The Pentagon paused CMMC certification. Your prime contractor paused nothing.
Third-party assessments are on hold while the DoD redesigns the program — but DFARS 252.204-7012, NIST SP 800-171, and every flow-down clause in your subcontracts remain fully enforceable. I help aerospace and defense manufacturers across Querétaro, Baja California, Chihuahua, Nuevo León, and Sonora build a compliance posture that holds up today — and under whatever the reformed program becomes.
Every subcontractor in the chain carries the requirement. A prime’s DFARS obligations flow down to every supplier touching Controlled Unclassified Information — including manufacturers based outside the United States. The July 2026 suspension changed how compliance is verified, not who has to comply.
CMMC Phase 2 was suspended on July 13, 2026 — here’s what that actually means.
The DoD froze mandatory C3PAO certification while a Reform Task Force redesigns the program. What stayed fully in force: Level 1 and Level 2 self-assessments, SPRS scores, and every DFARS 252.204-7012 safeguarding clause in your contracts. A reformed program is expected in fall 2026 — and every credible scenario keeps NIST SP 800-171 at its core.
The exposure
A purchase order can’t outrun a compliance clause.
Mexican aerospace manufacturers have spent years earning their place in the DoD supply chain on quality and cost. The certification calendar just changed — the qualifying question didn’t. It’s still “can you protect the data that comes with the part,” and your primes are still asking it.
Flow-down clauses didn’t get suspended
Your obligations to a prime come from your subcontract, not from Pentagon policy memos. DFARS 7012 and NIST SP 800-171 flow-downs remain enforceable, and primes are still vetting suppliers before awarding work.
NIST SP 800-171 wasn’t built with a shop floor in mind
110 controls written for IT environments have to be translated into a manufacturing plant’s network, machines, and file-sharing practices.
Your signature is now the audit
With third-party assessments paused, your self-assessment and SPRS score are the only proof a prime can check. An inflated score is a liability sitting in a federal database. A defensible one is how you stay in the bidding pool.
Who this is built for
Manufacturers already inside the U.S. defense supply chain — not new entrants to it.
This engagement is designed for Tier 2 and Tier 3 suppliers to U.S. DoD prime contractors, concentrated in Mexico’s aerospace manufacturing corridor.
What readiness looks like
A structured path from current-state to defensible.
Every engagement is scoped against your actual CUI footprint — not a generic checklist. The work you do now counts under today’s self-assessment regime and under whatever the reformed program requires next.
NIST SP 800-171 gap assessment
A control-by-control evaluation against the 110 NIST SP 800-171 practices, scoped to where Controlled Unclassified Information actually moves through your operation.
System Security Plan and POA&M
The core documentation behind a defensible self-assessment — and the first thing any future assessor will ask for — built to reflect how your plant, network, and vendors actually operate.
Policy development and evidence collection
Written policies mapped to each control, plus a practical system for capturing the evidence a prime’s supplier review — or a future assessment — will ask for.
Defensible SPRS score and remediation roadmap
An accurate score your leadership can stand behind, and a sequenced plan for closing gaps — ordered by what puts your current contracts at risk first, not by control number.
How this engagement fits the program as it stands today
I work with your organization as a CMMC readiness and advisory consultant. That work is backed by CISSP certification and eight-plus years leading enterprise information security programs — including banking-grade and telecom audit readiness under ISO 27001. My role is to close your gaps against NIST SP 800-171, build your SSP and POA&M, and give your leadership a self-assessment and SPRS score they can defend — to a prime today, and to an assessor whenever formal certification returns.
Since July 13, 2026, the DoD has suspended mandatory C3PAO assessments while a Reform Task Force redesigns the program. That shift makes advisory readiness — not certification scheduling — the work that matters right now. And it changes nothing about the preparation itself: every reform direction the DoD has signaled keeps NIST SP 800-171 as the foundation, which means the systems, documentation, and evidence we build together stay valid no matter what the program is called when it returns.
Find out where your gaps are before a prime does.
A 30-minute call is enough to map your CUI exposure against NIST SP 800-171, walk you through exactly what the July suspension does and doesn’t change for your contracts, and tell you honestly how much runway you have before the reformed program lands.