Construction and manufacturing firms are getting hit by ransomware at a rate that outpaces most other industries, and the regulatory picture that was supposed to force better defenses just got murkier. The Department of War suspended the next phase of CMMC 2.0 enforcement in July 2026, pulling back a deadline that was set to take effect this November. That does not mean the risk went away. It means the pressure to fix your security posture now comes from attackers instead of auditors.
Here is the direct answer: construction and manufacturing firms still face real ransomware exposure this year, and while CMMC 2.0's third-party certification requirement is paused for review, the underlying cybersecurity obligations under DFARS 252.204-7012 and NIST SP 800-171 have not gone anywhere. Waiting for the rule to settle is not a defensible strategy.
Construction firms run on fragmented networks. Project files spread across general contractors, subcontractors, and BIM platforms, often stitched together with minimal centralized security oversight and a job site network that changes every few months. Manufacturing adds operational technology to that mix, and a lot of plant floor equipment was never built with today's threat model in mind. Attackers know both facts, and they treat these sectors as softer targets than a bank or a hospital with a dedicated security team.
The Verizon 2025 Data Breach Investigations Report manufacturing snapshot found ransomware involved in 47 percent of confirmed manufacturing breaches, with malware-related incidents climbing to 66 percent of the sector's breaches this year. System intrusion is now the dominant attack pattern in manufacturing, showing up in 60 percent of breaches, more than double the rate of social engineering. Over 90 percent of the victim organizations in that data were small to mid-sized businesses, not the large multinationals people picture when they hear the phrase manufacturing breach.
Construction carries a version of the same problem without the OT layer. Every subcontractor, vendor, and cloud file share on a job site is a door into your network, and most construction firms do not have the IT headcount to lock all of them down. The FBI's 2025 Internet Crime Report lists critical manufacturing among the sectors most affected by the top ransomware variants tracked that year, alongside healthcare and government facilities, confirming that industrial and infrastructure-adjacent businesses are not incidental targets. They are a priority for ransomware crews because downtime on a job site or a production line creates urgency to pay.
None of this is limited to opportunistic file-encrypting malware picked up in a phishing email. The CISA StopRansomware initiative, run jointly with the FBI, NSA, and MS-ISAC, has published advisories tracking ransomware groups such as Royal, Black Basta, and Cuba specifically targeting manufacturing alongside healthcare, communications, and government facilities. These are organized groups that study which sectors pay fastest under pressure, and a company that cannot absorb a week of downtime on a production line or a job site is exactly the kind of leverage they look for.
The financial exposure is not abstract. IBM's research on data breach costs in the industrial sector puts the average breach at 5.56 million dollars, about 13 percent above the global average across all industries, and found that industrial organizations take longer than most to identify and contain an incident. The same research pegs unplanned downtime from an incident like ransomware at up to 125,000 dollars an hour once a production line stops. A ransomware event that locks scheduling software or shuts down a CNC line does not just cost a ransom. It costs the hours, the missed milestones, and the penalty clauses that come with them.
In July 2026, the Department of War suspended the CMMC Phase 2 requirements that were scheduled to take effect on November 10, 2026, and created a Reform Task Force to reassess the program. Phase 1 self-assessment requirements were not affected and remain in force. Contractors are not off the hook. They are working under the older rules while the government decides what the newer ones should look like, and that 60-day review clock puts a report on the Department's desk this September, so further changes could land with little warning.
According to the Department of War's own announcement, contractors handling covered defense information must continue to comply with NIST SP 800-171 Revision 2 through self-assessment and government-led review during this interim period, and the suspension does not eliminate the requirement for companies to protect federal data. DFARS clause 252.204-7012, the rule that actually obligates contractors to safeguard covered defense information and report incidents, was not touched. If your business has any exposure to a Department of War contract, that clause has applied to you since long before CMMC 2.0 existed, and it still does.
Yes. DFARS clause 252.204-7021 still requires prime contractors to flow the appropriate cybersecurity level down to every subcontractor touching federal contract information or controlled unclassified information, and primes are still expected to verify that status before awarding subcontracts. Nothing about the Phase 2 pause removes that obligation from your contract language. A prime that is nervous about its own compliance posture is not going to relax its vendor requirements while the rules are in flux. If anything, primes tend to over-comply during periods of regulatory uncertainty rather than under-comply.
NIST SP 800-171 lays out the actual security requirements behind all of this, covering access control, incident response, system monitoring, and a dozen other domains for any nonfederal system that touches controlled unclassified information. That is the standard your prime, or your prime's prime, is going to ask you to demonstrate against, whether the CMMC certification apparatus is fully active or on pause. Treating the pause as a green light to stop documenting your controls is the kind of decision that looks fine right up until an assessment request lands on your desk with a short deadline attached.
| Requirement | Status as of September 2026 | What it means for you |
|---|---|---|
| CMMC Phase 1 self-assessment | In effect | Still required for applicable contracts, documented and submitted through SPRS |
| CMMC Phase 2 third-party certification | Suspended, under review | No independent assessor required yet, but expect some version to return |
| DFARS 252.204-7012 | In effect, unchanged | You must safeguard covered defense information and report cyber incidents now |
| NIST SP 800-171 Rev 2 | In effect during the interim period | This is the control baseline assessors and primes will measure you against |
| Subcontractor flow-down, DFARS 252.204-7021 | In effect | Primes still must pass requirements to subcontractors and verify status |
Treat the regulatory pause as time to close gaps, not a reason to stop working on them. Ransomware groups are not waiting for the Reform Task Force to finish its review, and your existing obligations under DFARS 252.204-7012 have not moved. The businesses that use this window to document their controls and fix the gaps between OT and IT networks will be in a materially stronger position whenever the next phase of CMMC lands, whatever shape it takes.
Most construction and manufacturing firms do not have the in-house bandwidth to do this work properly on top of running the business. Segmenting OT networks, documenting controls against NIST SP 800-171, and preparing evidence for whatever CMMC ends up looking like after the Reform Task Force finishes is specialized work, and it competes for the same IT hours as help desk tickets and network maintenance. A managed partner that already understands compliance evidence, like Securafy's essential care managed IT and security services, can carry that load without you having to build an internal compliance team from scratch.
Yes, and the data backs that up regardless of Department of War exposure. Ransomware crews target construction and manufacturing firms because of how they operate, not because of who their end customer is, and the DBIR and IC3 data cited above cover the full sector, not just defense contractors. If you run a plant floor, manage job sites, or move project data between vendors, you have the exposure whether or not CMMC ever applies to you.
If you are trying to figure out whether your current IT provider is actually built for this kind of risk, or you are shopping for one that is, our cybersecurity buyer's guide walks through the questions to ask before you sign anything, including how a vendor handles incident response, OT segmentation, and compliance documentation. Do not take a vendor's word for it that they support your compliance requirements. Ask them to show you the last time they documented a control for a client in a situation like yours.
The rule around CMMC 2.0 will settle eventually, and when it does, contractors who spent this window improving their actual security posture will clear it faster than contractors who spent it waiting to see what happens. Ransomware does not check the Federal Register before it targets your job site or your production floor. Treat the two problems as connected, because from an attacker's perspective, and increasingly from a prime contractor's perspective, they already are.
The CMMC 2.0 timeline is paused, but the ransomware activity hitting construction and manufacturing firms is not, and closing that gap starts with knowing exactly where your environment stands today.
If your team is moving faster with AI than your guardrails are, start with structured training rather than another tool. Securafy AI University gives your people role-based AI training with security built into the material, not bolted on afterward.
If you would rather talk through your specific environment first, book a strategy call with Securafy and we will walk your current AI usage, exposure, and the fastest path to safe adoption.