If your company does business with the Department of Defense, CMMC compliance is still a requirement. A recent 60-day pause was issued to provide clarity on implementation timelines. The underlying standards remain in place, and the day when companies will need to pass a third-party audit is still coming. The question is whether you are preparing for it.
For manufacturers in the Defense Industrial Base, ERP is at the center of the compliance equation. A FedRAMP-authorized system addresses a significant portion of the technical security requirements before you ever sit down with an auditor. For defense contractors evaluating ERP, that kind of head start is hard to put a price on.
CMMC and FedRAMP explained
These two frameworks are related but serve different purposes and mixing them up creates confusion about what your company actually needs.
CMMC (Cybersecurity Maturity Model Certification) is a DoD program that sets cybersecurity requirements for defense contractors and subcontractors. If your company stores, processes, or transmits Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), CMMC applies to you. Most manufacturers in the defense supply chain will need to achieve CMMC Level 2, which requires a third-party audit against 110 security practices drawn from NIST 800-171.
FedRAMP (Federal Risk and Authorization Management Program) is a separate framework for cloud service providers selling to federal agencies. What it means for your company is that the cloud software you use, including your ERP, can be FedRAMP authorized. That authorization means the software has already been independently assessed and approved for handling federal data, which substantially reduces the technical security controls your company is responsible for proving during a CMMC assessment.
For a plain-language breakdown of how the two frameworks compare, this LinkedIn article by ERP consultant Andy Pratico is a helpful starting point.
What the enforcement pause means
The 60-day pause that was recently announced is about providing clarity on implementation timelines. The NIST guidelines companies need to follow remain in place. The CMMC levels remain in place. What is in flux is when the final audit deadline will land.
A practical constraint is driving urgency independent of any enforcement timeline: there are currently only a few hundred certified third-party auditors available to assess the thousands of companies that need to be audited. Think of it like a housing inspection bottleneck. Everyone needs one, there are not enough inspectors, and the companies that get in line early are the ones that get seen first.
A company in the Huntsville aerospace and defense corridor was recently fined over $400,000 for failing an audit. Beyond fines, companies that cannot demonstrate compliance risk losing DoD contracts entirely. For businesses that want to remain long-term players in the defense industrial base, compliance is coming, and the timeline is the only open question.
Your ERP and CMMC compliance
Most of the expense and complexity around CMMC compliance comes from building, documenting, and proving a secure environment. There are consulting firms charging hundreds of thousands of dollars to help companies go through this process when they are running a non-FedRAMP-authorized ERP in a standard cloud or on-premises environment.
Infor CloudSuite Industrial (CSI) is a FedRAMP-authorized ERP, formally authorized and listed on the FedRAMP marketplace since 2018. Infor Factory Track and Infor OS are included in that authorization. The system runs on AWS GovCloud.
Infor earned that FedRAMP authorization in 2018, and it does real work for you during a CMMC Level 2 assessment. A significant portion of the technical security requirements have already been addressed by the system itself. For defense contractors considering a move away from a non-authorized system, the difference in compliance burden is substantial. You can learn more about how Infor CSI supports government contractors on this page, and we have also written in more detail about how Infor ERP supports CMMC compliance for manufacturers.
Next steps for defense manufacturers
The pause is an opportunity. Companies that use this time to get their ERP environment in order will be ahead of the field when auditors start scheduling. That is a real competitive advantage in a space where contracts go to the companies that can prove compliance.
If you are running Infor CSI or evaluating ERP options as a defense contractor, we are happy to talk through what CMMC readiness looks like in the context of your ERP environment.






