Aerospace & Defense Contractors
CMMC enforcement is paused, but your contract obligations under DFARS and NIST 800-171 are not. MALA helps aerospace and defense contractors close real technology gaps — at zero upfront cost.
CMMC Enforcement Is Paused. Your Contract Obligations Are Not.
DoD suspended CMMC Phase 2 third-party certification on July 13, 2026 — but all 110 NIST SP 800-171 controls and DFARS 252.204-7012 still apply today.
In July 2026, the Department of Defense paused the requirement for third-party CMMC certification (C3PAO assessments) while a CMMC Reform Task Force reviews the program. That suspension has created real confusion — some contractors have quietly deprioritized compliance work as a result.
That's a mistake. Phase 1 self-assessment obligations remain fully in force: all 110 NIST SP 800-171 Rev. 2 controls, self-assessment and SPRS score submission under DFARS 252.204-7012, and annual affirmation of continuous compliance through a designated affirming official under DFARS 252.204-7021 where it applies.
How Our Advisors Help: MALA's advisors help you separate what actually changed (third-party certification timing) from what didn't (your underlying technical and contractual obligations), and keep your compliance work moving on your own schedule instead of a paused one.

Where Reality Assessments Find the Real Gaps
The technology gaps that put aerospace and defense contractors at risk rarely show up in a paper self-assessment. They show up on the floor: legacy engineering systems that can't support required controls, Controlled Unclassified Information flowing into unmanaged file-sharing tools, and subcontractors who were never actually required to flow down the same cybersecurity obligations.
The Real Cost: A subcontractor's unmanaged laptop or an engineer's personal cloud account can put an entire contract's compliance status at risk — and most organizations don't know it's happening until an assessment forces the question.
How Our Advisors Help: MALA's Technology Reality Assessment is scoped specifically for CUI-handling environments — mapping where controlled information actually flows, not just where policy says it should.

What the Affirming Official Requirement Actually Means
DFARS 252.204-7021 requires an annual affirmation of continuous compliance from a designated senior official — a requirement that's easy to underestimate until that person is asked to personally attest to something they can't verify. Most organizations haven't built the ongoing monitoring and documentation needed to make that affirmation defensible.
The Real Cost: An affirming official signing without a verifiable basis is a compliance and personal liability risk, not a formality.
How Our Advisors Help: MALA helps build the continuous monitoring, documentation, and evidence trail that makes an annual affirmation something your affirming official can actually stand behind.

Subcontractor Flow-Down Is Where Compliance Breaks
Prime contractors are responsible for flowing down cybersecurity requirements to every subcontractor touching CUI — but flow-down is frequently handled as a contract clause, not a verified technical reality. When a subcontractor's environment doesn't actually meet the requirement, the exposure runs up the chain.
The Real Cost: A prime contractor can be compliant on paper and still carry significant risk through subcontractors who were never actually verified.
How Our Advisors Help: MALA helps prime contractors build a real subcontractor verification process — not just a flow-down clause — so compliance holds up under scrutiny at every tier.

What a Reality Assessment Covers for CUI Environments
The suspension paused certification. It didn't pause your obligations — or the risk of getting this wrong.
A MALA Technology Reality Assessment for aerospace and defense contractors benchmarks your environment against all 110 NIST SP 800-171 controls, maps actual CUI data flow across engineering, program management, and subcontractor systems, and reviews your SPRS score methodology and affirmation readiness.
Typical Result: A prioritized remediation roadmap tied directly to NIST 800-171 control families, sequenced by contract risk exposure.
Your Advisor: Led by advisors experienced with defense-sector technology environments and DFARS compliance requirements.

Request a CMMC/NIST 800-171 Readiness Review
In a 30-minute conversation, a MALA advisor will walk through what's actually required today versus what's under review, and help you prioritize the gaps that carry the most contract risk.
-2.png?width=577&height=234&name=logo-01%20(4)-2.png)