Use our new CMMC Level 2 compliance resource page to get educated about CMMC requirements.

A 60-Day Pause Isn’t a 60-Day Pass

Enhance your machine shop processes using our QMS software and best practices.

On July 13, 2026, the Department of War suspended CMMC Phase II, the rollout that would have required third-party cybersecurity certification assessments in defense contracts starting this November.

If you run a precision machine shop in the defense supply chain, you probably heard about it within hours. And depending on where you heard it, you got one of two reactions: either this changes everything, or it changes nothing.

Neither position is quite right, so here’s what you need to know. And what you should do.

The DoW suspended C3PAO third-party certification assessments. These are the independent audits that were going to be required in applicable contracts beginning November 10, 2026. A 60-day reform task force will study the CMMC program and recommend changes.

That’s it. That’s what’s on pause.

But there’s plenty you still need to be aware of.

The same release that suspended Phase II included this line:

“This action does not eliminate the requirement for companies to protect federal data. All defense contractors and subcontractors remain contractually obligated to safeguard covered defense information in accordance with DFARS clause 252.204-7012.”

DFARS 252.204-7012 is the contracting clause that governs how defense contractors protect Controlled Unclassified Information (CUI). It requires you to implement security controls from NIST SP 800-171, report cyber incidents within 72 hours, and ensure that any cloud service provider storing your CUI meets the FedRAMP Moderate security baseline or its equivalent.

This clause has been in defense contracts since 2017. It predates CMMC entirely. And it was explicitly reaffirmed in the same announcement that paused Phase II.

The market is already conflating CMMC Phase 2 and CMMC Level 2, but there’s a difference between them.

CMMC Level 2 is the set of 110 NIST SP 800-171 security controls that contractors handling CUI must implement. It’s the what: the security requirements themselves.

CMMC Phase 2 is the enforcement timeline: the when. It’s the phase that would have required third-party C3PAO assessments in contracts.

Phase 2 is paused. Level 2 is not. The security requirements haven’t moved. Only the enforcement mechanism for verifying them through third-party audit has been put on hold.

You’re still responsible for meeting all the obligations laid out in Level 2. But now? They got a little harder to navigate.

With third-party assessments on hold, your compliance posture rests more heavily on self-attestation. Phase I self-assessments remain fully in force. You’re still required to maintain your SPRS score and submit a signed annual affirmation of compliance under DFARS 252.204-7021.

That affirmation is a legal certification of your cybersecurity posture. And without a third-party audit to serve as a check on your work, the responsibility for accuracy falls entirely on you.

Meanwhile, DIBCAC — the government’s own assessment arm — can audit your cybersecurity posture at any time, regardless of where CMMC stands. The DoW release references “select government-led assessments” as an ongoing enforcement mechanism. That authority is untouched by this suspension.

And your primes aren’t slowing down. Major prime contractors have spent years embedding cybersecurity requirements into subcontracts, and these requirements frequently exceed the DoD floor. A 60-day study isn’t going to change their flow-down language. If anything, primes who were counting on C3PAO assessments to vet their supply chain now have to find other ways to verify supplier compliance. That could mean more scrutiny, not less.

In the midst of all this, you can’t afford to overlook DFARS 7012. DFARS 7012 doesn’t just require you to implement security controls. It requires that any cloud service provider storing your CUI meets the FedRAMP Moderate security baseline or its equivalent. That’s section 7012(b)(2)(ii)(D), and it’s been there since 2017.

For most precision machine shops, CUI lives in the ERP system. Engineering drawings, work orders, inspection records, routing sheets, job travelers… it’s all there. If that data includes CUI and it’s hosted in a cloud environment, that environment needs to meet the FedRAMP Moderate baseline. Even now. Because those requirements aren’t in CMMC. They’re in 7012.

If the cloud environment hosting your CUI doesn’t meet this standard, your annual self-attestation has a gap in it. That gap existed before the announcement, and it still exists today.

The shops that come through this in the strongest position regardless of what happens with CMMC will be the ones that treat this pause as time to prepare, not permission to stop.

Any successor framework is going to rest on NIST SP 800-171 and DFARS 7012. The DoW release says as much. That means the fundamentals haven’t moved:

Know where your CUI lives. Map your CUI boundary. Understand which data in your shop qualifies as CUI and where it’s being stored, processed, and transmitted.

Make sure your cloud environment meets the standard. If your ERP or any other cloud system stores CUI, verify that it has been independently assessed against the FedRAMP Moderate baseline, as DFARS 7012 requires. Ask your provider directly. They should be able to provide evidence of independent assessment, and it’s an issue if they can’t.

Complete your NIST 800-171 self-assessment. Be confident in your SPRS score. With third-party certification on hold, your self-assessment is the primary record of your compliance posture, and the one you’re legally attesting to.

Understand your shared responsibility model. Know which controls your ERP provider handles for you and which fall on your organization. That division is the foundation of a defensible attestation.

Don’t wait for the task force. Sixty days isn’t long. And whatever comes out of it will build on the same controls, clause, and underlying requirements. Work done now is work you won’t have to redo later.

We’ve been doing this work ourselves. ProShop recently completed an independent third-party assessment of our AWS GovCloud hosting environment against the FedRAMP Moderate baseline because DFARS 7012 requires it of cloud service providers handling CUI. We’ll have more to share on that shortly.

In the meantime, we’ve built a library of resources to help shops understand their obligations and protect CUI with confidence:

We’re also hosting a live session the week of July 28 to walk through what this announcement means for shops in the defense supply chain and what you should be doing right now. Register here.