CMMC · NIST 800-171 · DFARS

CMMC for Manufacturers.
Made Clear. Reliably Forged.

The rules keep moving and the deadlines shift.

Most shops don’t know if it even applies to them.

The requirements read like they were written for lawyers.

RADIN Dynamics turns CMMC into plain language and a plan.

The real confusion

– Owners who assume it only applies to giant defense primes.

– Requirements buried in acronyms nobody explains.

– A deadline that got paused, so everyone stopped paying attention.

– Obligations already in the contract, unread.

– Readiness treated as an IT task instead of a business risk.

CMMC is not a future problem for someone else. If you touch defense work, the obligations are already in your contracts today.

The Cybersecurity Maturity Model Certification is how the U.S. Department of Defense verifies that its suppliers protect sensitive information. The certification checkpoint keeps moving, but the underlying rules, NIST 800-171 and DFARS 252.204-7012, are contractual requirements right now. RADIN Dynamics helps manufacturers understand where they stand and get their systems in order.

✔ CMMC in plain language

What It Actually Is

Status current as of July 2026. CMMC timelines are changing; we review this page regularly.

01

Who It Applies To​

Any manufacturer in the defense supply chain, not just the primes. If you make parts for a company that sells to the DoD, it can reach you.

02

What CUI Means​

Controlled Unclassified Information. Drawings, specs, and data a defense customer marks as sensitive. Handling it is what triggers the requirements.

03

NIST 800-171​

The 110 security controls at the heart of CMMC. These define what protecting CUI actually requires, and they apply today.

04

DFARS 252.204-7012​

The contract clause that already obligates defense suppliers to meet NIST 800-171 and report incidents. It is likely in your contracts now.

05

The Three Levels​

Level 1 for basic protection, Level 2 for CUI, Level 3 for the most sensitive work. Most manufacturers handling CUI are aiming at Level 2.

06

Self-Assessment vs. Certification​

Some tiers allow a self-assessment. Others require a third-party assessor. Knowing which applies to you is the first real question.

110​

NIST 800-171 controls required

3​

CMMC maturity levels

7012​

The DFARS clause already in play

1​

Connected system to manage it

✔ Where things stand in 2026

The Deadline Moved. The Work Didn't.

In mid-2026 the certification phase was paused for federal review, and a lot of manufacturers took that as a reason to relax. That is the trap. The pause changed the date, not the obligation.

 

01

What Got Paused​

The third-party certification checkpoint that was scheduled to phase in. It is under review, and the timeline is in flux.

02

What Did Not​

NIST 800-171 and DFARS 252.204-7012 remain contractual obligations right now. If you handle CUI, you are already expected to protect it.

03

Why Waiting Costs You​

Readiness takes months, not weeks. The shops using the pause to prepare will be ready when the date snaps back. The rest will scramble.

04

The Opportunity In It​

The work that makes you compliant is the same work that makes you faster and more competitive. Getting your house in order pays twice.

✔ How RADIN Dynamics helps

From Confusion to a Clear Plan

RADIN Dynamics is a Microsoft Dynamics 365 partner that helps manufacturers connect and modernize the systems CMMC readiness depends on. We translate the requirements into a plan you can act on.

01

Scope​

Determine whether CMMC applies to you, at what level, and what CUI you actually handle.

02

Assess​

Map your current systems and data against the requirements to find the real gaps.

03

Prepare​

Connect and modernize the systems that store and move sensitive data, on a Microsoft foundation.

04

Sustain​

Keep documentation and controls current so you stay ready as the requirements settle.

A note on our role.

RADIN Dynamics is pursuing Registered Provider Organization (RPO) status with the Cyber AB, the body that oversees CMMC readiness advisors. We help manufacturers prepare their systems and documentation. We do not perform the official certification assessment itself, that is handled by a separate accredited assessor. Our job is to get you ready and connected before that point.

 

Questions

FREQUENTLY ASKED
QUESTIONS

Does CMMC apply to a small shop like mine?

If you handle Controlled Unclassified Information for a defense customer, directly or as a subcontractor, it can apply regardless of your size. The trigger is the data you touch, not your headcount. The first step is confirming whether you handle CUI at all.

 

The certification checkpoint was paused for review, but NIST 800-171 and DFARS 252.204-7012 are still contractual obligations today. Readiness takes months, so the pause is time to prepare, not time to ignore it.

 
 

NIST 800-171 is the set of 110 security controls. CMMC is the framework that verifies you actually meet them, through self-assessment or a third-party assessor depending on your level. CMMC is the checkpoint; NIST 800-171 is the work.

 
 

Yes. If a subcontractor receives or handles Controlled Unclassified Information as part of a defense contract, the flow-down requirements apply to them too, even if they never contract directly with the Department of Defense.

 
 

Both, but treating it as only an IT task is why shops fall behind. Readiness touches how you store data, run your systems, and document your processes. That is a business risk, and the fix overlaps with modernizing your operation.

 
 

No. Official certification is performed by a separate accredited assessor. RADIN Dynamics helps you get ready, connecting and modernizing the systems and documentation that readiness depends on, so you walk into that assessment prepared.

 
 
 

See Where You Stand on CMMC

A free review shows whether CMMC applies to you, where your systems sit against the requirements, and what readiness would actually take.

 

Get CRM Clarity Today