Mechanical Solutions Blogs

CMMC Phase 2 Suspended with a 60 Day Review – Mechanical Solutions Take on the Pause

Written by Megan Marscher | Aug 6, 2026, 2:00:22 PM

Released August 5, 2026

Mechanical Solutions drives excellence in everything we do, including cybersecurity compliance. The CMMC Phase 2 rollout may have been paused but MSI’s compliance with DFARS 252.204-7012, NIST 800-171 Rev. 2 and CMMC has not!!!

We successfully completed our CMMC Level 2 C3PAO assessment on February 4, 2026 with a perfect score of 110. We chose to pursue a Level 2 third-party CMMC assessment ahead of many organizations because we are committed to implementing and maintaining strong security controls that protect and safeguard the information in our systems and within our physical environment. Protecting the United States of America and our nation’s warfighters is of the upmost priority to our organization. The CMMC Phase 2 sixty day suspension is not an opportunity for organizations to put on the brakes - It is imperative that companies handling CUI data in their systems and physical environments verify it is appropriately protected.

MSI is living proof that a small business (i.e., approximately 30 employees) can successfully be compliant with NIST 800-171 Rev. 2, obtain a perfect score on an C3PAO assessment, and maintain it thereafter.

*** Important Considerations regarding the CMMC Phase 2 60 Say Suspension***

  • CMMC is a verification program. Its purpose is to verify organizations are compliant with NIST 800-171 rev 2.
  • The CMMC Phase 2 pause solely delays the requirement to obtain a 3rd party assessment, nothing else.
  • DFARS 252.204-7012 requires compliance with NIST 800-171 rev 2
    • This is still a contractual obligation for organizations handling CUI (and has been since 12/31/17),
    • The DOW CIO has indicated companies must continue to comply, and
    • Complying is paramount to protect our war fighters
  • CMMC Phase 1 is still required
    • Organizations must continue to self-assess (i.e., verify) the company’s compliance against NIST 800-171 Rev. 2, and
    • Create and maintain evidence to support the self-assessments
  • Organizations that view this pause as an opportunity to halt moving forward to achieve compliance with NIST 800-171 Rev. 2 will:
    • Be subject to False Claims Act penalties and
    • Continue to put our national security and war fighters at risk
  • The FAR CUI rule is coming which will require complying with NIST 800-171 Rev. 3. Compliance with NIST standards does not appear to be going anywhere.
  • If self-assessments under Phase 1 are being performed correctly:
    • There are still annual costs associated with internally gathering evidence
    • If applicable, organizations must pay MSP & MSSPs used to support the organizations CUI environment to collect and provide evidence, as well as the cost of their time to be interviewed
    • There is cost associated with the self-assessor’s time to perform the assessment
    • Therefore, the net difference in cost between an appropriately performed self-assessment vs. a C3PAO third party assessment is minimal.
  • Actual cost of the assessment is minimal when compared to the cost of becoming and maintaining compliance with NIST 800-171 rev 2. Assessment cost is not the issue!

MSI believes CMMC Level 2 certification is an integral part of successfully serving the Department of War, DOW Primes and/or DOW Subcontractors, regarding projects that contain CUI. Mechanical Solutions is here to help!

Check out the top-tier services and products Mechanical Solutions provides

Check out our CMMC page

Contact Megan Marscher, Director of CMMC, Cybersecurity Officer, with any CMMC related questions