If your company sells to the Department of Defense, machines parts for a prime contractor, or sits anywhere in a defense supply chain, you have probably heard three different stories about CMMC compliance this year. One says a hard deadline is coming in November. One says the whole program was cancelled in July. One says nothing has changed at all. None of the three is accurate, and the gap between them is exactly where contractors lose contracts. This guide lays out what CMMC is, what the July 2026 suspension actually paused, what remains fully mandatory today, and how a small defense supplier gets ready without burning a year of margin on it.
Everything here reflects the program as it stands in September 2026, which matters more than usual, because a large share of what ranks online for this topic was written before July 13 and confidently describes a timeline that no longer exists.
What CMMC Is, and Who It Covers
The Cybersecurity Maturity Model Certification is the Department of Defense's program for verifying that companies in the defense industrial base actually protect the government information sitting on their networks. The rules live in federal regulation, 32 CFR Part 170 for the program itself and a DFARS clause, 252.204-7021, that inserts CMMC requirements into contracts. The department was restyled the Department of War in 2025, so official memos now carry that name, but the obligations flow through the same contracting machinery.
Coverage turns on two kinds of information. Federal Contract Information, or FCI, is information provided by or generated for the government under contract that is not intended for public release. Almost every defense contract involves FCI, which is why the lowest CMMC level reaches so widely. Controlled Unclassified Information, or CUI, is the sensitive tier: technical drawings, specifications, export-controlled data, and similar material that the government requires protection for even though it is not classified. If CUI touches your systems, you are in Level 2 territory, and most of the real cost of CMMC compliance lives there.
The program covers subcontractors as fully as primes. A five-person machine shop that receives a drawing marked CUI from a prime contractor carries protection obligations for that drawing, and the prime is expected to verify the shop's status before sending it. That flowdown mechanism, covered below, is how CMMC reaches thousands of companies that have never signed a contract with the government directly.
Where CMMC Stands Right Now: The Suspension, Honestly
Two facts define September 2026, and holding both at once is the whole trick.
First, Phase 1 is live and mandatory. Since November 10, 2025, new defense solicitations have required contractors to complete a CMMC self-assessment, submit the score to the government's Supplier Performance Risk System, known as SPRS, and affirm compliance annually. Without a current score and affirmation in SPRS, a company is not eligible for award on covered contracts. This is enforcement, not preview.
Second, Phase 2 is suspended. On July 13, 2026, the Department issued memoranda pausing the planned November 10, 2026 transition to Phase 2, the stage at which third-party certification assessments by a C3PAO would have become a condition of award for most contracts involving CUI. Phases 3 and 4 were frozen with it. A CMMC Reform Task Force was given sixty days to review the program, a window that closes in mid-September 2026, with recommendations going to the Department's Chief Information Officer and a public report expected in the weeks after. The Department has been explicit that the review targets the assessment bureaucracy, not the security bar. In the words of the acquisition under secretary, the standards are not being relaxed; contractors are still expected to meet the NIST requirements underneath.

So the honest status is this: the verification mechanism for Level 2 is under review, the security requirements and the self-assessment obligation are not, and a task force report cannot change a single contractual obligation by itself. Only a rule change or class deviation does that. Any advisor telling you CMMC is dead is reading headlines; any advisor still selling a November 10 certification deadline is reading last year's.
The Three Levels, Sized for Real Companies
CMMC has three levels, and which one applies is decided by the information in your environment, not by the size of your company.
Level 1 applies to companies handling FCI only. It contains 15 basic safeguarding requirements, things like limiting system access to authorized users and sanitizing media before disposal. Verification is an annual self-assessment, entered in SPRS with an affirmation from a senior company official. It is pass or fail: all 15 requirements must be met, and no plan of action is allowed to cover gaps.
Level 2 applies wherever CUI is stored, processed, or transmitted. It adopts the 110 security requirements of NIST SP 800-171 Revision 2 wholesale. Verification comes in two flavors: a self-assessment for some contracts, or a certification assessment by an accredited C3PAO valid for three years, with an annual affirmation either way. The suspended Phase 2 is about which flavor gets written into contracts, not about whether the 110 requirements apply. Certifications already earned keep their value.
Level 3 is for the small set of contractors supporting the most sensitive programs. It layers 24 enhanced requirements from NIST SP 800-172 on top of Level 2 and is assessed by the government's own assessment arm rather than a commercial C3PAO. If Level 3 applies to you, you already know, because your contracting officer has told you.
For most small manufacturers, engineering firms, and specialty suppliers around Los Angeles and Ventura County, the practical question is simply whether CUI is present. If it is, plan for Level 2. If genuinely only FCI is present, Level 1 is a manageable weekend-scale project, not a transformation.

What Is Mandatory Today, Even During the Pause
The suspension changed one future requirement. It changed nothing about the present ones, and the present ones have teeth.
DFARS 252.204-7012 has required contractors handling covered defense information to implement NIST SP 800-171 since 2017, and it still does. Its companion clauses require a current self-assessment score in SPRS and give the government the right to check. The Phase 1 requirement to affirm compliance annually sits on top. And because those affirmations are representations to the federal government, an inaccurate one is not a paperwork problem; it is False Claims Act exposure, a category of liability the Department of Justice has actively pursued against contractors who claimed security postures they did not have.
That is the trap in treating the pause as a holiday. A company that shrugs until the task force reports is still contractually bound today, still needs a truthful SPRS score today, and still has to answer a prime's flowdown questionnaire today. The pause is breathing room for fixing gaps, not permission to ignore them, and a documented, in-progress remediation effort reads very differently in any future dispute than a blank file does. Building that evidence trail is the same discipline as any structured compliance and risk program: scope, assess, remediate, document, repeat.
Self-Assessment or C3PAO: Choosing Your Verification Path
With Phase 2 paused, the near-term verification path for nearly everyone is self-assessment. The choice that remains is how seriously to run it.
A self-assessment done honestly is the same work as a certification assessment without the assessor: score every one of the 110 requirements against the official scoring methodology, write the System Security Plan that describes how each is met, and keep the evidence an assessor would ask for. Companies that do this are ready under every plausible outcome of the review, whether third-party assessments return on schedule, return narrowed, or give way to audited self-attestation with spot checks.
Scheduling and paying a C3PAO right now is a different calculation. If a prime is contractually demanding certification, or your pipeline depends on contracts where certification was already required, proceeding makes sense, and existing certificates remain valid. If neither is true, the reasonable move during the review window is to reach assessment readiness and hold the assessment spend until the Department announces what verification will look like. What is never reasonable is inflating a score to bridge the gap, for the False Claims Act reasons above.
The SPRS Score: How the Math Actually Works
The scoring system surprises everyone the first time. It does not run from zero to one hundred. A perfect implementation of all 110 requirements scores 110, and every unmet requirement subtracts a weighted penalty of one, three, or five points depending on its importance. Because the heavy penalties stack, the floor is minus 203, and a company that has done real but partial work routinely lands at a negative number.
That negative score is not a rounding error to hide. It is the honest input for a Plan of Action and Milestones, the POA&M, which documents each open gap and its closure date. Under CMMC rules, POA&Ms are permitted only within limits: Level 1 allows none at all, and Level 2 allows them only for lower-weight requirements, only above a minimum score, and only with closure inside 180 days. The practical translation for a small contractor is that the five-point items, the ones like multifactor authentication and encryption of CUI, cannot be parked on a plan. They have to actually be done.
Getting the heavy items closed is mostly identity, endpoint, and boundary work, the same layered security controls a well-run business wants anyway: enforced multifactor authentication, managed and encrypted endpoints, restricted administrative accounts, monitored boundaries, and logging that would let you reconstruct an incident.

The Subcontractor Trap: Flowdown
CMMC obligations move down the supply chain with the information. When a prime shares FCI or CUI with a subcontractor, the applicable CMMC requirement flows down with it, and primes are expected to verify a subcontractor's SPRS status before sharing. In practice this means the pressure on a small shop rarely arrives as a government letter. It arrives as an email from the prime's supply chain team with a questionnaire and a deadline, and the shop's answer determines whether the next purchase order comes.
Two consequences follow. First, a small supplier's CMMC posture is now a sales asset, because primes are consolidating work toward suppliers who can answer the questionnaire cleanly. Second, the flowdown works in both directions: if you pass CUI to your own vendors, a job shop, a coating house, a cloud service, you carry responsibility for where it lands. Mapping who touches your covered information is the same exercise as any managing third-party risk program, applied to one specific data type.
One vendor category deserves special care: cloud services. If a cloud product stores or processes CUI, the government expects it to meet FedRAMP Moderate or equivalent. Ordinary commercial email and file-sharing tiers generally do not, which is why defense suppliers end up on government-cloud versions of the major platforms. Discovering this after CUI has been flowing through a standard tenant is one of the most common and most expensive findings in a first assessment.

A Readiness Path That Works During the Pause
For a company starting close to zero, the sequence below turns the review window into an advantage rather than dead time.
- Find the CUI first. Inventory contracts and inbound documents for CUI markings and DFARS clauses. What you protect is decided by what you actually hold, and many companies hold less than they fear, or in more places than they think.
- Shrink the boundary. Confine CUI to a defined enclave, specific systems, accounts, and storage, rather than certifying the entire company network. Scope is the single biggest cost lever in the whole program.
- Score yourself truthfully. Run the 110 requirements with the official scoring methodology and record the real number, even if it is negative.
- Close the five-point items. Multifactor authentication, encryption, access restriction, and their peers are non-negotiable and carry the score fastest.
- Write the System Security Plan and POA&M. These two documents are what SPRS entries, prime questionnaires, and any future assessor all trace back to.
- Submit to SPRS and affirm. This is the step that restores contract eligibility, and it must reflect the evidence behind it.
- Train the people who touch CUI. Marking, handling, and incident reporting fail at the keyboard, not in the policy binder, which is where role-based security training earns its keep.
- Re-check quarterly and watch the task force outcome. The verification mechanics may change within months; the requirements underneath will not.
Companies that follow this arc are positioned for every announced outcome, and they are also simply harder to breach, which was the point of the entire program before the acronyms arrived.
Where CMMC Fits in the Bigger Compliance Picture
CMMC is a verification layer on top of security requirements that exist independently, and it rarely arrives alone. The same manufacturer facing a prime's questionnaire often has customers asking about the broader NIST Cybersecurity Framework, insurers asking about controls, and its own bankers asking about ransomware. Treating CMMC as one output of a single, well-scoped security program, rather than a standalone scramble, is what keeps the cost proportionate, and it is the approach we take with defense suppliers around Simi Valley and across the region, where aerospace and defense manufacturing sit unusually close together.
Getting the scoping decisions right early, before tools are bought and networks are rebuilt, is where experienced compliance-focused IT consulting covers its cost several times over.
Frequently Asked Questions
If defense work is part of your revenue and your SPRS entry is missing, stale, or scored on hope, a scoped readiness assessment will show you exactly where the 110 requirements stand in your environment and what the shortest honest path to CMMC compliance and contract eligibility looks like.
Comments
0 Comments
