1 min read
How Compliance Standards Like CMMC & NIST Affect Idaho Manufacturers
When most Idaho manufacturers think about compliance, the first thing that comes to mind is OSHA safety standards, environmental regulations, or...
3 min read
Chelsea Zimmerman
:
Updated on July 15, 2026
If you're an Idaho company doing business with the Department of War — whether as a prime contractor or a subcontractor — CMMC has been a moving target for years. Here's the current status as of July 2026.
On July 13, 2026, the Department of War announced the immediate suspension of CMMC Phase II, which would have required third-party assessments by a Certified Third-Party Assessor Organization (C3PAO) beginning November 10, 2026. A CMMC Reform Task Force has been stood up to conduct a 60-day review of the program, expected to report back by mid-September 2026.
The stated reason: CMMC compliance costs were driving innovative small and mid-sized companies out of the Defense Industrial Base entirely.
What does this mean for Idaho DIB companies? It means the certification gate has paused. But it does not mean your cybersecurity obligations have.
DFARS clause 252.204-7012 remains in full effect. This requires all defense contractors and subcontractors handling Controlled Unclassified Information (CUI) or Federal Contract Information (FCI) to implement NIST SP 800-171 Rev 2 security controls. That hasn't changed.
CMMC Phase I is still active. Level 1 self-assessments (17 basic cyber hygiene practices) for companies handling FCI, and Level 2 self-assessments (all 110 NIST 800-171 Rev 2 controls) for companies handling CUI are still required and still being enforced. Annual affirmation is still required.
The False Claims Act is still being enforced. The Department of Justice's Civil Cyber-Fraud Initiative continues to pursue contractors who self-attest to compliance they haven't actually implemented. Recent settlements have resulted in fines in the hundreds of thousands of dollars. Attesting to controls you don't have in place is a legal liability, not just a compliance gap.
The 60-day review could result in a restructured program, a scaled-back program, or — far less likely — cancellation. Whatever the Task Force recommends, NIST SP 800-171 Rev 2 controls will remain the baseline. The work you do now to implement those controls, document your posture, and close gaps is not wasted effort. It's the foundation of any future certification path and your legal defensibility today.
If you haven't started: begin your NIST SP 800-171 Rev 2 gap assessment now. The 60-day review is not a pause on the underlying requirement — it's a pause on who verifies it.
If you're mid-implementation: keep going. Document everything. The strength of a self-attestation is the evidence behind it.
If you've completed your self-assessment: stay current. Watch for the Task Force findings in September and be ready to adapt if Phase II requirements are restructured.
Even with Phase II suspended, understanding the structure helps you know where you stand.
The Cybersecurity Maturity Model Certification (CMMC) from the Department of War (DoW) made the adoption of NIST SP 800-171 Rev 2 mandatory for the Defense Industrial Base (DIB). This includes both prime contractors and subcontractors.
NIST SP 800-171 Rev 2 is a publication that lists specific security controls for Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. It puts forth a minimum standard of cybersecurity protections for businesses working with the Federal Government to ensure Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) are secure.
CMMC is designed to give the DoW a way to enforce the protection of national security information and American ingenuity.
CMMC only applies to DIB organizations. DIB organizations enable research and development of military weapons systems, subsystems, and components or parts. DIB companies perform under contract to the Department of War.

Image from ControlCase
This is ‘foundational’ cyber protection and requires the implementation of 17 basic cyber hygiene controls from NIST SP 800-171. In addition, an annual self-assessment is required. This level is mainly for a DIB company that does not process, store, or transmit CUI on its unclassified network, but does process, store or handle FCI.
This level is referred to as 'Advanced,' and includes all 110 controls from NIST SP 800-171 Rev 2. Self-assessment is currently in effect. Third-party C3PAO assessments are suspended pending review. This level is required for companies handling CUI.
This level builds on the previous two levels by requiring full implementation of all 110 controls from NIST SP 800-171 plus controls from NIST SP 800-172 (Enhanced Security Requirements for Protecting Controlled Unclassified Information). This ‘Expert’ level advances to a triennial assessment led by government officials. It is also suspended pending review.
We help Idaho defense contractors and subcontractors — in precision machining, firearms, aerospace components, agricultural equipment, and other defense-adjacent industries — understand where they stand against NIST SP 800-171 Rev 2 controls and build a roadmap to close the gaps.
We'll walk your organization through a security and technology review, create a roadmap outlining where you meet controls and where you need improvement, help you implement controls, and support your self-assessment process.
The suspension gives you a moment to get ahead. Use it. Contact TotalCare IT today.
The practical answer is short: if TotalCare IT doesn't touch your CUI, we're documented as an ESP in scope for your assessment but don't need our own certification. If we manage systems that do process CUI, our controls become part of your assessment boundary — which is exactly why working with an MSP that understands CMMC matters.
1 min read
When most Idaho manufacturers think about compliance, the first thing that comes to mind is OSHA safety standards, environmental regulations, or...
1 min read
If you run a manufacturing business—especially one that blends IT with OT—you’ve likely been told to “get compliant” or “follow NIST.” But what does...
1 min read
If you're an Idaho defense contractor navigating CMMC compliance, you've probably run into the term POA&M. What an acronym — CMMC has several of...