Edit Template

CMMC: The Gatekeeper for Government Contractors

CMMC Changes are here. Be ready by November.

You have been hearing about CMMC for years. The webinars, the vendor emails, the “start preparing now” warnings that were easy to file under later. Later is gone. CMMC is written into federal regulation, it is showing up in defense solicitations today, and the next hard deadline lands this November.

Here is where things stand. The 32 CFR Part 170 program rule took effect on December 16, 2024, locking the framework into law. The 48 CFR acquisition rule followed on November 10, 2025, inserting the DFARS 252.204-7021 clause into contracts and turning CMMC from guidance into a condition of award. Phase 1 is live now, with self-assessment requirements already appearing in solicitations. None of this is coming. It arrived.

The consequence is blunt. No certification, no award. A contracting officer cannot award a contract, exercise an option year, or extend performance to a company that lacks the required CMMC status when the solicitation closes. There is no probationary window and no grace period. The requirement flows downhill too, which is why primes are already demanding proof of certification before they issue a purchase order. For a tier-two or tier-three aerospace shop, the pressure arrives through your customer long before it arrives through a government contract of your own.

Which brings us to this November. On November 10, 2026, Phase 2 begins, and third-party Level 2 certification becomes the requirement for most contracts that touch controlled unclassified information. CMMC has three levels: Level 1 self-assessments for companies that handle only federal contract information, Level 2 for CUI, and a government-led Level 3 for the most sensitive work. Level 2 is where the aerospace and defense base lives. Technical drawings, specifications, and engineering data are textbook CUI, which puts most of the manufacturing base squarely in Level 2 territory.

That is the deadline to plan around, and it is closer than it looks. A Level 2 certification is not a form you file the week before a bid. It is an independent audit you have to earn, and earning it takes months. If you have been treating CMMC as a someday problem, this is your reminder that someday now has a date.

The timeline is shorter than the deadline suggests

The Defense Department is rolling this out in four phases across roughly three years. Phase 1 began on November 10, 2025, with self-assessments showing up in select solicitations. Phase 2, starting November 10, 2026, requires third-party Level 2 certification for most contracts that involve CUI. Phases 3 and 4 expand the requirement through 2028.

Reading “2028” as your deadline is the mistake that will cost contracts. The certification itself is the bottleneck. More than 300,000 companies in the defense industrial base are expected to need some form of CMMC status, and fewer than 80 accredited assessment organizations exist to certify them. C3PAO calendars are already booking months out. A contractor that waits for the clause to land in a contract before starting will be competing for assessor time against thousands of companies who did the same math too late.

A Level 2 effort runs six to twelve months from a standing start. Counting backward from Phase 2, the runway for many manufacturers is already measured in weeks, not years.

Timeline for new CMMC rules rollout

What the certification is really measuring

CMMC Level 2 maps one-to-one to the 110 security requirements in NIST Special Publication 800-171, organized into fourteen control families. The certification verifies that you actually implemented those controls across every system that touches CUI, and that you can produce evidence to prove it.

That last phrase deserves a second read: every system that touches CUI. Manufacturers tend to scope their CMMC environment around the obvious suspects, the engineering network and the ERP that holds program data. The boundary is wider than that. It includes the systems your CUI flows into, connects to, and depends on. Some of those systems are ones you would never think to put on a security diagram.

Timekeeping is one of them. Labor data sits at the intersection of your contracts, your billing, and your workforce, and it often connects directly to the ERP that holds your most sensitive program information. Whether your timekeeping platform belongs inside your CMMC boundary is a question worth answering deliberately, because guessing wrong cuts both ways. Leave a system out that should be in, and you have an assessment finding. Pull a system in that didn’t need to be there, and you have inflated the scope, cost, and timeline of your certification.

That scoping question is where this series goes next.

The stakes for getting it wrong

The downside of a misstep is no longer just a failed audit. Certification status is self-affirmed annually in the Supplier Performance Risk System, and the Department of Justice has been using its Civil Cyber-Fraud Initiative to pursue contractors that misrepresent their compliance under the False Claims Act. An inaccurate score is no longer a paperwork problem. It is legal exposure.

For aerospace and defense manufacturers, the strategic read is simple. CMMC is now the qualifier that decides who gets to compete. The companies that treat it as an engineering problem to solve early will keep their pipeline. The ones that treat it as a compliance chore to defer will watch contracts they have held for years go to competitors who got certified first.

AutoTime Solutions builds DCAA-compliant timekeeping for government contractors, and we spend our days inside the operational reality this regulation creates.

In the next post, we look at the question most manufacturers get wrong: whether your timekeeping system is sitting inside your CMMC boundary, and what NIST 800-171 actually expects it to do.

Contact

Copyright 2026 AutoTime Solutions. All rights reserved.