CMMC for Manufacturers: Phase 2 Is Paused. Your Obligations Aren’t.
Here’s what a lot of shops heard: “Phase 2 got canceled, so I can stop worrying about it.” That’s the most expensive thing you could take away from this.
Editor’s note: On July 13, 2026, the Department of War (DoW) suspended CMMC Phase 2, including the November 10, 2026 assessment deadline, and launched a 60-day reform review. We updated this post to reflect that. The short version: the deadline moved. The work didn’t. Here’s what still applies to your shop today. Ongoing details here.
What Got Paused (And What Didn’t)
In July 2026, the DoW hit pause on CMMC Phase 2. The November 10 deadline for third-party assessments? Suspended. A new CMMC Reform Task Force is running a 60-day review, with a public request for information due August 14, 2026. No replacement date has been set.
So if you were racing a clock, the clock just disappeared. For now.
But read the fine print, because this is where shops get it wrong. The only thing that got paused is the third-party assessment, the part where a CMMC Third-Party Assessment Organization (C3PAO) shows up and grades you. Almost everything else is still standing.
What Did NOT Change
Everything below is exactly where it was this spring:
- DFARS 252.204-7012
Safeguarding covered defense information and reporting cyber incidents. Live. - NIST SP 800-171 Rev 2
The 110 controls. Still the standard you’re held to. - Level 1 and Level 2 self-assessments
The Phase 1 requirements didn’t go anywhere. - Your SPRS score
You still run a NIST 800-171 self-assessment and post the resulting score to SPRS under DFARS 252.204-7019/7020. That obligation predates CMMC. It’s still your problem.
Translation: the assessor got sent home. The requirement stayed. If your contracts reference DFARS 7012 or NIST 800-171 today, you are on the hook today. No C3PAO required to make that true.
The Legal Liability the Pause Didn’t Touch
This is the part nobody’s talking about in the “it’s canceled!” chatter.
Start with what you’re still required to do. Under DFARS 252.204-7019/7020, you self-assess against NIST 800-171 and post a score to SPRS. A senior officer at your company still needs to sign off on it. None of that got paused. When that score is inflated, guessed at, or based on a gap analysis nobody actually ran, it’s not a paperwork slip. It’s a false certification.
$11.25M settlement. $4.6M settlement. Treble damages. Personal liability for a named officer. That was the DOJ’s 2025 message to defense contractors who falsely certify, and the Phase 2 pause did nothing to change it.
This isn’t theoretical. The DOJ settled seven cybersecurity-related False Claims Act cases in 2025 alone, including an $11.25M settlement with a defense contractor that falsely certified compliance and a $4.6M settlement with a contractor that submitted an inflated SPRS score. That’s the exact score you’re still required to submit today. The False Claims Act carries treble damages and per-claim penalties, and it can reach the individual who signed. Holland & Knight has a good breakdown of how that exposure works.
CMMC Level 2 also requires a senior company executive, your “Affirming Official,” to file an annual affirmation in SPRS attesting that the organization meets all applicable security requirements. That affirmation piece is part of what the 60-day review is now weighing, so it may change. But don’t let that distract you. The self-assessment score and the officer’s signature behind it exist independently of CMMC. They’re live right now, and they’re exactly what the DOJ has been going after.
The deadline is soft. The legal liability is not. Those are two very different things, and the shops that confuse them are the ones writing checks to the DOJ.
The Bottleneck We Called Out Is Exactly Why This Got Paused
When we first wrote about CMMC, we said the math didn’t add up. The assessment pipeline could never absorb the demand headed for it. The pause is that prediction coming true.
The government estimates more than 76,000 organizations need Level 2 certification. As of early 2026, fewer than 1,100 had gotten there. C3PAOs in aerospace and defense hubs were already booking into late 2026 and 2027. And a real readiness journey—gap analysis, remediation, documentation, pre-assessment, and the assessment itself—runs 12 to 14 months. That funnel was never going to clear in time.
The Department of War said as much. Its announcement pointed to prohibitive compliance costs and, citing Small Business Administration data, evidence that CMMC was pushing innovative companies out of the Defense Industrial Base entirely. The bottleneck didn’t just slow shops down. It started driving them out. That’s the problem the 60-day review is trying to fix.
Here’s what matters for you: Fixing the bottleneck doesn’t mean scrapping the requirement. Nobody rebuilds a program this size to walk away from cybersecurity. The DoW was explicit that a “strict security baseline” stays. Some form of assessment is coming back. And when it does, the pipeline will be exactly as jammed as before, except now you’ll be competing with every shop that treated the pause as permission to do nothing.
So here’s the honest way to see it. You didn’t get a cancellation. You got a head start. Use it. Run the gap analysis. Close the obvious holes. Walk into the next deadline ready. Sit on this window instead, and you start the 12-to-14-month clock the day the date comes back. By then it’s already too late.
What You Should Do Now (Yes, Now)
Read your contracts. DFARS 252.204-7012 or NIST 800-171 in the language means you’re already on the Level 2 path. Pause or no pause.
Run a real gap analysis. Not a self-quiz. Take a structured look at all 110 controls. Most shops find the lift is bigger than they thought. Better to find that out on your own clock than the DOJ’s.
Fix the obvious shop floor stuff. Shared machine logins. Default controller passwords nobody changed. USB sticks moving G-code with no audit trail. CAM workstations on shared accounts. Programmer laptops with no disk encryption. No separation between the office network and the floor. These are the gaps assessors find first, because they’re the ones you can see from across the room.
Don’t DIY the rest. A CMMC Registered Practitioner does this for a living and will move you faster than a part-time internal effort.
Keep your posture in your capability statement. Primes are still asking. A clean answer keeps you in the bid, deadline or not.
The G-Code Gap Most CMMC Plans Miss
Here’s one gap that doesn’t care what the DoW decides in the next 60 days. G-code.
Programs living on USB drives, shared folders, and FTP servers. No version control. No audit trail. That fails NIST 800-171 on day one, and 800-171 didn’t get paused. When assessments come back, this is a gap that’s still sitting there waiting for you.
Datanomix G-Code Cloud + DNC closes it: GovCloud-hosted on Azure, encrypted at rest and in flight, SSO authentication, role-based permissions, and a full audit trail on every change. It’s the G-code piece of your compliance plan, handled whether the deadline is next year or the year after.
The Bottom Line
CMMC isn’t a question of if. It’s a question of how ready you are when the date comes back. And it’s coming back!
The deadline moved. The rules you’re held to today did not. The legal exposure on a bad SPRS score is live right now. And the readiness clock still runs 12 to 14 months.
The shops treating this as a pause will scramble all over again when the date comes back around. The shops treating it as a head start will keep their work and win new bids.
Don’t let the reprieve talk you out of being ready.
Want the deeper walkthrough? Watch our webinar on what assessors actually look for: How to Streamline Your CMMC 2.0 Compliance.
Then check out our on-demand demo of G-Code Cloud + DNC.