Protecting CUI Has Never Mattered More
Be the Shop Defense Contractors and Primes Can Trust
In July 2026, the Department of War paused the rollout of third-party CMMC certification while it reviews the program. But nothing about the underlying requirement has changed: DFARS 252.204-7012 remains in effect, mandating NIST 800-171 for every company handling Controlled Unclassified Information, self-assessments and SPRS scores are still required, and False Claims Act exposure for inaccurate compliance claims hasn't gone anywhere. If anything, protecting CUI matters more than ever — and the shops that keep investing in their security posture now are the ones OEMs and primes will trust with their most sensitive work.
Cybersecurity Maturity Model Certification (CMMC) Compliance for Manufacturers
What’s changed about CMMC requirements in 2026?
Manufacturers handling CUI must still meet NIST SP 800-171, complete required self-assessments, and accurately report their compliance—the CMMC Phase II pause only changes how that compliance is verified.
Since 2016, DFARS 7012 has required DIB contractors handling CUI to meet NIST 800-171. That obligation hasn’t changed under CMMC, and hasn’t changed with recent developments either.
What did change: in July 2026, the Department of War paused the Phase II rollout, which required third-party certification through an accredited C3PAO. This does not affect what is required; it only affects how your compliance gets verified.
Self-assessment, annual affirmations, SPRS score submission, and full 800-171 implementation are all still mandatory, and the DOJ continues to pursue False Claims Act cases against contractors who misrepresent their security posture. For job shops, this is a shift back toward the accuracy of your own self-assessment rather than third-party validation — and with the underlying risks to CUI as serious as ever, Paperless Parts is built to support you through however the certification model evolves.
Does CMMC Compliance still matter?
Yes. The certification timeline may be paused, but the requirements (and OEM expectations) are not.
What is currently paused is the requirement that third-party C3PAO certification precede certain contract awards. The underlying obligations haven’t changed. Contractors handling CUI must still implement NIST SP 800-171, maintain a current SPRS self-assessment, and complete annual affirmations, with the False Claims Act still looming over inaccurate compliance claims. The pause also doesn’t stop OEMs and Tier Ones from setting their own bar: primes are still responsible for flowing DFARS requirements down the supply chain, and many have already built SPRS scores and CMMC status into their supplier qualification process.
That means third-party certification may end up following a path like AS9100: not always government-mandated, but increasingly a cost of entry with certain customers. DFARS and 800-171 compliance are the baseline for serving the DIB; certification is what helps you stand out with OEMs unwilling to lower their standards while the federal timeline stays unsettled.
Paperless Parts and CMMC
Is Paperless Parts CMMC-Compliant?
Paperless Parts is FedRAMP Moderate Equivalent, and is designed to support manufacturers looking to achieve CMMC Level 2. We completed our Federal Risk and Authorization Management Program (FedRAMP) Moderate Equivalency audit in 2023.
Over the last six years, we've invested millions of dollars in building CMMC-compliant security into Paperless Parts.
We have long been committed to protecting our nation’s intellectual property, and we will continue to ensure that our solution remains CMMC-compliant. Watch this video from our leadership team to learn more.
10 Security-Related Questions to Ask Every Software Vendor
Paperless Parts protects data through industry-leading encryption, rigorous, backup protocols, and U.S. sovereignty.
- ITAR-registered
- Encryption in Transit: All data moving between your browser and our platform is protected using FIPS validated encryption.
- Encryption at Rest: Sensitive files and database records are encrypted using FIPS validated encryption at the storage layer.
- Disaster Recovery: Data is backed up nightly with a resiliency model that ensures high durability and rapid recovery.
- Integrated Security: Every file uploaded to Paperless Parts undergoes automated virus and malware scanning before processing.
- U.S. Person Restriction: Our platform and support operations are managed 100% by U.S. Persons on U.S. soil.
- Network and servers approved for Controlled Unclassified Information
- Your files are never sold or shared with third parties
- All data is securely backed up nightly
- Always retain ownership of data you upload
Beyond infrastructure, Paperless Parts’ Aerospace & Defense Tier provides a suite of features to help you meet your CRM obligations and manage day-to-day risk.
- SAML 2.0 and SSO
- Multi-Factor Authentication (MFA)
- Permission management
- CUI Flagging
- CUI Audit Trails
- Secure External Collaboration
- Redaction tooling
CMMC FAQ
What do job shop manufacturers need to know about CMMC?
Manufacturers handling CUI must still meet NIST SP 800-171, complete required self-assessments, and accurately report their compliance—the CMMC Phase II pause only changes how that compliance is verified.
Since 2016, DFARS 7012 has required 800-171 in all DIB contracts. Any shop handling CUI since that time has been required to meet very specific security standards, and those that haven’t have been in violation of their contractual obligations and subject to financial penalties.
That did not change with the introduction of the Cybersecurity Maturity Model Certification (CMMC), nor has it changed under the recent program developments. What has changed is that in July 2026, the Department of War suspended the rollout of Phase II, which specifically required contractors to obtain third-party certification from an accredited assessor (a C3PAO). This does not affect what is required; it only affects how your compliance gets verified.
Phase I self-assessment, annual affirmations, SPRS score submission, and full implementation of NIST SP 800-171 remain in force, and the Department of Justice continues to pursue False Claims Act enforcement against contractors who misrepresent their security posture.
For job shops and contract manufacturers, think of this as a shift from an emphasis on third-party validation back to an emphasis on the accuracy of your own self-assessment. At a moment when the underlying risks to controlled unclassified information are as serious as they’ve ever been, Paperless Parts is designed to support you no matter how the certification model evolves.
Does CMMC Compliance still matter?
Yes. The certification timeline may be paused, but the requirements (and OEM expectations) are not.
What’s currently paused is the plan to make third-party C3PAO certification a precondition for certain contract awards. The underlying obligations have not changed. Contractors handling CUI must still implement NIST SP 800-171, maintain a current self-assessment in SPRS, and complete required annual affirmations. Inaccurate or unsupported claims about compliance can also carry serious legal and financial consequences under the False Claims Act.
The pause also does not limit what OEMs and Tier Ones can demand from their suppliers. Prime contractors are responsible for flowing applicable DFARS requirements down their supply chains, giving them a strong incentive to work with suppliers whose cybersecurity posture is documented, current, and defensible. Major OEMs have already invested heavily in validating NIST SP 800-171 implementation, SPRS scores, and CMMC status, and some incorporate those requirements into their own supplier qualification and award processes.
Third-party certification may therefore follow a path similar to AS9100: even when it is not expressly required by the government for every contract, it can become a cost of entry for working with certain customers. A strong SPRS score and C3PAO certification give buyers greater confidence that a shop can protect CUI—and give the shop credible proof that it is prepared to take on sensitive defense work.
Bottom line: DFARS and NIST SP 800-171 compliance are the baseline for serving the DIB. Third-party certification goes a step further, helping manufacturers stand out with OEMs that are unwilling to lower their standards while the federal certification timeline remains unsettled.
What does the recent CMMC announcement mean for your investment in Paperless Parts and other software tools?
Nothing has changed about the role your software vendors play in protecting CUI, or your responsibility to understand how every platform in your workflow supports your security requirements.
Whether or not you decide to pursue CMMC certification is a choice all businesses that handle CUI will have to make. Regardless, shops need to understand the security posture of every software vendor they rely on to handle CUI. Not all platforms are built the same way, and the tools you use to quote, manage, and share sensitive part data are part of your compliance picture.
Paperless Parts has long been committed to protecting our nation’s intellectual property, and we will continue to ensure that our solution remains CMMC-compliant.
Are CMMC compliance standards finalized?
The final CMMC rules were published in September 2025, and Phase 1 (self-assessment against NIST SP 800-171 for Levels 1 and 2) has been in full effect since November 2025. Phase 2, which would have added a third-party (C3PAO) certification requirement for Level 2, was scheduled to start November 2026, but was suspended by the Department of War in July 2026. A CMMC Reform Task Force is now reviewing the program with the goal of cutting bureaucracy and cost while keeping security intact, with recommendations expected within 60 days (by mid-September 2026).
Why is CMMC important?
The U.S. projects its power via military technology, in which we’ve invested trillions of dollars over many decades. We have started to see adversaries field extremely similar systems at a fraction of the timeline and cost, most likely helped by the theft of intellectual property. As critical national infrastructure, manufacturing is a major target for cybercrime. Businesses of all sizes and at any point in the supply chain are targeted. Cyberattacks cost businesses $200,000 on average, and four in 10 companies have experienced multiple incidents. Research shows that the number of publicly recorded ransomware attacks against manufacturing has tripled in the last year alone—and even job shops and contract manufacturers are at risk: 43% of cyberattacks are aimed at small businesses. To protect Controlled Unclassified Information (CUI), the government needs to ensure that shops are taking appropriate steps.
Does every shop have to be audited and certified?
Right now, no company is required to complete a third-party CMMC audit. In July 2026, the Department of War paused that requirement (CMMC Phase 2) while it reviews the program with the stated goal of cutting bureaucracy and cost for the defense industrial base. Self-assessment is the standard that currently applies: every company with a defense contract is still required to implement NIST 800-171 and submit its Supplier Performance Risk System (SPRS) score. Depending on the sensitivity of the work you perform, a third-party audit requirement could still return in some form once the government’s review wraps up later this year. Even without a mandate, most shops benefit from a third-party audit of their cybersecurity architecture. It’s a head start if certification requirements come back, and a way to build trust with buyers in the meantime.
Who do I contact to conduct a CMMC Compliance Audit?
A number of third-party accredited assessors offer audit services. Paperless Parts does not provide this service, however, we’re happy to work with you to provide recommendations as the landscape of services providers becomes clearer.
I don't make parts with CUI. Do I need to get CMMC certified?
No – but cybersecurity should be a top priority for all shops. More and more buyers are including cybersecurity in their vendor evaluation criteria. A buyer’s primary job is to manage risk. In addition to risks with hitting cost and delivery goals, part buyers are increasingly concerned about their intellectual property.