06/08/2026
CMMC Is Here - And the Clock Is Ticking for Defense Suppliers
On Thursday, June 4, the Manufacturers' Association hosted our 2nd Defense Buyers Round Table - and the room was engaged, the conversation was urgent, and the message was clear:
Cybersecurity compliance is no longer optional for defense contractors.
Our guest experts Rob McNellis, Chris Knox, and Chris Jones of CSMI walked our Central PA purchasing and supply chain community through the CMMC rollout timeline:
Nov 2025 - Phase 1 live: Level 1 & 2 self-assessments required
Nov 2026 - Level 2 C3PAO third-party certifications required
Nov 2027 - Level 3 DIBCAC certifications required
Nov 2028 - Full implementation; CMMC required on ALL solicitations and contracts
The hard truth? Most companies in our supply chain are not ready.
And the consequences are already real. In December 2025, the DOJ announced that Swiss Automation Inc., an Illinois precision machining subcontractor, agreed to pay $421,234 to resolve False Claims Act violations for failing to provide adequate cybersecurity protections on technical drawings supplied to DoD prime contractors.
The obligation to implement NIST SP 800-171 security controls has applied to DoD contracts, subcontracts, and suppliers since 2017. This isn't new, but enforcement is intensifying. And the whistleblower? A former quality control manager from inside the company.
If you supply parts, drawings, or services to a defense prime, this applies to you.
The Manufacturers' Association is a proud supporter of the Department of Defense's manufacturing priorities through three key programs: Talent Pipeline Program, TIDE (Talent & Innovation Defense Ecosystem), and PrimeReady. Each one is designed to help companies like yours stay competitive and compliant in the defense supply chain. Reach out to our team to learn more about what each program can do for your business.