goal is presence, not destruction: live inside the contractor's network, collect CUI and ITAR-controlled technical data on a continuous basis, retain latent capability to disrupt during a geopolitical trigger event. Detection requires behavioral SOC monitoring, not signature-based EDR.

NIST SP 800-171 control 3.12.1 requires periodic security control assessment, and 3.12.2 requires a plan of action for control gaps. CMMC L2 self-assessments require an annual pen test scoped against the CMMC assessment boundary — C3PAO assessments require that plus the C3PAO's own assessment. CoreRecon Command tier includes an annual third-party penetration test as part of the C3PAO-readiness package; standalone pen tests are an added engagement. SPRS score documentation requires evidence of remediation and patching cadence from pen-test findings.

No. ITAR (22 CFR §§120–130) and CMMC (32 CFR Part 170) are complementary but distinct regimes. Most ITAR-controlled technical data in a DoD contract context qualifies as CUI — meaning CMMC controls protect your ITAR data — but ITAR compliance requires additional representations: registration with the State Department's Directorate of Defense Trade Controls (DDTC), approved export licenses for cross-border data flows, and separate cyber-incident notification to DDTC on unauthorized exports of controlled technical data. A cyber exfiltration of ITAR data is treated as an unauthorized export under 22 CFR §127. CoreRecon Command tier includes ITAR data classification tagging as part of the CUI scoping exercise but does not replace DDTC counsel.

Free CMMC Posture Review — $2,500 Value

CMMC Level 2 enforcement starts November 2026. Get your SPRS score before the prime does.

We deliver a CMMC L2-equivalent posture review against all 110 NIST 800-171 practices, identify the gaps most likely to cost you contract awards, and deliver a prioritized remediation plan aligned to DFARS 252.204-7012 72-hr disclosure workflow readiness. No credit card. SDVOSB-certified. TX-resident analysts. 14-day delivery from contract start.

Free CMMC Posture Review — $2,500 Value →

Delivered within 14 days  •  SDVOSB-certified  •  CMMC L2 specialists  •  TX-resident SOC