On July 13, 2026, the Department of War, still DoD in every contract you have signed, suspended CMMC Phase 2. The third-party certification requirement that was scheduled to land on November 10, 2026 is on hold, a reform task force is reviewing the whole program, and every Indiana manufacturer with a DoD contract heard the same word: paused.
The wrong conclusion is that CMMC compliance stopped mattering. The obligations that actually create legal exposure for a manufacturer in Kokomo or Columbus or on the northwest side of Indianapolis were never part of Phase 2, and none of them were suspended. What changed is the deadline pressure. What did not change is the requirement.
What DoD Actually Suspended
The suspension is narrower than the headlines suggest. Here is the precise scope.
Suspended:
- Phase 2 mandatory third-party assessments by a C3PAO for applicable Level 2 contracts
- Phase 3 requirements for Level 3 certification assessments
- Pending and future CMMC implementation milestones in solicitations
- Existing contracts that already carry Phase 2 or Phase 3 requirements, which contracting officers must strip out by modification before the next option period
Still fully in force:
- DFARS 252.204-7012. Every safeguarding and incident-reporting obligation in that clause survives untouched. This is the clause that has been in your contracts since 2017.
- NIST SP 800-171. The 110 practices remain the mandatory security standard. The framework did not go away; only one method of verifying it did.
- Phase 1 self-assessments. Level 1 and Level 2 self-assessments remain a condition of award on new contracts.
- SPRS score posting. You still have to compute and post your self-assessment score in the Supplier Performance Risk System.
- Annual affirmation. Level 1 and Level 2 contractors still affirm compliance every year, by name, in a government system.
Read that second list again. Nearly every enforcement risk a small manufacturer actually faces lives in it.
Why the Pause Happened, and Why It Is Not a Repeal
DoD cited two reasons: cost and capacity. The administrative burden was falling hardest on small and mid-size businesses, and there were not enough accredited C3PAOs to assess the number of companies in the defense industrial base within any realistic timeframe. The math did not work.
A CMMC Reform Task Force has 60 days to deliver recommendations to the Chief Information Officer, and DoD published a request for information on sam.gov asking industry about assessment costs, C3PAO capacity, timelines, and alternatives.
That is the profile of a program being re-engineered, not cancelled. The underlying policy driver, which is that defense contractors keep losing Controlled Unclassified Information to foreign adversaries, has not improved. When the review concludes, some verification mechanism comes back. Nobody credible is predicting DoD walks away from verifying contractor security.
So the honest way to describe this moment is a reprieve on the audit, not a reprieve on the obligation.
The Real Liability Was Never the Certificate
This is the part most manufacturers get wrong, and it is the part that costs money.
When you post a self-assessment score to SPRS, you are making a representation to the federal government. When you sign the annual affirmation, you are making another one. If those representations are not accurate, you are exposed under the False Claims Act, and that exposure is entirely independent of whether a C3PAO ever visits your facility.
This is not theoretical. DoD’s Civil Cyber-Fraud Initiative has been pursuing contractors for misrepresenting their cybersecurity posture since 2021, and those cases turn on the gap between what a contractor said in SPRS and what was actually implemented. Phase 2 would have caught that gap through an assessment. Its suspension does not close the gap. It just means nobody is scheduled to walk in and find it for you.
A manufacturer with an inflated SPRS score is in more danger today than a manufacturer with an honest low score and a real Plan of Action and Milestones. The first one has a false statement on file. The second one has a documented improvement plan, which is exactly what the regulation contemplates.
If you inflated your score to stay eligible for an award, the correct move this quarter is to re-score honestly and fix the filing. That is uncomfortable. It is far less uncomfortable than the alternative.
What Indiana Manufacturers Should Do With the Reprieve
Indiana’s defense industrial base is heavily weighted toward small and mid-size manufacturers: machining, electronics, tooling, and subassembly shops that sit two or three tiers down a prime’s supply chain. Two things follow from that.
First, your prime does not care what DoD suspended. Flow-down security requirements in your purchase orders are contractual obligations between you and the prime, and primes have been writing their own security expectations into supplier agreements for years. Many will keep requiring evidence regardless of the federal timeline, because their own exposure did not change. Check your actual POs before you assume the pressure is off.
Second, this is the cheapest window you will ever get to do the work properly. The companies that struggle with CMMC are not the ones that lack a certificate. They are the ones that tried to compress two years of security engineering into the ninety days before an assessment. You now have time you did not have in June, without the cost of the assessment itself.
Here is where that time goes.
Get Your CUI Scope Right
Scoping determines everything downstream: what systems need controls, what your assessment boundary looks like, and how much this program costs to run every year. It is also where most engagements go wrong.
Scope too broadly and you are implementing and maintaining 110 controls across machines that never touch Controlled Unclassified Information, which is expensive and operationally miserable on a shop floor. Scope too narrowly and you have CUI sitting on systems outside your boundary, which is a compliance failure and a genuine security problem.
Trace it honestly. Where does CUI enter, usually as a print or a spec from a prime. Where does it live. Where does it move, including the engineer who emails a drawing to a vendor and the operator who loads a program onto a USB stick at a CNC machine. Where does it leave. The answer is almost never the whole network, and it is almost never as small as the first guess.
Do this while nobody is billing you by the hour to watch.
Fix the Controls That Fail Manufacturers Specifically
Some 800-171 controls are harder in a plant than in an office, and those are the ones worth attacking first.
Unmanaged network gear. Plenty of shops run flat networks on unmanaged switches, which makes segmentation between the business network and the CUI environment impossible to demonstrate. This is a hardware problem with a hardware fix, and it has a lead time. Start now. We covered the specifics in non-managed switches and CMMC.
Legacy machine controllers. The Windows 7 box running a press brake is not getting patched. That is a real constraint, not a failure, and 800-171 accommodates it if you isolate the asset, document the compensating controls, and put it in your System Security Plan honestly. What fails an assessment is pretending the machine is not there.
Shared accounts. One login on the floor that four operators use will fail access control and audit accountability every time. This is culture as much as technology, and culture takes longer to change than software does.
Weak MFA. SMS-based multi-factor authentication no longer satisfies a serious reading of the requirement, and it is trivially defeated. If you are going to buy MFA once, buy phishing-resistant MFA. See why SMS is not enough.
Backups nobody verifies. A backup job that has been silently failing for eight months is the single most common thing we find in a first assessment, and it is not really a compliance problem. It is a business continuity problem wearing a compliance costume.
Write the SSP Now, While It Is Cheap
The System Security Plan is the document any future assessor spends the most time with, and it is the one thing you can build entirely on your own schedule.
A weak SSP is generic language copied from a template, control descriptions that do not match the environment, no network diagram, and fuzzy CUI boundaries. A good SSP describes what your company actually does, machine by machine and process by process. It takes months to write well because writing it forces you to discover what you actually have.
Build it now and the eventual assessment, in whatever form it returns, becomes a verification exercise instead of a discovery exercise. That difference is worth six figures at some companies.
Keep Your POA&M Honest and Moving
A Plan of Action and Milestones with real dates, real owners, and visible progress is evidence of a functioning security program. A POA&M with items that have been open and untouched for two years is evidence of the opposite, and it will be read that way.
Use the pause to actually close items. Closing ten POA&M items in the next two quarters is the most defensible thing your company can do with this window.
What This Means If You Were Mid-Engagement
If you had a C3PAO assessment scheduled for late 2026, it is not required right now. Talk to your assessor before you cancel outright, because a readiness assessment still tells you the truth about where you stand and the price of finding out has not gone up.
If you were about to sign a large CMMC consulting engagement, this is a reasonable moment to renegotiate scope and pace. Slow the calendar, keep the gap assessment and the SSP work, and defer anything whose only purpose was hitting a November date.
If your contracting officer has not yet modified a contract that carries a Phase 2 requirement, expect that modification. It is supposed to happen before your next option period or next administrative mod. It is not automatic, and it is worth asking about.
What we would not do is stand the program down entirely and revisit it after the task force reports. The companies that do that will be starting from zero on a compressed timeline, again, and paying a premium for capacity in a market where every other company that stood down is competing for the same assessors. The last capacity crunch is a large part of why this suspension happened.
The Bottom Line
CMMC Phase 2 is suspended. DFARS 252.204-7012 is not. NIST SP 800-171 is not. Your SPRS score, your annual affirmation, and your False Claims Act exposure are not. The requirement to actually secure Controlled Unclassified Information never depended on the audit schedule.
Treat the next few quarters as engineering time you were given for free. Get the scope right, close the controls that were always going to be hardest in a manufacturing environment, write an SSP that describes reality, and make your SPRS score true. When verification returns, and it will return in some form, you will be verifying work that is already done.
That is a much better position than a certificate you had to sprint for.
Frequently Asked Questions
Do I still need CMMC to win a DoD contract in 2026?
For new contracts, yes, in the Phase 1 form. Level 1 and Level 2 self-assessments remain a condition of award, and you still post the score to SPRS. What you no longer need on the November 2026 timeline is a third-party C3PAO certification for Level 2.
How long will the CMMC Phase 2 suspension last?
The CMMC Reform Task Force was given 60 days from July 13, 2026 to deliver recommendations, and DoD collected industry input through a request for information on sam.gov. A 60-day review does not mean a 60-day suspension. Expect the shape of the replacement to become clear over the following months, and expect implementation to take longer than that.
What happens to my existing contract that already has CMMC requirements in it?
Contracting officers are directed to remove Phase 2 and Phase 3 requirements by modification before your next option period or next scheduled administrative modification. Phase 1 self-assessment obligations and DFARS 252.204-7012 stay in place. If you have not seen the modification, ask.
Can I be penalized for a wrong SPRS score if nobody assesses me?
Yes. Your SPRS score and your annual affirmation are representations to the government, and inaccurate representations carry False Claims Act exposure whether or not a C3PAO ever assesses you. DoD’s Civil Cyber-Fraud Initiative has pursued exactly these cases since 2021. The suspension removed a verification step, not the liability.
Should I cancel my C3PAO assessment?
Talk to the assessor first. The mandate is gone for now, but a readiness assessment still gives you an accurate picture of your gaps, and some primes will keep asking for evidence regardless of the federal timeline. Cancelling the mandatory certification is reasonable. Cancelling all outside verification is a judgment call worth making deliberately.
Do my prime contractor’s requirements change because of the suspension?
Not automatically. Flow-down security requirements in your purchase orders are contractual obligations between you and the prime, separate from the federal implementation schedule. Many primes will continue to require evidence of 800-171 implementation because their own exposure did not change. Read your actual POs rather than assuming.
Teknabyte helps Indiana manufacturers build CMMC programs that hold up whether or not an assessor is scheduled. If you want an honest read on where you stand, start with our CMMC compliance services or request an assessment.
Sources and further reading:
- Pentagon Suspends CMMC Phase 2 Requirements and Launches Review of Cybersecurity Certification Program (WilmerHale)
- What Defense Contractors Should Know About DOD’s Suspension of CMMC Phase 2 (Latham & Watkins)
- DOD halts cybersecurity requirements for CMMC Phase 2 (DefenseScoop)
- NIST SP 800-171 (NIST)