Our supplier website has been updated with improved navigation, clearer resource pathways, and a modernized design to better support your experience.
Explore what's new: Read the full announcement
Explore what's new: Read the full announcement
On July 13, 2026, the Department of War (DoW) temporarily suspended CMMC Phase II requirements and initiated a 60-day program review. All Phase I CMMC Level 1 (Self) and Level 2 (Self) assessment requirements in DFARS 252.204-7021 remain in place. This temporary suspension does not alter DoW contractors’ and subcontractors’ foundational cybersecurity obligations. Suppliers must continue complying with all applicable contractual cybersecurity requirements, including NIST SP 800-171 Revision 2 and DFARS 252.204-7012, unless formally directed otherwise through an authorized contract amendment or modification.
Resources:
For additional information, visit Chief Information Officer - U.S. Department of War.
With supply chain networks particularly at risk, RTX aims to establish a protected supply chain ecosystem with infrastructure that supports secure collaboration across the supply base. Outdated security systems render companies vulnerable to data breaches and information compromises that could have detrimental effects throughout the supply chain, for our customers, the aerospace and defense industry, and national security. We are steadfast in our commitment to working with our suppliers to keep sensitive information safe, secure and out of the hands of those who would use it to endanger global security.
RTX reminds its suppliers to take appropriate steps to protect RTX information in its possession, and to report cyber incidents in accordance with existing obligations and in a timely manner.
All suppliers who discover a cyber incident, or suspect a cyber incident may have occurred must report it to RTX
On September 10, 2025, the Department of War (DoW) published the final CMMC acquisition rule with an effective date of November 10, 2025. The rule amends the Defense Federal Acquisition Regulation Supplement (DFARS) to incorporate contractual requirements related to the final Cybersecurity Maturity Model Certification (CMMC) program rule (Title 32 Code of Federal Regulations (CFR) Part 170, effective December 2024). The rule prescribes the use of the solicitation provision at DFARS 252.204-7025 and the contract clause at DFARS 252.204-7021 in certain solicitations and contracts, task orders, or delivery orders.
The final rule’s November 10th effective date means the new DFARs clause, DFARS 252.204-7021, that requires some level of CMMC certification, may be included in all applicable DoW solicitations and contracts issued on or after November 10, 2025. Additionally, new contract awards (or task orders and delivery orders for existing indefinite-delivery indefinite-quantity (IDIQ) contracts) issued after this rule takes effect may include a requirement for CMMC, even if solicitation or IDIQ contract award was prior to November 10.
All RTX suppliers supporting DoW contracts and/or solicitations with DFARS 252.204-7021:
Note: While Phase 1 CMMC implementation, requiring CMMC level 1 or CMMC level 2 (self-certification) begins November 10th, the DoW may require higher levels of certification in advance of the full phased implementation.
Key Points on DFARS 252.204-7021:
In partnership with leaders from across RTX and the DIB (Defense Industrial Base) Community, we have created the Top 10 Cyber Best Practices guidebook. This resource highlights steps you and your team can take today to reduce risk while providing awareness on available resources to promote resiliency.
The identified top Cyber Best Practices are applicable to any industry and are a starting point on steps you can take to help reduce risk. Each slide briefly describes the best practices, phased actions to take, and some available resources or services to support this best practice. This list is not inclusive of all resources and services available.
Check back for additional updates and resources.

RTX Standard Terms & Conditions
Overview of elements:
Suppliers supporting DoW contracts and handing CDI must:



Applies if suppliers are required to implement NIST SP 800-171 pursuant to DFARS 252.204-7012 for handling CDI/ Prior to award, supplier must have:
CDI is unclassified controlled technical information or other information, as described in the Unclassified CUI Registry at www.archives.gov/cui/registry/category-list.html, which requires safeguarding or dissemination controls pursuant to and consistent with law, regulations and governmentwide policies, and is:
Marked or otherwise identified in the contract, task order or delivery order and provided to the contractor by or on behalf of DoW in support of the performance of the contract; or
Collected, developed, received, transmitted, used or stored by or on behalf of the contractor in support of the performance of the contract.
A covered contractor information system is an unclassified information system that is owned or operated by or for a contractor, and that processes, stores or transmits covered defense information.
NIST 800-171 refers to the National Institute of Standards and Technology Special Publication 800-171, which governs CUI (Controlled Unclassified Information) in Non-Federal Information Systems and Organizations. NIST SP 800-171 security requirements derive from security controls in NIST SP 800-53 Revision 4, which contains 14 key areas you will need to comply with. You can find a listing of these here. These new standards must be met by anyone who processes, stores or transmits this type of potentially sensitive information (CUI) for the DoW, GSA or NASA and other federal or state agencies.
For an accurate response, we recommend checking with your IT Security professionals and legal counsel. It is our policy to only share CDI with suppliers who have assured us that they are capable of handling it.