CMMC requirements for Japanese contractors — what still matters under the Department of War

The short version

If your company supports U.S. Department of War (DoW) primes or contracts and handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), cybersecurity obligations did not disappear. What changed is how the Department plans to verify higher-level certification in the near term — not whether you must protect the data.

Ryukyu Cyber Initiative, LLC (Okinawa) is a Cyber AB Registered Provider Organization (RPO). Dr. Aaron Ramey helps Japanese contractors prepare with gap analyses, documentation, and bilingual English/Japanese reporting.

What the old “November 20” post got wrong

Earlier marketing copy on this URL said new CMMC rules would start enforcing on November 20. That date was a simplification and is not the schedule you should plan against today.

What actually matters for planning:

  1. CMMC Phase I remains in place. Applicable Level 1 (Self) and Level 2 (Self) requirements, SPRS postings, and annual affirmations continue. Protecting covered defense information under DFARS 252.204-7012 remains a contractual obligation.

    1. CMMC Phase II was suspended on 13 July 2026 by the Department of War. Broad mandatory Level 2 C3PAO assessments are paused while the Department reviews the program.

      1. Primes still flow down requirements. Your subcontract language and your prime’s instructions govern day-to-day expectations. Do not assume “suspension” means “stop documenting controls.”

    2. Always confirm against your contract, your prime, and current DoW / Cyber AB publications. This page is practical orientation — not legal advice.

What Japanese subcontractors should do now

Map data: Do you process, store, or transmit FCI only, or also CUI? Scope drives level and evidence.

Keep Phase I evidence current: self-assessment artifacts, SPRS score discipline, and affirming-official readiness.

Close real gaps: access control, logging, incident reporting, media protection, and supplier flow-down — the work that protects contracts even when assessment timelines shift.

Separate prep from assessment: readiness coaching and mock reviews are not the same as an official C3PAO certification assessment.

Include FRCS/OT if in scope: Facility-Related Control Systems on or supporting DoW facilities often need UFC / UFGS / RMF-aligned cybersecurity — not only office IT.

How Ryukyu Cyber helps (and what we do not do)

We help you prepare: gap analysis, prioritized remediation plans, bilingual packages for Japanese leadership and U.S. primes, mock readiness reviews, and FRCS-aware consulting from Okinawa.

We do not certify your organization. RCI is an RPO, not a certification body. Aaron’s CCA credential means he is trained as an assessor; it does not mean RCI is a C3PAO, and holding CCA does not authorize us to issue your CMMC certification. Official Level 2 certification assessments are performed only by accredited C3PAOs. Prep ≠ assessment — we maintain that conflict-of-interest wall.

Local advantage

Hiring only U.S.-side consultants can mean timezone friction, travel cost, and translation lag. Local Okinawa support means clearer schedules, bilingual deliverables, and faster iteration with Japanese SMEs in the DoW supply chain.

[Contact us to scope a readiness review →](/contact)

[See credentials and Cyber AB alignment →](/certifications)

日本語(文)

Phase Iの自己評価・SPRS・年次アファーメーション等は継続していす。2026年7月、DoWPhase II(幅広い第三者C3PAO評価の義務化に向かう階)を停しました。データ保義や契約・ローダウンは消えまん。

琉球イバー(沖/Cyber AB RPO)は、ギャップ分析日英書・準備支援提しす。当社認定を行いませんCCA有=C3PAOではありません。準備と公式評価はしす。

[問い合せ](/contact) · [資格](/certifications)