CMMC Phase 2 Pause: What It Means for A&D
If you are an aerospace and defense manufacturer, the most important takeaway from the CMMC Phase 2 pause discussion is simple. Even if third-party assessment timing changes, your cybersecurity and contract obligations do not disappear.
That distinction matters because many manufacturers hear “pause” and assume they can delay work. In reality, defense contractor cybersecurity requirements have never depended only on the audit calendar. For companies handling controlled unclassified information (CUI), the underlying compliance work is still tied to DFARS clauses, NIST SP 800-171, internal evidence, and the ability to show that your actual processes match what your organization claims.[1][3][4]
CMMC Phase II Was Paused on July 13, 2026: Here’s What Changed
Before anything else, it helps to separate two terms that are often confused:
- CMMC phases are the rollout timing of contract requirements.
- CMMC levels are the security requirement sets tied to the type of information you handle.
Under the CMMC program structure, Phase 2 refers to the stage where Level 2 third-party assessment requirements become a condition of award for applicable solicitations.[2] That is different from Level 2 itself, which maps to the 110 security requirements in NIST SP 800-171 Rev. 2 for protecting CUI.[3]
On July 13, 2026, the Department of War officially announced the immediate suspension of CMMC Phase II requirements, which had been scheduled to begin on November 10, 2026. All Phase I self-assessment requirements remain in place.[1] In practical terms, the timing of mandatory C3PAO-led assessments has changed, but CMMC has not disappeared for aerospace and defense manufacturers.
What Did Not Change: A&D Manufacturers Still Have Cybersecurity Obligations
This is the part many companies cannot afford to miss.
DFARS 252.204-7012 still requires contractors to provide adequate security on covered contractor information systems and implement NIST SP 800-171 for covered defense information.[4] That obligation is not dependent on whether a C3PAO assessment date moves.
DFARS 252.204-7019 also requires contractors to have a current NIST SP 800-171 assessment on file in the Supplier Performance Risk System (SPRS) for eligibility in applicable awards.[5] The CMMC FAQ further clarifies the role of self-assessments versus third-party assessments in the broader program.[1]
The current working baseline for Level 2 remains NIST SP 800-171 Rev. 2, which contains 110 security requirements.[3] Although NIST released Revision 3, manufacturers should be careful not to assume an immediate transition in CMMC enforcement until the Department formally updates its requirements.
For A&D leaders, the practical message is this: CMMC is the check, but NIST 800-171 is still the work. If your team pauses the work because the assessment timeline changed, you are still building compliance debt.
Why This Matters Specifically to Aerospace and Defense Manufacturers
A&D manufacturers face this issue differently than many service-based contractors because CUI often moves through multiple operational systems, people, and physical processes.
CUI can include controlled technical information such as technical drawings, blueprints, and specifications.[8] In a manufacturing environment, that information may appear in:
- ERP records
- PLM and engineering systems
- MES and shop floor instructions
- QMS records and inspection documentation
- Shared drives and email
- Supplier portals and file transfer tools
- Machine programs derived from controlled drawings
Manufacturing derivatives of controlled technical information—such as machine programs created from controlled drawings or inspection records containing defense specifications—may also require protection when they contain or reproduce CUI.[8]
This is why the question of what the CMMC Phase 2 pause means is so important for manufacturers. Even if a formal C3PAO assessment deadline is delayed, your engineering data, revision history, supplier exchanges, and quality evidence still need to be controlled.
Subcontractors should pay close attention as well. DFARS 252.204-7012 obligations flow down to subcontractors when they handle covered defense information or CUI in support of a defense contract.[4] That means lower-tier suppliers cannot assume they are insulated from these requirements just because they are not the prime.
What the Pause Means for Contract Readiness and Bid Strategy
For leadership teams, the biggest mistake would be interpreting a C3PAO assessment pause as a reason to slow down across the board.
Why? Because legal requirements and market expectations are not always the same thing.
Legally, your company still needs to satisfy the underlying DFARS and NIST obligations already tied to your contracts and award eligibility.[4][5] Commercially, primes may still expect suppliers to demonstrate CMMC compliance for manufacturers through evidence, security plans, documented controls, and realistic readiness before awarding work.
There is also risk in overstating readiness. The U.S. Department of Justice has used its Civil Cyber-Fraud Initiative and the False Claims Act to pursue contractors that misrepresented their cybersecurity posture while doing business with the federal government.[6] In other words, even during a pause, inaccurate compliance claims can create exposure.
That does not mean every manufacturer needs to spend aggressively on every possible control right away. It does mean you should continue preparing in ways that improve contract readiness, operational discipline, and evidence quality whether formal assessment timing changes or not.
What Manufacturers Should Do in the Next 60 to 90 Days
If you are deciding how to respond to the CMMC Phase II pause, focus on actions that remain valuable under any future timeline.
-
Confirm where FCI and CUI live
Do not rely on assumptions. Map where federal contract information (FCI) and CUI enter your business, where they are stored, who touches them, and how they move between departments and systems.
-
Review your SPRS assessment status
Make sure your self-assessment is current where applicable and grounded in a real review against NIST SP 800-171 and its assessment procedures, not a rough estimate.[1][3][5]
-
Update your SSP and POA&Ms
Your System Security Plan should reflect current reality, including systems in use, roles, boundaries, and control implementation. If gaps remain, document them honestly and track remediation through formal plans of action and milestones.
-
Tighten role-based access
Review who can access engineering files, ERP records, inspection documents, and supplier data. Many compliance problems come from excessive access that accumulated over time.
-
Review supplier and subcontractor data sharing
Look closely at portals, email attachments, file shares, and ad hoc transfer methods. If sensitive files are being exchanged outside controlled workflows, fix that now.
-
Validate document and revision control
Manufacturers often struggle when approved drawings, work instructions, and quality records are spread across multiple locations. Unclear ownership and inconsistent revision control increase both compliance risk and production risk.
-
Start collecting evidence, not just policies
Future readiness depends on proving controls operate in practice. That includes access reviews, training records, change records, incident procedures, configuration baselines, and documented approvals.
-
Assign executive ownership
This cannot sit only with IT. Operations, engineering, quality, finance, program leadership, and executive management all influence how CUI is handled.
Use the Pause to Fix Process Gaps, Not Just Security Gaps
For many manufacturers, the real weakness is not the absence of a policy. It is the gap between policy and daily work.
Examples include:
- Unmanaged spreadsheets tracking sensitive jobs or customers
- Engineers sending revisions by email because the official workflow is too slow
- Shared folders with broad access rights
- Supplier file exchange happening outside approved systems
- Unclear ownership for document retention and approval history
- ERP, QMS, and document systems that do not align on who can see what
NIST SP 800-171 includes configuration management and access-related expectations that are hard to sustain when business processes are fragmented.[3] That is why the best response to uncertainty is not to wait for the next rule update. It is to reduce data sprawl, strengthen workflow control, and make your operating model easier to defend.
This is also where a business-systems perspective matters. ERP does not “solve CMMC” by itself, but your ERP, document control, quality systems, and surrounding applications shape how well your company can control data, enforce roles, and produce evidence when asked.
Key Questions A&D Leaders Should Ask Their Teams Right Now
If you are an owner, president, COO, CFO, CIO, IT director, quality leader, or program leader, these are good questions to ask this quarter:
- Do we know exactly where CUI and FCI reside today?
- Which of our systems store or move controlled information: ERP, PLM, MES, QMS, shared drives, email, portals, or machine-connected tools?
- Is our SPRS score current and based on a documented assessment rather than assumptions?
- Can we produce evidence of current controls, not just written policies?
- Who owns CUI handling across engineering, operations, quality, IT, and supplier management?
- Are subcontractor and supplier processes aligned with our contract obligations?
- Where are employees using workarounds outside approved workflows?
- Would a prime contractor or auditor see our actual process reality as credible?
- If Phase 2 timing changes again, do we have a plan that still moves us forward?
Bottom Line: Pause the Assumption, Not the Preparation
The right response to the CMMC Phase 2 pause is not panic, and it is not complacency.
If mandatory third-party assessment timing shifts, that may change how quickly some requirements appear in solicitations. It does not eliminate the need to protect CUI, maintain realistic NIST 800-171 self-assessments, support DFARS 252.204-7012 requirements, or stay ready for prime contractor scrutiny.[1][4][5]
For aerospace and defense manufacturers, this is a good time to strengthen the operational side of readiness: cleaner data flows, better role-based access, tighter document control, stronger supplier coordination, and better evidence across ERP and connected business systems.
If you need help turning uncertainty into a practical readiness plan, connect with SolutionsX. We help manufacturers evaluate how ERP, document control, workflows, and cross-functional business processes support cybersecurity and compliance readiness in regulated A&D environments.
Sources
- Cybersecurity Maturity Model Certification Program Frequently Asked Questions, Department of War Chief Information Officer, 2026.
- Cybersecurity Maturity Model Certification (CMMC) Program, 32 CFR Part 170 Final Rule, Federal Register, October 15, 2024.
- NIST SP 800-171 Rev. 2: Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, National Institute of Standards and Technology, February 2020; updated January 2021.
- DFARS 252.204-7012: Safeguarding Covered Defense Information and Cyber Incident Reporting, Acquisition.gov.
- DFARS 252.204-7019: Notice of NIST SP 800-171 DoD Assessment Requirements, Acquisition.gov.
- Deputy Attorney General Lisa O. Monaco Announces New Civil Cyber-Fraud Initiative, U.S. Department of Justice, October 6, 2021.
- CUI Policy and Guidance, National Archives and Records Administration.
- CUI Category: Controlled Technical Information, National Archives and Records Administration.