If you make parts for a prime contractor, or you're a level or two down from one, you've probably heard somebody say that CMMC got put on hold. That's about half true, and the half that isn't true is the half that can cost you a contract.
Here's where things actually stand.
The DoD acquisition rule (the 48 CFR piece) took effect on November 10, 2025. That kicked off Phase 1 of the CMMC rollout and gave contracting officers the ability to write CMMC requirements directly into new solicitations and contracts. In Phase 1, that means Level 1 and Level 2 self-assessments.
Then on July 13, 2026, the Department suspended Phases 2 through 4 pending a review. Phase 2 was the significant one. It would have made third-party certification mandatory starting November 10, 2026, meaning an outside assessor instead of your own self-assessment. That is on hold.
What is not on hold is Phase 1. It has been live since last November, self-assessment requirements are going into contracts right now, and during the review DoD is still enforcing NIST 800-171 through self-assessments plus some government-led checks.
So the accurate version is this: the certification deadline moved. The requirement didn't.
Northern Utah has more defense supply chain in it than people outside the industry tend to realize. Between Hill Air Force Base, the aerospace and composites cluster along the Wasatch Front, and the machine shops that feed both, there are a lot of small manufacturers with DoD work somewhere in their pipeline.
The part that surprises people is flow-down. If you're a subcontractor to a prime, the requirements reach you through your contract with them. You may never have spoken to a contracting officer in your life and still be on the hook. We've seen shops of a dozen people find this out when a prime sent over a security questionnaire with a two week deadline attached.
Broadly, there are two categories you could fall into:
A lot of shops assume they're Level 1 and turn out to be Level 2 because of the drawings sitting in a shared folder on the file server. It's worth pinning that down before you build a plan around the wrong level.
Level 1 is 15 basic safeguarding requirements, the same ones that have been sitting in FAR 52.204-21 for years. The list is not exotic: control who has access to your systems, limit what they can do once they're in, control physical access, sanitize media before you dispose of it, keep systems patched, run antivirus, and protect the boundary of your network.
You handle it as an annual self-assessment, and then someone with authority at the company affirms it in the Supplier Performance Risk System (SPRS). That affirmation is the part to take seriously, and we'll come back to why.
Level 2 is a different animal: 110 controls drawn from NIST SP 800-171, a System Security Plan, and a plan of action and milestones for anything you haven't closed yet. It's achievable for a small shop, but it is a project, not an afternoon.
In our experience it isn't the obscure controls that trip people up. It's four things, and they're the same four almost every time:
None of that is expensive to fix. It's just work nobody has had a reason to prioritize until a prime finally asked the question.
This is the practical side that gets lost in the acronyms. When a prime contractor comes asking, it usually looks like one of three things.
Sometimes it's a short questionnaire: do you handle CUI, what's your CMMC level, what's your SPRS score, when did you last self-assess. Sometimes it's a request for your System Security Plan and your plan of action, which means they want to see the actual documents rather than a yes or no. And occasionally it's a clause in a new purchase order that flows the requirement down to you with a date attached, which is the version that leaves the least room to negotiate.
In all three cases, the shops that respond well are the ones who already know the answers. The ones who go quiet for two weeks while they figure out what SPRS even is tend to find the prime has moved on to a supplier who was ready. That's the real risk here, and it's a commercial risk more than a regulatory one.
For a small shop that's genuinely Level 1, this is not a six figure undertaking. Most of the 15 practices are things a competently managed network already does. If your IT is in decent shape, the gap is usually MFA, some access cleanup, a written policy or two, and the documentation to show you did it. Think weeks, not quarters.
Level 2 is a bigger lift. Between the 110 controls, the System Security Plan, the policies, and the evidence collection, most shops we've worked with need somewhere between three and nine months depending on where they're starting from and how much of the work they do themselves. The network changes are usually the easy part. The documentation is what drags.
The expensive version is the one where a prime asks for your status, you don't have an answer, and you try to compress nine months of work into a month because a purchase order is sitting there waiting. That's when people overspend.
This is worth being blunt about. When you affirm compliance in SPRS, you are making a representation to the federal government. If that representation isn't accurate, it stops being a paperwork problem and becomes potential False Claims Act exposure. The Justice Department has been actively pursuing cases against contractors over cybersecurity misrepresentations, and those cases are not cheap even when they end well.
The short version: don't check the box because you assume you're fine. Find out whether you're actually fine, then check the box.
If you have DoD work now, or you want it, here's a sensible order of operations:
The pause on Phase 2 is a gift, not a reprieve. It means you can do this at a sane pace and a sane cost instead of scrambling when a customer gives you three weeks' notice.
We're a managed IT provider based in Murray, and we work with manufacturers across Salt Lake County and the Wasatch Front on exactly this: the network segmentation, the access controls, the documentation, and the evidence you'll need when somebody asks for it.
If you're not sure which level applies to you or where your gaps are, that's a good first conversation to have, and it doesn't cost anything to have it.
We help Utah manufacturers with the network segmentation, access controls, documentation, and evidence a prime will ask for. Start with a free, no-pressure assessment.
Get a Free IT Assessment