Blog

CMMC 2.0 Compliance for NH and MA Defense Contractors | LG Tech MSP

Short version: On July 13, 2026, the Department of Defense suspended CMMC 2.0 Phase 2 — the stage that would have required third-party C3PAO audits before contract award. The suspension was locked in by binding regulation in September 2026. Level 1 and Level 2 self-assessments under NIST SP 800-171 are still required, and the underlying DFARS 252.204-7012 obligations never went away. Here’s what that actually means if you’re a defense contractor in New Hampshire or Massachusetts.


CMMC 2.0 compliance for NH and MA defense contractors — current status October 2026
CMMC 2.0 Phase 2 is paused — but the underlying NIST 800-171 requirements still apply to anyone handling CUI.

If your business supports the Department of Defense supply chain — manufacturing components, providing engineering services, developing software, or performing specialized work for a prime — cybersecurity obligations have been in motion for years. The Cybersecurity Maturity Model Certification (CMMC) program has had a bumpy rollout, and 2026 brought a major course correction. For businesses across southern New Hampshire, the Merrimack Valley, and the broader New England defense ecosystem, the right question isn’t “what’s the deadline?” anymore. It’s “what still applies, what’s on pause, and what should I actually be doing today?”

LG Tech MSP has been the trusted managed IT partner for businesses in this region for years. We’re watching CMMC 2.0 continue to reshape how our defense contractor clients think about security — even with the current pause. This guide breaks down where things actually stand, what NH and MA contractors need to do now, and what to stop panic-planning around.

Where CMMC 2.0 Actually Stands Right Now (October 2026)

Here’s the current state, cleanly:

  • Phase 1 (Level 1 and Level 2 self-assessments): Still in effect. If you’re handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), you’re still required to perform the self-assessment and report your SPRS score. Nothing changed here.
  • Phase 2 (third-party C3PAO assessments for Level 2): Suspended indefinitely as of July 13, 2026. The DoD stood up a CMMC Reform Task Force for a 60-day top-to-bottom review informed by industry input. In September 2026, the Department issued a binding regulation that locked the suspension in — the originally planned November 10, 2026 transition date is no longer an active deadline.
  • Phase 3 (expanded Level 2 and Level 3 assessments): Still in the regulation on paper. In practice, the suspension covers the whole phased schedule — no new assessment dates have been announced.
  • DFARS 252.204-7012: Never went anywhere. If your contract has this clause (and most DoD contracts touching CUI do), you’re still obligated to implement NIST SP 800-171, maintain an accurate SPRS score, and report cyber incidents within 72 hours via DIBNet.

Translation: the audit requirement is paused. The underlying cybersecurity requirements are not. If anything, DoD contracting officers are now watching self-assessed SPRS scores more carefully, because the third-party verification layer isn’t there to catch overstatement.

What CMMC 2.0 Actually Is (The Three Levels)

CMMC 2.0 is the Department of Defense’s framework for ensuring that contractors handling CUI or FCI meet specific cybersecurity standards. The program responds to a simple fact: adversaries target defense contractors because they’re often easier to breach than the DoD itself. Compromise a small subcontractor’s network, and you potentially access designs, schedules, technical data, and communications that flow up the supply chain.


CMMC 2.0 Level 1 vs Level 2 vs Level 3 — controls, assessment type, and who it applies to
The three CMMC 2.0 levels — most Tier-2 defense subcontractors land in Level 2.
  • Level 1 (Foundational): Basic cyber hygiene for contractors handling FCI but not CUI. 17 practices drawn from FAR 52.204-21. Annual self-assessment. Most Tier-3 subs land here.
  • Level 2 (Advanced): Full implementation of all 110 NIST SP 800-171 security requirements for contractors handling CUI. Pre-suspension, this required a C3PAO audit; today it’s a self-assessment with executive affirmation. Most prime subcontractors need this.
  • Level 3 (Expert): Enhanced protections for the highest-priority programs — all 110 NIST 800-171 controls plus a subset of NIST SP 800-172 controls, originally assessed by the DoD directly.

Your contract will specify which level you need. Most subcontractors and mid-tier suppliers face Level 2 requirements, which means demonstrating — and documenting — that you’ve implemented every applicable control from NIST SP 800-171.

“The Phase 2 pause doesn’t lower the technical bar. It just removes the external auditor. The score you report in SPRS is now the only number between you and a contracting officer’s trust.”

Why NH and MA Defense Contractors Should Still Care

The New Hampshire and Massachusetts defense ecosystem is substantial — Hanscom AFB in Bedford MA, Portsmouth Naval Shipyard, and the dense Tier-2 and Tier-3 supplier network that supports them. While we don’t work directly with prime contractors, many of our clients serve as subcontractors, suppliers, and specialized service providers to businesses that do. That still puts them squarely in CMMC 2.0’s scope.

Here’s why this still matters, even with the Phase 2 pause:

  • Primes are not waiting for DoD: Many prime contractors are flowing down CMMC-aligned requirements in their subcontract language anyway. Your prime may require Level 2 self-assessment + executive affirmation before awarding you work, pause or no pause.
  • Your SPRS score is still a bidding factor: A low or stale SPRS score hurts you in competitive bids today. Contracting officers can and do look at it.
  • Breach reporting hasn’t changed: The DFARS 72-hour reporting clock still runs. If you can’t detect an incident, you can’t report it, and that’s a contract-ending problem.
  • The pause will end: When Phase 2 resumes (and it will, in some form), C3PAO assessor availability will again be the bottleneck. Contractors who used the pause to actually close gaps will be first in line. Those who treated it as a snooze button will be scrambling.
  • Remediation is slow: Most networks we assess have 15 to 40 gaps between current state and full NIST 800-171 compliance. Closing those gaps — implementing MFA, encrypting CUI at rest and in transit, segmenting networks, establishing incident response plans — takes months, not weeks.

Starting now gives you runway. Treating the pause as a pass means you’re still at step one when the music starts again.

The Most Common Gaps We See in NH and MA Defense Contractor Networks

When we conduct readiness assessments for clients in Hillsborough County, Rockingham County, Essex County, and beyond, certain gaps appear repeatedly. None of them are unique to the region — they’re systemic across small-to-mid-sized defense contractors nationwide — but they’re worth naming because they represent the most time-intensive remediation work.

1. Access Control Weaknesses

NIST SP 800-171 requires strict control over who can access CUI and what they can do with it. Many businesses allow broader permissions than necessary, lack centralized identity management, or haven’t implemented multi-factor authentication across every account that touches CUI. Fixing this means rethinking user roles, deploying MFA everywhere (including local admin logins), and enforcing least-privilege access.

2. Inadequate Encryption

CUI must be encrypted both at rest (on servers, workstations, removable media) and in transit (across networks or to external parties). Businesses that haven’t encrypted local drives, network shares, or email attachments face significant remediation. This isn’t a software toggle — it requires planning, testing, and user training to avoid breaking workflows.

3. Missing Audit Logging and Monitoring

CMMC 2.0 requires detailed logging of security-relevant events and the ability to review those logs for anomalies. Many networks log some activity but don’t centralize it, retain it long enough, or actively monitor it. Building this capability means deploying log aggregation, establishing baselines, and creating review processes you can actually show an assessor.

4. Weak or Non-Existent Incident Response Plans

You need a documented, tested plan for detecting, containing, and recovering from cybersecurity incidents. The plan must include roles, communication protocols, and the DFARS 72-hour breach notification process. Most businesses have informal response processes at best. CMMC requires formal documentation and evidence of training or tabletop exercises.

5. Inadequate Network Segmentation

If CUI shares a network with non-CUI systems — or if your guest Wi-Fi, HVAC controls, and engineering workstations all live on the same VLAN — you have a segmentation problem. CMMC expects logical or physical separation to limit the impact of a breach. Retrofitting segmentation into an existing network takes careful planning to avoid breaking connectivity or workflows.

What a Realistic CMMC Readiness Process Looks Like

Achieving compliance isn’t a one-time project. It’s a structured process with distinct phases, and starting during the Phase 2 pause gives you a real window to do it without firefighting.

Step 1 — Scoping and Data Flow Mapping

Identify where CUI lives in your environment. Which systems store it? Which users access it? Where does it flow in and out of your network? Scoping determines what’s in the assessment boundary and what’s not. Getting this wrong wastes money and creates risk.

Step 2 — Gap Assessment Against NIST SP 800-171

Compare your current environment to the 110 requirements in NIST SP 800-171. For each control, document whether you fully meet it, partially meet it, or don’t meet it. This produces your gap list — the roadmap for remediation and the input for your SPRS score.

Step 3 — Remediation Planning and Execution

Prioritize gaps based on risk, effort, and contract timelines. Some fixes are quick (enabling MFA, updating policies). Others require new tools, infrastructure changes, or vendor coordination (encryption, monitoring, segmentation). Build a project plan with realistic timelines and budget.

Step 4 — Documentation and Evidence Collection

Whether you’re self-assessing or ultimately being assessed by a C3PAO, no one takes your word for it. You need policies, procedures, configuration screenshots, logs, training records, and test results. As you implement controls, document what you did and how you’re maintaining it. Good evidence collection during remediation saves enormous headaches later.

Step 5 — Self-Assessment, SPRS Submission, and Executive Affirmation

Under the current (post-suspension) model, this is the finish line for Level 2 for most contractors. You formally document your assessment, calculate and submit your SPRS score, and your senior company official affirms compliance. Keep every artifact — if Phase 2 resumes and a C3PAO audits you, this is their starting point.

Step 6 — Continuous Compliance

CMMC compliance isn’t permanent. You’re expected to maintain controls between assessments, and when Phase 2 resumes, re-assessment will likely be a three-year cycle. That means ongoing monitoring, annual training, policy updates, and periodic internal reviews. Compliance is a program, not a project.

Why Defense Contractors Need Specialized IT Support for CMMC


LG Tech MSP supports defense contractors across southern New Hampshire and the Merrimack Valley
LG Tech MSP supports defense contractors across southern NH and the Merrimack Valley.

CMMC 2.0 compliance isn’t something you can bolt onto a general IT support relationship. It requires deep familiarity with NIST SP 800-171, experience designing and implementing the required controls, and ongoing management to maintain compliance over time.

At LG Tech MSP, we support businesses across southern New Hampshire, the Merrimack Valley, and other parts of the region — including those in the defense ecosystem and small-to-mid-sized businesses across other industries. For defense contractors, that means:

  • Readiness assessments that accurately scope your environment and identify gaps before you self-assess (or before an eventual C3PAO walks in the door)
  • Remediation roadmaps that prioritize work based on risk, timeline, and budget constraints
  • Implementation support for controls you don’t have internal expertise to deploy — encryption, monitoring, segmentation, incident response
  • Documentation assistance to create the policies, procedures, and evidence any assessor expects
  • Ongoing compliance management to maintain controls, monitor your environment, and keep your SPRS score accurate and defensible

We don’t replace an official C3PAO assessor — we get you ready so that whether you’re self-assessing today or being audited the day Phase 2 resumes, the answer is the same: ready.

Start Your CMMC Readiness Process Now — The Pause Is the Opportunity

If you’re an NH or MA defense contractor handling CUI, the Phase 2 suspension is a gift of time, not a reason to coast. The gap analysis, remediation, documentation, and self-assessment process takes months under the best circumstances — longer if you’re discovering complex infrastructure issues mid-project.

LG Tech MSP has been the trusted managed IT partner for businesses in this region for years. We know the defense ecosystem, we understand NIST SP 800-171, and we’ve guided clients through readiness processes that position them whether the finish line is a self-assessment today or a C3PAO assessment tomorrow.

If you’re ready to start — or if you just want a clear read on what today’s rules actually require — reach out:

  • Call: (603) 681-6130
  • Email: info@lgtechmsp.com
  • Stop by: Walk-ins welcome at our Pelham office — 2 Beaver Brook Way, Unit C, Pelham, NH 03076. No appointment needed.
  • Schedule a scoping call: We’ll review your contract requirements, assess your current state, and outline a readiness roadmap tailored to your timeline and budget.

CMMC 2.0 is still here — just on a different schedule than people originally planned around. The contractors who use the pause will be ready when it ends. The ones who treat it as a reprieve will be scrambling. Don’t let compliance become the reason you lose work.

Last updated: October 9, 2026. Reflects the DoD’s July 13, 2026 suspension of CMMC Phase 2 and the September 2026 binding regulation that locked it in. CMMC rules continue to evolve — if you want a current status read specific to your contracts, call us.

Let's Get Started

Get started with our managed IT solutions today and experience seamless, efficient, and secure IT operations. Contact us now to schedule your free assessment and discover how we can tailor our services to meet your business needs.

1. Schedule an Assesment
2. We create a solution that’s right for you with no hassle setup and installation
3. Enjoy running your business, not your IT

Schedule an appointment today

At LG Tech, our mission is to help your business run smarter, stay secure, and grow faster. Book a 30-minute call with us to discover if we’re the right fit to support your IT needs.
Enter your name and email to get started. We’ll take care of the rest.
Schedule Appointment

Featured Posts