CMMC Compliance in Houston for Defense and Aerospace Suppliers

Houston’s defense contract base looks nothing like Fort Worth’s, which changes who here actually needs CMMC and NIST 800-171 compliance. Harris County holds about 35% of Texas DoD contract actions and under 4% of the dollars. Most of that money buys fuel, freight and facilities work that only touches Federal Contract Information. The real CUI sits with a much smaller group of machine shops, engineering firms and electronics builders. NASA subcontracts do not trigger CMMC at all.

CMMC compliance in Houston applies only to companies holding a DoD contract or subcontract. NASA work at Johnson Space Center does not trigger it. Your required level depends on whether you handle Federal Contract Information or Controlled Unclassified Information.

Most Houston companies that ask us about CMMC don’t need it yet. A few that never ask already do.

That reads flippant. It isn’t. We pulled Harris County’s fiscal 2025 DoD prime contract data straight off USASpending, and the shape of it explains why so many local shops here guess wrong about their own obligation, in both directions and for reasons that have very little to do with negligence.

One city. One question. Which Houston suppliers actually carry a CMMC obligation, at what level, and what does the work look like once you know?

Houston is an aerospace town. By contract dollars it is barely a weapons town at all. That gap between reputation and contract reality is where the expensive mistakes live. We’ve watched a Clear Lake engineering firm budget for a Level 2 assessment it did not need, and we’ve watched a west side machine shop discover a DFARS clause buried in a purchase order it had signed 14 months earlier without anyone reading past the delivery schedule.

Both calls started the same way. “We think we might need this.”

What does CMMC compliance in Houston actually require?

CMMC applies to any company performing a DoD contract or subcontract that stores, processes or transmits federal contract information or controlled unclassified information. Your Houston address changes nothing. The clause in the contract decides.

The Cybersecurity Maturity Model Certification is a Defense Department program codified at 32 CFR Part 170. It grades a contractor against security standards that already existed. Level 1 covers the 15 basic safeguarding requirements in FAR 52.204-21. Level 2 covers all 110 controls in NIST SP 800-171, across 14 families.

None of that is new security. It’s verification of old rules that plenty of suppliers signed up for years ago and never implemented.

Worth knowing before you read further. The Defense Department was renamed the Department of War in 2025, and the July 2026 CMMC memoranda came out under that name, but DFARS clauses, SPRS and the contract writing systems still say DoD. Same agency. Two names in circulation. If your compliance vendor treats that as a substantive change, find another vendor.

Three things decide your obligation, and none of them is your industry.

  • Whether you hold a DoD contract or a subcontract under one. Prime or tier 4, it flows down the same way.
  • What data that contract puts on your systems. FCI and CUI are different categories with very different price tags.
  • Which clauses your contracting officer actually wrote in. Read the document, not the trade press.

Worth saying plainly, because it comes up on every call. CMMC is federal and it stacks on top of state law rather than replacing it. If you also hold data on Texas residents, the Texas data storage compliance rules under SB 2610 run in parallel and have their own headcount tiers.

Why Houston’s defense contracts look nothing like Fort Worth’s

Harris County recorded $2.36 billion in DoD prime contract obligations in fiscal 2025, fourth in Texas, against Tarrant County’s $33 billion. Houston’s share of the state’s contract actions is far larger than its share of the dollars.

Analyst reviewing Harris County Department of Defense prime contract spending data on dual monitors

Numbers first, argument second. Every figure below comes from the USASpending.gov award API, filtered to Department of Defense prime awards with a place of performance in Texas for fiscal year 2025.

Texas countyFY2025 DoD prime obligationsShare of state
Tarrant$33.00B54.2%
Dallas$11.54B19.0%
Bexar$4.96B8.2%
Harris (Houston)$2.36B3.9%
Hunt$1.57B2.6%
Collin$1.26B2.1%

Texas booked $60.84 billion in DoD prime obligations that year. Tarrant County took 54% of it, because that is where the F-35 line runs. Not close. Bexar County sits third on the strength of Joint Base San Antonio, which is why CMMC compliance work in San Antonio looks very different from ours, and why the DFW picture we covered in IT compliance for DFW manufacturers leans so heavily on aerospace primes.

Now flip to volume. Harris County logged 77,595 contract actions in fiscal 2025 out of 219,941 statewide. That’s 35.3% of the count against 3.9% of the money.

Read those two numbers next to each other and the picture resolves; Houston runs an enormous number of small defense transactions and almost none of the very large ones, which means the local supplier base skews small, private and thinly staffed on IT. That is exactly the population that struggles most with a 110-control framework and has the least budget to throw at it, usually with one internal IT person who is already underwater.

What that money bought is stranger still.

What DoD bought in Harris County, FY2025ObligationsUsual data category
Petroleum refineries$1.44BFCI
Deep sea freight transportation$198.2MFCI
Facilities support services$92.9MFCI
Other aircraft parts and auxiliary equipment manufacturing$69.7MOften CUI
Freight transportation arrangement$67.5MFCI
R&D in physical, engineering and life sciences$57.4MOften CUI
Other heavy and civil engineering construction$49.8MFCI
Engineering services$44.7MOften CUI
Marine cargo handling$35.7MFCI
Electronic computer manufacturing$28.5MOften CUI

Obligation figures are ours from the USASpending API. The right-hand column is a generalisation from how these contract types usually behave, and it is not a substitute for reading your own clause list.

Petroleum refining alone is 61% of Harris County’s DoD dollars. Fuel contracts to the Defense Logistics Agency. That work generally touches federal contract information and stops there, which puts those companies at Level 1, 15 requirements, self-assessed. Deep sea freight, freight brokerage, facilities support and marine cargo handling behave much the same way.

The CUI is in the smaller rows. Aircraft parts manufacturing at $69.7 million. Engineering services at $44.7 million. Electronic computer manufacturing at $28.5 million. Add them up and you get roughly $143 million, about 6% of the county’s defense money, carrying most of its Level 2 exposure.

The biggest DoD money in Houston has the lightest cybersecurity obligation. The heaviest obligation sits with companies most people here have never heard of.

Does NASA work at Johnson Space Center trigger CMMC?

No. CMMC is a Defense Department program that flows through DFARS clauses, and NASA is a civilian agency. A Johnson Space Center subcontract can carry controlled unclassified information and still carry zero CMMC requirement right now.

Aerial view of a Texas coastal airfield with commercial aerospace hangars on one side and a separate military apron on the other

This is the single most common misread we hear in the Bay Area corridor, and it costs real money in both directions.

Houston’s aerospace identity is civilian. Johnson Space Center runs a $5.35 billion annual budget with more than 10,000 people on a 1,700 acre campus, and NASA places roughly $2.5 billion a year with Texas suppliers, including about $442 million with small businesses, according to the Greater Houston Partnership. The Houston Spaceport sits on the southeast side of Ellington Airport, the first FAA-licensed urban commercial spaceport in the country.

None of that is CMMC.

Ellington is where it gets interesting, because the same airfield hosts Ellington Field Joint Reserve Base, with units from all five armed services including the Texas Air National Guard’s 147th Attack Wing flying MQ-9 Reapers. Two neighbors. Same runway. Different rulebooks. A tenant on the spaceport side and a supplier to the JRB side can sit a mile apart with nothing in common on paper.

So what should a JSC supplier do? Watch the FAR, not the DFARS.

The FAR Council, jointly with DoD, GSA and NASA, published a proposed Federal Acquisition Regulation rule on controlled unclassified information in January 2025, with a further proposed rule following on June 23, 2026 and comments closing that July. It would push NIST SP 800-171 safeguarding onto every federal contractor holding CUI, civilian agencies included. It is not final. It has no effective date. But the direction of travel is not subtle.

Bias disclosed, because we sell this work. If NASA is your only federal customer, you can wait, and nothing is going to bite you this fiscal year. What we’d actually recommend is cheaper than waiting. Build the environment to 800-171 while you’re doing your next hardware refresh anyway, because retrofitting a network that grew for 12 years without any of it costs multiples of doing it once on a schedule you control, and the difference tends to show up as emergency capital spend in the quarter you least want it.

FCI or CUI, and why that one answer sets your whole budget

Federal contract information is basic non-public contract data and puts you at Level 1, a 15-requirement self-assessment. Controlled unclassified information puts you at Level 2, all 110 NIST controls, with documentation and a posted score.

Same framework. Wildly different bill.

If your Houston contract involvesData categoryCMMC levelWhat that means in practice
Refined fuel, food or freight capacity sold to DLAFCILevel 115 requirements from FAR 52.204-21, annual self-assessment and affirmation
Machining parts to a prime’s controlled drawingsUsually CUILevel 2110 NIST 800-171 controls, system security plan, plan of action, SPRS score
Engineering or analysis work on a DoD programCUILevel 2Same, plus scoping every engineering workstation and CAD seat
Facilities, grounds or logistics support at a baseFCILevel 1Rarely more, though base access rules are a separate matter
Anything marked CUI//SP-EXPT or ITAR controlledCUI plus export controlLevel 2Enclave, US-person access control, GCC High usually required
Engineering blueprints and a secured laptop on a manufacturing workbench showing where controlled unclassified information lands

The tell is almost never the customer name. It’s the drawing.

Pull the technical data package on your last defense job and look at the markings, because distribution statements B through F, export control warnings and anything stamped CUI or the older FOUO all point at the same conclusion about where your assessment boundary has to sit. If those markings are on prints sitting on a shop floor PC, that PC is in scope, and so is every system it talks to, including the backup target, the file server and the personal laptop somebody used to open the drawing at home.

We have yet to run a Houston scoping conversation where the CUI turned out to live in the ERP. It’s in email and on a shared drive. Every time.

That single finding is usually good news, because it makes an enclave viable instead of a full network rebuild. The enclave approach we use on Texas CMMC projects covers when a full Microsoft 365 GCC High migration is genuinely required and when a properly configured commercial tenant will hold.

What the Phase 2 pause changed for Houston, and what it didn’t

The Department of War suspended CMMC Phase 2 on July 13, 2026, removing the third-party C3PAO assessment requirement that was scheduled for November 10, 2026. Everything underneath the certification layer survived intact.

We covered the full sequence in our CMMC 2.0 compliance timeline for Texas defense contractors, so here is the short version and the part that matters locally.

Suspended. Not cancelled. The verification mechanism paused while a reform task force runs its review, and per Holland & Knight’s read of the two memoranda, the underlying obligations were never touched, which is the detail most of the vendor emails that landed in Houston inboxes last month managed to leave out entirely.

Still fully in force today.

  • DFARS 252.204-7012, including the 72-hour cyber incident reporting clock
  • FAR 52.204-21 and its 15 basic safeguarding requirements
  • All 110 NIST SP 800-171 Rev 2 controls, with a system security plan behind them
  • Your SPRS self-assessment score under DFARS 252.204-7019 and 7020, which sat outside the CMMC rulemaking entirely
  • The annual affirmation, signed by a senior official

That last one deserves more space than it’s getting here. Read it again. A senior official signs a statement about the condition of your security program, and the Latham & Watkins analysis is blunt about what that signature actually is, because a false representation to the government carries an enforcement path that has nothing to do with CMMC and predates the program by roughly a century and a half.

The SBA Office of Advocacy flagged the task force request for information for small business input, which closed August 14, 2026. Recommendations are expected around mid-September. Anyone selling you certainty about what comes next is guessing.

The Houston companies that get blindsided

Oil and gas machine shops with occasional defense subcontracts are the most common surprise in Houston. They do not think of themselves as defense suppliers, so nobody reads the flow-down clauses in the purchase order.

Three profiles, over and over.

The first is a valve, pump or pressure vessel shop on the west side or in Pasadena that has run energy work for 30 years and has never once described itself as a defense supplier to anyone, including its own insurance broker. Then a prime needs a machined component to a spec their usual vendor can’t hold, and a purchase order arrives with DFARS 252.204-7012 flowed down in the terms. Nobody reads clause text. The obligation attaches anyway. If that describes your shop, our oil and gas IT services in Houston page and the broader manufacturing IT services work we do here cover how those environments get scoped.

Second profile, and this one is genuinely hard. An engineering services firm in Clear Lake or Webster running NASA work and DoD work on the same network, with the same engineers, on the same file server, sharing one Microsoft 365 tenant and one nightly backup job that copies both. One customer triggers CMMC. The other doesn’t. Segmenting that cleanly is a design problem before it’s a security problem, and getting it wrong in either direction is expensive.

Third, the electronics and instrumentation builder. Smallest group, highest control density, usually the furthest along already because their commercial customers pushed them there years ago.

There’s a fourth category we should be honest about. Companies that took one small defense subcontract, decided the compliance cost exceeded the revenue, and walked away from that market. That is a legitimate answer. We have told two Houston clients exactly that, because if you do $180,000 a year of defense work on a $14 million book, the math on a full Level 2 program does not work at any honest price, and no MSP should pretend otherwise.

What a realistic Houston readiness sequence looks like

Most Houston suppliers already aligned with NIST 800-171 need 3 to 6 months to reach Level 2 readiness. Starting from a standard commercial network, plan on 6 to 12 months and a budget that starts near $75,000.

Two IT engineers configuring network switches in a server rack while building a CMMC Level 2 enclave

Order matters. Skipping straight to buying tools is how compliance budgets double.

  1. Read the contracts. Not the website, not the sales team’s memory. Pull every active DoD purchase order and subcontract and search the clause list for 7012, 7019, 7020 and 7021.
  2. Find the data. Walk the drawings, the email threads, the shared drives and the engineering workstations. Mark where CUI physically lands.
  3. Draw the boundary. Enclave or whole network. This one decision drives every dollar that follows, and reversing it later is painful.
  4. Write the system security plan first. Before a single purchase order goes out. The SSP is what an assessor reads, and writing it early exposes the gaps that tools were never going to close.
  5. Score yourself honestly. Post it to SPRS. A low score with a credible plan of action is defensible. An inflated score is a signed statement you cannot support.
  6. Close the plan of action. On a schedule someone owns by name.
  7. Keep the evidence. Screenshots, logs, ticket history, change records. Assessors ask for proof, and good intentions are not proof.

Industry cost bands for a small or mid-sized contractor run roughly $75,000 to $250,000 across 12 to 24 months, and the spread is almost entirely about scope, which is why two companies of the same headcount in the same industrial park can get quotes that differ by a factor of three without either quote being wrong. A 25-person shop with everything in one enclave lands at the bottom. A 75-person operation with CUI moving across shared drives, engineering workstations and shop floor systems lands in the middle. Legacy operating systems on production equipment blow through the top every time, because unsupported machines cannot be patched and have to be isolated instead, which means new switching, new firewall rules and a conversation with the equipment vendor that rarely goes well.

Same framework. Three very different projects.

If your plant floor is part of this conversation, the OT side carries its own problems that the 800-171 control list does not address well. We wrote about that in OT and IT security mistakes Texas manufacturers make.

Where an MSP helps, and where it can’t

An MSP can build and operate the environment that passes a CMMC assessment. It cannot conduct the assessment. Those roles are separated on purpose, and any vendor offering both should be treated with suspicion.

Uprite is not a C3PAO. We do not certify anyone. We build and run the IT environment underneath the certification, which is a different job with a different set of skills.

What that looks like in practice. Standing up the enclave, hardening identity and access, getting MFA and conditional access right, logging and retaining what the controls require, managing the endpoint and patch position, and producing the evidence when someone finally asks for it. We’re a team of 42 across Houston, San Antonio and Dallas, and the compliance work sits inside the same managed security service rather than off to the side as a project nobody maintains after month 9.

We also work alongside the assessors and consultants who handle the certification side, rather than competing with them.

Where we’re not the right call. If you need a gap assessment written by a Registered Practitioner Organization because a prime specifically demanded one, that’s a different vendor. If your whole compliance question is one signature on a Level 1 affirmation and 15 requirements you already meet, hiring anyone for it is overkill. Read FAR 52.204-21, check yourself against it, and file.

The short version for a Houston supplier

Three things worth carrying out of this.

Your obligation comes from the contract, not from your industry or your zip code. Houston’s aerospace reputation and Houston’s defense contract reality are two different things, and confusing them is what produces both the wasted Level 2 budget and the ignored flow-down clause, which are the two failure modes we see here constantly and almost never see in Fort Worth.

The pause moved a deadline. It did not move DFARS 252.204-7012, your SPRS score, or the affirmation you sign every year.

Scope is everything. Where the CUI lives determines whether this is a $75,000 project or a $250,000 one, and that answer usually comes out of a two-hour walk through your own file shares rather than a proposal.

If you’re a Houston supplier and you genuinely don’t know which level applies to you, start by pulling your last three defense purchase orders and searching them for 7012. If the clause is there, we can help you scope what comes next. Our cybersecurity services and managed IT services in Houston teams handle the environment side of that work.

What Houston suppliers ask before they call

We only sell to NASA. Do we need CMMC?

No, not today. CMMC flows through DFARS clauses on Defense Department contracts, and NASA is a civilian agency, so a Johnson Space Center subcontract does not trigger it.

Watch the proposed FAR CUI rule, though. If it finalizes in something close to its current form, NIST 800-171 obligations reach civilian agency contractors too, and the companies that built to the standard early will spend a fraction of what the late movers spend when the effective date lands.

Our prime says we need Level 2. Are they wrong?

Wrong question, slightly. A prime can contractually require more than the government requires, and many do, because their own assessment scope reaches into your systems.

Even if the DoD clause on your subcontract points to Level 1, the prime’s purchase order terms are what you actually signed. Negotiate it if the requirement is genuinely disproportionate to the work. Ignore it and you lose the customer.

Realistically, how fast can a 40-person Houston shop get Level 2 ready?

3 to 6 months if you are already running a modern Microsoft 365 environment with MFA everywhere, decent logging and someone who owns patching. Longer if not.

Plan on 6 to 12 months when you are starting from a flat network with a file server, local admin rights on every workstation and a domain controller somebody stood up in 2014 and has been afraid to touch since. The variable is almost never the control list.

Do we have to migrate to Microsoft 365 GCC High?

Probably not. Microsoft has contractually supported DFARS 252.204-7012 requirements in its standard commercial and GCC environments for several years now, and a correctly configured commercial tenant holds up for a lot of Level 2 scenarios.

Export-controlled data under ITAR or EAR is the clear exception, and that is where GCC High stops being optional. Get the classification first. Then take the migration quote.

Is a SPRS score still required now that Phase 2 is paused?

SPRS never went anywhere. The score requirement lives in DFARS 252.204-7019 and 7020, which sat outside the CMMC rulemaking entirely. A stale score is a live problem this quarter, not a 2028 problem.

We just won our first defense subcontract and we have none of this. Where do we start?

Start with the contract file, before you spend a dollar. Identify the clauses, identify whether the data is FCI or CUI, and get an honest picture of where that data will sit once work begins.

Most first-time suppliers find that their real problem is not the 110 controls at all, but that nobody has documented the network in 8 years and there is no accurate asset inventory to scope anything against. Fix that first and everything downstream gets cheaper.

About Author

Learn More