If you make parts, assemblies, or test data for Pratt & Whitney, Sikorsky, Electric Boat, or one of their tier-1 suppliers, you have probably heard two contradictory things this summer. One is that CMMC is coming and you need to be certified by November. The other is that CMMC got cancelled. Neither is right, and the gap between them is where small shops get hurt.
Here is where things actually stand as of late August 2026, and what it means for a shop with 6 to 60 people.
What happened on July 13
The Department of War (the Department of Defense's current name) issued two memos on July 13, 2026. The first suspended Phase 2 of the CMMC rollout. Phase 2 was scheduled to start November 10, 2026, and it would have let contracting officers require a third-party CMMC Level 2 certification, done by an outside assessor, before awarding contracts that involve Controlled Unclassified Information.
The second memo created a CMMC Reform Task Force and gave it 60 days to recommend changes to the program. Industry comments closed August 14. Recommendations are expected in the second half of September.
So the outside audit is on hold. Nobody knows for how long, and nobody knows what the program looks like after the task force reports.
What did not change
This is the part that matters, and it is the part most people miss.
DFARS 252.204-7012 is still in your contracts. That clause has required you to implement NIST SP 800-171 since 2017. It did not go anywhere.
NIST SP 800-171 is still the standard. All 110 controls. The suspension paused the audit of whether you meet them. It did not pause the requirement to meet them.
Phase 1 is still running. Since November 10, 2025, new DoD contracts can require a Level 1 or Level 2 self-assessment with a score posted to SPRS, the Supplier Performance Risk System. A senior official at your company has to affirm that score every year. That affirmation is a statement to the federal government, and a knowingly false one is a False Claims Act problem.
Your prime can still ask. Primes have their own flow-down obligations and their own risk to manage. Many of them are using the pause to clean up their supplier lists. A letter asking for your SPRS score, your System Security Plan, or your CMMC status can arrive any day, and "the program is paused" is not an answer they will accept.
Why the pause is actually good news for a small shop
Getting a shop through a third-party Level 2 assessment with a large compliance firm routinely runs into six figures. Assessors bill by the hour. The hours that cost the most are the ones spent documenting what you got wrong, because every open finding turns into remediation and then a second visit.
The shops that were going to struggle in November were the ones starting from zero with a deadline breathing on them. Deadline work is expensive work. The pause turns that into pace-yourself work, and pace-yourself work costs a fraction as much.
The 110 controls are not going to disappear. Whatever the task force recommends, it will not say "stop protecting CUI." So the rational move is to use the quiet period to get the controls in place at a small-shop price, so that whenever the certification requirement returns, the assessment is a formality.
What "the controls" look like in a real shop
NIST 800-171 sounds abstract until you translate it into things you can point at. In a typical Connecticut machine shop or test lab, the gaps we find first are:
- Everyone logs in as a local administrator, or with one shared "shop" account
- No multi-factor authentication on email, remote access, or the file server
- CUI drawings sitting in email, in a personal Dropbox, or on a USB stick at the CNC
- No central logging, so if something happened last Tuesday nobody can say what
- Windows 10 machines on the floor, a year past end of support
- Antivirus on some computers and nobody sure which
- Backups that exist but have not been tested in a long time
- No written policies, no System Security Plan, no incident response plan
- Accounts still active for people who left two years ago
None of these are unusual. All of them are fixable. Most of them are cheap to fix compared to what they cost you at assessment time.
What to do this fall
1. Find out what CUI you actually have. Drawings, specs, test reports, anything marked CUI or flowed down from a program. If you are not sure, that is the first conversation to have. Sometimes the answer is "only three machines ever touch it," and that shrinks the whole project.
2. Get an honest score. Score yourself against the 110 controls, or have someone do it with you. If the real number is 40, you need to know that before you post anything in SPRS.
3. Write the two documents. A System Security Plan that describes how your shop actually operates, and a Plan of Action and Milestones for what is not done yet. Every prime and every assessor asks for these first.
4. Fix the cheap, high-impact gaps first. MFA, admin rights, retiring Windows 10, retiring old accounts, and central logging. These are most of the points.
5. Keep evidence as you go. Screenshots, configurations, signed policies. Assessors want proof, not promises. Collecting it at the end is miserable. Collecting it as you go is free.
Where we fit
CT Tech Express does the readiness work: the preliminary review, the full gap assessment, the documents, the technical controls, and the evidence package. We are not an assessor and we do not issue certificates. When you are ready, we work directly with a Connecticut partner that holds its own CMMC Level 2 certification and can introduce you to an independent C3PAO for the assessment itself.
If you handle defense work and you want to know where you stand, the CMMC readiness page explains the process, and the preliminary on-site review is free.
