...
Facet Technologies home

(309) 689-3900

Call our office!

3024 W. Lake Ave., Suite 1

Peoria, IL 61615

8:00AM - 5:00PM

Monday – Friday

Facet Blog

CMMC Phase 2 Paused: Central Illinois Manufacturer Guide

January 23, 2026

Brian Ford

Brian Ford

Brian is the President of Facet Technologies, Inc. Since 1989, he has helped business owners make smart, profit-driven technology moves. He has grown Facet to support hundreds of companies through managed services, IT support, cybersecurity, and compliance. His career experience in the agriculture and manufacturing industries gives him a unique understanding of their technology needs. He writes about IT and cybersecurity from a growth-focused business owner's standpoint.

Yes. CMMC is still required. On July 13, 2026, the Pentagon suspended only the Phase 2 rollout, the step that would have made third-party C3PAO assessments mandatory for most contracts involving Controlled Unclassified Information starting November 10, 2026. Phase 1 stays in force: NIST SP 800-171 self-assessments, SPRS scores, and annual affirmations continue, and DFARS 252.204-7012 still applies to every contract that carries it.

If you machine parts, supply materials, or provide engineering services to a defense prime from anywhere in Central Illinois, your obligations did not shrink. What changed is the deadline pressure and the question of who verifies your work.

At a glance:

CMMC Phase 2 was suspended on July 13, 2026, and the November 10, 2026 start date for mandatory C3PAO assessments no longer applies.

CMMC Phase 1 remains active, so Level 1 and Level 2 self-assessments, SPRS score postings, and annual affirmations continue in new Department of War solicitations.

NIST SP 800-171 Revision 2 remains the required security standard for any contractor that stores, processes, or transmits Controlled Unclassified Information.

A 60-day CMMC Reform Task Force is reviewing the program, with recommendations expected around September 13, 2026.

The Small Business Administration reported CMMC certification costs approaching $600,000 for some companies, which is the burden the review was launched to address.

What exactly did the Pentagon suspend in July 2026?

The Department of War, the current name for the Department of Defense, issued two memoranda on July 13, 2026: a Chief Information Officer memo titled “Removing Barriers to Defense Industrial Base Expansion” and an implementing memo from the Under Secretary for Acquisition and Sustainment. Together they pause the advancement to CMMC Phase 2.

Phase 2 was the point where the program moved from trusting your own assessment to requiring someone else’s. A C3PAO, or Certified Third-Party Assessment Organization, is an independent assessor authorized to certify that a contractor has implemented all 110 NIST SP 800-171 controls. Under the original timeline, most contracts involving CUI would have required a C3PAO certification before award beginning November 10, 2026. That requirement is now on hold with no replacement date.

The stated reason is cost. According to the Wiley law firm’s analysis of the memos, the Small Business Administration reported that CMMC certification costs were approaching $600,000 for individual companies and affecting more than 100,000 small businesses. The department tied the pause to its Acquisition Transformation Strategy, which aims to lower barriers for small and non-traditional suppliers. For a 60-person machine shop in Peoria, that is the right problem to be solving.

What CMMC requirements still apply right now?

Everything in Phase 1. The suspension memos are explicit that self-assessments, SPRS postings, annual affirmations, and the underlying DFARS clauses continue without interruption. Holland & Knight’s summary quotes the guidance directly: “Phase I remains in full effect. Self-assessment requirements, DFARS 252.204-7012, NIST SP 800-171 Rev 2 compliance, SPRS score postings and annual affirmations continue without interruption.” The 72-hour cyber incident reporting requirement also stays.

The pieces that still matter:

Federal Contract Information, or FCI, is information generated or provided under a government contract that is not meant for public release, such as pricing, delivery schedules, and contract terms. Handling FCI puts you at Level 1, which requires 15 security practices and a self-assessment.

Controlled Unclassified Information, or CUI, is sensitive but unclassified technical data: engineering drawings, specifications, test results, and anything carrying a CUI marking. Handling CUI puts you at Level 2, which requires all 110 controls from NIST SP 800-171 Revision 2 and a System Security Plan documenting how each one is met.

SPRS, the Supplier Performance Risk System, is the government database where you post your self-assessment score so contracting officers can check it. A Level 2 score is out of 110 and must be affirmed annually by a company official.

A POA&M, or Plan of Action and Milestones, is the documented list of controls you have not finished implementing and the dates you will close them. Level 2 allows conditional status with a score of at least 88 out of 110 and a POA&M closed within 180 days. Level 1 allows no POA&M at all.

None of that changed in July. If your contracts include DFARS 252.204-7012, 7019, 7020, or 7021, those clauses stay binding until the government formally modifies them.

What is the CMMC Reform Task Force likely to change?

Nobody outside the Pentagon knows yet. What we do know is the scope of the review. The department issued a Request for Information with an August 14, 2026 deadline covering seven topics: cost drivers, which controls are most effective, assessment burden, commercial alternatives, streamlining self-assessment, whether self-assessment is effective, and reform for small businesses. The task force’s 60-day window points to a report around September 13, 2026.

What is unlikely to change is the NIST SP 800-171 baseline itself. That standard has been a contract requirement under DFARS 252.204-7012 since 2017, long before CMMC existed. CMMC was built as a verification layer on top of it, and the review is about the verification layer. If the task force trims anything for small suppliers, it will trim from the 110, so nothing a manufacturer implements now becomes wasted work. What may change is who checks the work and how often.

Should a manufacturer keep working toward Level 2 while the program is under review?

Yes, for three reasons that have nothing to do with the CMMC calendar.

First, your prime contractor still has to verify its supply chain, and primes did not stop asking for SPRS scores in July. Primes that wrote CMMC readiness into supplier scorecards before the suspension have no reason to remove it.

Second, the False Claims Act exposure is unchanged. Affirming a SPRS score you have not earned is a false certification to the federal government whether or not a third party ever checks it. The Department of Justice has settled multiple cybersecurity-related False Claims Act cases with defense contractors, and the suspension did not touch that enforcement track.

Third, the threat to manufacturers does not care what the task force decides. The IBM 2026 X-Force Threat Intelligence Index again ranked manufacturing as the most targeted industry, counted 109 distinct extortion groups in 2025 versus 73 the year before, and found exploitation of public-facing applications up 44 percent as an initial entry point. Supply chain incidents have increased nearly fourfold in five years. The 110 controls exist because those attacks work.

What you can reasonably pause: prepaying for a C3PAO assessment slot, signing a multi-year certification engagement, or buying tooling sized for a November deadline that no longer exists. Keep the controls moving. Hold the certification spend until the task force reports.

What does a realistic NIST 800-171 timeline look like without a hard deadline?

Most manufacturers need 6 to 12 months to reach full Level 2 implementation, and the suspension is a chance to run that timeline without panic pricing.

Months one and two are assessment: identify which level your contracts require, map where FCI and CUI live, and compare current practice against the 110 controls. Months two through four are planning: prioritize gaps by risk and effort and build a budget. Months four through eight are implementation, where most of the work happens and where manufacturers most often underestimate the effort. Months eight through ten are documentation and testing: finish the System Security Plan, collect evidence, and verify each control works as written. The final stretch is the self-assessment: calculate the score, post it to SPRS, and affirm it.

Shops with an existing security program and decent documentation move faster. Shops starting from a home router and shared passwords, or with a 15-year-old CNC on Windows XP that needs network segmentation and documented compensating controls, may need the full year. We covered the shop-floor side of this in why Central Illinois manufacturers are prime targets. Either way, a current SPRS score built on real controls is what matters now, and it will still matter under whatever the task force recommends.

How does Facet Technologies help Central Illinois manufacturers with CMMC?

Facet Technologies has supported Central Illinois businesses since 1989, including manufacturers across the region who supply components, materials, and services to defense primes. We are not a C3PAO and do not certify anyone. What we do is build and run the security environment that a self-assessment or a future third-party assessment measures.

Our president, Brian Ford, spent years in food manufacturing, where documentation and process control are part of daily operations. That background shapes how we treat CMMC: as an ongoing quality system, not a one-time project.

Our CMMC compliance consulting starts with a gap assessment that follows how data actually moves through your operation rather than comparing policies to a checklist. From there we build a remediation plan sequenced around production schedules, because you cannot shut down the floor to install controls. We deploy and manage the technical layer, including firewalls, endpoint detection, backup isolation, access controls, and 24/7 monitoring through our security stack. We help prepare the System Security Plan, policies, and evidence, and we support you through the SPRS submission or, when the program calls for it again, a C3PAO assessment. Quarterly reviews help maintain your score as the environment changes.

Compliance consulting is billed separately from our managed services agreement, so a manufacturer can engage us for a CMMC gap assessment without changing how day-to-day IT support works. Many defense suppliers also find that cyber insurance requirements and NIST SP 800-171 controls overlap heavily, which lets one project satisfy two audiences.

Frequently Asked Questions

Does the suspension change anything for subcontractors who never contract with the DoD directly?

No. CMMC and NIST SP 800-171 obligations flow down from primes to any subcontractor that handles FCI or CUI, and primes remain responsible for verifying supplier compliance. Expect primes to keep asking for SPRS scores and readiness evidence during the review period, since their own contract clauses did not change.

I already scheduled a C3PAO assessment. Should I cancel it?

The July memos do not address assessments already scheduled or completed, so ask your prime what it expects before deciding. A completed Level 2 certification still documents full NIST SP 800-171 implementation, which has value with primes and insurers. If the assessment is months out, consider holding the deposit until the task force reports.

How much does CMMC compliance cost for a Central Illinois manufacturer?

Gap assessments typically run $5,000 to $15,000 depending on environment size. Remediation ranges from about $20,000 for small shops with good existing practices to $100,000 or more for larger operations with major gaps. C3PAO assessment fees, when required, run $15,000 to $50,000. Facet Technologies provides a detailed estimate after the gap assessment.

Let’s talk about where your SPRS score stands

If you supply the defense industry from Central Illinois and you are not sure where your SPRS score stands, or whether it is built on controls that would survive an assessor’s questions, now is a good time to find out. The pause bought everyone breathing room. Using it well is the difference between a calm year and a scramble when the new rules land.

Call (309) 689-3900 or schedule a conversation with Facet Technologies. We will walk through your contracts, your data flows, and what a realistic path to a defensible self-assessment looks like for your shop.

Brian is the President of Facet Technologies, Inc. Since 1989, he has helped business owners make smart, profit-driven technology moves. He has grown Facet to support hundreds of companies through managed services, IT support, cybersecurity, and compliance. His career experience in the agriculture and manufacturing industries gives him a unique understanding of their technology needs. He writes about IT and cybersecurity from a growth-focused business owner's standpoint.

Share this post