Blog / US compliance
US compliance
CMMC in the Phase 2 Pause: What a Dallas Machine Shop Still Owes This Quarter
The CMMC Phase 2 pause suspended the C3PAO mandate on 13 July 2026. What a Dallas machine shop still owes on SPRS, DFARS 7012 and Phase 1 this quarter.
The email that arrived on a Thursday
The contracts administrator at a 60-person precision machine shop off Stemmons Freeway has spent the morning on a delivery schedule. At 11:40 an email arrives from the supply chain manager at a prime she has worked with for nine years. Subject: supplier assurance refresh. Body: please confirm your current SPRS score and the date of your last self-assessment, by the fifteenth.
She looks it up. There is a score. It is negative, it was posted in 2023 by an IT consultant who no longer returns calls, and nothing about the shop resembles what that score describes. The shop has since added two CNC cells, a cloud quoting portal and a shared drive full of customer drawings that anyone in the building can open.
She asks the owner. The owner says he read that the government paused CMMC in July, and that the whole thing is on hold.
He read correctly, and he drew the wrong conclusion. The pause moved one deadline. The clause in his contract did not move, the score he posted did not move, and the prime asking the question is not waiting for a rule change to decide who gets the next award.
Four working days later she is rebuilding a system security plan from a spreadsheet, and the drawings are still on a share with no access control.
CMMC, SPRS and 7012, in plain words
CMMC is the Cybersecurity Maturity Model Certification: the Defense Department's programme for confirming that contractors protect the sensitive information they receive. Phase 2, the stage that would have required a third-party assessment for many contracts, was suspended on 13 July 2026.
Here is what did not stop.
Phase 1 self-assessments continue. You assess your own compliance with NIST SP 800-171 Rev 2, which remains the contractual baseline for protecting controlled unclassified information.
SPRS posting continues. SPRS is the Supplier Performance Risk System, the government database where your self-assessment score lives. The scale runs from -203 to 110, and both your prime and the contracting officer can see the number and its date.
DFARS 252.204-7012 remains in force. It is the contract clause that requires you to safeguard covered defense information and report a cyber incident within 72 hours.
CUI is controlled unclassified information: the drawings, specifications, test data and part numbers that are not classified but are not public either. In a machine shop it is usually a PDF in an email and a folder on a shared drive.
The numbers that matter
Ransomware appeared in 61 percent of breaches in manufacturing and vulnerability exploitation in 38 percent, according to the Verizon 2026 Data Breach Investigations Report. Manufacturing is not a quiet corner of the threat picture. It is one of the loudest, and a shop that runs older machine controllers on the same flat network as the office is the reason those two numbers sit where they do.
Median time to remediate a known exploited vulnerability was 43 days in the same Verizon 2026 report. Compare that with the 72 hours DFARS 252.204-7012 gives you to report an incident. The clock you are held to is short; the clock you actually run on is long.
Ransomware was present in 88 percent of breaches at small and medium businesses in the Verizon 2026 report, against 48 percent of breaches overall. A 60-person shop is not too small to be interesting. It is exactly the size that pays.
What to do this week
- Find the CUI. Walk the shop and the systems with a printed list: email, the quoting portal, the shared drive, the ERP, the laptop in the programming office, the USB drive taped inside a machine enclosure. Mark every place a customer drawing or specification lands. (CIS 3 Data Protection)
- Put access control on those places today. Named accounts, multi-factor authentication, and permissions by role so a temp on the shop floor cannot open a folder of aerospace drawings. (CIS 3 Data Protection)
- Redo the self-assessment against NIST SP 800-171 Rev 2 as the shop is today, not as it was in 2023, and repost the SPRS score with the current date. A negative score with a dated plan of action beats a stale score every time a prime looks. (CIS 8 Audit Log Management)
- Scan and patch, and separate the machine network from the office network. If a controller cannot be patched, it should not be reachable from a desk where somebody opens email. (CIS 7 Continuous Vulnerability Management)
- Turn on logging where CUI lives and keep it long enough to answer questions. The 72-hour reporting clock in DFARS 252.204-7012 assumes you can say what happened, and logs are the only way you will. (CIS 8 Audit Log Management)
- Write the incident card: who declares an incident, who reports to the DoD portal, who calls the prime, and the phone numbers, on one laminated page in the front office. Read the CMMC certification path so the card matches the process you will eventually be assessed against. (CIS 17 Incident Response Management)
Where AccuSights fits
Our assessment produces the SPRS score with the evidence behind it, the system security plan and the plan of action, written in the language of a shop floor rather than a policy library. Our team implements the controls that come out of it at a reasonable rate, from data loss prevention to vulnerability scanning to protecting the assets that hold your drawings. We work with defense suppliers across Dallas and North Texas. Start with the three-minute Cyber Hygiene Test, or book 15 minutes with an engineer.
Questions people ask
Does the Phase 2 pause mean CMMC is cancelled? No. Phase 2 was suspended on 13 July 2026, which stops the third-party assessment mandate from taking effect on the schedule it was on. Phase 1 self-assessments continue, SPRS posting continues, and DFARS 252.204-7012 with its 72-hour reporting clock was never part of the pause. A pause is not a pardon.
What is a good SPRS score for a small shop? The scale runs from -203 to 110, and 110 means every NIST SP 800-171 Rev 2 requirement is fully implemented. Most small manufacturers start negative because the scoring subtracts heavily for multi-factor authentication, encryption of CUI at rest and audit logging. A negative score is not a disqualification by itself, but a stale score with no plan behind it is what makes a prime nervous.
Our prime says they handle the CUI, so does 800-171 apply to us? If controlled unclassified information reaches your systems in any form, including a drawing in an email attachment or a specification in a quoting portal, the requirements flow down to you through the contract. The prime's controls protect the prime. Ask your contracts lead to identify every clause in your active awards that mentions 7012 or 800-171, and then find where that data actually sits in your shop.
The pause bought you time, and time is only worth something to the people who spend it. Spend this quarter finding the drawings.
Controls this post maps to
CIS Controls v8.1. These are the same controls our assessment scores and the console watches.
Sources
Dr. Kashmala Khalid, Co-Founder, healthcare and defense programs. The clinical and regulatory authority behind the HIPAA and CMMC programs. Compliance with the precision of a surgeon and none of the fear-mongering. About the team →
Keep reading
Three more from the same shelf.
CMMC in 2026: The Pause Is Not a Pardon
CMMC 2026 status: Phase 2 certification is suspended, but Phase 1 self-assessments, SPRS scores and DFARS 7012 are still in force. What to do now.
US complianceCMMC Watch: What the Return of Phase 2 Would Change, and Why None of the Readiness Work Is Wasted
CMMC Phase 2 return readiness: what changes when third-party assessment comes back, what conditional status at 88 means, and the work that counts either way.
US complianceNIST 800-171 Self-Assessment: Why an Honest 60 Beats a Fake 110
How a NIST 800-171 self assessment and SPRS score really work, why a false 110 is now a signed federal statement, and how to post a score you can defend.
