Cybersecurity Assistance Program (SC-CAP) Phase 4
Why It Matters
CMMC May Be on Pause—But Cybersecurity Readiness Shouldn’t Be.
The Department of War’s suspension of the CMMC Phase II requirements has understandably raised questions across the Defense Industrial Base. While the timeline has shifted, one thing has not: cybersecurity remains a critical business requirement for manufacturers serving the defense supply chain. The pause is intended to allow additional review of implementation—not to eliminate the need for stronger cybersecurity practices.
For manufacturers, this is an opportunity—not a reason to wait.
Organizations that use this time to assess their current cybersecurity posture, address gaps, and begin building the processes required for compliance will be in a much stronger position when the program resumes. Delaying preparation can create unnecessary risk, compress implementation timelines, and make it more difficult to compete for future defense contracts.
At SCMEP, we’ve consistently encouraged manufacturers to view CMMC preparation as more than a compliance exercise. Strong cybersecurity protects intellectual property, strengthens customer confidence, reduces operational risk, and helps position companies for long-term growth—whether they currently serve the defense industry or hope to in the future.
That’s why we’re launching Phase 4 of our South Carolina Cybersecurity Assistance Program (SC-CAP4). The program is designed to help South Carolina manufacturers understand the requirements, evaluate their current state, prioritize improvements, and develop a practical roadmap toward CMMC Level 2 compliance.
The timeline may have shifted, but the destination has not. Manufacturers that invest in cybersecurity readiness today will be better prepared for tomorrow’s requirements—and more resilient regardless of when those requirements officially take effect.
For South Carolina Manufacturers
What is the Program?
The program provides funding and assistance for South Carolina manufacturers seeking to improve their cybersecurity and data security posture and to become compliant with CMMC Level 2 requirements.
Who should seek this certification?
Manufacturers with a physical location in SC for at least one year, and have at least four or more full-time employees.
How much does it cost?
Funds are available to cover between 80 and 85% of the costs for your company. Typical maximum investment will be around $8,000, significantly less in many cases. The purchase of hardware, software, or software subscriptions is not an eligible expense under this program.
How long does it take to complete?
Most companies will take about 3-6 months to complete the program. All work must be completed by June 30, 2027.
Successful Completion
This program is funded through the South Carolina Department of Commerce (SCDoC) and is being coordinated and delivered by the South Carolina Manufacturing Extension Partnership (SCMEP).
After successfully completing this program, your company will:
Questions? Need More Information?
For more detailed information, contact your SCMEP Regional Vice President.
Applications must be submitted via e-mail to sccap@scmep.org no later than 11:59pm on March 31, 2027.