AnalysisAnalysis

CMMC Requirements for Defense Contractors

CMMC self-assessments remain required during the certification rollout suspension. Contract terms determine the necessary safeguards, assessment status, and records.

ByMilitary Contractor Editorial
PublishedSeptember 7, 2026
Last checkedSeptember 7, 2026
Reading time10 minutes
A uniformed technician inspects equipment between server racks and bundles of network cables.
A Joint Interoperability Test Command technician inspects server equipment at Fort Huachuca, Arizona, in September 2024. This photograph illustrates system maintenance, not a contractor CMMC assessment. The appearance of U.S. Department of War (DoW) visual information does not imply or constitute DoW endorsement.

For a defense supplier, the immediate job is to identify the information it receives, define the systems handling it, implement the required safeguards, and maintain the corresponding records. The July suspension changes assessment implementation; it does not authorize contractors to stop protecting contract information.

On This Page

What the July 2026 suspension changes

Phase I began November 10, 2025. On July 13, 2026, the department suspended Phase II, previously scheduled for November 10, 2026, and announced a program review. Its current CMMC overview says implementation remains in Phase I, with Level 1 and Level 2 self-assessments and selected government-led assessments. An old rollout chart is therefore an unreliable basis for a purchasing or bid deadline. Current CMMC guidance

The implementing memorandum gives acquisition personnel specific instructions during the suspension:

  • Designate only Level 1 (Self) or Level 2 (Self) in procurement requirements.
  • Amend active solicitations that included Level 2 certified third-party assessment organization (C3PAO) or Level 3 Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) requirements.
  • Remove those requirements from existing contracts or agreements through a modification before the next option exercise or at the next scheduled administrative modification.

For an existing award, obtain the actual modification and confirm the resulting language with the contracting officer. Do not treat the announcement as an executed change to your contract. The memorandum preserves DFARS 252.204-7012 cybersecurity duties and says further guidance will follow the review. It does not provide a replacement Phase II start date. Implementation memorandum, attachment 1

Which contractors and systems need CMMC

Start with the solicitation and its amendments. DFARS 252.204-7025 identifies the required CMMC level and assessment type. It requires current status and an affirmation in the Supplier Performance Risk System (SPRS) before award for each relevant contractor information system. It also requires the offeror to provide the applicable CMMC unique identifiers in its proposal and update them when new identifiers are generated. DFARS 252.204-7025

The information determines the safeguarding problem:

  • Federal contract information (FCI) is nonpublic information provided by or generated for the government under a contract. Publicly released information and simple payment-processing information are excluded.
  • Controlled unclassified information (CUI) has safeguarding or dissemination controls grounded in law, regulation, or government-wide policy. A company document does not become CUI merely because someone considers it commercially sensitive.

CMMC concerns unclassified contractor systems. It does not replace requirements for classified work or personnel and facility security. The DFARS prescription excludes acquisitions solely for commercially available off-the-shelf (COTS) items; it does not exclude every commercial product or service. DFARS subpart 204.75

Subcontractors are part of this analysis. DFARS 252.204-7021 requires the substance of the clause to flow down when a subcontract requires processing, storing, or transmitting FCI or CUI, excluding COTS items. The flowdown includes paragraph (f) but excludes the prime's identifier-reporting provision in paragraph (e)(1). Before subcontract award, verify the appropriate current status. Match the level to the information actually passed down rather than automatically assigning every supplier the prime's level. DFARS 252.204-7021

Consider a hypothetical machine shop receiving nonpublic scheduling information for one job and controlled engineering drawings for another. The contracts manager should resolve the information designation and required assessment type for each job before IT assumes both can use the same environment. A useful first conversation includes contracts, engineering, IT, and the prime's supplier manager.

What Level 1 and Level 2 require

The two self-assessment paths differ in their safeguards and renewal cycle. The table describes current Phase I implementation, not a forecast of the program review's outcome.

RequirementLevel 1 (Self)Level 2 (Self)
Information protectedFCICUI
Safeguarding baseline15 requirements in FAR 52.204-21110 requirements in NIST SP 800-171 Revision 2
Assessment intervalAnnuallyEvery three years
Continuing-compliance affirmationAfter assessment and annuallyAfter assessment and annually thereafter
Conditional status using a plan of action and milestonesNot permittedLimited eligibility; closeout within 180 days

Source: official CMMC assessment overview, checked September 7, 2026. Assessment intervals do not replace continuous implementation.

Level 1 includes controlling authorized access, identifying and authenticating users, managing external connections, protecting public-facing systems, sanitizing media, controlling physical access, and maintaining malware protection and scanning. Visitor escort and physical-access logs also matter. A small office cannot reduce the requirement to installing antivirus software. FAR 52.204-21

Level 2 reaches further into how the business operates its systems. NIST SP 800-171 Revision 2 includes access control, training, audit records, configuration management, authentication, incident response, maintenance, media protection, personnel and physical security, risk assessment, security assessment, communications protection, and system integrity.

For example, requirement 3.5.3 calls for multifactor authentication for privileged local and network access and for nonprivileged network access. Requirement 3.13.11 requires FIPS-validated cryptography when cryptography protects CUI confidentiality. Requirement 3.12.4 requires a system security plan describing boundaries, operating environments, implementation, and connections. These are implementation obligations, not assurances satisfied by a product's marketing label. NIST SP 800-171 Revision 2

Revision 2 remains the baseline identified by current CMMC guidance. Do not silently substitute a newer NIST revision in the assessment workbook. The codified model also contains Level 3, adding 24 selected enhanced requirements from NIST SP 800-172 to Level 2. That model remains distinct from the suspension memorandum's instruction against designating Level 3 assessments during the review. 32 CFR 170.14

The records that support an assessment

An assessment needs a defined boundary. For Level 2, the asset inventory, network diagram, and system security plan must account for CUI assets and security-protection assets. Security infrastructure can be in scope even if it does not itself store CUI. Contractor risk-managed assets and specialized equipment have their own treatment; calling a machine “shop-floor equipment” does not establish that it is outside the boundary. 32 CFR 170.19

Organize the supporting material around questions a reviewer can answer:

QuestionMaterial to have ready
What environment was assessed?Scope description, asset inventory, network diagram, system security plan, and associated CAGE codes
How do controls work in practice?Relevant configurations, access records, training records, procedures, and evidence of recurring activities
What was concluded?Assessment results, score, status date, and permitted remediation items
Who owns shared responsibilities?Provider service description and customer responsibility matrix, tied to the system security plan
Who affirms continuing compliance?Authorized senior official and the SPRS affirmation record

This records checklist combines Level 2 assessment procedures, NIST requirements, and affirmation rules. It is not a substitute for assessing each applicable requirement.

Final Level 2 requires a MET result for every security requirement. SPRS entries include the level, status date, scope, associated Commercial and Government Entity (CAGE) codes, score, and applicable remediation status. Assess using NIST SP 800-171A's June 2018 procedures and CMMC scoring rules. Retain assessment evidence for six years from the CMMC status date. 32 CFR 170.16

The affirming official must be an authorized senior representative within the organization. Affirmation follows each assessment, including remediation closeout, and annually thereafter. Assign that responsibility explicitly and give the official current implementation evidence before submission. 32 CFR 170.22

Where readiness breaks down

The following are practical failure points implied by the requirements, not a ranking of measured assessment failures.

A score is mistaken for complete CMMC status

A current basic NIST SP 800-171 DoD assessment can be required under separate acquisition rules. An existing basic-assessment score is not, by itself, proof of the CMMC status and affirmation demanded by a solicitation. Have the contracts team check which requirements apply and verify the relevant SPRS entries before committing to an award date. DFARS 204.7302

The boundary omits outsourced services

For Level 2, a cloud service handling CUI must satisfy the applicable FedRAMP Moderate-or-higher authorization or equivalency requirements. A noncloud external provider's relevant services are assessed within the contractor's scope. The contractor's own connecting infrastructure and customer responsibilities still matter. Obtain the provider's service description and responsibility matrix before assuming a service transfers the entire obligation. 32 CFR 170.16

A remediation plan is treated as permission to defer any control

Level 1 permits no plan of action and milestones (POA&M). Conditional Level 2 requires a score of at least 80% of 110, or 88, plus restrictions on which unmet requirements may remain. The system security plan cannot be deferred. Most requirements worth more than one point are excluded, with a specific exception for implemented encryption that is not FIPS-validated. Several one-point requirements are also excluded, including listed public-information and physical-access safeguards.

Reaching 88 alone therefore does not establish eligibility. Each open item must qualify, and successful closeout must occur within 180 days of conditional status. Missing that deadline causes conditional status to expire. 32 CFR 170.21

Assessment preparation displaces incident readiness

DFARS 252.204-7012 separately requires rapid reporting of qualifying cyber incidents within 72 hours of discovery. It also requires preserving relevant system images and monitoring or packet-capture data for at least 90 days from report submission. Verify who can report, who can preserve the evidence, and what the service provider must supply. A current assessment does not perform those actions for the company. DFARS 252.204-7012

Status becomes stale during performance

DFARS 252.204-7021 requires the appropriate status throughout performance, current annual affirmations, and reporting of changed CMMC identifiers. A new business unit, platform, or data-handling arrangement warrants a scope review before covered information moves. Put assessment renewal, annual affirmation, and any conditional-status closeout on separate calendars. DFARS 252.204-7021

Before the next bid or option

Bring the amended solicitation or contract, information requirements, system boundary, and SPRS records into one review. Contracts should identify the required status; IT and security should demonstrate the corresponding implementation; supplier management should verify relevant flowdowns; and the affirming official should resolve discrepancies before signing.

The practical investment decision is which work the business can support within a defined, maintained environment. Use the Phase II suspension to correct scope and evidence gaps, while tracking the actual amendments and subsequent official guidance. Continue the safeguards and self-assessments that apply today.

Source notes

The CFR links reproduce the July 1, 2025 edition; current implementation is addressed separately by the official suspension guidance above.

Last checked: September 7, 2026.

Sources

These are the recoverable records used for this analysis. Dates describe the source record; access dates describe our verification pass.

  1. July 13, 2026 suspension announcementU.S. Department of War · Publication date not recorded · checked September 7, 2026
  2. Official CMMC overviewU.S. Department of War · Publication date not recorded · checked September 7, 2026
  3. Implementing Suspension of CMMC Phase IIU.S. Department of War · Publication date not recorded · checked September 7, 2026
  4. DFARS 252.204-7025Acquisition.gov · Publication date not recorded · checked September 7, 2026
  5. DFARS subpart 204.75Acquisition.gov · Publication date not recorded · checked September 7, 2026
  6. DFARS 252.204-7021Acquisition.gov · Publication date not recorded · checked September 7, 2026
  7. FAR 52.204-21Acquisition.gov · Publication date not recorded · checked September 7, 2026
  8. NIST SP 800-171 Revision 2National Institute of Standards and Technology · Publication date not recorded · checked September 7, 2026
  9. 32 CFR 170.14U.S. Government Publishing Office · Publication date not recorded · checked September 7, 2026
  10. 32 CFR 170.19U.S. Government Publishing Office · Publication date not recorded · checked September 7, 2026
  11. 32 CFR 170.16U.S. Government Publishing Office · Publication date not recorded · checked September 7, 2026
  12. 32 CFR 170.22U.S. Government Publishing Office · Publication date not recorded · checked September 7, 2026
  13. DFARS 204.7302Acquisition.gov · Publication date not recorded · checked September 7, 2026
  14. 32 CFR 170.21U.S. Government Publishing Office · Publication date not recorded · checked September 7, 2026
  15. DFARS 252.204-7012Acquisition.gov · Publication date not recorded · checked September 7, 2026