By Cyber Defense Technologies September 22, 2026 5 min read
The Cybersecurity Maturity Model Certification (CMMC) program exists for one reason: to make sure the companies that support the Department of War (DoW) actually protect the sensitive information entrusted to them. For years, defense contractors self-attested to NIST SP 800-171 under DFARS 252.204-7012, and reviews repeatedly found that many had not implemented the requirements they claimed. CMMC adds verification, and it ties that verification to contract eligibility.
This guide explains the three levels, how assessments work, where the rollout stands today, and what a practical contractor should do next.
Two kinds of information, three levels
CMMC starts with the information you handle under a contract.
- Federal Contract Information (FCI) is information provided by or generated for the government under a contract that is not intended for public release. Almost every contractor handles some.
- Controlled Unclassified Information (CUI) is information that law, regulation or government policy requires to be safeguarded, such as controlled technical information, export-controlled data and many program documents.
The contract, not the contractor, determines which level applies.
The three CMMC levels
Level 1
Federal Contract Information (FCI)
- 15 basic safeguarding requirements (FAR 52.204-21)
- Annual self-assessment
- Annual affirmation in SPRS
Level 2
Controlled Unclassified Information (CUI)
- 110 requirements of NIST SP 800-171 Rev. 2
- Self-assessment or third-party (C3PAO) assessment every three years, as the contract specifies
- Annual affirmation in SPRS
Level 3
CUI facing advanced persistent threats
- Level 2, plus 24 requirements from NIST SP 800-172
- Government-led assessment (DIBCAC)
- Annual affirmation in SPRS
Level 1: basic safeguarding of FCI
Level 1 covers the 15 basic safeguarding requirements in FAR 52.204-21, such as limiting system access to authorized users, sanitizing media, and keeping malware protection current. Organizations perform an annual self-assessment and a senior official affirms compliance in the Supplier Performance Risk System (SPRS).
Level 2: protecting CUI
Level 2 aligns with the 110 security requirements of NIST SP 800-171 Revision 2. Depending on the contract, compliance is shown through a self-assessment or through an assessment by an authorized CMMC Third-Party Assessment Organization (C3PAO). Either way, scores are recorded, and a senior official affirms continued compliance every year.
Level 3: CUI facing advanced threats
Level 3 applies to a small number of programs where CUI is a priority target of advanced persistent threats. It requires a final Level 2 certification plus 24 selected requirements from NIST SP 800-172, assessed by the government through the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).
How the rollout has unfolded
The program rule, 32 CFR Part 170, took effect in December 2024 and defines the levels and assessment process. The acquisition rule that puts CMMC requirements into DoW contracts took effect on November 10, 2025, starting a planned four-phase rollout.
CMMC rollout milestones
-
December 16, 2024
Program rule takes effect
32 CFR Part 170 establishes the CMMC program, its levels and its assessment process.
-
November 10, 2025
Phase 1 begins
The DFARS acquisition rule takes effect. Solicitations can require Level 1 and Level 2 self-assessments.
-
July 13, 2026
Phase 2 suspended
The Department of War pauses the planned Level 2 third-party (C3PAO) requirements and launches a 60-day reform review.
-
Now
Phase 1 still in force
Self-assessments, SPRS scores and annual affirmations continue, as do DFARS 252.204-7012 obligations.
Phase 1 began on November 10, 2025. Solicitations can require Level 1 or Level 2 self-assessments as a condition of award.
Phase 2 was scheduled for November 10, 2026, when Level 2 third-party certification would have become a condition of award for many contracts involving CUI. On July 13, 2026, the Department suspended Phase 2, froze the later phases, and set up a CMMC Reform Task Force to review the program. The Department pointed to limited assessor capacity and the cost burden on small and midsize businesses. The task force's findings had not been made public at the time of writing, so contractors should watch for official announcements, class deviations or rule changes.
What the suspension did not change
It is easy to read "suspended" as "optional." That would be a mistake.
- DFARS 252.204-7012 still applies. If you handle covered defense information, you must implement NIST SP 800-171 and report cyber incidents within 72 hours.
- Phase 1 is still in force. Self-assessment requirements, SPRS scores and annual affirmations continue.
- Affirmations carry legal weight. A senior official affirming compliance that does not exist creates False Claims Act exposure. The Department of Justice has pursued cybersecurity cases under its Civil Cyber-Fraud Initiative.
- Primes still flow requirements down. Many prime contractors expect subcontractors to demonstrate compliance, regardless of the federal timeline.
- Government-led assessments continue. DIBCAC retains its authority to assess contractors.
How scoring works
Level 2 self-assessments use the DoD Assessment Methodology. You start at 110 points and deduct 5, 3 or 1 point for each requirement that is not met, depending on its weight. A score can go far below zero; what matters is that it is accurate.
Under the CMMC rule, a Level 2 assessment can end in conditional status only if the score is at least 88 and every open item is eligible for a Plan of Action and Milestones (POA&M). High-weight requirements such as multifactor authentication must be met on assessment day. Open POA&M items must be closed within 180 days.
A practical plan for contractors
Whatever the task force recommends, the work that protects CUI is the same. We recommend this sequence:
- Confirm what you handle. Identify FCI and CUI flows for each contract, including what primes and customers send you.
- Scope deliberately. Decide where CUI lives and draw a boundary around it. A smaller, well-defined enclave is cheaper to secure and assess.
- Assess honestly. Evaluate all 110 requirements against evidence, not intentions, and correct your SPRS score if it is wrong.
- Document as you go. Keep your System Security Plan (SSP) and POA&M current; assessors expect both to match reality.
- Close the high-weight gaps first. Multifactor authentication, incident response, encryption and access control carry the most weight and the most risk.
- Rehearse an assessment. A mock assessment exposes gaps in evidence as well as in controls.
If your contracts do not yet require CMMC, starting now still pays off. Implementation typically takes months, not weeks, and assessor availability will be tight once third-party requirements resume in whatever form.
Frequently asked questions
Do we need CMMC if we only handle FCI? If your contracts include FCI and require CMMC, you need Level 1: the 15 basic safeguarding requirements, an annual self-assessment and an affirmation.
Is NIST SP 800-171 Revision 3 required? The Department has kept Revision 2, with 110 requirements, as the baseline for DFARS 252.204-7012 and CMMC. Watch for official changes before shifting your program to Revision 3.
What should subcontractors do? Subcontractors that handle FCI or CUI generally have the same obligations, flowed down from the prime. Ask your primes what they require of you, and expect questionnaires and evidence requests.
How CDT can help
CDT's CMMC and NIST SP 800-171 readiness engagements take organizations from gap analysis to assessment-ready, including scoping, SSP and POA&M development, and technical remediation. For a quick first look, try our free CMMC readiness self-check.