Blog · Compliance · July 12, 2026 · By Mike Parker

CMMC 2.0: What Defense Suppliers Need to Do Now

Enforcement started in November 2025. The November 2026 third-party assessment phase-in was suspended in July 2026 — the obligation underneath it was not. If your parts, code, or services end up inside a Department of Defense program — even several tiers below the prime — here's the plain-English version of what still applies.

Updated August 6, 2026 — on July 13, 2026 the Department of War suspended CMMC Phase II and paused the Phase III and IV milestones pending a program review. This guide has been revised throughout to reflect that. DFARS 252.204-7012, NIST SP 800-171, SPRS scoring and annual affirmations are unaffected and remain conditions of doing defense work.

For years, CMMC lived comfortably in the future tense: a rule being drafted, a deadline being debated, a problem for next year. That ended on November 10, 2025, when the acquisition rule took effect and CMMC clauses began appearing in new Department of Defense solicitations. Suppliers now have to show their cybersecurity posture before award — and the requirement doesn't stop at the prime contractor. It flows down the supply chain to the machine shop, the software subcontractor, the logistics firm.

Southern California, with its dense aerospace and defense manufacturing base, is full of exactly the kind of small supplier this lands on hardest: companies with real DoD-adjacent work and a two-person (or zero-person) IT department. Here's what you actually need to know.

What CMMC 2.0 is — and isn't

The Cybersecurity Maturity Model Certification isn't a new rulebook. Contractors handling controlled unclassified information (CUI) have been contractually required to implement the NIST SP 800-171 safeguards since the DFARS clause took hold in 2017. The problem was that compliance ran on the honor system, and self-reported scores were often generous fiction.

CMMC 2.0 is the Department of Defense checking receipts. It takes requirements that already existed and adds verification: self-assessments with executive affirmations at the low end, independent third-party assessments in the middle, government-led assessments at the top. Two rules make it real: the program rule (32 CFR Part 170), effective December 16, 2024, and the acquisition rule (48 CFR), effective November 10, 2025, which puts CMMC requirements into contracts — both per the Federal Register.

The three levels, in plain terms

  • Level 1 — Foundational. For companies that handle federal contract information (FCI) but not CUI. It requires the 15 basic safeguarding practices from FAR 52.204-21 — things like access control, malware protection, and secure disposal — verified by an annual self-assessment and an affirmation from a senior official.
  • Level 2 — Advanced. For companies that handle CUI: drawings, specifications, technical data. It requires all 110 security requirements of NIST SP 800-171. For most contracts, verification means a certification assessment by an authorized C3PAO (CMMC Third-Party Assessment Organization) every three years; a smaller set of contracts will accept a self-assessment. This is where most defense suppliers land, and it's the heavy lift.
  • Level 3 — Expert. For suppliers on the most sensitive programs: 134 requirements (the 110 from NIST SP 800-171 plus 24 from NIST SP 800-172), assessed by the government itself. A small share of the industrial base — but if it's you, you already know.

The timeline you should actually plan around

The rollout is phased over roughly three years, but two dates matter most:

  • November 10, 2025 — Phase 1 (already live). New applicable solicitations require at least a current self-assessment, a score posted in the government's SPRS system, and a senior official's affirmation as a condition of award.
  • November 10, 2026 — Phase 2 (suspended). Third-party C3PAO certification requirements were to begin appearing in applicable contracts involving CUI. On July 13, 2026 the Department of War suspended this phase, paused Phases 3 and 4, and directed contracting officers to remove Level 2 (C3PAO) and Level 3 (DIBCAC) requirements from existing contracts by modification — Level 1 (Self) and Level 2 (Self) stay, and waivers are suspended during the review. No replacement date has been announced.

Now the fine print that bites. First, primes aren't waiting for the government's schedule — many are already asking subcontractors for SPRS scores and remediation plans, because their own awards depend on a clean supply chain. Second, the suspension pauses a certification schedule, not a security requirement — DFARS 252.204-7012 predates CMMC, outlives it, and still obliges you to implement NIST SP 800-171. Third, an affirmation is a legal statement: the Department of Justice's Civil Cyber-Fraud Initiative has pursued contractors over misrepresented cybersecurity compliance. Guessing your score is not a strategy.

Key takeaways

CMMC 2.0 by the numbers

Three levels, built almost entirely on security requirements that defense contracts have referenced for years.

15

basic practices for Level 1 (FCI) — annual self-assessment and affirmation

FAR 52.204-21

110

security requirements for Level 2 (CUI) — C3PAO certification for most contracts

NIST SP 800-171

134

requirements for Level 3 — government-led assessment for the most sensitive programs

NIST SP 800-171 + SP 800-172

Why suppliers underestimate the lift

The pattern we see with small manufacturers and engineering firms is consistent: leadership assumes CMMC is "an IT project" that a busy administrator can knock out in a few weekends. Then the gap assessment lands, and three realities set in:

  • Scoping is the hard part. Before you can protect CUI you have to find it — in email threads, file shares, CAD systems, shop-floor machines, laptops, and cloud apps. Everywhere it flows is in scope, and scope drives cost.
  • A third of the work is paperwork, in the best sense. The 110 requirements demand policies, a System Security Plan, a plan of action for open items, training records, and evidence that controls actually operate. Assessors read documents, not intentions.
  • The technical gaps are predictable but not trivial. MFA everywhere, encryption that meets federal standards, centralized logging, access reviews, controlled media handling — straightforward to name, slow to retrofit across a company that's never had them.

A realistic six-step path

  1. Confirm your level and map your CUI. Ask your primes and contracting officers what you hold and what's coming. If you only touch FCI, your path is far lighter.
  2. Shrink the scope. Many suppliers save real money with an enclave strategy: concentrating CUI into a contained, hardened environment so the 110 controls apply to one enclave instead of the whole company.
  3. Run an honest gap assessment against NIST SP 800-171 and post a truthful SPRS score. Truthful matters — see the DOJ note above.
  4. Remediate in priority order. Identity and access first, then encryption, logging, and response capability. Fix what an assessor will fail you on, not what's easiest.
  5. Build the paper trail. System Security Plan, policies, plan of action — maintained as living documents, not a binder written the week before the assessment.
  6. Book the C3PAO early and rehearse. A mock assessment finds the surprises while they're still cheap.

How your IT partner should help

Start with the disclaimer that should be on every MSP's website: no IT provider can certify you. Level 2 certification comes only from an assessment by an authorized C3PAO, and Level 3 from the government. CRC Cloud doesn't certify anyone — and anyone who promises "guaranteed certification" is telling you to walk away. What a competent partner does is get you ready and keep you ready:

  • Scoping and enclave design, so you're not securing the whole building to protect one room
  • A gap assessment against NIST SP 800-171 with a prioritized, costed remediation plan
  • Remediation engineering — MFA, monitoring, logging, and 24/7 detection and response that satisfy the control families and protect you regardless
  • Documentation and evidence support: SSP, policies, and a shared-responsibility matrix that says plainly which controls the provider operates and which stay yours — assessors ask
  • Ongoing operations, solo or co-managed with your internal IT, so year two doesn't undo year one

We work with Southern California manufacturers and defense-adjacent suppliers on exactly this preparation work. If CMMC is on your contracts — or your primes are starting to ask questions — a free 30-minute assessment will tell you roughly where you stand and how far the gap runs.

The deadline moved. The obligation didn't. A suspended phase-in is not a repealed rule — and the suppliers who stand down now are the ones who will be scrambling when a date comes back.

Quick answers

CMMC, answered plainly

We're a small subcontractor two tiers below the prime. Does CMMC really apply to us?

If federal contract information or controlled unclassified information flows down to you, yes. Primes are required to flow CMMC requirements to their subcontractors, and many are asking for evidence well ahead of contract deadlines. Your required level depends on the data you touch: FCI generally means Level 1, CUI generally means Level 2.

Can our MSP or a consultant certify us?

No — and be wary of anyone who says otherwise. Level 2 certification can only be issued through an assessment by an authorized C3PAO (CMMC Third-Party Assessment Organization), and Level 3 assessments are government-led. An IT partner's legitimate role is preparation: scoping, gap assessment, remediation, documentation, and keeping you assessment-ready. The separation between the people who prepare you and the people who assess you is deliberate.

How long does CMMC Level 2 preparation actually take?

It depends on your starting point and how tightly you can scope where CUI lives, but for most small suppliers the honest answer is quarters, not weeks. The 110 NIST 800-171 requirements include policy, documentation, and evidence work as well as technical fixes, and although the third-party assessment phase-in was suspended in July 2026, your DFARS 252.204-7012 duty to implement NIST 800-171 continues regardless. Starting after a solicitation names CMMC is usually starting late.

Find out how far you are from CMMC-ready

A free 30-minute assessment with the owner — a straight read on your gap, your scope, and your realistic timeline.

Book a Free 30-Minute IT Assessment