conflicting road signs

CMMC Readiness Is Becoming a Supplier Qualification Issue—Not Just a Compliance Deadline

by Marc Gonzalez | 2026-08-28

The federal CMMC schedule just became less certain.

On July 13, 2026, the Department of War suspended CMMC Phase II requirements, which had been scheduled to take effect November 10. CMMC implementation remains in Phase I while the Department reviews the requirements. Phase I requirements remain in effect, as do existing contractual obligations to protect covered defense information under DFARS 252.204-7012.

For defense contractors, that creates an understandable question:

Do we have more time?

The suspension itself does not answer that question.

The Department has not announced what will follow its review or when Phase II will resume.

And for many manufacturers, the more immediate question may not be what date the government eventually puts on the calendar.

It may be:

What will our customers expect to see from us before they issue the next purchase order, renew the next contract, or qualify us for future work?

That timeline can be very different from the federal implementation schedule.

CMMC requirements and supplier-risk decisions are related—but they are not the same thing

CMMC is already connected to federal procurement.

When a solicitation requires a specific CMMC level, the contracting officer must verify the appropriate current CMMC status before award.

But something else is happening alongside those formal requirements.

Prime contractors are also using cybersecurity information to understand the risk associated with their suppliers.

Lockheed Martin provides a useful example.

In 2026, Lockheed reinstated its Cybersecurity Compliance and Risk Assessment, or CCRA, as its primary cybersecurity form for suppliers in Exostar. The process captures both regulatory compliance information and cyber-risk information. Lockheed also requires active suppliers to provide their CMMC status through that supplier-management process.

Lockheed goes further than simply collecting the information. Its supplier cybersecurity guidance states that assessing supplier cybersecurity risk is part of its acquisition process and an integral part of the buying decision.

And this is not exclusively a Lockheed initiative.

The CCRA was developed through the Defense Industrial Base Sector Coordinating Council as a common approach that participating organizations can use to obtain cybersecurity compliance and risk information while reducing the burden of multiple proprietary questionnaires. Organizations involved in its adoption have included major defense companies such as Boeing, BAE Systems, Northrop Grumman, RTX, L3Harris and others, although each organization determines how it implements the process.

That distinction matters.

A manufacturer may be thinking:

“When will CMMC certification be required on my contract?”

A customer may simultaneously be asking:

“How much cybersecurity risk does this supplier introduce into our supply chain?”

Those are related questions.

They are not identical.

The business risk is uncertainty

Consider two manufacturers competing for similar work.

Both have strong production capabilities.

Both understand that cybersecurity requirements apply to their business.

But when a customer asks about cybersecurity readiness, their answers look very different.

One supplier can clearly explain:

  • Which cybersecurity requirements apply to its environment
  • Whether it handles FCI or CUI
  • Its current assessment and CMMC status
  • What its SPRS information represents
  • Which material gaps remain
  • What remediation is underway
  • Who inside the organization is accountable for cybersecurity compliance
  • When the next meaningful milestones will occur

The other says:

“Our IT company is handling CMMC.”

That answer does not necessarily mean the supplier is failing its requirements.

But it leaves the customer with considerably more uncertainty.

And when procurement, supply-chain, cybersecurity and program leaders are evaluating suppliers, uncertainty creates work.

It can create additional questions.

Additional reviews.

Escalations.

Delays.

Or concern about whether the supplier will be ready when the requirement becomes material to a contract.

Lockheed's own supplier guidance provides a concrete example. The company has warned that suppliers without sufficient cybersecurity readiness can create risk for programs anticipating CMMC requirements and can lead to mitigation actions intended to reduce dependency on underprepared suppliers.

That is why the first commercial consequence of CMMC may arrive before a future Phase II date does.

Your practical deadline may not be a date on the CMMC calendar

Defense contractors naturally follow the federal implementation schedule.

They should.

But that should not be the only timeline leadership monitors.

Your next meaningful cybersecurity milestone could be:

  • A supplier recertification
  • A customer cybersecurity questionnaire
  • An Exostar or other supplier-portal update
  • A new bid
  • A contract renewal
  • Qualification for a new piece of work
  • A request for an updated SPRS or CMMC status
  • A customer's internal supply-chain risk review

None of those events needs to be officially labeled a “CMMC deadline” to influence revenue.

The practical deadline is the point at which your cybersecurity posture becomes relevant to someone's decision about whether, how or when to do business with you.

A cybersecurity questionnaire is more than administrative paperwork

That changes how manufacturers should think about the requests arriving from primes and other major customers.

A request for your CMMC status, SPRS information, assessment date, remediation status or broader cybersecurity posture can look like another administrative obligation.

It is also market intelligence.

Your customer is showing you which cybersecurity questions matter to its supply-chain risk process.

Pay attention to the patterns.

Which questions keep appearing?

Which answers are difficult to produce?

Which information is outdated?

Which responses require several people to reconstruct what happened six months ago?

Where does the answer from sales differ from the answer from IT or leadership?

Those situations do not necessarily mean you need more compliance documentation.

They may mean the information you already maintain is not being managed well enough to support the business.

Credibility starts with an accurate answer

A supplier does not become more credible by pretending everything is complete.

It becomes more credible by accurately explaining its current position.

Where are we now?

Which requirements apply, and what is our current assessment or CMMC status?

What remains?

Which gaps have actually been identified?

What are we doing about them?

What remediation, validation or assessment activities are underway?

What happens next?

Which milestones have real owners and dates?

Who is accountable?

Someone inside the organization should be able to answer those questions without sending the company on a week-long search for information.

That is substantially more useful than saying:

“CMMC is in progress.”

Do not build another CMMC binder

This is where manufacturers should resist creating unnecessary administrative work.

For organizations subject to NIST SP 800-171 and CMMC Level 2 requirements, much of the information needed to understand their current security posture should already exist within established compliance artifacts.

The System Security Plan describes the system boundary and how applicable security requirements are implemented.

The Plan of Action and Milestones identifies deficiencies and planned remediation where POA&Ms are permitted.

Assessment results and applicable CMMC information are maintained through systems such as SPRS.

CMMC itself places specific limits on the use of POA&Ms for conditional status.

The objective should not be to duplicate those materials in a new “customer-ready” document.

Instead, make the evidence you already maintain usable.

Know which source contains the authoritative answer.

Keep it current.

Assign responsibility for responding to external requests.

Maintain a history of what customers have asked.

And establish a review process for determining what information is appropriate to provide externally.

Your SSP, POA&M and related cybersecurity evidence exist to manage and demonstrate your security posture—not to become another sales document recreated every time a questionnaire appears.

The goal is less duplication and greater clarity.

Use the Phase II suspension to ask a better question

The suspension of Phase II gives defense contractors a reason to review their assumptions.

But the question should not simply be:

“Can we slow down?”

A better question is:

“What will our customers need from us during the next 6 to 12 months, regardless of when Phase II resumes?”

Review the cybersecurity requests you have already received.

Look at upcoming bids and renewals.

Confirm what your contracts actually require.

Verify that your SPRS and CMMC information reflects your current position.

Make sure your SSP and remediation information are current.

Talk with important customers about what they expect from suppliers.

And identify where cybersecurity readiness could intersect with revenue before the government publishes another implementation milestone.

That produces a much more useful operating plan than waiting for another date.

The easiest supplier to qualify creates the least uncertainty

CMMC will continue to evolve.

The Department of War's current review could change future implementation requirements or timing.

Prime contractors and other defense companies will continue evolving their own supply-chain cybersecurity processes as well.

But the underlying business requirement is unlikely to disappear.

Organizations responsible for defense programs have to understand the cybersecurity risk within their supply chains.

Manufacturers that can accurately explain their security posture, provide the appropriate evidence, acknowledge known gaps and demonstrate disciplined remediation make that risk easier to evaluate.

That is the larger opportunity.

Not creating more CMMC paperwork.

Not racing toward a date that may change.

Building a cybersecurity posture that your customers can understand, evaluate and confidently depend on when the next opportunity arrives.

Not Sure Where Your CMMC Readiness Stands?

• Clarify your CUI boundary

• Identify priority risks and evidence gaps

• Get a practical next-step roadmap

Recent Posts in CMMC Readiness