If you run a plating, anodizing, heat treatment, or chemical processing shop that supplies the aerospace or defense industry, the next twelve months will reshape your business whether you’re ready or not.
November 10, 2026 isn’t a date most surface finishing shop owners have circled on the wall. But it should be. It’s the day CMMC Phase 2 enforcement begins, which means third-party cybersecurity certification not self-attestation becomes mandatory for contractors handling Controlled Unclassified Information (CUI).
Pair that with the steady tightening of NADCAP audit expectations, and you have something that hasn’t existed before in this industry: two parallel compliance frameworks, on the same shop floor, on the same timeline, with the same downside if either one fails.
Most shops are treating these as separate problems. That’s the mistake. Here’s why.
CMMC 2.0 the Cybersecurity Maturity Model Certification is now an enforceable contract requirement, not a future concern. The Department of Defense formalized it in DFARS in late 2025, and the rollout is happening in four phases:
The number that should keep you up at night: industry surveys suggest only about 1% of the 220,000+ defense contractors are fully prepared for Phase 2. That number actually dropped from 4% in 2025 and 8% in 2023 preparation is moving backwards while the deadline closes in.
Here’s the part most surface finishing shops miss: you don’t need to be a direct DoD contractor for this to hit you. If you supply a prime Lockheed Martin, Boeing, Northrop, Raytheon they’re already requiring your CMMC status documented in SPRS (the Supplier Performance Risk System). Lockheed has been pushing this down to suppliers ahead of the deadline. A prime’s demand can arrive well before any DoD solicitation does.
If you handle CUI and most aerospace platers, anodizers, and heat treaters do, because part drawings and specifications are CUI by default you need Level 2 certification. That means implementing all 110 security controls from NIST SP 800-171, documenting them in a System Security Plan (SSP), and passing a C3PAO audit.
With roughly 80 authorized C3PAOs and 80,000 contractors needing Level 2 certification, the math is brutal. C3PAO availability is already constrained. By Q3 2026, wait times for assessments will stretch past 12–18 months for shops that wait too long to start.
NADCAP the aerospace industry’s accreditation program for special processes has been the dominant quality standard in surface finishing for decades. If you do plating, anodizing, heat treating, or chemical processing for aerospace, you’re either NADCAP-accredited or you’re locked out of meaningful work.
The audit criteria for chemical processing (AC7108) and heat treating require granular documentation: every process step, every tank chemistry pull, every cycle log, every operator training record, every piece of equipment calibration evidence. Auditors don’t just want to know that you have processes they want to see proof, traceable to the part level, of every special process performed.
NADCAP audits in 2026 are getting more rigorous, not less. The Performance Review Institute has been tightening interpretations, and the most common audit non-conformances continue to cluster around documentation gaps, traceability failures, and inconsistent process control. The audits are also more expensive when you fail them every non conformance extends your audit time, costs you the auditor’s day rate, and delays your accreditation renewal.
Here’s the uncomfortable overlap that nobody’s writing about: NADCAP wants you to document everything about your processes, and CMMC wants you to secure all of that documentation.
Same data. Two compliance frameworks. Most shops are handling them with two completely separate systems paper travelers and quality binders on one side, a bolted-on cybersecurity tool on the other. That’s expensive, fragile, and audit-hostile.
Walk into a typical small aerospace finishing shop today and you’ll see roughly this stack:
When CMMC Phase 2 hits in November 2026, this stack breaks in three ways:
Meanwhile, your NADCAP audit prep continues to consume two to three weeks of senior staff time, twice a year, because nothing is connected.
It’s not a sustainable model. And it’s not the model that will win aerospace and defense work in 2027 and beyond.
The shops that will come out ahead are the ones treating NADCAP, ERP, and CMMC as a single integrated environment instead of three separate initiatives.
Here’s what that looks like in practice:
That’s the model PROPLATE was built for. We didn’t add CMMC readiness as a bolt-on we built the platform from the ground up to unify manufacturing discipline (NADCAP), production management (ERP), and cybersecurity maturity (CMMC/RMF) in one environment. Process integrity and information security advance together.
If you take nothing else from this article, here’s the minimum sequence:
1. Conduct a CMMC gap assessment in the next 60 days. Not a vendor sales pitch an actual evaluation of where you stand against the 110 NIST 800-171 controls. Most small shops are at 30–50% compliance without realizing it.
2. Inventory where CUI lives in your environment. Part drawings, specifications, customer communications, ITAR-controlled data. If you don’t know where it is, you can’t protect it. Auditors will ask this first.
3. Document your current production and quality processes in a way that maps to both NADCAP traceability AND CMMC audit accountability. If you’re rebuilding documentation anyway for NADCAP renewal, do it once and make it serve both frameworks.
4. Engage a C3PAO early to get on their calendar. Wait times are already stretching. By late 2026 they will be brutal. Get in line now.
5. Evaluate whether your current production system can actually support what’s coming. If your ERP can’t generate the access logs, audit trails, and traceability records needed for both NADCAP and CMMC, you’re going to be retrofitting under deadline pressure the most expensive possible time to do it.
Compliance fatigue is real in this industry. NADCAP renewals, ISO audits, AS9100 surveillance, customer-specific quality requirements the documentation burden never stops growing. CMMC is the newest layer, and for many shop owners, it feels like one more thing eating into margin and time.
But here’s the strategic read: every supplier who can’t meet CMMC Phase 2 will lose DoD-tied work. That work doesn’t disappear it consolidates into the suppliers who can meet it. The shops who treat 2026 as an inflection point, not an obstacle, will absorb the market share that their less-prepared competitors leave on the table.
The infrastructure to do this exists. The timeline to install it doesn’t stretch forever. The question every aerospace finishing supplier needs to ask isn’t whether to integrate NADCAP, ERP, and CMMC into one operational environment it’s how fast to do it before the deadline does it for them.
PROPLATE™ is the next-generation ERP platform built specifically for surface finishing operations. We unify NADCAP-aligned manufacturing controls, production management, and CMMC cybersecurity readiness in a single environment purpose-built for plating, anodizing, heat treatment, and chemical processing operations that supply aerospace and defense. Hosted on Microsoft Azure, delivered as a monthly subscription, and supported by a team with deep federal compliance experience.
Ready to see how an integrated NADCAP + ERP + CMMC environment would work for your shop?