
CMMC is now in your contracts.
Here’s what defense manufacturers need to do now.
For years, CMMC lived in a planning zone. It was something to track, assign someone to monitor, and revisit when capacity allowed. That window has closed.
The DFARS acquisition rule implementing CMMC became effective on November 10, 2025. When the program office or requiring activity assigns a CMMC level to a procurement, contracting officers include that level in the solicitation provision and contract clause. Before award, an offeror must have the required current CMMC status entered in the Supplier Performance Risk System, known as SPRS, along with a current affirmation of continuous compliance.
That makes CMMC a contract eligibility issue. A strong delivery record, competitive pricing, and a long history with a prime contractor all matter. Eligibility now also depends on whether the contractor information systems that will process, store, or transmit FCI or CUI have the required CMMC status.
For manufacturers that hold direct DoD contracts, this may already be on the leadership agenda. The larger exposure surface sits deeper in the supply chain. Companies that supply components, fabricated parts, specialty materials, assemblies, engineering support, or technical services to prime contractors can also fall under CMMC requirements when the data they handle triggers CMMC obligations.
The companies that use 2026 to get their CMMC house in order will be better positioned to answer customer questionnaires, respond to solicitations on schedule, and avoid the disruption that comes when a contract requires a status which they have yet to pursue.
A Quick Orientation on the Three CMMC Levels
Most manufacturers in the defense supply chain are either at Level 1 or working toward Level 2. The right level depends on the type of information the company processes, stores, or transmits in performance of the contract.
CMMC Level 1 covers the protection of Federal Contract Information, or FCI. FCI is nonpublic information provided by or generated for the government under a contract to develop or deliver a product or service to the government. Public government information and simple transactional information, such as payment-processing data, fall outside that definition.
Level 1 requires an annual self-assessment and annual affirmation against 15 security requirements drawn from FAR 52.204-21. These are foundational safeguards: limiting system access, controlling information flows, protecting information during transmission, and disposing of sensitive information appropriately. For manufacturers whose work involves FCI only, Level 1 is the target. It is achievable, and it still requires documentation, evidence, and an honest internal review against each requirement.
CMMC Level 2 applies to organizations that process, store, or transmit Controlled Unclassified Information, or CUI. This is where the program becomes substantially more demanding, and where many manufacturers handling defense technical data will land.
Under the current CMMC rule, Level 2 maps to the 110 security requirements in NIST SP 800-171 Revision 2. Depending on what the solicitation specifies, Level 2 may require either a self-assessment or a third-party assessment by a Certified Third-Party Assessment Organization, known as a C3PAO. Level 2 assessments are valid for three years, with annual affirmations in between.
Level 2 spans 14 domains: access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity. That list touches nearly every department in a manufacturing operation.
CMMC Level 3 applies to a narrower set of programs involving higher-risk CUI and advanced persistent threat concerns. It requires a DCMA DIBCAC assessment and compliance with selected requirements from NIST SP 800-172, in addition to Final Level 2 C3PAO status for the same assessment scope. Most manufacturers will encounter Level 3 only in specific program contexts, but companies supporting sensitive defense programs should understand whether it is on the horizon.
Where CUI Actually Lives in a Manufacturing Environment
This is the question that separates organizations that prepare well from those that spend more on remediation later: Where is your sensitive contract data, and what systems does it touch?
In a manufacturing environment, CUI moves. A drawing arrives from a prime and gets saved to a shared drive. An engineer opens it in a CAD tool. A buyer sends a specification excerpt to a supplier for quoting. A quality manager uploads an inspection record to a customer portal. A program manager sends an agenda that includes contract-specific technical details. Team members are focused on doing their jobs. The data path still matters.
Each touch point can create a compliance gap when the underlying system falls within scope, and the safeguards are incomplete.
The environments that typically require scrutiny in a manufacturing context include:
Engineering and design systems. CAD platforms, PDM or PLM tools, file servers holding drawings and specifications, and collaboration tools used to share technical data with customers or suppliers.
ERP and production planning. Order management, work orders, routings, and production records that reference contract-specific parts, customer numbers, technical requirements, or controlled production information.
Quality systems. Inspection records, nonconformance reports, first article documentation, test results, and audit records tied to defense programs.
Procurement and supplier communications. RFQ packages, supplier qualification documents, and purchase orders that flow technical requirements to subcontractors.
Email and file sharing. The communication layer through which controlled information often moves across teams, customers, and suppliers.
Remote access and endpoints. Laptops used by engineers, shop-floor terminals with network access, and any device that can reach systems containing CUI.
Backup and recovery systems. Backup infrastructure that stores CUI falls into the same scoping conversation as the primary systems that hold it.
The goal of scoping is accuracy. Organizations that work carefully on scope can often reduce complexity and cost by identifying where CUI truly lives, where it travels, and where it can be kept out of unnecessary systems.
The Supply Chain Dimension: CMMC Flows Down
One of the most important structural features of the CMMC program for manufacturers is how it moves through the supply chain.
The rule is explicit: CMMC requirements apply to prime contractors and subcontractors at all tiers when they process, store, or transmit FCI or CUI on contractor information systems in performance of a DoD contract or subcontract. Prime contractors must flow down CMMC requirements to subcontractors, and subcontractors may need to follow those requirements further.
This means a precision machining shop, specialty electronics manufacturer, fabrication company, or engineered-materials supplier working as a second- or third-tier supplier may receive CMMC requirements through a prime relationship. The trigger is data handling. If a supplier receives technical data that meets CUI criteria or is flowing down with CUI handling requirements, CMMC may apply. Suppliers should confirm the CUI status, markings, and required CMMC level with the customer before assuming the data sits outside scope.
For manufacturers that both supply primes and use their own supply chains for defense-related work, this creates a two-sided obligation. You may receive CMMC requirements from a customer above you and need to pass appropriate requirements to suppliers below you.
Supplier mapping belongs at the leadership level. Which vendors receive controlled technical data; which suppliers handle defense-related drawings, specifications, process sheets, or quality records? And what systems do they use? What evidence can they provide?
Prime contractors are increasingly asking their supply chains to provide documentation of CMMC status, self-assessment results, or readiness plans. Companies that can respond clearly will have an advantage over suppliers still trying to understand their exposure.
Plans of Action and Milestones: A Short Remediation Bridge
The CMMC program allows conditional status in limited Level 2 and Level 3 cases through Plans of Action and Milestones, commonly called POA&Ms. A POA&M identifies security gaps, the tasks required to close them, resources needed, milestones, and scheduled completion dates.
Level 1 uses final status only. POA&Ms apply only in limited Level 2 and Level 3 circumstances, and only selected requirements may be placed on a POA&M. For Level 2 and Level 3, conditional status must meet the requirements in 32 CFR 170.21, and every POA&M item must be closed within 180 days of the conditional status date.
This matters for manufacturers that are partway through remediation when a contract opportunity arrives. A properly structured POA&M can preserve eligibility in some situations. It requires well-documented gaps, a credible remediation timeline, and active leadership execution.
Treat the POA&M as a short remediation bridge. The 180-day window is tight. A manufacturer that enters conditional status with difficult remediation work still ahead has limited room for procurement delays, technology rollout issues, policy gaps, or evidence problems.
The stronger position is to reach final status before the contract requires it and use POA&Ms only when the remaining gaps are narrow, documented, and actively being closed.
What a Practical CMMC Roadmap Looks Like for Manufacturers
The companies handling CMMC well share a few traits. Leadership owns the business risk. Scope is defined before tools are purchased. Evidence is treated as an operational output rather than a last-minute assessment exercise.
A practical path forward looks like this:
Start with your contract portfolio. Pull together current DoD contracts, prime contractor relationships, subcontract obligations, upcoming renewals, and likely recompetitions. For each one, identify whether the work involves FCI, CUI, or both. Then determine the CMMC level and assessment type that may apply.
Map where the data goes. Walk the path of a CUI document from receipt to storage, use, sharing, and disposal. Identify who receives it, where it lands, which systems it touches, and who has access. This exercise often surfaces systems leadership had overlooked. It can also reveal systems that can be kept outside the assessment scope with better process design.
Run an honest gap assessment against NIST SP 800-171. For Level 2, this means reviewing all 110 requirements and determining whether each one is fully implemented, partially implemented, or missing. Partial and missing items should be reflected in the System Security Plan, and eligible remediation items may feed a POA&M when appropriate.
Prioritize by impact and timeline. Some gaps close quickly, such as a missing policy, an informal access review, or a configuration setting. Other gaps take longer, such as deploying multi-factor authentication across all applicable systems, establishing log monitoring and retention, formalizing incident response, or segmenting systems to control CUI movement. Build the roadmap around real dependencies and the date your CMMC status needs to be in place.
Build evidence into daily operations. Assessment readiness is an ongoing operating posture. Access reviews need a schedule. Training records need to stay current. Configuration baselines should reflect actual systems. Incident response plans need testing. Backup, endpoint, and remote-access controls need evidence. Organizations that build these practices into normal operations find CMMC easier to maintain.
Communicate with customers and suppliers. Prime contractors are asking questions. A manufacturer that can explain its CMMC status, assessment plan, scope, and remediation progress strengthens the customer relationship. The same clarity matters with suppliers that may receive CUI or FCI. Early conversations reduce friction when a program office or prime contractor asks for documentation.
The Competitive Angle
A defensive approach to CMMC focuses on preserving eligibility. That is a practical starting point, and it misses part of the opportunity.
Defense manufacturers that achieve and maintain CMMC status ahead of broad enforcement create a meaningful differentiator. Prime contractors managing supplier risk want subcontractors that can demonstrate compliance with less uncertainty. When a solicitation window is tight and a prime needs to move quickly, a supplier with documented CMMC status removes a point of friction.
Starting November 10, 2026, Phase 2 begins. Under the current phased implementation plan, DoD intends to include Level 2 C3PAO status for applicable solicitations and contracts as a condition of award, with discretion to delay that requirement to an option period in some cases. That will widen the gap between suppliers that are assessment-ready and those still building their programs.
Manufacturers that move early get to pace the work, learn what evidence gathering actually requires, and improve security practices in ways that often strengthen operations beyond compliance. Better access controls reduce insider risk. Stronger configuration management supports uptime. Formalized incident response helps contain problems faster. Done well, CMMC becomes a maturity lift that makes the operation more resilient.
The Bottom Line for Leadership
CMMC implementation has begun. Applicable contracts can include CMMC requirements. Supply chain customers are asking about status. Assessors are conducting evaluations. The preparation window has become a remediation window, and for some companies it is narrowing quickly.
The decisions that belong at the leadership table are business decisions: Who owns CMMC? What is our contract exposure? Where does sensitive data live? What status do we need, what timeline is realistic, and what does readiness require in people, process, technology, and evidence?
Assigning CMMC to IT alone creates risk. CMMC affects contract eligibility, supplier relationships, operational continuity, and revenue protection for manufacturers that depend on defense work.
The right move in 2026 is to understand your current state, define scope accurately, commit to a realistic path to certification, and start building the evidence and practices CMMC requires before a solicitation deadline makes the work urgent all at once.
Questions about CMMC readiness, scoping, or gap assessments for your organization? Connect with our team to start the conversation.
Sources
- Federal Register, DFARS Case 2019-D041, Assessing Contractor Implementation of Cybersecurity Requirements. Final DFARS rule implementing CMMC contractual requirements, effective November 10, 2025. (Federal Register)
- eCFR, 32 CFR Part 170, Cybersecurity Maturity Model Certification Program. Current codified CMMC program requirements, including applicability, implementation phases, levels, scoping, POA&Ms, affirmations, and flow-down. (eCFR)
- DoD CIO, About CMMC. Official DoD CMMC overview, implementation status, assessment types, and affirmation reminder. (U.S. Department of Defense CIO)
- Acquisition.gov, DFARS Subpart 204.75. DoD acquisition policy and procedures for CMMC level requirements, award eligibility, SPRS checks, and clause use. (Acquisition.GOV)
- Acquisition.gov, DFARS 252.204-7025, Notice of Cybersecurity Maturity Model Certification Level Requirements. Solicitation provision requiring current CMMC status and current affirmation in SPRS prior to award. (Acquisition.GOV)
- eCFR, 32 CFR 170.14, CMMC Model. Official CMMC model mapping for Level 1, Level 2, and Level 3 requirements. (eCFR)
- eCFR, 32 CFR 170.17 and 170.18, Level 2 and Level 3 assessment requirements. Requirements for Level 2 C3PAO assessment, Level 3 DIBCAC assessment, assessment validity, POA&M closeout, and Level 3 prerequisite status. (eCFR)
- eCFR, 32 CFR 170.21, Plan of Action and Milestones requirements. Official POA&M limitations, Level 1 restriction, Level 2 and Level 3 conditions, and 180-day closeout requirement. (eCFR)
- eCFR, 32 CFR 170.23, Application to Subcontractors. Official CMMC flow-down rule for prime contractors and subcontractors at all tiers. (eCFR)
- Acquisition.gov, FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems. Official definition of Federal Contract Information and Level 1 source requirements. (Acquisition.GOV)
- NIST SP 800-171 Revision 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. NIST publication referenced by the current CMMC Level 2 model. (NIST Computer Security Resource Center)
- NIST SP 800-172, Enhanced Security Requirements for Protecting Controlled Unclassified Information. NIST publication referenced by the CMMC Level 3 model. (NIST Computer Security Resource Center)
- National Archives CUI Registry, Controlled Technical Information. Official CUI category definition and examples for controlled technical information. (National Archives)
- DoD CUI Program, Controlled Technical Information. DoD guidance describing technical information with military or space application, including blueprints, drawings, plans, instructions, software, and documentation. (dodcui.mil)
