35 / 63CMMC Compliance

CMMC compliance when the certificate is suspended and the obligation isn't

CMMC compliance for Canadian suppliers in the US defence chain, built on the controls that survived the suspension.

  • CCIE Security-led team
  • All 110 controls, all 14 families
  • Canadian data residency
THE WORK

CMMC compliance, three pillars, one operator.

One Canadian team scopes the data, closes the controls, and scores you honestly. Defence contractor compliance starts with the clause your prime flowed down, not with a programme announcement.

  1. 1

    Close the 110

    The NIST 800-171 Rev 2 controls didn't move in July. Only the audit that checked them did, so the work is unchanged and the party asking for it is now your prime.

  2. 2

    Score every family

    Fourteen control families, scored one at a time, into an SPRS submission backed by a system security plan and a remediation plan you can hand to a contracting officer.

  3. 3

    Ready for what lands

    Phases 2, 3 and 4 are suspended, so no C3PAO can assess you at CMMC level 2 today. Phase 1 self-assessment and your DFARS clause carry on, and a restart finds you in shape.

THE PROOF

Built to last. Evidence over promises.

Phase 2 was suspended on 2026-07-13. DFARS 252.204-7012 and your SPRS score were not.

IN PRODUCTION

A Canadian supplier that kept its US contract.

Our American prime flowed the clause down and gave us a date. Then July happened and two vendors told us to stand down. SMEnode said the clause in our subcontract hadn't changed and neither had our score. We closed the gaps anyway. When the prime came back and audited us, we were the only tier two who could show a real plan.

SMEnode · Engineering principle
  • CCIE Data Center
  • CCIE Security
  • CCDE Design
  • Canadian data residency
THE DEEP DIVE

CMMC compliance in Canada, made real.

You're a Canadian supplier and an American prime sent you a clause. That clause is what binds you, not a programme announcement.

Draw the boundary before you count controls.

Good work starts by drawing a boundary around the data. Which of your systems touch CUI, meaning controlled unclassified information, which touch only Federal Contract Information, and which touch neither. Most suppliers we meet have let controlled data spread across a general-purpose network because nobody drew the line, and that turns a manageable enclave into a company-wide project. Scope the enclave properly and the 110 controls apply to a fraction of your estate. Skip that step and they apply to all of it.

The score has to be one you can defend.

Then it's the score, and the score has to be honest. Your SPRS submission is a self-assessment with a number attached, backed by a system security plan and a remediation plan for anything open. An inflated score is a false claim to a government customer, which is a different category of problem from a low one. We would rather hand you a defensible 88 with dated remediation than a fictional 110.

What actually changed in July, clause by clause.

What changed is narrower than the headlines suggested. On 2026-07-13 the US Department of Defense (now the Department of War) suspended Phase 2, so third-party CMMC assessment is off and the requirement is being removed from live contracts by modification. Phase 1 self-assessment, SPRS reporting and DFARS 252.204-7012 all stayed. The review reports around 2026-09-13 and could restructure or scrap the certificate, but the Department has said plainly it is cutting audit burden and not the baseline. Every outcome leaves the 110 standing.

Control checklist
THE METHOD

How our NIST 800-171 and CMMC level 2 readiness work runs.

Four steps, and step 01 is reading your subcontract. Not the news. The clause your prime flowed down names a standard, a level and sometimes a date, and it survives announcements about the programme because it's a term of your contract until somebody modifies it. Suppliers who stood down in July on the strength of a headline are the ones who will scramble when their prime asks for a score. We start with the paperwork that binds you.

  1. Step 01

    Read the clause

    Which DFARS clauses sit in your subcontract, whether you touch CUI or only Federal Contract Information, what level was named, and what your prime has actually asked for in writing.

  2. Step 02

    Draw the enclave

    A defensible boundary around the systems that handle controlled data, so the 110 controls land on a scoped environment rather than on your whole network.

  3. Step 03

    Score and close

    Every one of the 14 families assessed, a system security plan written, a remediation plan for what's open, and an SPRS score we can defend line by line.

  4. Step 04

    Stay ready

    Quarterly reassessment as your estate changes, and a read on the reform outcome when it lands. If third-party assessment returns, you're already in shape for it. We prepare you and never assess you.

QUESTIONS

CMMC compliance questions, answered straight.

Answers first, including the one where we tell you the certification you're asking about is suspended and the obligation behind it isn't. An architect takes the call, not a salesperson.

Partly. On 2026-07-13 the US Department of War suspended Phase 2 with immediate effect, cancelling the third-party assessment requirement that was due 2026-11-10, and halted phases 3 and 4. Phase 1 self-assessment, SPRS reporting and DFARS 252.204-7012 all remain in force. A reform task force reports around 2026-09-13, and formal decisions aren't expected before mid-October. Nobody credible can tell you the final shape yet.

CPCSC, Canada's own cyber security certification programme, which covers Canadian federal and defence contracts the way CMMC covers American ones. They're separate programmes with separate paperwork, and holding one doesn't satisfy the other. If you sell to both Ottawa and a US prime you'll answer to both, though the underlying control work overlaps heavily and we scope it once.

No. A third-party assessment has to come from an authorised C3PAO, and we're a readiness firm, not one. That distinction matters less this month than usual, since third-party assessment is exactly what got suspended. What you need now is a defensible self-assessment, and that's the work we do: enclave, controls, plan, score.

Rev 2, today. A DFARS class deviation issued in May 2024 keeps contractors under 252.204-7012 on NIST SP 800-171 Rev 2, and Rev 2 is what your score is measured against. Rev 3 exists, cuts to 97 requirements across 17 families, and the rulemaking to adopt it is in progress with realistic timing somewhere between late 2026 and mid-2027. We build so the move costs you weeks, not a restart.

When no clause has reached you, because scoping controlled data you don't hold is expensive theatre. When your prime hasn't said in writing whether CMMC level 2 applies, since guessing high is how a small enclave becomes a whole-network programme. And when your real exposure is Canadian federal work rather than American, because the other programme is the one that will be asked about.

The enclave boundary in writing, a system security plan covering all 110 requirements, a plan of action with owners and dates against everything still open, and an SPRS score with the working shown behind each family. All of it editable and in your hands, with no tool to buy from us. If third-party assessment comes back, that same pack is what an assessor reads, so nothing gets rebuilt.

LET'S CONNECT

A senior engineer replies within an hour, 24/7.