Skip to the main content.

3 min read

What Idaho DIB Companies Need to Know About CMMC Right Now

What Idaho DIB Companies Need to Know About CMMC Right Now
6:22

If you're an Idaho company doing business with the Department of War — whether as a prime contractor or a subcontractor — CMMC has been a moving target for years. Here's the current status as of July 2026.

CMMC Phase II has been suspended — but your obligations haven't.

On July 13, 2026, the Department of War announced the immediate suspension of CMMC Phase II, which would have required third-party assessments by a Certified Third-Party Assessor Organization (C3PAO) beginning November 10, 2026. A CMMC Reform Task Force has been stood up to conduct a 60-day review of the program, expected to report back by mid-September 2026.

The stated reason: CMMC compliance costs were driving innovative small and mid-sized companies out of the Defense Industrial Base entirely.

What does this mean for Idaho DIB companies? It means the certification gate has paused. But it does not mean your cybersecurity obligations have.

What's still required — right now:

DFARS clause 252.204-7012 remains in full effect. This requires all defense contractors and subcontractors handling Controlled Unclassified Information (CUI) or Federal Contract Information (FCI) to implement NIST SP 800-171 Rev 2 security controls. That hasn't changed.

CMMC Phase I is still active. Level 1 self-assessments (17 basic cyber hygiene practices) for companies handling FCI, and Level 2 self-assessments (all 110 NIST 800-171 Rev 2 controls) for companies handling CUI are still required and still being enforced. Annual affirmation is still required.

The False Claims Act is still being enforced. The Department of Justice's Civil Cyber-Fraud Initiative continues to pursue contractors who self-attest to compliance they haven't actually implemented. Recent settlements have resulted in fines in the hundreds of thousands of dollars. Attesting to controls you don't have in place is a legal liability, not just a compliance gap.

Don't use this as an excuse to stop.

The 60-day review could result in a restructured program, a scaled-back program, or — far less likely — cancellation. Whatever the Task Force recommends, NIST SP 800-171 Rev 2 controls will remain the baseline. The work you do now to implement those controls, document your posture, and close gaps is not wasted effort. It's the foundation of any future certification path and your legal defensibility today.

What Idaho DIB companies should do right now:

If you haven't started: begin your NIST SP 800-171 Rev 2 gap assessment now. The 60-day review is not a pause on the underlying requirement — it's a pause on who verifies it.

If you're mid-implementation: keep going. Document everything. The strength of a self-attestation is the evidence behind it.

If you've completed your self-assessment: stay current. Watch for the Task Force findings in September and be ready to adapt if Phase II requirements are restructured.

Understanding CMMC's three levels:

Even with Phase II suspended, understanding the structure helps you know where you stand.

The Cybersecurity Maturity Model Certification (CMMC) from the Department of War (DoW) made the adoption of NIST SP 800-171 Rev 2 mandatory for the Defense Industrial Base (DIB). This includes both prime contractors and subcontractors.

NIST SP 800-171 Rev 2 is a publication that lists specific security controls for Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. It puts forth a minimum standard of cybersecurity protections for businesses working with the Federal Government to ensure Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) are secure.

CMMC is designed to give the DoW a way to enforce the protection of national security information and American ingenuity.

CMMC only applies to DIB organizations. DIB organizations enable research and development of military weapons systems, subsystems, and components or parts. DIB companies perform under contract to the Department of War.

CMMC-2.0-Levels-ControlCase-1

Image from ControlCase

CMMC 2.0 is the newest version of the program and has 3 levels of maturity, with each level increasing in the robustness of cybersecurity controls, processes, and procedures.

 

CMMC Level 1

This is ‘foundational’ cyber protection and requires the implementation of 17 basic cyber hygiene controls from NIST SP 800-171. In addition, an annual self-assessment is required. This level is mainly for a DIB company that does not process, store, or transmit CUI on its unclassified network, but does process, store or handle FCI.

CMMC Level 2

This level is referred to as 'Advanced,' and includes all 110 controls from NIST SP 800-171 Rev 2. Self-assessment is currently in effect. Third-party C3PAO assessments are suspended pending review. This level is required for companies handling CUI.

CMMC Level 3

This level builds on the previous two levels by requiring full implementation of all 110 controls from NIST SP 800-171 plus controls from NIST SP 800-172 (Enhanced Security Requirements for Protecting Controlled Unclassified Information). This ‘Expert’ level advances to a triennial assessment led by government officials. It is also suspended pending review.

How TotalCare IT helps Idaho DIB companies:

We help Idaho defense contractors and subcontractors — in precision machining, firearms, aerospace components, agricultural equipment, and other defense-adjacent industries — understand where they stand against NIST SP 800-171 Rev 2 controls and build a roadmap to close the gaps.

We'll walk your organization through a security and technology review, create a roadmap outlining where you meet controls and where you need improvement, help you implement controls, and support your self-assessment process.

The suspension gives you a moment to get ahead. Use it. Contact TotalCare IT today.

If I use TotalCare IT as my MSP, does that complicate my CMMC assessment?

The practical answer is short: if TotalCare IT doesn't touch your CUI, we're documented as an ESP in scope for your assessment but don't need our own certification. If we manage systems that do process CUI, our controls become part of your assessment boundary — which is exactly why working with an MSP that understands CMMC matters.

How Compliance Standards Like CMMC & NIST Affect Idaho Manufacturers

1 min read

How Compliance Standards Like CMMC & NIST Affect Idaho Manufacturers

When most Idaho manufacturers think about compliance, the first thing that comes to mind is OSHA safety standards, environmental regulations, or...

Read More
From Firefight to Futureproof: A Cybersecurity Roadmap for Manufacturers

1 min read

From Firefight to Futureproof: A Cybersecurity Roadmap for Manufacturers

If you run a manufacturing business—especially one that blends IT with OT—you’ve likely been told to “get compliant” or “follow NIST.” But what does...

Read More
What is a POA&M in CMMC?

1 min read

What is a POA&M in CMMC?

If you're an Idaho defense contractor navigating CMMC compliance, you've probably run into the term POA&M. What an acronym — CMMC has several of...

Read More