
Elbit America Tells Suppliers to Stay the Course: Why the CMMC Pause Doesn't Change Prime Flowdown Requirements
On July 16, 2026, three days after the Department of War (DoW) paused the transition to CMMC Phase 2, Elbit America sent its suppliers an open letter with a three-word instruction in the subject line: stay the course.
Elbit’s message was simple: The assessment timeline may be changing, but the underlying cybersecurity requirements did not. Suppliers that receive or expect to receive controlled unclassified information (CUI) must still implement NIST SP 800-171 Rev 2 and be ready to complete a CMMC Level 2 self-assessment when required in purchase orders.
This guidance matters for all subcontractors, not just Elbit's supply chain, because it points to what many organizations in the Defense Industrial Base (DIB) are getting wrong right now: Your obligation to protect federal data is already a term of your contracts with CMMC Phase 1 and DFARS 7012 requirements. It is not a future milestone on the DoW's rollout calendar and it is not impacted by the Phase 2 pause or pending review.

What Elbit America’s latest supplier notice said about CMMC
Elbit's letter tells suppliers to keep doing four things while CMMC Phase 2 is on hold:
- close identified security gaps
- work down open Plans of Action and Milestones (POA&Ms)
- keep your System Security Plan (SSP) and supporting evidence current, and
- maintain current cyber reports and required affirmations in SPRS.
The most consequential line is the one about third-party assessments. Elbit instructs suppliers to confirm the applicable requirement with their Elbit America buyer “before scheduling or cancelling a C3PAO assessment.”
That signals that the DoW pause is not, on its own, permission to walk away from a third-party assessment a prime is still expecting.
That’s because despite continued confusion and conflation, the DoW’s implementation timelines are not the same as prime contractor deadlines. So while memo 26-P-1023 directs DoW program managers to remove any Level 2 (C3PAO) and Level 3 (DIBCAC) requirement from active solicitations, it does not rewrite any prime’s supplier terms.
Elbit goes on to signal that the DoW's phased rollout mandating which assessment requirements can be inserted in solicitations and when will return in some form: “Organizations that remain focused on maturing their cybersecurity programs will be better positioned when the revised assessment timeline is announced.”
Vice President of Supply Chain Jason Allen closes the letter by telling suppliers the pause is "an opportunity to strengthen your program, not a reason to delay it.”
Takeaway: Elbit is still flowing down and enforcing CMMC requirements in their purchase orders, and suppliers that receive or expect to receive CUI must implement NIST 800-171 and be prepared to prove it through a CMMC assessment to win them.

Image source: Elbit America’s open letter to suppliers sent on July 16, 2026
Why a Level 2 (C3PAO) certification still carries weight with primes
Plenty of industry stakeholders published a take on the Phase 2 pause, but very few of them were primes that have completed a CMMC Level 2 certification assessment themselves and are actively managing supplier compliance.
Elbit America completed its own CMMC Level 2 certification in 2025 and has been one of the most consistent voices among primes enforcing CMMC ahead of the government's schedule.
Why? Because prime deadlines are business decisions made for supply chain risk reasons, and they were never tied to the government’s phased rollout. The Cyber AB delivered a reality check on exactly this point back in the April 2026 Town Hall: primes build supply chain teams years ahead of major proposals and were already looking for subcontractors who could demonstrate Level 2 certification or proof of readiness well in advance of the government's phases.
In fact, Elbit told suppliers in January that it only took 32 days from the start of Phase 1 enforcement to receive a solicitation that required Level 2 (C3PAO) certification.
In February, Michael "Bo" Birdwell, Elbit America's Director of Supply Chain Business Excellence, described the company as part of the small share of defense companies that have moved past internal compliance and into managing flowdown across their supply base. He explicitly named and discouraged the “wait and see” strategy some suppliers were quietly using to delay their cybersecurity efforts, saying: “Complying with the CMMC program is a requirement, not a request.”
The July 16 letter is the fourth in a series of open letters to suppliers that have all emphasized Elbit’s commitment to working with companies that have been focused on implementing and maintaining cybersecurity requirements and mitigating risks, either by getting CMMC Level 2 (C3PAO) compliant proactively or accelerating their compliance efforts.
Elbit’s open letters to suppliers so far:
- November 5, 2025: Completing a CMMC Level 1 self-assessment in SPRS is the minimum requirement to continue to do business with Elbit.
- January 9, 2026: Buyers "will not issue purchase orders" to suppliers that miss contractual CMMC flowdown requirements. Those who have not yet achieved Level 2 (C3PAO) certification should engage a C3PAO now to schedule an assessment.
- February 9, 2026: Suppliers who have already completed a Level 2 assessment should email Elbit to join their network of CMMC certified suppliers.
- July 16, 2026: The assessment timeline has changed, but the underlying cybersecurity requirements did not. Be prepared to complete a CMMC Level 2 self-assessment, and confirm with your buyer before scheduling or cancelling a C3PAO assessment.
With Phase 2 paused, Level 2 certification still provides the most assurance to primes and remains a genuine differentiator. As Cyber AB Chief Executive Officer Matthew Travis put it in the organization's response to the announcement, a Level 2 (C3PAO) certification remains “a compelling calling card for subcontracting viability to primes and the best insurance policy against False Claims Act risk.”
Takeaway: Primes were never waiting for the DoW’s implementation timeline, which is exactly why the timeline changing does not release their suppliers from their immediate cybersecurity obligations to implement NIST 800-171 and prepare to validate it through CMMC assessments.
What subcontractors should do now
Elbit's letter, and the primes that will follow it, are a reminder that the Phase 2 “deadline” was never the only reason to be ready. Adversaries did not pause on July 13. Neither did your prime's supply chain risk team, its own certification obligations, or the False Claims Act.
Contractors that treat the next 60 days as a reprieve will be exactly where they are now when the revised timeline lands. Contractors that treat it as a runway to strengthen their cybersecurity will be ready for whatever verification remains in place or returns, and they will be the ones primes can still put on a bid in the meantime.
If you supply Elbit America, or any prime that has flowed CMMC requirements down to you, here is what to do during the 60-day review period:
- Ask your buyer, in writing, what still applies. Confirm whether your prime is holding its existing requirement, deferring it, or waiting on DoW guidance. Do not infer an answer from silence, and do not cancel a scheduled C3PAO assessment before you have reached out to your prime.
- Submit a comment to the DoW's RFI. The Task Force is gathering industry input on compliance cost drivers and which requirements deliver real risk reduction. Responses close August 14, 2026, and small suppliers are the population the review claims to be about.
- Keep implementing NIST 800-171 Rev 2. DFARS 7012 has required it since 2017 and is untouched by the pause. A gap analysis against all 110 requirements and 320 assessment objectives is still the single most useful thing most contractors can do this quarter.
- Close open POA&Ms rather than rolling them forward. A paused deadline is the cheapest time you will ever get to work down remediation items, and open POA&Ms are what a prime's supplier questionnaire asks about first.
- Keep your SSP and evidence current. Your SSP and supporting documentation need to describe the environment you actually run today, not the one you described at your last assessment. Revisit scoping and your CUI boundary if anything has changed.
- Verify your SPRS score is supportable and your affirmation is current. Both are legal representations that carry False Claims Act risk (although rare). If your score reflects planned rather than implemented controls, fix the score or fix the controls.
- Check your own sub-tier suppliers. Your flowdown obligations to fourth parties did not pause either, and your prime will eventually ask what you have done about them.
- Confirm your cloud environment can actually hold CUI. Commercial Microsoft 365 cannot. Migrating CUI workloads to GCC High, Google Workspace, or another scoped CUI enclave is important work to start now if you haven’t already.
Free SSP, POA&M, and policy templates are available in the Resources library, and you can check any individual requirement in the Requirement Explorer.