5 min read

The 3 Most Common CMMC Mistakes (#3 Is a Huge Liability)

The 3 Most Common CMMC Mistakes (#3 Is a Huge Liability) 

What we've learned from dozens of conversations with manufacturers trying to get this right 

CMMC has been looming over the defense supply chain for more than a decade. Many manufacturers have started the journey and exactly zero have found it easy. Beyond an implementation that is genuinely complex and genuinely expensive, the rules keep moving underneath the people trying to follow them. 

They moved again on July 13, 2026, when the Department of War suspended Phase 2 of the CMMC rollout. The third-party (C3PAO) certification requirement that was scheduled to take effect on November 10, 2026 is on hold while a reform task force reviews the program, and contracting officers have been directed to pull the C3PAO requirement out of active solicitations (Latham & Watkins). 

Here is the part that keeps getting misread: the pause suspended the audit, not the obligation. If you handle CUI, you still owe all 110 NIST SP 800-171 Rev. 2 controls, a current score in SPRS, an annual affirmation of continuous compliance signed by a senior company official, and everything DFARS 252.204-7012 has required since 2017. Level 1 and Level 2 self-assessment requirements remain fully in effect. 

Your primes may not have paused at all. L3Harris Missile Solutions held suppliers to a July 30, 2026 deadline for proof of Level 2 certification — a date set in April and never withdrawn after the announcement (Secureframe). Prime deadlines are business decisions, made independently of the government's rollout. 

So the fundamental questions have not gone away. The pause just bought you time to answer them properly. Before you spend another dollar, here are the three mistakes we see most often. 

Mistake 1: You haven't sized the opportunity you're protecting 

Based on dozens of client calls, the most common gap isn't technical. It's that the manufacturer never ran a real risk-and-opportunity analysis before committing to the project. 

Start with a baseline: what share of your current revenue is actually subject to CUI handling requirements? Not defense revenue — CUI revenue. Those are different numbers, and for a lot of shops the second is far smaller than the first. Pull the contracts, look for the DFARS 7012 and 7021 clauses, and check what your primes have flowed down in writing so far. If the language isn’t showing up, make a call to them and ask about their timeline to ensure you aren’t surprised. 

Then size the upside. Talk to prospective customers who buy from manufacturers like you and find out what they will and won't award to a supplier without a Level 2 posture. That conversation gives you the addressable market — the work you could win, not just the work you could lose. Remember, in many supply chains, smaller providers will not reach (or even attempt to reach) Level 2 compliance, so you may want to target new niches as well. 

Now put a number on the other side of the ledger. DoD's own regulatory analysis pegged a small entity's Level 2 certification assessment at roughly $105,000 over three years (DefenseScoop) — and that covers the assessment and affirmations, not the implementation work required to pass one. The remediation, tooling, and documentation come on top of it. 

Then do the arithmetic your CFO would do. Call it $35,000 a year for the assessment side alone. At a 30% gross margin, that's roughly $117,000 of annual revenue consumed just to carry the compliance line. If the CUI work on your books runs $200,000 a year and no prime has told you more is coming, you are spending well over half that work's gross margin to keep it. That is a strategic decision, not an IT project — and the right answer might be to exit the CUI work, or to subcontract the CUI portion to a shop that is already certified. 

We would much rather you reach that conclusion deliberately, up front, than discover it $60,000 into an implementation. 

Mistake 2: You haven't scoped who actually touches CUI

The single biggest lever on cost is the number of people and systems that touch CUI. Every additional user, workstation, server, and application inside your assessment boundary means more controls to implement, more evidence to maintain, and more hours to pay for. 

Most manufacturers are surprised by how far it has already spread. A customer print arrives as an email attachment. It gets saved to a shared drive so estimating can quote it. It gets attached to the job in the ERP so planning can route it. It prints at a workstation on the floor. It gets photographed for a first-article report. It gets emailed to an outside plater. Six systems and a dozen people, from one attachment. 

Map that before you buy anything. Walk one CUI job end to end and write down every place the data lands: 

  • Where it enters — customer portals, email, EDI, paper drawings
  • Where it lives — file shares, the ERP, the quality system, engineering workstations
  • Who opens it — estimating, engineering, program management, planning, quality, shipping
  • Where it leaves — outside processors, calibration labs, your own subcontractors

Then ask the question that saves the most money: how few people can actually do this work? If you can get CUI down to a handful of named users operating inside a tightly contained enclave, the cost profile changes completely. You are securing one controlled environment instead of your entire company. 

That is why we have pushed enclave solutions for most of the manufacturers we work with. It keeps the assessment boundary small and leaves the rest of the business — the ERP everyone lives in all day, the shop floor terminals, the office network — outside of scope. 

The ERP question deserves its own line. If CUI is sitting in job attachments inside your ERP, your ERP is in scope, and so is every user who can reach it. For most shops that is the difference between a contained project and a company-wide one. Getting customer drawings out of the ERP and into a controlled repository is frequently the highest-return move on the entire list. 

And if you are already down the NIST path, it is not too late. We regularly find that consolidating workflows after the fact takes real scope, and real cost, back out of a project already underway. 

Mistake 3: Self-assessing with no independent check (the scariest one!) 

With Phase 2 suspended, most manufacturers will attest to Level 2 on the strength of their own self-assessment. That feels like relief. It is actually a transfer of risk — off a C3PAO auditor and onto your own signature. 

What fills the gap when third-party audits go away is government-led assessments and whistleblowers. The Justice Department has been enforcing exactly this through the False Claims Act since 2021, and the pace is picking up. A senior DOJ official said in January 2026 that compliance enforcement is on a "significant upward trajectory," citing $52 million recovered across nine cyber False Claims Act settlements in the prior year (Akin). 

The cases are worth studying, because none of them are about a breach. They are about what the company said: 

  • MORSECORP reported a score of 104 to SPRS in January 2021. An independent consultant later put the real score at −142. The company paid $4.6 million in March 2025, and the whistleblower — a former employee — collected $851,000 (DOJ).
  • LOGZONE, a Huntsville defense contractor, paid $507,144 in June 2026 after the Defense Contract Management Agency scored its NIST 800-171 implementation at −170, on a scale that bottoms out at −203 (Mayer Brown).

Note the second one in particular. Small company, modest contracts, and a settlement that would be existential for a lot of the shops we talk to. False Claims Act damages are trebled before penalties are added on top. 

Note also who signs. The annual affirmation of continuous compliance is executed by a senior company official. That signature is the artifact a case gets built around and is a legitimate reason to lose sleep at night. 

So our recommendation has not changed, and the pause makes it more important rather than less: bring in an independent third party to validate your posture before you claim Level 2. Not as a formality — as a check on the people who did the work. 

That includes us, and it includes whoever else you hire. An MSSP that implements your controls and then assesses its own implementation is grading its own homework. Don't let the fox guard the henhouse. We have already seen a number of these relationships fail to actually secure the client, and when that unravels the liability does not land on the MSSP. It lands on the officer who signed the affirmation. 

The bottom line 

The pause is a gift, but only if you use it. You have been handed time to answer the questions that should have come first: how much of your business genuinely depends on CUI work, how small you can make the footprint of that work, and whether what you have already claimed in SPRS is actually true. 

Upward Technology works exclusively with manufacturers, we have a Certified CMMC Professional on staff, and we have enclave deployments running today. If you want a straight answer on whether this program is worth it for your shop — including the possibility that it is not — we are happy to have that conversation. 

Contact us to talk through your scope, your costs, and where you actually stand. 

 

www.upward-technology.com

 

 
 
 

Related Posts