CMMC and NIST 800-171 Compliance for Dallas Defense Suppliers
Uprite scopes, scores and remediates NIST 800-171 for Dallas defense suppliers, then keeps the SPRS number honest between annual affirmations. Almost every engagement here starts with a flow-down clause buried in a purchase order rather than a prime contract. We cover Dallas, Tarrant, Collin and Denton counties, and we say so plainly when a company does not need Level 2 at all.
In Dallas County, 90 cents of every Department of Defense dollar goes to one company. The CMMC problem belongs to everybody else.
Get a Free CMMC Gap AssessmentIn Texas Since 1999 | MSP 501 Winner | SOC 2 Type 1 | 120-Day Guarantee
87 Reviews
4.9/5.0 ★★★★★
Get Your Free CMMC Gap Assessment
Recognized Across Texas for Managed IT and Security
Where The Obligation Comes From
In Dallas, CMMC Arrives in a Purchase Order
Open the federal contract data for Dallas County and the picture looks settled. In fiscal 2025 the Department of Defense obligated $11.54 billion on prime contracts performed here. Lockheed Martin took $10.40 billion of it, most of that through the Missiles and Fire Control headquarters on West Freeway in Grand Prairie.
That is 90.2 percent of a county. To one company.
Now read the other column. Dallas County logged 43,695 contract actions last year. Tarrant County, holding nearly three times the money, logged 28,496. More orders. Smaller orders. Spread across far more businesses. That is what a supplier metroplex looks like in data.
Here is the part that decides your compliance position. Most companies in Dallas with a CMMC obligation do not appear in that data at all. A subcontract is not a prime award. If you machine housings for a tier one, wire harnesses for a sensor program in McKinney, or run finishing work for an aerostructures shop in Grand Prairie, your company name is not in the file. Your clause is.
The obligation reaches you through DFARS 252.204-7012, which primes are required to flow down to subcontractors whose work involves covered defense information. It arrives attached to an order for a part. Nobody sends a letter about it.
So the first honest question is not which CMMC level you need. It is whether that clause is already sitting in a document somebody in purchasing signed eighteen months ago. Start there.
We start there. Sometimes the answer is that a company holds federal contract information only, owes Level 1, and can stop reading. We would rather find that out in week one than sell nine months of work nobody needed.
The Part With Your Name On It
The Score Is Signed by a Person, Not a Company
The program rule defines the affirming official as a senior company representative responsible for ensuring compliance. At a 70-person machining business in Garland that is the owner or the president. Not the network administrator. Not the outside IT firm.
What gets affirmed is narrow and specific. The applicable security requirements are implemented, and the score currently posted in the Supplier Performance Risk System is accurate as of the date signed. Annually. Per contract.
The risk lives in drift. Somebody scored the environment in 2023, posted a number and moved on. Since then a program folder went onto a share so the second shift could reach it. A CAM contractor got a login and kept it. An engineer put a model file on a personal laptop because the connection was slow and the part had to ship Friday. None of that is misconduct. All of it moves the real score away from the posted one, quietly, across months.
The Department of Justice has already settled False Claims Act cases built on cybersecurity representations in defense contracts through its Civil Cyber-Fraud Initiative. None of them required a third-party assessor to exist. A paused audit does not pause that exposure. It only removes the gentler way of finding out.
We do not sign it. We are not your lawyers. Our job is narrower. Produce a score you can defend line by line, a System Security Plan describing the environment as it runs rather than as it was planned, a Plan of Action with an owner and a date on every open item, and a quarterly re-check so the person signing is signing something current.

Where The Points Go
Six Places North Texas Suppliers Lose Points
A Level 2 self-assessment starts at 110 and subtracts. Most unmet requirements cost a single point. Some cost three. A small group costs five, and those put a respectable-looking environment underwater before you finish the first page. These six come up most often in DFW engineering and machining shops. Roughly in this order.
Multifactor Authentication, Worth 5
The most expensive single line on the sheet and the one most often left half-finished. Multifactor on Microsoft 365 but not on the remote-access gateway. Switched on for office staff, skipped for the two contractors who keep the machine-monitoring network alive. There is no partial credit. That surprises companies who have genuinely done most of the work.
Who Can Open the Drawing Folder
Access limited to authorized users, and to the transactions those users are permitted to run. In practice this fails on one shared engineering drive that everybody in the building can open, because that is how it has worked since the company had eleven people. Unglamorous to fix. Usually the fastest points on the board.
FIPS Validated Encryption
Not encrypted. Validated, with a module certificate number from the NIST Cryptographic Module Validation Program. Full-disk encryption running in the wrong mode does not count, and neither does a vendor page promising military grade. This is the requirement most often marked complete on the strength of marketing copy.
The Boundary Nobody Drew
Where controlled unclassified information lives, what touches it, and what should never see it. Until somebody draws that line, every laptop, every mailbox and the whole ERP sit inside the assessment boundary. That makes the other 109 requirements far more expensive than they need to be, and it is why a week of scoping pays for itself twice. Draw the line first.
The Suppliers Below You
Dallas shops send plating, heat treat, anodizing and inspection out to local firms, often to a business two miles away that has done the work for twenty years. If controlled technical data travels with the part, the clause travels with it too. Flow-down runs downhill. Most companies have never sent it anywhere.
The System Security Plan Itself
Not a control. The price of entry. No plan means no assessment, and a plan describing a network you replaced two years ago is worse than none, because it is now a document that contradicts you in writing. Ours are built from what the tooling reports rather than from an interview.
We never post a score on your behalf. What we hand over is the assessment behind it, the evidence filed under each requirement, and a written plan for everything still open, in a form the person signing can read in an afternoon.
The Numbers
Six Numbers a Dallas Supplier Can Check
Four of these come from public federal data and one dated memorandum. Two are ours. The federal figures are Department of Defense prime contract obligations by place of performance for fiscal year 2025, pulled from USASpending.gov in September 2026. Go and check them before you believe anything else here.
$11.54B
Department of Defense prime contract obligations performed in Dallas County in fiscal 2025
90.2%
Share of that total going to a single company, Lockheed Martin, whose Missiles and Fire Control headquarters sits in Grand Prairie
43,695
Contract actions recorded in Dallas County, against 28,496 in Tarrant County, which took nearly three times the money
Sept 13, 2026
Approximate date the CMMC Reform Task Force is due to report to the Department CIO, sixty days after the July 13 suspension
5 minutes
Uprite average first response across every priority level and every ticket tier
120 days
Uprite satisfaction promise. Not satisfied inside four months and you can leave the contract
What You Actually Get
What a Dallas CMMC Engagement Covers
Six workstreams. The first two carry the rest, and in North Texas almost every engagement succeeds or stalls on the second one.
Clause Review and CUI Scoping
We read the DFARS clauses on your live and pending orders, trace where controlled data enters the business, and draw a boundary around it instead of hardening the whole company. For most DFW suppliers that means a controlled enclave inside Microsoft 365 rather than a GCC High migration. The statewide CMMC and NIST 800-171 practice covers enclave design in detail.
Scored Assessment and SPRS Support
All 110 requirements scored the way a government assessor would score them, evidence attached to each one, weighted deductions applied without flattering anybody. You see the number before anything is posted. Before, not after. If a score is already sitting in SPRS and it is wrong, this is the step where that surfaces.
System Security Plan and POA&M
Written from the assessed environment rather than the intended one. Every open item on the Plan of Action carries an owner and a date, because a finding with neither is a sentence waiting to be read back to you in a meeting.
Remediation and Ongoing Security
Closing the gaps and keeping them closed. Endpoint detection, log retention, validated encryption, conditional access, and the multifactor coverage that is worth five points on its own. Delivered through our managed security work in Dallas.
Incident Reporting Readiness
DFARS 252.204-7012 requires a cyber incident to be reported to the Department within 72 hours and the affected media preserved for 90 days. Most contractors read the media preservation clause for the first time during an incident. Worst possible moment.
Annual Affirmation Support
A quarterly re-score against the posted number, and an evidence pack assembled before the affirmation falls due rather than the week it does. It is the unglamorous half of this work. Almost nobody sells it.
North Texas Specifics
Four Ways the Clause Reaches a Dallas Shop
DFW defense work does not look like Houston defense work. Tarrant County is essentially one aircraft program on one campus, with $30.84 billion of its Department of Defense money sitting in a single industry code. Dallas County money is 78 percent guided missile and space vehicle manufacturing. Collin County is sensors and optics. Hunt County is aircraft modification out at Greenville. Four different data classifications. Sometimes all four reach the same supplier in one week. That shape produces four specific failure modes.
| Where it starts | What actually goes wrong | What closes it |
|---|---|---|
| A purchase order for a bracket | A prime drops DFARS 252.204-7012 and 7021 into an order for a machined part. Purchasing signs it, because it is a purchase order. Nobody in the building reads clause text for a living | A clause check at order intake, and one named person who owns the answer to whether a given order carries controlled data |
| Two programs, one CAD vault | Commercial work and defense work share one file server, one Microsoft 365 tenant and one drawing vault. The assessment boundary quietly becomes the entire company | An enclave. Separate the controlled work first, then assess the enclave instead of assessing the business |
| ITAR arriving with the drawing | Technical data for a defense article lands in the shop. ITAR obligations attach to manufacturing, not only to exporting, so companies that never ship overseas assume it cannot reach them. Missile and aircraft work makes this common in DFW | A data classification pass separating ITAR technical data from ordinary CUI, done before either one lands on a laptop |
| The plater down the road | Heat treat, plating and inspection go out to local firms on a router and a handshake. Controlled technical data travels with the part, and the flow-down obligation travels with the data | A supplier list showing exactly who receives controlled data, the clause flowed down in writing, and access that expires on a date |

Before You Read Further
Ten Minutes With Your Last Three Purchase Orders
Pull the three most recent defense orders in the building and search the clause list for 252.204-7012 and 252.204-7021. If either one appears, ask the second question straight away. What score is posted for us in SPRS right now, who posted it, and what date is on it?
Most North Texas suppliers we speak to can answer the first question and not the second. The silence is the finding. It will tell you more than the rest of this page does.
What We Will And Will Not Claim
We Are Not a C3PAO, and That Is on Purpose
There is a conflict of interest in this market. Worth naming out loud. A Certified Third Party Assessment Organization is not permitted to prepare a company and then assess that same company. Any firm offering to do both is describing an arrangement the accreditation body does not allow.
So we prepare, we remediate, and we run the environment afterwards. Somebody independent certifies it. When Phase 2 restarts we will help you choose them and get into the queue.
That queue is the part North Texas contractors have not priced in. There were 103 authorized assessment organizations in the entire ecosystem as of March 2026, against a defense industrial base where roughly 80,000 companies are expected to need Level 2, and about 1,074 certificates had been issued by that point. The arithmetic is not subtle.
Which is why the September report matters more than the suspension did. Whatever the task force recommends, the constraint waiting on the other side of it is assessor capacity rather than the calendar. Capacity, not calendar. Companies holding a finished System Security Plan and an evidenced score will book slots ahead of the ones starting their first scoping conversation that month. Read the full CMMC rollout timeline if you want the phase-by-phase detail.
The honest limit on what we can show you: we cannot publish a named Dallas defense supplier as a reference, and we are not going to invent one. What is published is adjacent and real. There is a growing manufacturer we modernized while bringing it into cybersecurity compliance, plus continuing work in manufacturing IT across Dallas and our notes on IT compliance for DFW manufacturers. Ask us about the ones we cannot publish.
Honest Qualification
Who This Is For
| This is built for |
|---|
| DFW suppliers between roughly 15 and 300 people with a signed or pending Department of Defense subcontract carrying DFARS 252.204-7012 |
| Machining, fabrication, tooling and electronics firms feeding primes in Grand Prairie, Fort Worth, McKinney or Greenville |
| Engineering and design practices where controlled technical data arrives as a model file attached to an order rather than as a contract |
| Companies whose prime has started asking for a SPRS score, a System Security Plan, or a supplier questionnaire with a return date on it |
| Anyone who posted a score two or three years ago and genuinely does not know whether it is still true today |
The Pushback We Hear
Five Objections We Hear in North Texas
“CMMC is paused. Why spend money now?”
The audit paused. The affirmation did not. Phase 1 is live, and if the clause sits in your contract then your obligation is current today. There is a timing argument as well. The reform task force reports in September, public guidance normally follows a report like that by several weeks, and everybody who waited will start moving in the same fortnight.
“We only machine a bracket. There is no CUI in it.”
Possibly true. Establish it, do not assume it. The test is not what the part does. It is whether the drawing, tolerance data, specification or process sheet you were sent is controlled. In DFW that material usually arrives as a model file attached to an order, which is exactly why it gets handled like ordinary engineering traffic.
“Our prime has not asked us for anything.”
They will, and it normally arrives as a questionnaire with a two-week return date stapled to an award you have already priced and staffed. Primes push this down the chain because their own position depends on it. Being asked is not the start of the process. It is the deadline.
“We already have an IT company.”
Then keep them. Assuming they are good at what they do. Co-managed support in Dallas exists for exactly this shape. Your provider keeps the helpdesk and the day-to-day, we own scoping, scoring, the System Security Plan and the evidence. Most general providers have never scored a 110-requirement assessment, and there is no shame in that.
“We will just move everything to GCC High.”
You probably do not need to, and it is an expensive place to guess. GCC High matters for ITAR technical data and for certain prime-specific mandates, which is a live question around missile and aircraft work in a way it is not in most industries. It also roughly doubles per-seat cost. Commercial Microsoft 365 with a properly built enclave satisfies Level 2 for a large share of suppliers here. Ask first. We will tell you which one you are before you buy either.

How We Start
Four Weeks, Starting With Your Clause List
Not with a network scan. With the clause list on your actual purchase orders, because that decides whether any of the rest applies to you and at what level. We have told North Texas companies they did not need this. It happens more often than you would expect.
1
Clause and Scope Review
About a week. We read the DFARS clauses on current and pending orders, trace where controlled data enters and where it travels, and draw a boundary around it. If the honest answer is federal contract information only and Level 1, we say so, and the engagement gets much smaller and much cheaper.
2
Scored Assessment
All 110 requirements against the DoD Assessment Methodology, evidence attached, weighted deductions applied honestly. Scored, not estimated. You see the real number before a thing gets posted. If the figure already sitting in SPRS is wrong, better that it surfaces here than in a prime audit.
3
Plan and Remediation Roadmap
The System Security Plan written from the assessed environment, and a Plan of Action carrying an owner and a date against every open item, priced individually. You keep both documents whether or not you hire us to close them. Some companies take them straight to their existing provider, which is a perfectly good outcome.
4
Remediation and Quarterly Re-scoring
We close the findings, then re-score each quarter so the posted number stays true in the months between affirmations. When Phase 2 restarts, this folder is what goes to the assessor. The alternative is a scramble. Queues punish scrambles.
What Clients Say
Hector and Kareem are super helpful! They are always willing to take on my computer problems even if its small. I had my mouse disappear off my screen, it was an user issue but Hector didn't make me feel small or "dumb" for this error. We love uprite!
Gerardo Sanchez was very helpful & professional. Uprite Services has great customer service and outstanding technicians. We have used them for several years and will continue our business with them.
I had been having trouble with an IT matter that I didn't think would be fixed but Arvin Ebueng from Upright took his time with me and worked with me until we were able to resolve the issue. The issue was an internal issue with the way the program was written, but Arvin came up with a great work around so that I am now able to do what I need to do at my job. Long story short, he got me access to both things that I need access to simultaneously and daily. Thanks 😊 Arvin, you are much appreciated 👏 💐 🥳.
I’ve been extremely satisfied with Uprite Services and would recommend them without hesitation. They consistently deliver reliable, high-quality work and truly feel like a true partner rather than just another vendor. A special thank you goes to Arvin Ebueng, he is always quick to respond to our needs and incredibly easy to communicate with. No matter how busy things get, Arvin makes sure we’re taken care of promptly and with a smile. His responsiveness and clear communication have made every interaction smooth and stress-free. Thank you, Arvin and the entire Uprite team, Peerless Equipment is a customer for life!
I'm am not a "tech" person, however the team at Uprite gets me through the technological side of computers and software so that I can function on a daily basis... but the most enduring quality is that they care. Special shoot out to Mary, Sergio, Eufemio, Hector, and Jeff just to name a few... I appreciate each of you and the help you give me.
Great service by Juan and Jacob. Always helping us out at Alamo City Trailer Sales. We have been using this company for over 10 years and always happy with the work they do.
FAQ
What Dallas Defense Suppliers Ask First
Yes. Only the third-party assessment stage stopped. Level 1 and Level 2 self-assessments still go into solicitations, the score still gets posted, and a senior official at your company still signs the annual affirmation. Nothing in 32 CFR Part 170 or DFARS 252.204-7021 was amended by the July 2026 memorandum, because a memorandum cannot amend a regulation. Nothing else changed.
Nobody outside the Department knows yet, and any provider telling you otherwise is guessing. The task force was given sixty days from July 13, which puts its report to the Department CIO around September 13, 2026, with public implementation guidance normally following a report like that by several weeks. Plausible outcomes run from a narrower Phase 2 to a later restart date. None of them changes what Phase 1 already requires of you today.
Yes, if the prime flowed the clause down to you. DFARS 252.204-7012 travels with the data rather than with the size of the order. In Dallas that is the normal case rather than the exception.
Usually not. GCC High is genuinely required for ITAR technical data and for some prime-specific mandates, and it roughly doubles per-seat cost. Commercial Microsoft 365 with a properly scoped enclave satisfies Level 2 for a large share of DFW suppliers. Because ITAR turns up more often around missile and aircraft work than around most other manufacturing, this is worth settling early rather than assuming in either direction.
It depends almost entirely on scope, which is why the boundary work comes first. A 40-person shop with one defense line and a tight enclave is a fraction of the cost of a 300-person company where controlled data has spread across every share. Fully managed IT starts at $138 per user per month, our plans start at $40 for security-only augmentation, and the assessment and remediation are quoted separately. Our Texas managed IT pricing page shows the ranges.
Four weeks to a scored assessment and a written plan for a scoped supplier. Then remediation. That is the variable part and it usually runs three to nine months depending on how much has to change. Multifactor coverage and the controlled-data boundary take longest, because they change how people work rather than which software you own.
A senior official at your company signs it. Not your IT provider, and not us. The exposure is that a stale score stops being an internal documentation problem and becomes a false representation inside a federal contract, which is the theory the Department of Justice has already used to settle cybersecurity cases with no third-party assessor involved anywhere. We re-score quarterly so the number and the environment do not drift apart in the first place.
Yes. Our Dallas office is on Alpha Road at the top of the Dallas North Tollway, and we cover Dallas, Tarrant, Collin and Denton counties from it. Suppliers in Grand Prairie, Garland, Plano, McKinney, Irving, Richardson, Arlington and Fort Worth are all inside normal dispatch range, and most of this work happens remotely in any case. Day-to-day support runs through our managed IT team in Dallas and Fort Worth.
Start Here
Find Out What Your Real Score Is
Two things turn up in most North Texas assessments we run. A clause nobody in the building had read, sitting in a purchase order signed eighteen months ago. And a posted SPRS score describing a network the company has since replaced. Both are ordinary.
Neither is a crisis today. Both are how a bad year begins, and both are cheap to fix while the audit is still suspended.
The gap assessment takes about a week, costs nothing, and the written roadmap is yours whether or not you hire us. We support defense suppliers across Dallas and Fort Worth, Houston, San Antonio and the rest of Texas.
Or call the Dallas office directly at (469) 699-8766. We are at 5757 Alpha Rd, Suite 530, Dallas, TX 75240.




















