CMMC Phase 1 is no longer a future deadline. It is the current operating environment for defense sourcing.
The first phase of Cybersecurity Maturity Model Certification implementation began on November 10, 2025, and runs through November 9, 2026. According to the program’s official implementation guidance, Phase 1 focuses primarily on Level 1 and Level 2 self-assessments, although Level 2 certification assessments may appear in some procurements. That makes the request for quote—not the purchase order—the right place to establish how sensitive information will be handled.
For a buyer sourcing precision machining, metal finishing, or assembly, the practical question is not simply, “Does this supplier understand CMMC?” The better question is, “Have we given the supplier enough information to determine which systems, people, files, and subcontractors fall within the work?”
Why CMMC Changes the Manufacturing RFQ
CMMC is designed to provide greater assurance that contractors and subcontractors have implemented the cybersecurity requirements associated with Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The applicable requirement is established through the solicitation or contract; it should not be guessed by the supplier.
That distinction matters in manufacturing. A technical data package may include models, drawings, specifications, inspection criteria, marking instructions, or other program information. Whether any of that material is FCI or CUI depends on the contract and the information’s designation—not on the file type or the part’s appearance.
NIST explains that SP 800-171 requirements apply to components of nonfederal systems that process, store, or transmit CUI, or that protect those components. In practical terms, a poorly scoped RFQ can expand the systems and workflows involved before a supplier has even had the opportunity to review the job.
A Seven-Point RFQ Checklist for Defense Manufacturing Buyers
1. Identify the information category before files are sent
State whether the RFQ package contains FCI, CUI, export-controlled technical data, or none of these. Use the markings and handling instructions supplied by the contracting authority. Do not rely on a filename, email subject line, or general assumption that all defense-related drawings are handled the same way.
If the classification or marking is unclear, resolve it with the appropriate program or contracting contact before distributing the package.
2. State the applicable CMMC requirement
Include the required CMMC level and assessment type when the solicitation or contract establishes one. The official CMMC program describes a four-phase rollout over three years, with requirements added incrementally until full implementation. Phase 1 primarily introduces Level 1 and Level 2 self-assessment requirements, but the Department may require a Level 2 certification assessment in selected Phase 1 procurements.
This is why a generic statement such as “supplier must be CMMC compliant” is not sufficiently precise. The RFQ should reflect the actual contract requirement.
3. Define a secure exchange method
Tell suppliers how the RFQ package will be delivered, where responses should be submitted, and whether alternate transmission methods are prohibited. Avoid sending sensitive files through an unapproved channel simply because it is convenient.
A controlled exchange process also helps the supplier limit access to the personnel who need the information for estimating, engineering review, programming, quality planning, and production.
4. Describe the complete manufacturing scope
Cybersecurity scope and manufacturing scope need to be understood together. An RFQ should identify the required material, quantity, tolerances, inspection level, special processes, marking, packaging, delivery schedule, and any approved-supplier restrictions.
When the requirement includes multiple operations, consider whether an integrated supplier can reduce the number of external transfers. CMF provides precision machining, metal finishing, and assembly services under one roof. Fewer handoffs can simplify coordination, but the required information-handling rules still apply throughout the workflow.
5. Make flow-down expectations explicit
If subcontracting is permitted, identify which requirements must flow down and whether buyer approval is required before work leaves the primary supplier. This is especially important when a special process, outside test, or material certification could involve another organization.
The official CMMC program applies assessment requirements through defense contracts and subcontracts when applicable. A clear RFQ gives the primary supplier the information needed to evaluate its own scope and any downstream dependency before quoting.
6. Separate cybersecurity status from manufacturing qualifications
CMMC, ITAR registration, JCP certification, AS9100 certification, and NADCAP accreditation address different requirements. One does not automatically satisfy another.
A sound supplier review checks each requirement independently: cybersecurity status for the applicable information environment, export-control eligibility where required, quality-system certification, special-process approval and scope, technical capability, capacity, and delivery performance.
CMF publicly maintains its current facility qualifications and registrations. Buyers should also confirm that the required process and customer specification are within the approved scope before releasing work.
7. Request confirmation before technical data moves
Add a checkpoint that lets the supplier confirm the required handling method, assessment requirement, and manufacturing fit before receiving the complete technical package. For early sourcing, a sanitized capability inquiry may be enough to establish equipment, process, capacity, and schedule fit without distributing controlled details.
What CMMC Phase 1 Does—and Does Not—Mean
Phase 1 does not mean every manufacturing supplier needs the same assessment level. It also does not mean every defense-related RFQ contains CUI. The applicable requirement depends on the solicitation, contract, information, and work scope.
What Phase 1 does change is the cost of ambiguity. If a buyer sends files before identifying handling requirements, or if a supplier assumes the required level without checking the contract, both parties can create avoidable rework and schedule risk.
The official CMMC program page states that Phase 1 began November 10, 2025, and focuses primarily on Level 1 and Level 2 self-assessments. The Department’s current guidance also reminds organizations to submit required affirmations with their assessments in the Supplier Performance Risk System. Buyers and suppliers should use the current official program materials for contract-specific decisions.
Build Cybersecurity Requirements Into the Sourcing Conversation
The most effective RFQs align information handling with the real manufacturing route. That means identifying the applicable requirement, controlling how files are exchanged, defining the full process sequence, and verifying each qualification on its own terms.
If your program needs machining, finishing, and assembly support, CMF can review the manufacturing scope and applicable handling requirements with your team. Share the contract clauses, required certifications, process specifications, quantities, and delivery target so we can confirm fit before sensitive technical data is exchanged.
Contact CMF to discuss your defense manufacturing RFQ.
This article is general information, not legal, contracting, export-control, or cybersecurity advice. Contract requirements and official government guidance control.
