Status: CMMC program status, reviewed July 25, 2026: On July 13, 2026, DoD announced the immediate suspension of CMMC Phase II requirements, which had been scheduled to begin November 10, 2026. All Phase I self-assessment requirements remain firmly in place - Level 1 and Level 2 self-assessments, with results and affirmations in SPRS, are still conditions of award in covered contracts. The program remains codified at 32 CFR Part 170, and NIST SP 800-171 protection of CUI is still contractually required under DFARS 252.204-7012 regardless of CMMC's rollout schedule. Source: DoD CIO.

What Is CMMC and Why It Matters

The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense program that verifies contractors and subcontractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). It is codified at 32 CFR Part 170, published as a final rule on October 15, 2024 (89 FR 83214), and applied to contracts through DFARS clause 252.204-7021.

CMMC is not guidance and not optional. If your organization does business with the DoD, or supports a prime contractor in the defense supply chain, CMMC determines whether you can bid on or retain covered contracts.

One thing changed recently, and it matters. The rollout is partially paused: Phase II, the stage that would have made third-party certification a condition of award, was suspended on July 13, 2026. Phase I self-assessment requirements remain firmly in place. The status note on this page has the details.

What It Is

CMMC does not invent new security controls. It verifies requirements that already exist in defense contracts, and it adds three things: defined assessment levels, required assessments, and a signed affirmation of compliance filed in the Supplier Performance Risk System (SPRS).

Under CMMC 2.0 there are three levels:

  • Level 1 (Foundational): basic safeguarding of FCI - the 15 requirements of FAR 52.204-21. An annual self-assessment with results in SPRS, plus an affirmation. 32 CFR 170.15 permits no POA&Ms at Level 1 - every requirement must be met.
  • Level 2 (Advanced): protection of CUI through the security requirements of NIST SP 800-171. Depending on the contract, a self-assessment or a certification assessment by a C3PAO (an authorized third-party assessment organization). New third-party certification requirements are currently suspended with Phase II; Level 2 self-assessments continue.
  • Level 3 (Expert): enhanced requirements drawn from NIST SP 800-172 for the highest-risk programs, assessed by the government (DIBCAC). Rare, and limited to critical programs.

Most defense contractors that handle CUI fall under Level 2 - that is what the level is scoped to (32 CFR 170.17).

In short: NIST SP 800-171 defines the controls. CMMC verifies and enforces them.

Who It Applies To

CMMC applies to every organization in the DoD supply chain that handles FCI or CUI, including:

  • Prime defense contractors: the direct award holders whose contracts carry the clause.
  • Subcontractors and suppliers: requirements flow down the chain with the data.
  • Manufacturers and engineering firms: drawings, specs, and test data are exactly what CUI covers.
  • IT, MSP, SaaS, and cloud providers supporting DoD work: if your systems touch covered data, you are in scope.
  • Professional services firms handling defense-related data: legal, accounting, logistics, and consulting included.

Company size does not matter. If you handle covered DoD information, CMMC applies.

What Information Is Regulated

CMMC protects two data types, and the distinction drives your level.

Federal Contract Information (FCI) is information provided by or generated for the government under a contract and not intended for public release. FCI triggers Level 1.

Controlled Unclassified Information (CUI) is sensitive government information that requires safeguarding under law, regulation, or government-wide policy. CUI triggers Level 2 and includes:

  • Technical drawings and specifications: the engineering core of most defense work.
  • Export-controlled data: technical data that also sits under ITAR or EAR jurisdiction.
  • Defense-related intellectual property: designs, processes, and research tied to DoD programs.
  • Operational and logistics data: schedules, quantities, and movement information.
  • Certain personal and financial data: where tied to defense programs.

From an IT perspective, CUI rarely sits in one system. It lives across email, file storage, endpoints, cloud platforms, and vendor systems - which is why scoping is where most CMMC efforts succeed or fail.

Relation to Other Frameworks

CMMC sits at the end of a chain that starts with the data itself:

  • **CUI Program:** defines what data requires protection.
  • NIST SP 800-171: defines how that data must be protected.
  • **DFARS 252.204-7012:** makes that protection a binding contract obligation.
  • CMMC: verifies and enforces it through assessment and affirmation.

CUI is the what. NIST defines the how. DFARS and CMMC enforce it.

The Phase II suspension paused the certification tier, not the chain. Contractors still owe full NIST SP 800-171 implementation under DFARS 252.204-7012 today, exactly as before.

CMMC also builds on FAR 52.204-21 for basic FCI safeguarding, and it runs parallel to ITAR, which controls who may access export-controlled technical data rather than how systems are secured.

IT Requirements

CMMC is control-heavy, technical, and evidence-driven. The requirement areas:

  • Access control and identity: role-based access, least-privilege permissions, multi-factor authentication, secure remote access, and account monitoring and reviews.
  • Asset and data management: inventory of systems and users, identification of systems handling CUI, data flow documentation, and secure storage and transmission.
  • System and endpoint security: secure configurations, endpoint protection, patch and vulnerability management, and malware protection.
  • Logging, monitoring, and incident response: audit logging, monitoring for security events, incident response plans, and cyber incident reporting to DoD within the 72-hour window DFARS 252.204-7012 sets.
  • Configuration and change management: baseline configurations, controlled changes, and documented modifications.
  • Vendor and supply chain risk: identifying vendors with CUI access, flowing requirements down to subcontractors, and holding them accountable.
  • Policies, procedures, and evidence: written policies, implemented procedures, and technical proof - screenshots, logs, and configurations.

Controls must exist and be provable. Two paperwork mechanics carry legal weight. First, a senior official affirms compliance in SPRS annually and after every assessment (32 CFR 170.22). Second, POA&Ms are restricted: none are permitted at Level 1, and at Levels 2 and 3 they are limited to select requirements and must close out within 180 days (32 CFR 170.21).

Why It Matters

Failure to meet CMMC requirements can result in:

  • Ineligibility for DoD contracts: the required CMMC status is a condition of award where the clause applies.
  • Loss of existing work and contract termination: the obligation continues through performance, not just at bid.
  • Legal exposure for false affirmations: an SPRS affirmation that overstates compliance is a legal risk, not a formality. /* ⚖️ COUNSEL - FCA framing; fact-check flags legal-risk claims for counsel review before publish */
  • Reputational damage and supply chain scrutiny: primes increasingly audit their subs.

Most CMMC failures share the same causes: poor scoping of CUI, weak MFA or access controls, missing documentation, over-reliance on informal processes, and assuming IT vendors handle compliance. None of these are exotic. All of them are fixable before an assessment instead of during one.

How It Fits Into Cyber Risk Management

CMMC aligns closely with the NIST Cybersecurity Framework, NIST SP 800-53, ISO 27001, and SOC 2. The control language differs; the fundamentals do not.

Organizations that implement CMMC well typically see real improvements in overall security posture, not just compliance readiness. The work you do for CMMC is the same work that stops ransomware and passes insurance reviews.

How We Help With CMMC Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment maps your environment against NIST SP 800-171 and the 32 CFR Part 170 assessment criteria, so your SPRS score and affirmation rest on evidence.

How to Prepare

  1. 01Determine your CMMC level and scope

    Identify the level your contracts require, which contracts are affected, which systems handle FCI or CUI, and which vendors are in scope. Scoping errors here cascade into everything downstream.

  2. 02Perform a CMMC readiness and gap assessment

    Evaluate control implementation, documentation gaps, technical weaknesses, and evidence availability. This step prevents failed assessments and inaccurate SPRS scores later.

  3. 03Implement and harden required controls

    Focus on MFA and access management, secure configurations, endpoint and email security, logging and monitoring, and incident response readiness. These areas decide most assessments.

  4. 04Build documentation and evidence

    Prepare policies and procedures, a System Security Plan (SSP), and evidence artifacts. Where POA&Ms are permitted, use them correctly: none at Level 1, time-limited with a 180-day closeout at Level 2 (32 CFR 170.21).

  5. 05Prepare for assessment and affirmation

    Confirm controls are consistently enforced, evidence is current, staff understand the processes, and vendors meet flow-down requirements. The affirmation a senior official signs should be one they can defend.

Frequently Asked Questions

Does CMMC apply to my business?

If you hold DoD contracts or support a prime contractor, and you handle Federal Contract Information or Controlled Unclassified Information, yes. Company size does not matter, and outsourcing IT does not transfer the obligation. The contract clauses tell you definitively - look for DFARS 252.204-7012, 7019, 7020, and 7021.

Is CMMC still being enforced after the July 2026 suspension?

Partially, and the distinction matters. Phase I remains fully in effect: Level 1 and Level 2 self-assessments, SPRS submissions, and affirmations are still conditions of award in covered contracts. What is suspended is Phase II - the rollout of third-party C3PAO certification requirements - while DoD reviews the program. NIST SP 800-171 protection of CUI is still required under DFARS 252.204-7012 regardless.

What CMMC level do we need?

It depends on the data. Handling only FCI points to Level 1. Handling CUI points to Level 2, which is where most contractors with CUI land. Level 3 is limited to the highest-risk programs and is government-assessed. Your contracts and your data inventory determine it - not your preference.

What is the difference between CMMC and NIST SP 800-171?

NIST SP 800-171 is the control set - the specific security requirements for protecting CUI. CMMC is the verification program that assesses whether you actually implemented them. You have owed 800-171 under DFARS 252.204-7012 since before CMMC existed; CMMC adds the checking.

Can we use POA&Ms to close gaps after assessment?

Only within limits. 32 CFR Part 170 permits no POA&Ms at Level 1 - every requirement must be met. At Level 2, POA&Ms are allowed only for select requirements and must be closed out within 180 days. A POA&M is a short bridge, not a parking lot.

What is the SPRS affirmation and why does it matter?

A senior company official affirms in the Supplier Performance Risk System that your organization is compliant with its CMMC requirements, annually and after each assessment. It is a signed representation to the government. If it overstates your compliance, it becomes a legal problem, not a paperwork problem.

What does CMMC compliance cost?

It depends on your current posture, your CUI footprint, and your level. We publish no pricing - you get a firm quote before any work begins, and the conversation costs nothing. The assessment tells you the real scope before you spend on remediation.

Where do we start?

Start by finding your CUI - what it is, where it lives, and who touches it. Then get a gap assessment against NIST SP 800-171 before an assessor or a prime does it for you. Our Cyber Risk & Compliance Gap Assessment is built for exactly that first step.

CMMC in Florida

Defense work is not remote from the Treasure Coast - it surrounds it. The corridor running from the Space Coast's launch, avionics, and defense electronics operations south through the Treasure Coast's aviation and precision manufacturing base puts DoD primes, subcontractors, and specialty shops within an hour of our Hobe Sound office. Many are small firms holding flowed-down DFARS clauses they have never fully scoped. /* FLAG: named-employer specifics (e.g., individual primes or installations) intentionally omitted - would need a qualifying source before naming */

Florida also adds a state notification layer on top of federal incident reporting. The Florida Information Protection Act (F.S. 501.171) requires notice to affected individuals no later than 30 days after determining a breach of personal information. Breaches affecting 500 or more Florida residents must also be reported to the Florida Department of Legal Affairs within the same 30 days, with one 15-day extension available on written request. Third-party agents - including IT providers - are required by the statute to notify the covered entity within 10 days of determining a breach.

Those clocks run separately from the 72-hour DoD cyber incident report under DFARS 252.204-7012. A breach at a Florida defense contractor can start both timers on the same day.

Official source

Official source: DoD CIO, CMMC Program

Secondary source: eCFR, 32 CFR Part 170

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25