When Is CMMC Required and What Defense Contractors Should Do Now
CMMC is required now. Phase 1 took effect on November 10, 2025, and since that date contracting officers have been writing Level 1 and Level 2 self-assessment requirements into applicable solicitations as a condition of award.
Then July 13, 2026 happened, and a lot of contractors stopped work on their compliance programs. The Department of War suspended Phase 2, and the message that traveled through the defense industrial base was some version of CMMC is off.
It is not off. And the most damaging version of this misreading is a simple mix-up of two terms that sound alike and mean completely different things. Phase 2 was suspended. Level 2 was not. Those are not the same thing, and confusing them is how a contractor talks itself out of eligibility for its next award.
This article covers when CMMC applies, what the suspension actually changed, what Level 2 requires, and what to do with the months between now and whatever the review produces.
When Is CMMC Required?
CMMC is required now, for any DoD contract above the micro-purchase threshold where you process, store, or transmit Federal Contract Information or Controlled Unclassified Information. The only carve-out is contracts solely for commercial off-the-shelf items.
Two rules put it there. The 32 CFR Part 170 program rule was published October 15, 2024 and took effect December 16, 2024, establishing the levels, scoring, and assessment methods. The 48 CFR acquisition rule was published September 10, 2025 and took effect November 10, 2025, giving contracting officers the authority to write CMMC into solicitations through DFARS provision 252.204-7025 and clause 252.204-7021.
Under the current posture, contracting officers may require a Level 1 self-assessment or a Level 2 self-assessment as a condition of award. Results go into the Supplier Performance Risk System before award, option exercise, or extension, and a senior official affirms them annually. DFARS 204.7503(b) still directs contracting officers to verify CMMC status in SPRS before award.
The honest framing is this. Your deadline was never a date on the government's rollout calendar. It is the date your next solicitation, option exercise, or prime flow-down asks for a status. That date did not move on July 13, and for most contractors it is closer than the phase schedule ever was.
When Did CMMC Go Into Effect?
CMMC went into effect on November 10, 2025, when the acquisition rule became enforceable and Phase 1 began. The obligations underneath it are much older.
- December 2017. DFARS 252.204-7012 required implementation of the 110 controls in NIST SP 800-171 for any system handling covered defense information. Everything CMMC verifies has been contractually required since this date.
- December 16, 2024. The 32 CFR Part 170 program rule took effect, defining levels, scoring, POA&M rules, and affirmation requirements.
- November 10, 2025. The 48 CFR acquisition rule took effect and Phase 1 began. CMMC became a condition of award.
- July 13, 2026. The Department of War suspended the transition to Phase 2, along with pending and future implementation milestones.
That first date is the one contractors forget. CMMC did not create the security requirements. It created the verification layer on top of requirements that have been binding for nearly a decade, which is why the suspension of a verification mechanism changes so much less than it appears to.
Is CMMC Level 2 Suspended?
No, CMMC Level 2 is not suspended. Phase 2 was suspended, and Phase 2 and Level 2 are entirely different things. This is the single most consequential mix-up in the defense industrial base right now.
Phase 2 is a stage in the rollout calendar. It was scheduled for November 10, 2026, and it would have expanded the number of contracts requiring a third-party assessment by a Certified Third-Party Assessment Organization.
Level 2 is a security tier. It applies to any contractor handling CUI and requires the 110 requirements in NIST SP 800-171 Revision 2. It has nothing to do with the calendar.
Suspending a phase of the rollout does not remove the safeguards or the contract clauses requiring them. Level 2 self-assessments are still being required as conditions of award today. What paused was one method of verifying Level 2, not Level 2 itself.
The Department has been direct about this. Under Secretary of War for Acquisition and Sustainment Michael Duffey said the Department is not relaxing the standards and expects businesses to adhere to what NIST has outlined, describing what is being removed as the bureaucracy of third-party assessment. CIO Kirsten Davies framed the goal as focusing on tangible cyber hygiene rather than third-party certifications.
What Did the July 2026 Suspension Actually Change?
The suspension paused mandatory third-party assessment as a condition of award and froze all remaining implementation milestones, and it changed nothing else. Contracting officers may not require a C3PAO Level 2 assessment or a DIBCAC Level 3 assessment for new solicitations during the review, and active solicitations carrying those requirements are being amended.
Phases 3 and 4 are frozen as well. A CMMC Reform Task Force is conducting a top-to-bottom review, informed by a public Request for Information, and will deliver recommendations to the DoW CIO within 60 days, on or about September 13, 2026.
What remains fully in force:
- Phase 1 self-assessments. Level 1 and Level 2 Self requirements continue as conditions of award.
- DFARS 252.204-7012. Untouched, including 72-hour incident reporting to DIBNet and mandatory flow-down to subcontractors.
- All 110 NIST SP 800-171 Rev 2 controls. The Department has said it will enforce this standard through self-assessments and select government-led assessments during the interim.
- SPRS reporting and annual affirmations. Signed by a named senior affirming official, and subject to enforcement.
- False Claims Act exposure. The Department of Justice's cyber-fraud enforcement did not pause.
- Existing contract clauses. Enforceable as written until formally modified. Until your contract is amended, the clause on it is still the clause on it.
- Cloud requirements. Services holding CUI must still meet the FedRAMP Moderate baseline under DFARS 7012.
The table below separates what is paused from what is not, as the position stands in August 2026 under the DoW CIO memorandum and the underlying rules.
Requirement
Status now
Authority
Level 1 self-assessment
Required
32 CFR 170; FAR 52.204-21
Level 2 self-assessment
Required
32 CFR 170; NIST SP 800-171 Rev 2
Level 2 C3PAO certification
Suspended as a condition of award; available voluntarily
DoW CIO memo, July 13, 2026
Level 3 DIBCAC assessment
Suspended
DoW CIO memo, July 13, 2026
NIST SP 800-171 implementation
Required
DFARS 252.204-7012
SPRS score and annual affirmation
Required
DFARS 252.204-7019, 7020; 204.7503(b)
72-hour incident reporting
Required
DFARS 252.204-7012
FedRAMP Moderate cloud services
Required
DFARS 252.204-7012
Subcontractor flow-down
Required
DFARS 252.204-7012; prime contract terms
The suspension arrived as a memorandum, not a regulation. 32 CFR Part 170 is still law and DFARS 252.204-7021 is still in the code. A memorandum changes what contracting officers may require, and it can be reversed as quickly as it was signed.
Contractors who dismantle their government contracting compliance programs during this window are betting on an outcome nobody has seen yet.
The safer read is that the cybersecurity rules underneath CMMC have been stable for nine years and are the part least likely to change, whatever the Task Force recommends about how they get verified.
Why the Pause Increases Your Legal Risk
Removing third-party assessment removes the independent expert who used to check your math before the government saw it, which concentrates the legal exposure onto your own affirmation. The risk did not disappear. It moved.
Consider the mechanics. The CMMC Level 2 Self tab in SPRS records each control you mark as met. A senior official affirms it. SPRS retains that record for years, and it is directly available to investigators pursuing False Claims Act cases. Under Phase 2, a C3PAO would have reviewed those markings against evidence before they carried contractual weight. Now nothing sits between an optimistic internal judgment and a signed federal representation.
Enforcement is climbing while this happens. The Department of Justice recovered $52 million across nine cybersecurity False Claims Act settlements in fiscal year 2025, part of a record $6.8 billion in total FCA recoveries. Analysis by the firm Fluet found the aggregate value of 2025 cyber settlements rose 233% over 2024.
The case worth studying happened here. In June 2026 the Department of Justice announced that a Huntsville defense contractor agreed to pay $507,144 to resolve False Claims Act allegations. The company had posted a perfect SPRS score of 110 in October 2021. A DIBCAC assessment in February 2024 scored the same systems at negative 170. There was no breach and no whistleblower; the case came out of a government assessment.
Nothing about that scenario requires Phase 2 to exist. It requires only a score that does not match reality and an invoice submitted against a contract that asked for one. A documented gap analysis against actual evidence is what keeps the two numbers the same.
What Is CMMC Level 2 and Who Needs It?
CMMC Level 2 is the security tier for any contractor that processes, stores, or transmits Controlled Unclassified Information under a defense contract. If CUI touches your systems, Level 2 is your level.
CUI covers export-controlled technical data, engineering drawings, manufacturing specifications, cybersecurity vulnerability information, and operationally sensitive program details. Federal Contract Information is the lighter category, covering non-public information provided or generated under a contract, and it maps to Level 1.
Level 1 requires 15 basic safeguarding controls from FAR 52.204-21, an annual self-assessment, and an annual affirmation. POA&Ms are not permitted at Level 1, so all 15 controls must be fully implemented at the time of assessment.
Level 3 sits at the top, covering the most sensitive CUI on critical programs. It requires the 110 Level 2 controls plus 24 enhanced controls from NIST SP 800-172, for 134 in total, verified by DIBCAC. That assessment path is currently suspended along with the rest of the phase schedule.
Most contractors land at Level 2, and the practical work is deciding what falls inside your assessment boundary. Scope is the strongest cost lever in the entire program, and a narrow, well-segmented CUI environment is meaningfully cheaper to secure and evidence than an open corporate network.
How Many Controls Are in CMMC Level 2?
CMMC Level 2 requires 110 security controls from NIST SP 800-171 Revision 2, measured against 320 assessment objectives. The controls are the requirements; the objectives are the individual determinations an assessor makes to decide whether each control is met.
That distinction explains why contractors who believe they are close often are not. A single control can carry several assessment objectives, and missing any one of them means the control is not met. There is no partial credit.
The 110 controls span 14 families: access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.
Scoring runs from 110 down to negative 203. You start at 110 and subtract 5, 3, or 1 points per unmet control based on its security weight. A score of 88, which is 80% of the total, is the threshold for a conditional status with a POA&M, and every POA&M item must close within 180 days. Certain critical controls cannot go on a POA&M at all.
When Will CMMC Level 2 Certification Be Required?
No date currently exists for mandatory third-party Level 2 certification, because the Reform Task Force review has not concluded. The November 10, 2026 date is gone, and no replacement has been published.
Three outcomes are plausible. The Department restores third-party certification on a new schedule. It replaces certification with a different verification model, which the RFI language about optimizing self-attestation suggests is under active consideration. Or it keeps the current self-assessment posture indefinitely.
What every outcome shares is the 110 controls. Interim enforcement is tied to NIST SP 800-171 Rev 2, and an interim final rule defining the eventual transition to Revision 3 is in the final rulemaking stage per the 2026 Unified Regulatory Agenda. Contractors building to Rev 2 today are building to the standard that survives all three scenarios.
One requirement worth tracking separately: the government-wide FAR CUI rule is a distinct rulemaking that the CMMC suspension does not touch. As drafted it applies on finalization without a phase-in period, which means it could reach contractors faster than any CMMC restart.
Can You Still Get CMMC Certified Right Now?
Yes, voluntary Level 2 certification remains fully available. The Cyber AB confirmed in July 2026 that the entire ecosystem stays operational: C3PAOs remain authorized to conduct Level 2 certification assessments, issue certificates, and record them for publication to SPRS, alongside continued training, professional exams, Registered Practitioner services, and DIBCAC's oversight of C3PAOs.
Existing certifications keep their full value. As of the Cyber AB's May 2026 town hall, 1,391 Final Level 2 certificates had been issued, and nothing about the suspension invalidates any of them.
What changed is the reason to pursue one. No DoW contract can require certification during the suspension, so a voluntary assessment now serves two purposes instead: satisfying prime contractors who continue to set their own supplier requirements, and strengthening your position against False Claims Act exposure by putting independent verification behind your affirmation.
For most small contractors the sensible move is not to cancel a scheduled engagement but to convert it. A mock assessment or readiness review delivers the same gap-finding value at lower cost and keeps the relationship warm for whenever certification returns. Review your C3PAO and vendor agreements for deferral and refund terms while you still have leverage, because that market is about to consolidate.
What Happens if You Stop Preparing?
Stopping compliance work during the suspension creates contract risk immediately and cost risk later. Seven consequences follow, and none of them wait for the Task Force.
- DFARS obligations still apply. Your 7012 duties never depended on the CMMC schedule.
- Primes keep asking. Flow-down is a private contract between two companies and does not move when a federal memorandum does.
- An inaccurate SPRS score is still a representation. Government-led assessments continue during the interim.
- Your CUI stays exposed. Adversaries did not observe the pause.
- Future solicitations may carry revised requirements. Nobody knows their shape yet.
- You lose competitive standing. Contractors who can evidence compliance move through prime qualification faster than those who cannot.
- Restarting costs more than continuing. Unwinding and rebuilding a CUI enclave is more expensive than maintaining one.
That last point is the one finance teams miss. Compliance decays quietly. Configurations drift, staff turn over, documentation ages, and a program left idle for a year does not resume where it stopped. It resumes several months behind where it stopped, which is why continuous CMMC compliance support costs less over a contract cycle than stopping and restarting.
What Should Defense Contractors Do Right Now?
Defense contractors should use this window to close gaps, verify their scores against real evidence, and get answers in writing from their contracting officers and primes. Nine steps, in the order they pay off.
- Verify your SPRS scores against evidence. Recheck each control marking on both the NIST 800-171 tab and the CMMC Level 2 Self tab against what is actually implemented, not what is planned.
- Confirm your contract requirements in writing. Ask your contracting officer what applies to your specific awards. Until a contract is modified, its clauses stand.
- Ask your primes what they still expect. Many will continue requiring evidence regardless of the federal schedule. Get the answer documented.
- Map your CUI environment. Identify every employee, system, application, device, and service provider with access. A tight scope is cheaper to secure and faster to evidence.
- Validate your NIST 800-171 implementation. Assess each requirement on current state, and treat a risk assessment as the input to remediation priority rather than a document to file.
- Update your system security plan. An accurate system security plan is the foundation of both self-assessment and any future third-party assessment, and an outdated one is the fastest way to lose credibility with an assessor.
- Collect and organize evidence. Policies alone prove nothing. Logs, screenshots, configurations, training records, and review reports are what a compliance audit actually examines.
- Check your cloud services. Every service holding CUI must meet the FedRAMP Moderate baseline or documented equivalency under DFARS 7012. This obligation is entirely independent of the CMMC pause.
- Keep closing POA&M items on schedule. Documented progress holds value under every outcome the Task Force might recommend.
One time-limited item worth acting on: responses to the DoW Request for Information are due August 14, 2026. The Department is specifically asking which cost drivers are most prohibitive and which controls deliver the most real risk reduction. Small and mid-size contractors are the population most affected and the least likely to file. If compliance costs have materially hit your business, this is the rare moment when your cost data can move policy.
Does CMMC Flow Down to Subcontractors?
Yes, CMMC flows down to subcontractors at every tier of the supply chain. Prime contractors must verify that subcontractors handling FCI or CUI hold the appropriate status for the information flowing to them.
The scale here is easy to underestimate. The Department of Defense regulatory analysis behind the final acquisition rule identifies 337,968 impacted entities, of which 229,818 are small businesses. Defense programs here routinely run several supplier tiers deep, and CUI travels down all of them.
For a subcontractor, the practical consequence is that your prime's requirements are the ones that bind you commercially. A prime managing its own risk may keep requesting SPRS information, questionnaires, written representations, SSP details, corrective action plans, or certification, and none of that depends on what the Department suspends. Before you change your compliance plans, ask your customer directly and get any change confirmed in writing.
How a Managed Partner Handles This Better Than Break-Fix IT
Compliance during a suspension is entirely preemptive work, which is precisely the work a break-fix IT arrangement is not built to deliver. Nothing is broken. No systems are down. No tickets are open.
Most IT companies bill by the hour or à la carte, and they get paid when something fails. In a window where the only work that matters is keeping evidence current, reviewing access logs, closing POA&M items, and re-verifying cloud vendors, that model has nobody assigned. The predictable outcome is a compliance program that quietly ages for twelve months and then costs far more to restart than it would have cost to maintain.
Our Managed IT Department is built the opposite way: fully managed or co-managed, unlimited remote and onsite support, no additional labor charges for onsite calls or out-of-scope work, one all-inclusive monthly fee. Clients are not nickel and dimed for the preventive work, which is the only reason it reliably gets done in a month when nothing goes wrong.
Our managed compliance program runs CMMC, NIST, and DFARS obligations as one continuous operation rather than a project with an end date, which is what annual affirmations and continuous monitoring actually require. That is the difference between a partner accountable for the state of your environment and a vendor you call after something has already gone wrong.
Frequently Asked Questions
What Is the Difference Between CMMC Phase 2 and CMMC Level 2?
Phase 2 is a stage in the government's implementation schedule that would have expanded third-party assessment requirements. Level 2 is the security tier requiring 110 NIST SP 800-171 controls for contractors handling CUI. Phase 2 was suspended on July 13, 2026. Level 2 remains in force and is still required as a self-assessment on applicable contracts.
Who Is Required To Follow CMMC Guidelines?
Every organization in the defense supply chain that processes, stores, or transmits FCI or CUI under a DoD contract must follow CMMC guidelines, including primes, subcontractors, and suppliers at every tier. Foreign suppliers and small businesses are covered on the same terms. Contracts solely for commercial off-the-shelf items are excluded.
Is a CMMC Level 2 Self-Assessment Enough?
A Level 2 self-assessment is sufficient for current requirements on most contracts during the suspension, but it must be supported by real evidence. Self-assessment does not mean checking boxes or reporting planned controls as implemented. Your score should be defensible against configurations, logs, training records, and an accurate system security plan.
How Long Is a CMMC Level 2 Certification Valid?
A Final Level 2 status is valid for three years, with an annual affirmation signed by a senior official in each intervening year. Failing to affirm annually causes the status to lapse. Level 1 operates on an annual self-assessment cycle instead.
What Happens if a Contractor Is Not CMMC Compliant?
A contractor without the required status loses eligibility for awards, task orders, and option exercises that carry a CMMC requirement, because status is a condition of award rather than a post-award item. Misrepresenting compliance carries separate exposure under the False Claims Act, including treble damages and whistleblower suits.
What Is SPRS and How Do Contractors Report Scores?
SPRS is the Supplier Performance Risk System, the Department's portal for cybersecurity assessment results. Contractors report on two tabs: the NIST 800-171 tab required under DFARS 7012, and the CMMC Level 2 Self tab required under Phase 1. On the Level 2 tab you mark each of the 110 controls as met or not met and the system calculates the score.
How Does CMMC Level 2 Relate to NIST SP 800-171?
CMMC Level 2 maps directly to the 110 requirements in NIST SP 800-171 Revision 2, with identical controls. CMMC adds the assessment and verification framework on top. Contractors who genuinely implemented NIST SP 800-171 under DFARS 7012 have already completed the substantive work, which is why NIST compliance is the right place to start rather than CMMC itself.
Where Things Stand
CMMC is not cancelled and it is not optional. Phase 1 self-assessments still decide award eligibility, DFARS 252.204-7012 never moved, primes are still enforcing flow-downs, and the 110 controls behind Level 2 have been contractually required since 2017. What paused was one method of verification, on a memorandum that can be reversed as fast as it was issued.
The Reform Task Force reports on or about September 13, 2026. Contractors who spend the intervening weeks closing gaps and making their SPRS scores defensible will be ready for whatever it recommends. Contractors who read the headline and stopped will be doing the same work later, under more pressure, against a queue of everyone else who waited.
We have spent more than 20 years building and maintaining compliant IT environments for defense suppliers across Huntsville and North Alabama, and this pause is the cheapest window most of them will get. A free scoping audit will map your CUI environment, test your SPRS score against actual evidence, and show you the honest distance between where you are and what your next contract will ask. That is the foundation of any defense contractor compliance program that holds up under a changing enforcement model.
Reach out to Interweave Technologies or call (256) 837-2300.
.webp)
.webp)



.webp)





Share Post