Proplate

CMMC + NADCAP in 2026: What Every Aerospace Surface Finishing Supplier Needs to Know Before November

If you run a plating, anodizing, heat treatment, or chemical processing shop that supplies the aerospace or defense industry, the next twelve months will reshape your business whether you’re ready or not. 

November 10, 2026 isn’t a date most surface finishing shop owners have circled on the wall. But it should be. It’s the day CMMC Phase 2 enforcement begins, which means third-party cybersecurity certification not self-attestation becomes mandatory for contractors handling Controlled Unclassified Information (CUI). 

Pair that with the steady tightening of NADCAP audit expectations, and you have something that hasn’t existed before in this industry: two parallel compliance frameworks, on the same shop floor, on the same timeline, with the same downside if either one fails. 

Most shops are treating these as separate problems. That’s the mistake. Here’s why. 

The CMMC reality nobody is talking about loudly enough 

CMMC 2.0 the Cybersecurity Maturity Model Certification is now an enforceable contract requirement, not a future concern. The Department of Defense formalized it in DFARS in late 2025, and the rollout is happening in four phases: 

  • Phase 1 (November 10, 2025): Level 1 and Level 2 self-assessments required in applicable solicitations 
  • Phase 2 (November 10, 2026): Mandatory third-party C3PAO assessments for Level 2 contractors handling CUI 
  • Phase 3 (November 10, 2027): Level 3 government-led assessments for higher-risk programs 
  • Phase 4 (November 10, 2028): Full implementation across the Defense Industrial Base 

The number that should keep you up at night: industry surveys suggest only about 1% of the 220,000+ defense contractors are fully prepared for Phase 2. That number actually dropped from 4% in 2025 and 8% in 2023 preparation is moving backwards while the deadline closes in. 

Here’s the part most surface finishing shops miss: you don’t need to be a direct DoD contractor for this to hit you. If you supply a prime Lockheed Martin, Boeing, Northrop, Raytheon they’re already requiring your CMMC status documented in SPRS (the Supplier Performance Risk System). Lockheed has been pushing this down to suppliers ahead of the deadline. A prime’s demand can arrive well before any DoD solicitation does. 

If you handle CUI and most aerospace platers, anodizers, and heat treaters do, because part drawings and specifications are CUI by default you need Level 2 certification. That means implementing all 110 security controls from NIST SP 800-171, documenting them in a System Security Plan (SSP), and passing a C3PAO audit. 

With roughly 80 authorized C3PAOs and 80,000 contractors needing Level 2 certification, the math is brutal. C3PAO availability is already constrained. By Q3 2026, wait times for assessments will stretch past 12–18 months for shops that wait too long to start. 

Meanwhile, NADCAP isn’t getting easier eitherMeanwhile, NADCAP isn’t getting easier either 

NADCAP the aerospace industry’s accreditation program for special processes has been the dominant quality standard in surface finishing for decades. If you do plating, anodizing, heat treating, or chemical processing for aerospace, you’re either NADCAP-accredited or you’re locked out of meaningful work. 

The audit criteria for chemical processing (AC7108) and heat treating require granular documentation: every process step, every tank chemistry pull, every cycle log, every operator training record, every piece of equipment calibration evidence. Auditors don’t just want to know that you have processes they want to see proof, traceable to the part level, of every special process performed. 

NADCAP audits in 2026 are getting more rigorous, not less. The Performance Review Institute has been tightening interpretations, and the most common audit non-conformances continue to cluster around documentation gaps, traceability failures, and inconsistent process control. The audits are also more expensive when you fail them every non conformance extends your audit time, costs you the auditor’s day rate, and delays your accreditation renewal. 

Here’s the uncomfortable overlap that nobody’s writing about: NADCAP wants you to document everything about your processes, and CMMC wants you to secure all of that documentation. 

Same data. Two compliance frameworks. Most shops are handling them with two completely separate systems paper travelers and quality binders on one side, a bolted-on cybersecurity tool on the other. That’s expensive, fragile, and audit-hostile. 

Why most shops are handling this wrong 

Walk into a typical small aerospace finishing shop today and you’ll see roughly this stack: 

  • Production tracking: Paper job travelers, a scheduling whiteboard, and Excel 
  • Quality documentation: Three-ring binders, manual log sheets, and a NADCAP coordinator who lives in fear of audit week 
  • Cybersecurity: Whatever the IT guy (often a part-timer or MSP) set up, with no formal SSP, no documented controls, and no audit trail tied to production data 

When CMMC Phase 2 hits in November 2026, this stack breaks in three ways: 

  • The data the C3PAO assessor wants to see who accessed what part data, when, and with what authorization doesn’t exist in retrievable form because production records are on paper and information access isn’t logged 
  • The 110 NIST 800-171 controls can’t be evidenced without an information system that actually captures access logs, configuration baselines, and audit accountability 
  • The cost of bolting on a separate compliance platform to your existing production system can run $30,000–$100,000 for a small shop, plus ongoing C3PAO audit costs and consulting fees 

Meanwhile, your NADCAP audit prep continues to consume two to three weeks of senior staff time, twice a year, because nothing is connected. 

It’s not a sustainable model. And it’s not the model that will win aerospace and defense work in 2027 and beyond. 

The integrated approach: one platform, both frameworks 

The shops that will come out ahead are the ones treating NADCAP, ERP, and CMMC as a single integrated environment instead of three separate initiatives. 

Here’s what that looks like in practice: 

  • Production traceability that doubles as compliance evidence. Every job tracked at every processing step. Tank chemistry tied to actual production activity. Time-warning enforcement on every process to prevent under- or over-treatment per SAE/ISO standards. The data NADCAP wants is captured automatically, not transcribed onto a clipboard. 
  • Access control and audit accountability baked into the production environment. Every user action logged. Role-based access enforced. Configuration changes tracked. The same system that runs the shop becomes the evidence record for CMMC controls. 
  • System Security Plan (SSP) documentation aligned with how the shop actually operates. Not a generic 80-page binder that doesn’t reflect reality an SSP grounded in your real production environment, with controls mapped to actual workflows. 
  • Risk Management Framework (RMF) support from teams that have done this work before. Including in federal and defense-aligned environments. This isn’t theoretical compliance written by consultants who’ve never been on a shop floor. 

That’s the model PROPLATE was built for. We didn’t add CMMC readiness as a bolt-on we built the platform from the ground up to unify manufacturing discipline (NADCAP), production management (ERP), and cybersecurity maturity (CMMC/RMF) in one environment. Process integrity and information security advance together. 

What aerospace finishing suppliers should do between now and November 2026 

If you take nothing else from this article, here’s the minimum sequence: 

1. Conduct a CMMC gap assessment in the next 60 days. Not a vendor sales pitch an actual evaluation of where you stand against the 110 NIST 800-171 controls. Most small shops are at 30–50% compliance without realizing it. 

2. Inventory where CUI lives in your environment. Part drawings, specifications, customer communications, ITAR-controlled data. If you don’t know where it is, you can’t protect it. Auditors will ask this first. 

3. Document your current production and quality processes in a way that maps to both NADCAP traceability AND CMMC audit accountability. If you’re rebuilding documentation anyway for NADCAP renewal, do it once and make it serve both frameworks. 

4. Engage a C3PAO early to get on their calendar. Wait times are already stretching. By late 2026 they will be brutal. Get in line now. 

5. Evaluate whether your current production system can actually support what’s coming. If your ERP can’t generate the access logs, audit trails, and traceability records needed for both NADCAP and CMMC, you’re going to be retrofitting under deadline pressure the most expensive possible time to do it. 

The shops that win will be the ones that saw this coming 

Compliance fatigue is real in this industry. NADCAP renewals, ISO audits, AS9100 surveillance, customer-specific quality requirements the documentation burden never stops growing. CMMC is the newest layer, and for many shop owners, it feels like one more thing eating into margin and time. 

But here’s the strategic read: every supplier who can’t meet CMMC Phase 2 will lose DoD-tied work. That work doesn’t disappear it consolidates into the suppliers who can meet it. The shops who treat 2026 as an inflection point, not an obstacle, will absorb the market share that their less-prepared competitors leave on the table. 

The infrastructure to do this exists. The timeline to install it doesn’t stretch forever. The question every aerospace finishing supplier needs to ask isn’t whether to integrate NADCAP, ERP, and CMMC into one operational environment it’s how fast to do it before the deadline does it for them. 

About PROPLATE™ 

PROPLATE™ is the next-generation ERP platform built specifically for surface finishing operations. We unify NADCAP-aligned manufacturing controls, production management, and CMMC cybersecurity readiness in a single environment purpose-built for plating, anodizing, heat treatment, and chemical processing operations that supply aerospace and defense. Hosted on Microsoft Azure, delivered as a monthly subscription, and supported by a team with deep federal compliance experience. 

Ready to see how an integrated NADCAP + ERP + CMMC environment would work for your shop? 

Schedule a 20-minute demo → 

Download Now!

8 Proven Surface Finishing Techniques Every Professional Should Know