Skip to main content
| 13 min read

CMMC 2.0 Compliance Memphis: Paused Clock, Same Rules

CMMC Phase 2 is suspended, but NIST 800-171, DFARS 7012, and your SPRS affirmation still bind. What CMMC 2.0 compliance Memphis defense suppliers owe now.

On July 13, 2026, the Department of War suspended CMMC Phase 2 — the November 10 milestone that would have made a third-party certification assessment a condition of DoD contract award. If you run a Memphis operation with DoD work in the mix, the certification clock stopped. Almost nothing else did.

That distinction is the whole story for CMMC 2.0 compliance Memphis defense suppliers face this quarter. The suspension paused a verification mechanism. It did not touch the security requirements underneath it, the contract clauses that carry them, or the affirmation you sign in the Supplier Performance Risk System. The Justice Department settled a $2 million cybersecurity False Claims Act case seven weeks into the pause, which is the clearest evidence available that enforcement did not go on holiday with the deadline.

Memphis’s defense exposure is also not what most people picture. There is no aerospace prime here. We have Naval Support Activity Mid-South in Millington — the Navy’s personnel and human-resources headquarters, roughly 7,500 sailors, civilians, and contractors, one of the largest single employers in Tennessee — plus the Army Corps of Engineers Memphis District and the freight and warehousing operations that follow a hub this size. The controlled data moving through those channels is personnel records, procurement information, and logistics detail. All three are CUI categories. That is why the firms we meet across Memphis, Germantown, Collierville, and DeSoto County are almost never prime contractors and almost always subcontractors who inherited a DFARS clause from someone upstream.

Pro Tip

If any part of your revenue touches a DoD prime or a subcontract with DFARS clauses in it, pull your current SPRS score before you do anything else. It takes ten minutes and it tells you whether you are 15 requirements away from defensible or 70 — which is the difference between a budget line and a board conversation.

What the Phase 2 Suspension Changed — and What It Didn’t

DoW Chief Information Officer Kirsten Davies and Under Secretary of Defense for Acquisition and Sustainment Michael Duffey signed the suspension on July 13, 2026. Davies told reporters the program had grown too burdensome for the industrial base to absorb, citing Small Business Administration figures putting future CMMC phases at more than $7 billion a year for small and mid-sized firms, and a capacity gap of more than 100,000 defense industrial base companies needing assessments from roughly 100 accredited assessment organizations. Her summary, as reported by DefenseScoop: “the math just simply doesn’t math.”

The memo suspended Phase 2 along with Phases 3 and 4, and it expressly prohibits program managers from designating CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments while the review runs. Contracting officers were directed to strip those requirements from existing contracts by modification before the next option period. A CMMC Reform Task Force took 60 days to review the program; its findings went to the CIO in mid-September 2026, and the public recommendations are expected in the weeks after.

Here is the part that matters more than the headline. A task force report is advice. Changing what binds you takes a class deviation, a DFARS rule change, or an amendment to 32 CFR Part 170 — and none of those has happened. Until one does, the obligations below are live.

Suspended vs. Still Binding
  • Suspended, and no longer a deadline: the Phase 2 transition originally set for November 2026, plus Phases 3 and 4; Level 2 C3PAO and Level 3 DIBCAC designations; no CMMC waivers granted during the review
  • Still binding — DFARS 252.204-7012: implement NIST SP 800-171 and report cyber incidents to DoD within 72 hours through DIBNet
  • Still binding — DFARS 252.204-7021: maintain a current CMMC status, post self-assessment results to SPRS, sign an annual affirmation, and flow the substance of the clause down to subcontractors
  • Still binding — Phase 1: Level 1 (Self) and Level 2 (Self) requirements continue to appear in new solicitations
  • Still binding — 32 CFR Part 170: the scoring model, POA&M rules, and 180-day closeout window are unchanged
  • Unaffected: False Claims Act exposure for an inaccurate score or affirmation

Do You Even Need CMMC? FCI, CUI, and the Flow-Down Trap

The trigger is data, not company size. A four-person shop and a 400-person operation face the same requirement if they handle the same information.

Federal Contract Information (FCI) is government contract information not intended for public release — a delivery schedule, a statement of work, a purchase order detail. FCI puts you at Level 1.

Controlled Unclassified Information (CUI) is the tier that matters. The National Archives CUI Registry defines the categories, and the ones that reach Memphis most often are Privacy (including personnel records), Procurement and Acquisition, Export Control, and Defense-grouped controlled technical information. If a prime sends you data in any of those categories, you are at Level 2, and the 110 requirements apply to every system that stores, processes, or transmits it.

Level 1: 15 Requirements and No POA&M, Ever

Level 1 maps to the 15 basic safeguarding requirements — limiting system access to authorized users, sanitizing media before disposal, running current antivirus. You self-assess annually and an affirming official signs the result in SPRS. Under 32 CFR 170.21, a POA&M is not permitted at any time for Level 1. There is no partial credit: you meet all 15 or you do not have a valid assessment.

Level 2: 110 Requirements and Two Ways to Verify Them

Level 2 requires all 110 security requirements in NIST SP 800-171, scored out of 110 points and reported in SPRS. It comes in two forms: a self-assessment every three years with an annual affirmation, or a certification assessment by an accredited third party on the same cycle.

The suspension paused the second form. It left the first one entirely intact — and the control set is identical either way. The same System Security Plan, the same evidence, the same defensible score. Only the verifier changes, and the affirmation you sign carries the same legal weight in both.

The Clause Numbers on Your Contract Changed in February

This one catches people, and it is unrelated to the suspension. Effective February 1, 2026, the Revolutionary FAR Overhaul class deviations renumbered the clauses most suppliers had memorized. DFARS 252.204-7019 and 252.204-7020 were replaced by DFARS 252.240-7997, and the standalone requirement to upload a “Basic” self-assessment score to SPRS under those clauses went away with them. FAR 52.204-21 became FAR 52.240-93, carrying the same 15 safeguarding requirements under a new number.

Two things to take from that. First, the CMMC obligation did not move: DFARS 252.204-7012 and 252.204-7021 are unchanged, and 7021 is what requires your CMMC status, your SPRS results, and your annual affirmation. Second, clauses already written into an existing award keep binding you as written until someone modifies them. Read the clauses in your actual contract rather than the ones you remember.

Flow-Down: How Memphis Firms End Up in Scope

Flow-down is where most local firms discover they are covered. DFARS 252.204-7021 requires a prime to insert the substance of the clause into subcontracts that involve FCI or CUI, and to confirm the subcontractor holds the appropriate CMMC status before award. That reaches well past the obvious defense names: a 12-person machine shop in Bartlett handling CUI-marked drawings is in scope, and so is the logistics provider warehousing controlled components in DeSoto County.

The contract does not ask whether you consider yourself a technology company. It asks whether the drawing you just received is protected — and it expects evidence, not intent.

The 110 Requirements — and Where Memphis Firms Actually Lose Points

NIST SP 800-171 organizes its 110 requirements into 14 families, from Access Control (22 requirements, the largest) down to Personnel Security (2). You start at 110 points and subtract 5, 3, or 1 for each requirement you do not meet, which is why a first honest self-assessment can land below zero. In our gap assessments, the same four areas account for most of the lost points.

Multifactor Authentication

MFA is required for local and network access to privileged accounts and for network access to every other account. Almost every shop we assess has it on Microsoft 365, and almost none have it on the VPN, the ERP, the file server, or the local administrator accounts on floor workstations. Partial coverage scores the same as no coverage.

The bar is also moving. Attackers have shifted from breaking in to logging in, and assessors and insurance underwriters both want phishing-resistant methods now. If you are already working through the MFA and documentation requirements your cyber insurance carrier demands, much of that work counts twice.

Access Control and Least Privilege

Access Control is the biggest family at 22 requirements, and it is where long-standing floor practice collides with federal expectations. Shared logins on production terminals, every user configured as a local administrator, CUI drawings on the same file share as the lunch schedule, no automatic session lock, no CUI marking on printed drawings — each is a finding.

The most effective fix is usually scope reduction rather than remediation. Moving CUI into a defined enclave with its own identity boundary, storage, and device set shrinks the assessable footprint, which shortens the assessment and lowers the cost of every requirement you still have to implement.

Incident Response

Incident Response is only 3 requirements, and it is missing at nearly every firm we assess. You need a written plan with named roles, a defined detection-through-recovery process, and evidence that you have tested it. Separately, DFARS 252.204-7012 obligates you to report a cyber incident to DoD within 72 hours through DIBNet, which requires a medium assurance certificate you obtain in advance rather than during the incident. Our 30-minute action plan for the moment after an employee clicks a phishing link is the kind of concrete, testable procedure an assessor wants attached to that plan.

Audit Logging and Accountability

Nine requirements cover creating logs, retaining them, protecting them from modification, reviewing them, and correlating events across systems. Default retention in Microsoft 365 and on most small-business firewalls falls short of what an assessor expects, and the request is specific: show me the authentication logs for this workstation from a date four months ago. If the answer is “they rolled off,” that is points gone.

Enforcement Did Not Pause

On September 1, 2026 — seven weeks into the suspension — the Justice Department announced that Honeywell Aerospace agreed to pay $2,042,518 to resolve False Claims Act allegations that it failed to comply with NIST SP 800-171 requirements on a DoD contract network between April 2020 and December 2023. The case began as a whistleblower suit brought by a former employee.

Read that timing carefully. The certification requirement was suspended. The liability for saying you met requirements you had not met was not. That is the asymmetry that should drive your decision this quarter: the pause removed a cost and a queue, and left every legal exposure exactly where it was.

The Affirmation Is a Legal Claim

An annual affirmation in SPRS is a representation to the government. A contractor can face False Claims Act liability for an inaccurate score even when no breach ever occurs — the misrepresentation is the violation. If your posted score reflects controls you intended to implement rather than controls you can evidence today, correct it before anyone asks.

What to Do With the Pause: Your Next 90 Days

The pause is a scheduling gift, not a reprieve. Every plausible outcome of the reform review — reinstatement on a later date, a scaled-down tiering model, or a permanent shift to self-attestation with government spot checks — rests on the same 110 requirements and the same evidence. The work does not change. Only the audience for it does.

Start with the requirements you could never defer anyway. Under 32 CFR 170.21, a Conditional Level 2 status requires a score of at least 88 of 110, and nothing worth more than 1 point may sit on a POA&M — with one narrow exception, CUI encryption, which may be deferred if you already encrypt but have not yet moved to FIPS-validated cryptography. Six requirements are named as never deferrable regardless of point value, and one of them is the System Security Plan itself.

POA&M Rules Under 32 CFR 170.21
  • Minimum for Conditional Level 2: score ÷ 110 must be 0.8 or higher, so 88 of 110 points
  • Point ceiling: no requirement worth more than 1 point may go on a POA&M
  • The one exception: SC.L2-3.13.11 CUI Encryption, if encryption is employed but not FIPS-validated
  • Never deferrable, by name: AC.L2-3.1.20 External Connections, AC.L2-3.1.22 Control Public Information, CA.L2-3.12.4 System Security Plan, PE.L2-3.10.3 Escort Visitors, PE.L2-3.10.4 Physical Access Logs, PE.L2-3.10.5 Manage Physical Access
  • Closeout window: 180 days from the Conditional CMMC Status Date, or the status expires
  • Level 1: no POA&M permitted at any time

Here is the sequence that fits a quarter. Run a gap assessment, which takes two to four weeks. Write a System Security Plan that describes the business you actually operate, not a template with your logo on it — it is one of the six requirements you can never defer, and it is the artifact a prime’s supplier questionnaire asks for first. Then close the requirements above the 1-point line, starting with MFA everywhere and CUI encryption, because those are the long-lead items once procurement and floor scheduling get involved.

Sequence It This Way

Score first, then write the System Security Plan, then close everything above the 1-point line. Firms that remediate in whatever order a consultant’s spreadsheet lists spend the same money and finish months later — and during a suspension, the SSP is the document that keeps you on a prime’s bid list, because it is the only thing they can ask for while C3PAO designations are prohibited.

Most of this is ordinary IT hygiene done deliberately and documented properly — identity, patching, logging, backup, segmentation. It is the same foundation behind our managed IT services for Memphis businesses, pointed at a federal control set. If your operation spans a plant floor and an office, our Memphis manufacturing IT support covers the OT/IT split that makes CUI scoping tricky; if you warehouse controlled components, Memphis logistics and warehouse IT is where scanner fleets and WMS fold into the same boundary.

Start Your CMMC Gap Assessment With a Memphis Partner

A gap assessment answers four questions: where does CUI actually live in your environment, what is your real score against all 110 requirements, which gaps can be deferred and which cannot, and what does remediation cost in dollars and calendar time.

CMMC 2.0 compliance Memphis suppliers can defend starts with an accurate score and a System Security Plan that matches how the business runs. Remediation after that is project work with a schedule, run alongside the day-to-day cybersecurity monitoring and response that keeps controls from drifting back out between assessments.

Key Takeaways
  • Phase 2 is suspended, not cancelled — third-party certification paused on July 13, 2026, and only a class deviation, DFARS rule change, or 32 CFR 170 amendment can change what binds you
  • DFARS 252.204-7012 and 252.204-7021 still apply — NIST 800-171 implementation, 72-hour incident reporting, SPRS results, and an annual affirmation all survived the pause
  • Level 1 covers FCI with 15 requirements and no POA&M ever; Level 2 covers CUI with all 110 NIST SP 800-171 requirements
  • Enforcement continued — DOJ settled a $2 million NIST 800-171 False Claims Act case seven weeks into the suspension
  • Use the pause to score honestly, write the SSP, and close everything above the 1-point line — that work is a prerequisite under every outcome of the reform review

If a DoD prime is asking what your CMMC posture looks like now that Phase 2 is paused, that is the conversation to have this month. We will scope your CUI boundary, score all 110 requirements, and give you a remediation plan with real dates and real numbers — schedule a free IT assessment or call us at (901) 306-7575 and we will tell you honestly where you stand.

Common Questions

Frequently Asked Questions

Is CMMC still required after the Phase 2 suspension?
Yes, in the form that applies today. On July 13, 2026, the Department of War suspended CMMC Phase 2, along with Phases 3 and 4, and barred program managers from designating Level 2 (C3PAO) or Level 3 (DIBCAC) assessments while the review runs. Phase 1 was not suspended: Level 1 and Level 2 self-assessments still appear in new solicitations, DFARS 252.204-7021 still requires a current CMMC status and an annual affirmation in SPRS, and DFARS 252.204-7012 still requires NIST SP 800-171 implementation and 72-hour incident reporting. The suspension paused who verifies your controls, not whether you need them.
What's the difference between CMMC Level 1 and Level 2?
Level 1 covers Federal Contract Information and requires 15 basic safeguarding practices, verified by an annual self-assessment and affirmation in SPRS. A POA&M is never permitted at Level 1 — you meet all 15 or you have no valid assessment. Level 2 covers Controlled Unclassified Information and requires all 110 security requirements in NIST SP 800-171, scored out of 110 points. Level 2 comes in two forms, self-assessment and third-party certification, and the certification form is what the suspension paused. The control set is identical in both; only the verifier changes.
What should a Memphis defense supplier do during the CMMC pause?
Score yourself honestly against all 110 requirements, write a System Security Plan that matches how the business actually runs, and close the requirements that could never go on a corrective action plan anyway. Those three things take most firms one to two quarters and are prerequisites under every plausible outcome of the reform review. Skip the C3PAO queue for now — program managers are prohibited from designating one — but keep your SPRS score and annual affirmation current, because those obligations never paused and they carry False Claims Act exposure.
Does defense contractor cybersecurity in Tennessee follow different rules?
No. CMMC is a federal acquisition requirement, so a machine shop in Bartlett faces the same requirements as one in San Diego. What differs locally is the supplier mix. Memphis has no aerospace prime. It has Naval Support Activity Mid-South in Millington — the Navy’s personnel and human-resources headquarters — the Army Corps of Engineers Memphis District, and the freight and warehousing operations that follow a hub this size. The controlled data moving through those channels is personnel, procurement, and logistics information rather than weapons-system drawings, and most local firms in scope are subcontractors who inherited a DFARS clause from a prime rather than bidding on one directly.

How's your IT?

7 quick questions. Instant score. Personalized recommendations.

Get My Free IT Checkup

Epicor locking up during production runs? We fix that.

Get a no-obligation review of your manufacturing IT — network, ERP performance, OT/IT security, and compliance. Most assessments uncover 3-5 gaps.

Call Let's Talk