What Is CMMC in Cyber Security and What DoD Suppliers Should Know
CMMC in cyber security is the U.S. Department of Defense program that verifies defense contractors and subcontractors actually protect the sensitive government information they handle. The program applies one standardized set of cybersecurity requirements across the Defense Industrial Base (DIB), sorts those requirements into three levels, and ties a specific level to a contract as a condition of award.
The current status matters as much as the definition. CMMC Level 1 and Level 2 self-assessments are live requirements today. The Department suspended CMMC Phase II, the phase that would have made third-party certification a condition of award, on July 13, 2026. The underlying security obligations in your contract did not move.
Below we cover what CMMC protects, how the three levels work, how CMMC relates to NIST, which contract clauses actually carry the obligation, what the suspension changed, who falls in scope, the implementation timeline, who performs assessments, and what DoD suppliers should be doing right now.
What Is CMMC in Cyber Security?
CMMC in cyber security is a certification framework that verifies Department of Defense contractors have implemented the cybersecurity requirements their contracts already impose. The framework does not invent new security controls. It takes control sets that federal regulation already required, groups them into levels, and adds a verification step so the government can confirm implementation instead of taking a supplier's word for it.
That verification step exists because self-attestation alone produced uneven results. Inspector general audits and DoD assessments found suppliers attesting to standards they had not implemented, which is the gap CMMC was built to close. Closing that gap matters at scale: the Defense Industrial Base consists of over 220,000 companies that process, store, or transmit sensitive federal data, according to the DoD CMMC Model Overview. Those 220,000 companies include roughly 212,657 unique prime contractors and 8,309 known unique subcontractors in Federal Procurement Data System records.
The threat driving the program is quantified in the same DoD documentation. Malicious cyber activity cost the U.S. economy between $57 billion and $109 billion in 2016, according to the White House Council of Economic Advisers, and the Center for Strategic and International Studies put the total global cost of cybercrime as high as $600 billion in 2017. Attackers target the lower tiers of the supply chain specifically because smaller subcontractors hold the same design data as the primes with a fraction of the security budget. We walk suppliers through CMMC certification from that starting point, because the level you need follows from the data you hold.
What Does CMMC Stand For in Cyber Security?
CMMC stands for Cybersecurity Maturity Model Certification. Each word carries weight. "Cybersecurity" identifies the subject matter, "Maturity Model" describes the tiered structure where each level represents deeper implementation, and "Certification" names the verification outcome. The program is administered by the DoD Chief Information Officer with the Office of the Under Secretary of Defense for Acquisition and Sustainment, which led the model's development.
One naming note that trips people up in 2026 documents: the Department of Defense is now referred to in many federal communications as the Department of War (DoW). The acronym CMMC did not change, the program did not change hands, and contract clauses still read the same. Only the department name in newer memoranda differs.
What Is CMMC 2.0?
CMMC 2.0 is the streamlined version of the program that reduced the original five maturity levels down to three and dropped the CMMC-specific practices that had no basis in existing federal standards. The original 2019 model layered custom maturity processes on top of federal requirements, which made compliance expensive without making data measurably safer. CMMC 2.0 stripped those custom processes out and aligned every level directly to published NIST standards and the Federal Acquisition Regulation.
Alignment to published standards is what makes the model predictable. A supplier reading CMMC Level 2 is reading NIST SP 800-171 Rev 2, nothing more and nothing different. That predictability starts with knowing which categories of information the program covers.
What Information Does CMMC Protect?
CMMC protects two categories of unclassified information: Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Every other decision in the program follows from which of these two categories your systems touch. Your required level, your assessment type, your assessment scope, and your cost all trace back to this one determination.
Federal Contract Information is information provided by or generated for the government under a contract to develop or deliver a product or service, and not intended for public release. FCI is defined in 48 CFR 4.1901 and 32 CFR 170.4. Controlled Unclassified Information is information the government creates or possesses that a law, regulation, or governmentwide policy requires to be safeguarded, defined in 32 CFR 2002.4. CUI in the defense context covers material like technical drawings, engineering specifications, and export-controlled research data.
What Is the Difference Between FCI and CUI?
The difference between FCI and CUI is sensitivity and the volume of controls each triggers. FCI is the broader, lower-sensitivity category and triggers 15 basic safeguarding requirements. CUI is the narrower, higher-sensitivity category and triggers 110 security requirements. A purchase order, a delivery schedule, and a statement of work are typically FCI. A controlled technical drawing of a component you machine for a weapons platform is CUI.
Sensitivity drives the control count, and the control count drives everything a supplier spends. This is why the first hour of any CMMC engagement goes into data classification rather than technology. A supplier who assumes CUI when they only hold FCI buys an assessment path seven times more expensive than the one their contract requires.
Does CMMC Only Apply to CUI?
No, CMMC does not apply only to CUI. CMMC applies to FCI as well, through Level 1. Any contractor whose information system processes, stores, or transmits FCI under a Department of Defense contract falls within the program even if no CUI ever touches their network.
This catches a large population of small suppliers off guard. A company machining simple brackets with no controlled drawings still receives purchase orders, delivery instructions, and quality requirements from a prime. That material is FCI, and FCI puts the company at Level 1. The requirement tiers make the distinction concrete.
What Are the Three CMMC Levels?
The three CMMC levels are Level 1 Foundational, Level 2 Advanced, and Level 3 Expert, and each level maps to a specific published standard and a specific assessment method. The table below draws its requirement counts from the DoD CMMC Model Overview and its clause references from the Federal Acquisition Regulation and the Defense Federal Acquisition Regulation Supplement.
CMMC LevelFocusData ProtectedRequirementsSource StandardAssessment TypeLevel 1 FoundationalBasic safeguardingFCI only15 requirementsFAR 52.240-93, formerly 52.204-21Annual self-assessment plus annual affirmationLevel 2 AdvancedIntermediate protectionCUI110 requirementsNIST SP 800-171 Rev 2, via DFARS 252.204-7012Triennial self-assessment or C3PAO certification, plus annual affirmationLevel 3 ExpertAdvanced persistent threat protectionCUI in high-priority programs110 plus 24 selected enhanced requirementsNIST SP 800-172, with DoD-approved parametersTriennial government-led DIBCAC assessment
The 24 enhanced requirements at Level 3 are itemized as items (i) through (xxiv) in Table 1 to 32 CFR 170.14(c)(4), and a Final Level 2 certification is a prerequisite before a Level 3 assessment can happen. One figure in the Level 1 row deserves a clarification, since published summaries disagree on it. FAR 52.240-93 contains 15 security requirements, and those 15 requirements map to 17 controls in NIST SP 800-171. Sources citing 17 are counting the NIST mapping rather than the clause itself. Both numbers describe the same obligation.
What Are the Differences Between CMMC Level 1 and Level 2?
The differences between CMMC Level 1 and Level 2 are the data type, the requirement count, the assessment frequency, and who performs the assessment. Level 1 covers FCI with 15 requirements, self-assessed annually. Level 2 covers CUI with 110 requirements, assessed every three years either by the contractor or by a certified third party, with an annual affirmation in the intervening years.
Assessment frequency creates a practical difference that catches suppliers out. A Level 1 self-assessment is a yearly event that a small team can complete internally. A Level 2 environment carries 110 requirements across every system that touches CUI, which usually means segmentation work, encryption work, logging infrastructure, and documentation that did not previously exist. Suppliers moving from Level 1 to Level 2 frequently need advanced security tooling they have never operated before.
What Are the DoD CMMC Requirements for Contractors?
The DoD CMMC requirements for contractors are to determine the level their contract specifies, implement every security requirement at that level, assess implementation through the method the level prescribes, post the result where the government can see it, and affirm continued compliance annually through a senior official.
That last element carries more weight than most suppliers realize. A senior official signs the affirmation personally. The signature is a representation to the federal government about the state of a network, which converts a technical exercise into a legal one. The requirements themselves come from standards published outside the CMMC program.
Are NIST and CMMC the Same?
No, NIST and CMMC are not the same. NIST writes the security requirements, and CMMC verifies that contractors implemented them. The National Institute of Standards and Technology publishes SP 800-171 and SP 800-172, which catalog the controls. The Department of Defense built CMMC as the assessment and certification layer that confirms those controls are in place before a contract is awarded.
The assessment layer inherits the NIST structure wholesale. The CMMC model consists of 14 domains that align directly with the security requirement families defined in NIST SP 800-171 Rev 2:
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
These 14 domains give every requirement a stable address. A requirement identifier reads as domain, level, and source reference, so AC.L2-3.1.5 is the Access Control domain, Level 2, drawn from NIST SP 800-171 Rev 2 requirement 3.1.5. Anyone working through NIST compliance is already working through the CMMC model, whether or not they call it that.
Is NIST 800-53 the Same as CMMC?
No, NIST 800-53 is not the same as CMMC, and the two apply to different organizations. NIST SP 800-53 is the control catalog for federal information systems operated by government agencies and by cloud providers seeking federal authorization. CMMC Level 2 draws on NIST SP 800-171 Rev 2, a separate publication written specifically for nonfederal systems that hold CUI.
SP 800-171 exists because SP 800-53 was written for federal agencies and does not translate cleanly to a 40-person machine shop. NIST derived the 110 requirements in SP 800-171 from the SP 800-53 catalog, then trimmed away everything that only a federal agency could implement. A contractor meeting SP 800-171 is meeting a purpose-built subset, not a lighter version of the same document.
What Is the Difference Between ITAR and CMMC?
The difference between ITAR and CMMC is that ITAR governs who may access defense technical data, and CMMC governs how well that data is secured. The International Traffic in Arms Regulations (ITAR) restrict the export and the disclosure of defense articles and technical data to foreign persons. CMMC sets and verifies the cybersecurity controls protecting the systems that hold such data.
Both regimes frequently land on the same supplier at the same time, and they reinforce each other. ITAR restricts access by nationality, while CMMC requirements like access control, media protection, and boundary protection are the mechanisms that make that restriction enforceable on a network. Neither regime, however, is what puts the obligation into your contract. Contract clauses do that.
What Are the Cybersecurity Requirements for DoD Contractors?
The cybersecurity requirements for DoD contractors live in contract clauses, and they consist of FAR 52.240-93 for FCI, DFARS clause 252.204-7012 for CUI, a current NIST SP 800-171 self-assessment score posted in SPRS, and an annual affirmation of continued compliance. These four obligations attach through the contract itself, which means they operate independently of any CMMC certification status.
Clause numbering shifted in 2026 and a great deal of published material has not caught up. Effective February 1, 2026, under the Revolutionary FAR Overhaul, FAR clause 52.204-21 was renumbered to FAR 52.240-93. The clause title and the 15 requirements are unchanged, and it still flows down to subcontractors. On the defense side, DFARS provision 252.204-7019 was eliminated and DFARS clause 252.204-7020 was renumbered to 252.240-7997. DFARS 252.204-7012 and 252.204-7021 were not changed. Suppliers reviewing a solicitation against an old clause checklist will find numbers that no longer exist, which is a common failure point in government contract compliance reviews.
What Is a SPRS Score?
A SPRS score is the numeric result of a NIST SP 800-171 self-assessment, posted to the Supplier Performance Risk System where contracting officers can see it. Scores run from a floor of -203 to a maximum of 110. Every requirement not fully implemented deducts 5, 3, or 1 points depending on how much risk that gap creates, and the methodology is binary, so partial implementation counts as not implemented.
A score of 110 means all 110 requirements are fully implemented. There is no universal pass mark, and contracting officers set thresholds at their discretion, commonly at 80, 100, or 110. The score is visible on every solicitation a company bids, which makes it a competitive number as well as a compliance number. It is also the number the government can test later.
Is CMMC Required Now?
Yes, CMMC is required now at Level 1 and Level 2 through self-assessment, and the third-party certification requirement is suspended. Phase 1 of implementation took effect on November 10, 2025, making Level 1 and Level 2 self-assessments a condition of award on new Department of Defense contracts that carry a CMMC requirement. That phase remains fully in force.
Suppliers hearing "CMMC is paused" and standing down are making an expensive mistake. Phase 1 conditions awards today. Program managers can currently designate CMMC Level 1 Self or CMMC Level 2 Self in new solicitations, which means self-assessment is the operative path for more contracts rather than fewer. Our managed compliance clients treat the current period as implementation time, not idle time.
Is CMMC Phase 2 Suspended?
Yes, CMMC Phase 2 is suspended. The Department of War announced the immediate suspension of Phase II requirements on July 13, 2026, through two memoranda issued by the Chief Information Officer. Phase II had been scheduled to take effect on November 10, 2026, and would have made third-party certification by a C3PAO a condition of award for most contracts involving CUI. Pending and future implementation milestones, including Phases 3 and 4, were suspended alongside it.
What the suspension did not touch is the more important half of the announcement. Phase 1 self-assessments continue. DFARS 252.204-7012 continues. NIST SP 800-171 Rev 2 implementation continues. SPRS score postings continue. Annual affirmations continue. The Department paused one verification mechanism and left every underlying security obligation intact.
Why Was CMMC Phase 2 Suspended?
CMMC Phase 2 was suspended because the Department concluded that third-party assessment costs and administrative burdens were discouraging small, medium, and nontraditional businesses from competing for defense work. The Department's own published estimates support that conclusion. In the Regulatory Impact Analysis behind the CMMC program final rule at 32 CFR Part 170, DoD modeled a Level 1 self-assessment and affirmation at roughly $6,000 for a small entity, a Level 2 self-assessment cycle at approximately $37,000, and a Level 2 certification assessment cycle at approximately $105,000 over three years.
Those figures assume the security controls are already implemented, so they measure the cost of proving compliance rather than achieving it. Alongside the suspension, the Department established a CMMC Reform Task Force and gave it a 60-day review, informed by a public Request for Information whose comment period closed on August 14, 2026. The task force delivers recommendations to the Chief Information Officer, and recommendations alone change nothing. Only a class deviation, a DFARS rule change, or an amendment to 32 CFR Part 170 changes the law.
Is CMMC Required for DoD Contracts?
Yes, CMMC is required for DoD contracts above the micro-purchase threshold where a contractor or subcontractor processes, stores, or transmits FCI or CUI on its information system. The solicitation states the required level explicitly, and meeting that level is a condition of award. Contracts exclusively for commercially available off-the-shelf items are exempt, and there is no general exception for commercial product or commercial service contracts.
Requirement level and assessment method are two separate questions, and only the assessment method moved in July 2026. The level still appears in the solicitation, and the self-assessment still gates the award.
Is DoD Enforcing CMMC for Defense Tech Vendors?
Yes, DoD is enforcing CMMC for defense tech vendors, and the enforcement mechanism is the accuracy of what a supplier represents rather than the certification itself. A SPRS score is an affirmative representation to the federal government. When the score a company posts overstates what is actually implemented, the difference becomes evidence of a false claim, and False Claims Act exposure carries treble damages and per-claim penalties.
The suspension of third-party assessment increases this exposure rather than reducing it, for a straightforward reason. Self-assessment is now the only mechanism operating, and self-assessment is where score inflation happens. The C3PAO assessment was, among other things, the control that would have caught an overstated self-assessment before the government did. The Department of Justice has continued settling defense cybersecurity fraud cases throughout the review period, including one matter where a contractor posted a self-assessed score of 110 and a later government-led assessment scored the same environment at -170.
Survey data shows how wide that representation gap runs across the industry. The 2026 State of the Defense Industrial Base Report from CyberSheath and Merrill Research, based on 302 contractors surveyed in May 2026, found the average SPRS score climbed to a five-year high of +51, up from +33 in 2025. Confidence in the accuracy of those same scores fell to 65 percent, down from 89 percent in 2025 and 94 percent in 2024. Scores rose while trust in the scores fell.
A separate Kiteworks survey of 273 defense contractors taken in the days after the suspension found 96 percent confident their self-attested SPRS score would hold up under review, while only 29 percent could point to both a current SPRS submission and an authorized platform. In the same survey, 84 percent reported concern about False Claims Act liability. This pattern is visible up close in North Alabama, where the density of Redstone Arsenal suppliers means a single prime's subcontractor tier can carry dozens of companies each holding the same technical data. Suppliers who want to see how the pieces fit together can start with how contractors meet federal cybersecurity rules in practice. Exposure follows the data, and the data also determines who falls in scope.
Who Is Required to Comply With CMMC?
Any contractor or subcontractor at any tier that processes, stores, or transmits FCI or CUI on its information system under a Department of Defense contract is required to comply with CMMC. Company size does not matter. Contract value matters only through the micro-purchase threshold. Position in the supply chain does not exempt anyone.
Scope determination starts with data, not with organizational charts. A two-person engineering firm holding a controlled drawing sits at Level 2. A 500-person distributor handling only purchase orders sits at Level 1. We build compliance programs from that determination outward, because a scope that is wrong at the start is wrong in every downstream document.
Which Companies Need to Be CMMC Certified?
Companies that need to be CMMC certified are those whose Department of Defense solicitations specify a CMMC level and whose systems handle FCI or CUI in performing that work. Defense manufacturers, engineering and research firms, IT and professional services providers, logistics and distribution suppliers, and higher education institutions performing contracted research all fall inside the program.
Manufacturers carry a distinctive complication, because shop-floor equipment often sits on the same flat network as the engineering workstations holding controlled drawings. Programmable machine controllers, inspection systems, and older equipment that cannot be patched all land inside the assessment boundary unless the network is segmented first. That segmentation work drives much of the effort in manufacturing compliance projects.
Does CMMC Flow Down to Subcontractors?
Yes, CMMC flows down to subcontractors, and it flows to every tier of the supply chain. A subcontract is subject to the CMMC level that matches the sensitivity of the information the subcontractor will actually handle in performing that subcontract. Prime contractors bear responsibility for confirming that their subcontractors hold a current self-assessment or certification at the appropriate level before flowing work down.
Flow-down is where the commercial pressure lands hardest. Kiteworks found that 38 percent of surveyed contractors lost or were disqualified from a contract over CMMC Level 2 requirements, and the burden fell unevenly: Tier 2 and lower subcontractors reported bid losses at 55 percent, nearly double the 31 percent rate among primes. Primes enforce ahead of the government because their own eligibility depends on the tiers beneath them.
Is CMMC Just for DoD?
Yes, CMMC is currently just for DoD contractors and subcontractors, and no formal rulemaking has extended the program to other federal agencies. Civilian agencies have not adopted CMMC as a condition of award.
The broader direction of travel points elsewhere, though. A governmentwide CUI rule is proceeding through the Revolutionary FAR Overhaul rulemaking under new FAR Part 40, which consolidates information security and supply chain security requirements across all agencies. That rulemaking is entirely separate from the CMMC Phase II suspension and was unaffected by it. Contractors working across both defense and civilian agencies get no relief from a CMMC pause.
What Is the Timeline for Implementing the CMMC Rule?
The timeline for implementing the CMMC rule was a four-phase rollout over three years beginning November 10, 2025, with Phase 1 currently in force and Phases 2, 3, and 4 suspended as of July 13, 2026. The phases were designed to widen the requirement gradually rather than apply it to every contract at once.
- Phase 1, effective November 10, 2025 and currently in force. CMMC Level 1 and Level 2 self-assessments became a condition of award for new contracts carrying a CMMC requirement. A limited number of contracts could require Level 2 C3PAO assessments at the Department's discretion.
- Phase 2, scheduled for November 10, 2026 and now suspended. The Department would have begun adding Level 2 certification requirements to applicable contracts, with Level 3 requirements appearing in a limited number at its discretion.
- Phase 3, scheduled for November 10, 2027 and now suspended. Level 2 certification requirements would have extended to existing contracts, and Level 3 certification would have been required on applicable contracts.
- Phase 4, scheduled for November 10, 2028 and now suspended. CMMC would have applied to all Department contracts above the micro-purchase threshold involving FCI or CUI, including options exercised on active contracts.
Contracts that were not awarded or extended during the phased rollout were always going to pick up CMMC requirements upon award or extension, which is why the schedule never functioned as a deadline a supplier could wait out. Anyone rebuilding their plan around the current status should start from the CMMC requirements that remain in force rather than the phases that do not.
What Is the Final Rule for CMMC in 48 CFR?
The final rule for CMMC in 48 CFR is the Defense Federal Acquisition Regulation Supplement rule under DFARS Case 2019-D041, titled Assessing Contractor Implementation of Cybersecurity Requirements, published September 10, 2025 and effective November 10, 2025. This is the acquisition rule that puts CMMC requirements into contracts.
Two rules govern the program and people mix them up constantly. The 48 CFR rule is the contracting mechanism. The program rule at 32 CFR Part 170, published October 15, 2024, defines the model itself: the levels, the requirements, the assessment procedures, and the scoping guidance. The 32 CFR rule says what CMMC is. The 48 CFR rule says how it reaches your contract. Neither rule was repealed in July 2026, which is why the suspension is a policy pause rather than a regulatory change.
Who Performs CMMC Audits?
CMMC audits are performed by three parties depending on level: the contractor itself for self-assessments, an accredited CMMC Third-Party Assessment Organization (C3PAO) for Level 2 certification assessments, and the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) for Level 3. The Cyber AB maintains a public marketplace of authorized C3PAOs, Certified CMMC Assessors, Certified CMMC Professionals, and registered practitioner organizations.
Self-assessment is a permitted and currently primary path, which corrects a persistent misstatement in older reference material. Some published sources still claim CMMC does not permit self-certification. That was accurate under the original 2019 model and has not been accurate since CMMC 2.0 introduced the self-assessment path for Level 1 and for a portion of Level 2.
During the suspension, the assessment infrastructure remains operational. SPRS and eMASS continue to run, C3PAO assessments are still being performed for organizations that want them, and existing certifications remain valid and still post to SPRS. What is paused is the Department's ability to require a C3PAO assessment in new solicitations. One structural rule is worth knowing before hiring anyone: the program bars ecosystem members from assessing an organization they consulted for within the previous three years, so readiness work and certification assessment must be purchased from different firms. That separation shapes how a supplier should sequence a compliance audit and the preparation leading into it.
What DoD Suppliers Should Do During the CMMC Pause
DoD suppliers should use the pause to implement controls rather than to postpone work, because every task that matters under the current rules matters under any outcome the Reform Task Force produces. The Department has been explicit that it is removing an assessment mechanism, not lowering the security standard. NIST SP 800-171 survives every plausible reform scenario.
Five pieces of work hold their value regardless of what the task force recommends. Finish the CUI scoping so you know where controlled data lives and how it flows. Implement the NIST SP 800-171 requirements that DFARS 252.204-7012 already obligates you to meet. Re-run the self-assessment against actual evidence and correct the SPRS score if it overstates reality, because a corrected score is a commercial problem while an uncorrected overstatement is a legal one. Keep the system security plan current and the plan of action dated. Keep collecting evidence continuously rather than assembling it in a panic before an assessment.
One budgeting caution deserves attention during a pause. Cybersecurity staff hired against a November 2026 deadline get reassigned or leave when the deadline evaporates, and the capability has to be rebuilt from scratch when the timeline resumes. Separate certification-specific spending from control-implementation spending before pausing either, and pause only the first. Across Huntsville and the surrounding defense corridor, the suppliers who kept implementing through the review period are the ones who will be assessable whenever the requirement returns.
How Do You Reduce CMMC Assessment Scope?
You reduce CMMC assessment scope by isolating CUI into a defined enclave rather than allowing it to spread across the whole network. A supplier who confines controlled data to a segmented environment with controlled access points brings far fewer systems into the assessment boundary than one whose CUI sits on a flat network shared with general business operations.
Scope determines cost more than any other single variable. Every system inside the boundary carries all 110 requirements, so a workstation that touches a controlled drawing once a quarter costs as much to assess as the primary engineering server. A proper gap analysis begins with the boundary drawing, since assessing the wrong boundary produces the right answer to the wrong question.
How Long Does CMMC Certification Take?
CMMC certification takes 12 to 18 months for full implementation and audit readiness at Level 2 for most organizations starting from a partially implemented environment. Suppliers with mature security programs move faster, and suppliers starting from an unsegmented network with no documentation take longer.
The duration comes from sequence rather than effort. Scoping has to precede remediation, remediation has to precede documentation, documentation has to precede evidence collection, and evidence collection has to run long enough to demonstrate the controls operate continuously rather than on assessment day. That sequence cannot be compressed by adding people to it. Suppliers who wait for a solicitation to appear before starting have already lost the contract, which is precisely why the current pause is the most valuable preparation window the industry has had. Our audit defense work begins long before an assessor is scheduled.
Frequently Asked Questions
How Long Is a CMMC Certification Valid?
A CMMC certification is valid for three years, with an annual affirmation of continued compliance required in each intervening year. Level 1 differs, requiring a fresh self-assessment and affirmation every year. A self-assessment is considered current if it is not more than three years old, unless the solicitation specifies a shorter window.
What Happens If You Fail a CMMC Assessment?
If you fail a CMMC assessment, you may receive Conditional certification status if the remaining gaps qualify for a plan of action, or you restart the assessment process entirely if they do not. Conditional status requires closing every listed deficiency within 180 days of the final findings briefing. Deficiencies remaining after 180 days cause the Conditional certification to be revoked.
What Is a POA&M in CMMC?
A POA&M in CMMC is a Plan of Action and Milestones, the document that identifies unmet security requirements and tracks the specific actions, owners, and dates for closing them. CMMC Level 2 requires this document directly through requirement CA.L2-3.12.2. A POA&M with stale dates and no closure evidence is worse than no document, because it records a gap the organization knew about and left open.
Can You Use a POA&M to Pass a CMMC Assessment?
You can use a POA&M to pass a CMMC assessment only for a limited set of lower-weighted requirements, and only with a minimum score threshold met. The highest-weighted requirements, worth 5 points each, cannot sit on a plan of action. A POA&M buys 180 days to close the gap, not permission to leave it open.
Can a Subcontractor Have a Lower CMMC Level Than the Prime?
Yes, a subcontractor can have a lower CMMC level than the prime when the subcontractor handles less sensitive information. The level follows the data that actually flows down in that subcontract. A prime at Level 2 handling CUI may flow only FCI to a distribution subcontractor, which puts that subcontractor at Level 1.
Does CMMC Apply to Commercial Off-the-Shelf Suppliers?
No, CMMC does not apply to contracts exclusively for commercially available off-the-shelf items. COTS-only contracts are expressly exempt from CMMC requirements. The exemption covers the contract type rather than the company, so a supplier selling COTS products under one contract and performing custom engineering under another falls inside the program through the second contract.
What Is the Micro-Purchase Threshold for CMMC?
The micro-purchase threshold for CMMC is the dollar value below which contracts do not carry CMMC requirements, as defined in the Federal Acquisition Regulation. Contracts above that threshold where a contractor processes, stores, or transmits FCI or CUI carry a CMMC level, with COTS-only contracts excepted. The threshold is adjusted periodically for inflation, so the current figure should be confirmed against the solicitation.
The Bottom Line
CMMC is the verification layer over cybersecurity requirements that your Department of Defense contract already imposes. Level 1 covers FCI with 15 requirements, Level 2 covers CUI with 110 requirements drawn from NIST SP 800-171 Rev 2, and Level 3 adds 24 enhanced requirements for the most sensitive programs. Phase 1 self-assessments have conditioned awards since November 10, 2025 and remain in force. Phase II third-party certification is suspended as of July 13, 2026 while a reform task force reviews the program.
The suspension changed when certification arrives, not what a supplier owes. DFARS 252.204-7012, NIST SP 800-171 implementation, an accurate SPRS score, and the annual affirmation all still bind, and the accuracy of what you attest is where the real exposure sits. Suppliers who spend this window scoping their CUI, implementing controls, and correcting their score will be ready under any outcome the task force produces. Suppliers who treat it as dead time will be rebuilding under a deadline.
We have spent over 20 years helping Huntsville-area organizations weave technology into a compliant infrastructure, with Certified CMMC Assessors and Certified CMMC Professionals leading the process from assessment through continuous compliance. If you would like a clear picture of where your organization stands and what it would take to close the distance, the team at Interweave Technologies is glad to talk it through. You can reach us at (256) 837-2300.
.webp)
.webp)



.webp)





Share Post