
The DoD Paused CMMC. Your Prime Didn’t.
Compliance Pulse · Monday, August 3, 2026
The DoD Paused CMMC. Your Prime Didn’t.
On July 13, DoD suspended Phases 2–4 of the CMMC rollout while the Reform Task Force reviews the program. I have watched more than a few subcontractors read that as breathing room.
Their primes read it differently — and the primes sign the purchase orders.
Why the pause doesn’t reach you. DFARS 252.204-7021 took effect November 10, 2025. Under the rule, prime contractors may not award purchase orders to noncompliant subcontractors, and neither contracting officers nor primes may waive CMMC requirements. Flow-down is contractual, not phased. A prime that waits for your certification is a prime carrying program risk — so they aren’t waiting.
Lockheed Martin — verified from their own supplier communications. Since November 10, 2025, LM requires every supplier handling CUI to post a CMMC Level 2 self-assessment in SPRS, and directs suppliers to pursue Level 2 C3PAO certification now because some GFY 2026 contracts may include a C3PAO requirement. Compliance is tracked through the CCRA questionnaire in Exostar; a green rating means attesting all 31 identified NIST 800-171 requirements. LM’s language for suppliers who fall short: programs “may evoke program mitigation actions to reduce or eliminate dependencies.” Translation — you get designed out.
Northrop Grumman — verified from their supplier notice. NG formally notified its supply base of the CMMC final rule and the November 10, 2025 effective date, quoting the rule’s teeth back to suppliers: no purchase orders for noncompliant subcontractors, no waivers. NG collects SPRS scores and cybersecurity questionnaires at onboarding and renewal. They are less publicly prescriptive than Lockheed — the required level follows the data on the contract, Level 2 wherever CUI flows — but the enforcement mechanism is identical.
And NG just showed you why this is accelerating. Today, Northrop Grumman announced multi-year framework agreements totaling more than $3 billion — with the government and with Lockheed Martin — to surge PAC-3 MSE and THAAD interceptor production: PAC-3 MSE solid rocket motor output climbing from roughly 600 units a year toward thousands, THAAD component production quadrupling over seven years, capacity doubling in Utah and nearly tripling in West Virginia by 2027. Read the org chart on that deal: on PAC-3 and THAAD, Northrop Grumman is the subcontractor — to Lockheed Martin. The same flow-down LM enforces on its supply base lands on NG, and NG passes it to every machine shop, energetics supplier, and electronics house it onboards for the surge. A production ramp of this size pulls new suppliers into missile programs that are saturated with CUI. Every one of them inherits Level 2 obligations on day one — pause or no pause.
They are not outliers. Reporting across the DIB shows the same posture at nearly every major prime, all of it running regardless of DoD’s phase suspension. L3Harris Missile Solutions set a July 30, 2026 certification deadline — suppliers without Level 2 “precluded from the program.” That date passed last week. Elbit Systems of America has required Level 2 (C3PAO) certification for purchase orders since January. HII flowed Level 2 C3PAO requirements to its supply chain in late 2025 and is expected to push Level 3 requirements to select suppliers next. RTX requires CMMC status disclosure at annual supplier registration and an active certification before purchase orders on contracts carrying DFARS 252.204-7021. Boeing’s Cybersecurity Supplement (SP5) sets binding minimum security requirements for every supplier touching FCI or CUI, verified through Exostar. General Dynamics has embedded CMMC requirements directly into contracts — and suppliers have already lost work for failing to prove compliance.
Now the math. Roughly a hundred authorized C3PAOs serve tens of thousands of companies that will need Level 2 — and munitions-surge onboarding is about to add more to the line. The queue is the deadline. A sub that starts its assessment cycle when its prime asks for the certificate has already missed.
What this means. Your CMMC deadline is not November 10, 2026, and it is not paused. It is whatever date sits in your prime’s supplier portal. If CUI touches your systems: a current Level 2 self-assessment in SPRS is table stakes today, and a C3PAO slot on the calendar is a supply-chain survival decision — not a compliance line item.
Security brings compliance. Compliance does not bring security.