CMMC compliance

CMMC compliance: what still applies, after the pause.

CMMC compliance means holding the CMMC status your contract requires — Level 1, 2 or 3 — and affirming it annually. On 13 July 2026 the Department suspended Phase 2 of the rollout and every milestone after it, pending a reform review that reports in mid-September 2026. Phase 1 was not suspended. Neither was DFARS 252.204-7012, or the 110 NIST 800-171 requirements it imposes. This page sets out what CMMC is, what it requires, what the suspension actually did, and what a defense contractor should be doing between now and whatever comes next.

Last reviewed

CMMC at a glance

3
CMMC levels
15, 110 and 134 requirements
110
Requirements at Level 2
NIST SP 800-171 Rev 2
3 yrs
Certification validity
with annual affirmation
180
Days to close a POA&M
from a Conditional status

What is CMMC?

A verification program bolted onto a security requirement that already existed.

The Cybersecurity Maturity Model Certification is the Department’s program for verifying that companies in the defense industrial base actually implement the security requirements their contracts already impose. It does not, at Level 2, invent new requirements: it takes the 110 requirements of NIST SP 800-171 Revision 2 — binding through DFARS 252.204-7012 since 2017 — and attaches an assessment and a recorded status to them.

That distinction explains the whole program. For years, compliance was self-attested and rarely checked. Assessments by the government’s own assessment center found that self-reported scores and reality diverged sharply. CMMC is the response: same requirements, verified.

The program rule sits at 32 CFR part 170, effective 16 December 2024. The acquisition side — the clause that puts a CMMC requirement into a contract, DFARS 252.204-7021 — was published on 10 September 2025 and took effect on 10 November 2025, starting a phased rollout.

CMMC 2.0, and why the numbering confuses everyone

One program, two designs, and a lot of stale content in between.

The original model, announced in 2020, had five levels and included maturity processes as well as security practices. It was widely criticized as unworkable for small suppliers, and in November 2021 the Department replaced it with CMMC 2.0: three levels instead of five, no separate maturity processes, alignment to existing NIST standards rather than a bespoke practice set, and self-assessment permitted at the lower tiers.

What is in force today is that second design. “CMMC 2.0” and “CMMC” now describe the same program, and any page still explaining five levels, or referring to Level 4 and Level 5, predates November 2021 and should be disregarded entirely. It is a useful test to run on any CMMC advice you are reading: if it has five levels, it is at least five years out of date, and if it does not mention the July 2026 suspension it is at least a month out of date on the part that matters most right now.

Who needs CMMC compliance

Decided by the information on your systems, not by your size or your tier.

CMMC applies to every company in the DoD supply chain — prime contractors and subcontractors at every tier — that will process, store or transmit Federal Contract Information or Controlled Unclassified Information on its own systems in performance of a contract. Contracts solely for commercial off-the-shelf items are excluded.

There is no small-business exemption, and this is the point most under-communicated to the lower tiers. A five-person supplier that receives a technical data package by email holds CUI on its systems and carries the same 110 requirements as a company a thousand times its size. The scale of the assessment differs; the requirements do not.

Which level applies depends on the information: FCI only means Level 1, CUI means Level 2, and a small population of highest-priority programs means Level 3. For subcontractors, the level is set by what actually flows down to you — CMMC levels works through the decision in full.

CMMC requirements by level requirements

What each level asks for, and who checks.

LevelProtectsRequirementsAssessed byCadence
Level 1FCI15, from FAR 52.204-21SelfAnnual
Level 2CUI110, from NIST SP 800-171 Rev 2Self or C3PAO, per the contractEvery 3 years, affirmed annually
Level 3CUI, highest-priority programsLevel 2 plus 24 from NIST SP 800-172DCMA DIBCACEvery 3 years, affirmed annually

Per 32 CFR part 170. Status as at 23 August 2026.

The CMMC timeline, and the July 2026 suspension

The part of this subject that changed most recently, and the part most published advice now gets wrong.

The rollout was designed to phase in over three years from 10 November 2025:

  • Phase 1 — from 10 November 2025. Level 1 and Level 2 self-assessment requirements appear in applicable solicitations and contracts, with discretion for the Department to require Level 2 certification earlier.
  • Phase 2 — was to begin 10 November 2026. Level 2 C3PAO certification starts appearing as a condition of award.
  • Phase 3 — was to begin November 2027, adding Level 3 DIBCAC assessments.
  • Phase 4 — was to begin November 2028: full implementation across all applicable contracts.

On 13 July 2026 the Department suspended Phase 2 with immediate effect, together with the phases and milestones after it, and stood up a CMMC Reform Task Force to conduct a 60-day review of the program. A request for information gathered industry input, with responses due 14 August 2026, and the task force is due to report to the Chief Information Officer in mid-September 2026.

What that means in practice, as at 23 August 2026:

  • Phase 1 continues. Level 1 and Level 2 self-assessment requirements are in solicitations now, and the associated affirmations are due.
  • The 10 November 2026 certification date is gone unless and until it is reinstated. Nobody should be planning against it as a fixed deadline.
  • DFARS 252.204-7012 is unaffected. Adequate security, 72-hour incident reporting, cloud equivalency and flow-down remain contract terms.
  • The security baseline is not being lowered. The Department has been explicit that the review is about the cost and burden of certification, not about relaxing what has to be protected.

The reasonable planning assumption is that verification returns in some form, quite possibly cheaper and simpler, and that the 110 requirements are permanent. Treating the pause as cancellation is a bet on the Department deciding that CUI no longer needs protecting, which is not what it said and not what it is reviewing.

How to become CMMC compliant compliant

The sequence that holds whatever the task force recommends, because every step is owed under 7012 regardless.

  1. Establish your level
    From the information your contracts put on your systems, and from what the solicitation says. Where a contract is silent and CUI is plainly in play, plan for Level 2. See CMMC levels.
  2. Find the CUI and set the boundary
    Trace the real flow, then decide between an enclave and the whole estate. This single decision drives assessment cost, remediation cost and running cost together.
  3. Write the System Security Plan
    One entry per requirement: implementation, owner, evidence. Written first it is a plan; written last it is fiction, and assessors can tell.
  4. Self-assess, score, and post to SPRS
    Start at 110, deduct 5, 3 or 1 point per unimplemented requirement. Post honestly — the score is an attestation, visible to contracting officers and to the primes deciding whether to award you a subcontract. The CMMC compliance checklist sets out the steps.
  5. Close the heavy gaps first
    The 3- and 5-point requirements cannot be carried on a plan of action. Multi-factor authentication and FIPS-validated cryptography are the usual offenders.
  6. Prepare for assessment, and book early if certification returns
    Fewer than 100 C3PAOs serve the whole industrial base, and lead times ran to six to nine months before the pause. See the CMMC audit.
  7. Flow down, verify, and keep watching
    Pass the requirement to every subcontractor that touches covered information, confirm their status before award, and monitor what their networks look like between attestations.

CMMC certification does not stop at your perimeter

The obligation flows down. The visibility does not come back up.

A prime contractor is accountable for CMMC requirements reaching every tier of its supply chain, and for confirming that subcontractors hold the right status before award and affirm annually. What it is not given is any right to inspect them. The evidence that comes back is a self-attestation and, at best, a status recorded in a government system.

Both are photographs. A Level 2 status lasts three years; a self-assessment score describes the day it was calculated. In between, suppliers migrate systems, expose services during busy periods, let certificates expire, get acquired, and are breached — and none of that reaches the prime through the attestation process. It is not a paperwork failure. It is a design limitation of point-in-time assurance applied to a continuously changing thing.

Continuous external assessment is how that gap gets closed. RiskXchange rates suppliers from the outside — no questionnaire, no cooperation required — and reports when something changes: a new exposed service, an expiring certificate, infrastructure appearing where it should not be. It does not replace the flow-down obligation, which is contractual. It tells you when the thing you were relying on stopped being true.

For the mechanics, see supplier risk management and third-party risk management software.

CMMC compliance questions.

What is CMMC compliance?
Holding the CMMC status a DoD contract requires — Level 1, 2 or 3 — based on an assessment against that level’s security requirements, recorded in SPRS and affirmed annually by a named official.
Is CMMC still required in 2026?
Phase 1 requirements are, and they are in solicitations now: Level 1 and Level 2 self-assessments with annual affirmations. Phase 2, which would have begun requiring third-party certification from 10 November 2026, was suspended on 13 July 2026 together with the later phases, pending a reform review reporting in mid-September 2026. The underlying NIST 800-171 obligation under DFARS 252.204-7012 is unaffected.
What is the difference between CMMC and CMMC 2.0?
CMMC 2.0 is the redesign announced in November 2021 that replaced the original five-level model with three levels, dropped the separate maturity processes and aligned the requirements to existing NIST standards. It is what is in force today, so the two terms now mean the same thing.
How much does CMMC compliance cost?
The assessment fee at Level 2 commonly runs to tens of thousands of dollars and is driven by scope. Remediation is usually the larger figure and depends on your starting point. Reducing the number of systems that touch CUI lowers assessment, remediation and running costs at once.
Does CMMC apply to small businesses?
Yes. There is no small-business exemption. The level is set by the information you handle, not by headcount or contract value, so a small supplier holding CUI carries the same 110 requirements as a large one.
What should we do during the suspension?
Implement NIST 800-171. It is required by DFARS 252.204-7012 regardless of what the reform review recommends, it is the whole of Level 2, and it is the work that takes months. Companies that use the pause to implement will be ready for whatever verification returns; companies that use it to wait will not.

Certification paused. Your supply chain did not.

Book a 30-minute call and we will rate one of your CUI-handling subcontractors from the outside — the evidence a three-year certificate and an annual affirmation cannot give you.