Short version. Bay Area aerospace suppliers rarely lose prime work because of a breach. They lose it at supplier qualification, months earlier, when a buyer opens a portal and finds no current assessment record, no system security plan, and no evidence that flow-down clauses were passed to their own vendors. The July 2026 CMMC pause removed an audit. It did not remove that gate.
Aerospace suppliers in the Bay Area lose prime contracts because their IT documentation is missing or stale at the qualification stage, not because their security is weak. A prime cannot legally award a covered subcontract to a supplier with no current assessment posted, no matter how good the shop is.
We see it most often in Clear Lake, Webster, and Nassau Bay, where a machine shop or an engineering services firm has held the same NASA or defense work for years and suddenly gets dropped from a bid list. Nothing went wrong technically. The paperwork expired. If you want the operational side of this, our Clear Lake managed IT services team runs the same review for firms across the Bay Area corridor.
Here is the part that catches people. The person who removes you is not a security assessor. It is a procurement analyst with a checklist and a portal. That is the whole problem.
What Counts as IT Documentation on an Aerospace Subcontract
IT documentation on a defense or space subcontract means the written artifacts a prime is contractually required to collect before award. That set includes your posted assessment score, a system security plan describing your boundary, a plan of action for open gaps, a signed portal questionnaire, and proof you flowed the same clauses to your own suppliers.
None of that is a security tool. All of it is a contract deliverable. Different owner. Different calendar. That distinction is the whole article.
Shops that treat documentation as an IT project put it last, behind the server refresh and the new firewall, which is exactly the order that leaves them exposed at the one moment a prime is looking. Shops that treat it as a contract deliverable put it on the same calendar as first article inspection and certificate of conformance paperwork, which is where it belongs. That reordering is free.
Why Does a Prime Reject a Supplier Before Anyone Looks at the Network?
Because the clause says so. DFARS 252.204-7020 paragraph (g) is not advisory. It reads that the contractor “shall not award a subcontract or other contractual instrument, that is subject to the implementation of NIST SP 800-171 security requirements, in accordance with DFARS clause 252.204-7012 of this contract, unless the subcontractor has completed, within the last 3 years, at least a Basic NIST SP 800-171 DoD Assessment.”
Read that again. The prime is barred from awarding. Your quality record does not enter into it, and neither does your price. Neither does your on-time delivery.
The same paragraph then requires the prime to “insert the substance of this clause, including this paragraph (g), in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial products or commercial services (excluding commercially available off-the-shelf).” So the obligation travels. A tier-three shop cutting a bracket for a tier-two supplier inherits it without ever seeing the prime contract.
On the solicitation side, DFARS 252.204-7019 says an offeror must have an assessment “not more than 3 years old unless a lesser time is specified in the solicitation” to be considered for award. Three years sounds generous. It is not, because the clock started the day you first posted rather than the day you last won something, and most shops never put that date on a calendar anywhere. Check your date today.
Here is what a buyer actually opens before they call you. It takes about 5 minutes.
| What the prime checks | Who looks at it | What ends the conversation |
|---|---|---|
| Assessment record in the Supplier Performance Risk System | Procurement and supply chain | Nothing posted, or the record is more than 3 years old |
| System security plan describing your assessment boundary | The prime’s supplier cyber team | Missing, generic, or the boundary does not cover the work being quoted |
| Plan of action and milestones for open requirements | Same team | Open gaps with no owner, no date, and no remediation plan |
| Prime portal questionnaire | Automated inside the portal | Expired, incomplete, or contradicts your posted score |
| Incident reporting path and named contacts | Contracts, at flow-down review | No 72-hour reporting route, no person named to run it |
| Evidence you flowed the clauses to your own vendors | Contract administration and audit | You never passed 7012 and 7020 to the shops you buy from |

Did the July 2026 CMMC Pause Take the Pressure Off?
No. It moved the pressure onto the paperwork.
Two DoD memoranda dated July 13, 2026 suspended the Phase 2 third-party assessment requirement and placed pending and future implementation milestones in abeyance until further notice, with a reform task force running a 60-day program review and industry responses due August 14, 2026. Contracting officers were told to strip Level 2 and Level 3 assessment requirements from affected contracts by modification. Read that as a reprieve.
Now read the next part. What did not move is everything in the table above. DFARS 252.204-7012 still applies. The 110 requirements in NIST SP 800-171 Revision 2 still apply, and DoD has not switched to Revision 3, so Revision 2 remains the standard you are scored against. FAR 52.204-21 and its 15 basic safeguarding requirements still apply to anyone touching federal contract information. Our CMMC timeline explainer for Texas contractors tracks where the program sits now.
Think about what the pause actually did to a buyer. It took away the independent check. That check is gone. The only compliance signal left for most of the defense industrial base is a self-reported number sitting in a government database, plus whatever a supplier writes in a portal.
Primes did not respond to that by relaxing. Several tightened their own questionnaires instead, because the score they are now relying on is one you gave yourself. So they read it harder.
What Each Prime Actually Asks a Bay Area Supplier For
This is where suppliers get surprised. There is a federal floor, and then there is whatever the prime layers on top of it, submitted through a portal that has nothing to do with SPRS and renews on a schedule nobody tells you about.
| Prime | Where you submit | What it asks beyond the federal floor |
|---|---|---|
| Lockheed Martin | Exostar On-Boarding Module, moved off the older Partner Information Manager | The Cybersecurity Compliance and Risk Assessment, roughly 60 questions, which replaced the separate NIST 800-171 questionnaire and cybersecurity questionnaire |
| Boeing | Enterprise Supplier Lifecycle portal | The SP5 terms of use and cybersecurity supplement, plus evidence submitted through the portal and incident reports routed to a Boeing abuse mailbox |
| RTX | Supplier terms and contract flow-down | A written security program you develop, implement, maintain, monitor and update, standard encryption, restricted access to RTX information, and incident reporting to the Defense Counterintelligence and Security Agency first |
Notice the pattern. Every one of those is a document, an attestation, or a named process. Not a firewall.
Notice something else. A supplier working for two primes fills out two different questionnaires against one environment. If those answers drift apart, and they do, the inconsistency itself becomes the finding. We see that drift constantly.

Five Documentation Failures That Cost Bay Area Suppliers Work
These are the ones we actually pull out of client files, in rough order of how often we see them.
1. The score is posted, and nobody knows who posted it
Someone did the self-assessment in 2022 to win a specific job. That person left. Nobody updated it. The score is still sitting in the system, still being read by buyers, and it reflects a network that has since moved to Microsoft 365, added a second building, and taken on two new programs. Scores run from -203 to 110. Yours is describing a company that no longer exists.
2. The system security plan describes a boundary that does not match the quote
A supplier writes the plan around one segmented room where the engineering workstations live, which is a perfectly sound design and also the exact thing that quietly stops being true. Then a program manager starts receiving drawings by email on the general network. The plan is now fiction, and the first prime auditor who walks the floor will notice. Twenty minutes, maybe less.
3. The plan of action has no dates and no owners
Open gaps are not automatically disqualifying. Open gaps with no remediation date, no assigned owner, and no evidence of progress are disqualifying, because they tell a buyer that nothing is being managed rather than that something is still being fixed. A short honest plan beats a long optimistic one. Write the dates down.
4. Nothing was ever flowed down to your own suppliers
This is the quiet one. Paragraph (g) requires you to insert the substance of the clause into your own subcontracts. Almost nobody does this. Then a prime asks for the evidence during a supplier audit and there is nothing to hand over, which turns what would have been a clean file into a corrective action you now have to answer in writing.
5. The portal answers and the posted score tell different stories
A prime questionnaire says multifactor authentication is fully implemented. The assessment worksheet behind the posted score says partially. Both are visible to the same buyer. We have watched that single contradiction stall a qualification for a full quarter while the supplier reconstructed, from memory and old tickets, which of the two answers had ever been true. One line. One quarter lost.

How Do You Build the Package in 30 Days?
You do not need a year. Thirty days is realistic. What you need is a scoped boundary, honest answers, and someone who owns the file after the project ends. Most of the delay we see comes from trying to fix the network first and write the documents later. Do it the other way around. Documents first.
| Week | What you produce | Who owns it |
|---|---|---|
| Week 1 | Data flow map showing every place covered information enters, sits, and leaves. Draft assessment boundary | Operations plus IT, together in one room |
| Week 2 | Honest scoring against all 110 requirements, with the worksheet retained as evidence | IT provider, reviewed by an owner who will sign it |
| Week 3 | System security plan and plan of action with real dates and named owners | IT provider drafts, leadership approves |
| Week 4 | Posted score refreshed, prime portal questionnaires reconciled against it, flow-down language added to your purchase orders | Contracts, with IT supplying the answers |
Four things make this stick after the 30 days are over.
- Put the assessment expiry date on the same renewal calendar as your insurance and your quality certifications, because that is the deadline everybody forgets.
- Name one person who signs off before any portal questionnaire is submitted, so two primes never get two different answers about the same network.
- Re-score whenever the environment changes materially, not annually by habit. A new building, a new tenant, or a new program is a trigger.
- Keep the evidence, not just the conclusion. Screenshots, policy documents, and the completed worksheet are what a prime auditor asks for, and reconstructing them later is how a two-week request becomes a two-month one.

What This Costs, and What It Does Not
Documentation work is cheap relative to the contract it protects. A scoped boundary review, an honest assessment, a system security plan, and a plan of action is a defined piece of work with a defined end. Rebuilding a network is not, and the two get conflated constantly in quotes. That confusion costs real money.
The ongoing spend is a different question, and it is driven by which clauses your prime flowed down rather than by your headcount. We break those bands down in our aerospace IT support cost guide for Texas, which prices the four rungs of the clause ladder separately.
One honest caveat. If your assessment is truthful and your score is genuinely low, documentation alone will not save the bid. It buys you a credible plan of action, which is often enough to keep you on a bid list while the remediation work runs in the background over the next two or three quarters. Fix the gaps too.
Questions Bay Area Suppliers Ask Us
What IT documentation does a prime contractor actually ask for?
A current assessment record in SPRS, a system security plan, a plan of action and milestones, a completed portal questionnaire, and evidence that you flowed the same clauses to your own suppliers. Five artifacts. Most rejections trace to one of them being missing or stale.
Can we lose a subcontract without ever failing an audit?
Yes, and that is the common case. DFARS 252.204-7020 bars a prime from awarding a covered subcontract unless you have completed a Basic assessment within the last 3 years. No assessment means no award, and no auditor was ever involved in that decision.
Does the CMMC suspension mean we can stop working on documentation?
The opposite. The July 13, 2026 memoranda paused third-party assessments, which leaves your self-reported score as the primary signal a prime has. Removing the independent check made the document you wrote yourself more decisive, not less.
How old can our assessment be before it stops counting?
Not more than 3 years, unless the solicitation names a shorter window. Check the date on your posted record today rather than assuming. Suppliers who posted a score to win a specific job in 2022 or 2023 are often already outside the window without knowing it.
Our prime uses Exostar. Is that the same as SPRS?
No. SPRS is the government system that holds your assessment score. Exostar hosts prime-specific questionnaires such as the Lockheed Martin assessment. You have to keep both current, and you have to keep them consistent with each other.
What if our system security plan describes controls we have not finished?
That is what the plan of action is for, and it is expected. Describe the control as planned, give it a date and an owner, and score it honestly. Overstating implementation in a document a prime will audit is a far worse position than an open gap.
Should our IT provider write this, or should we?
Both, in defined lanes. Your provider supplies the technical evidence and drafts the plan. Your leadership owns the boundary decision and signs the attestation, because the representation goes to the government under your company name and cannot be delegated to a vendor.
Get an Assessment
Send us your flow-down clauses, the last portal questionnaire you submitted, and the date on your posted score. We will tell you where the file is thin before a prime does, and what it takes to close it. No pressure to switch. Uprite has supported Texas businesses for more than 20 years, triages incoming issues within 10 minutes, holds SOC 2 Type 1 certification, and backs every engagement with a 120-day satisfaction guarantee.
If you are further along and need the full program, start with our CMMC compliance services for Houston defense suppliers or read how we approach NIST 800-171 compliance across Texas.









