Compliance

CMMC in 2026: The Compliance Clock is Ticking. Are You Ready?

CMMC Phase 1 self-assessments are already in DoD solicitations. Phase 2 third-party certification was suspended on 13 July 2026 for a reform review, so here's what still applies and how to stay ready.

TL;DR. CMMC is a contract requirement: the solicitation names your level, and the contracting officer checks SPRS for a current status before award. Phase 1 (self-assessments) has applied since 10 November 2025. Phase 2 (third-party Level 2 certification in solicitations) was suspended on 13 July 2026, and no new date had been announced as of late September 2026. Evidence still rules, so a security control with no paperwork is basically a rumor.

  • New to this? Level 1 covers Federal Contract Information (annual self-assessment). Level 2 covers CUI and is built on the 110 requirements of NIST SP 800-171; for now, solicitations ask for a Level 2 self-assessment. Level 3 is government-led.
  • Small business? Run a gap analysis first. Fixing the gaps often costs more than any assessment.
  • Handling CUI? DFARS 252.204-7012 still requires NIST SP 800-171 today, pause or no pause. A C3PAO assessment is voluntary for now and lasts three years if you get one.
  • Prime contractor? Vet your subs. You're only as ready as the weakest one.

Where CMMC Stands in September 2026

This post first ran on 7 July 2026. Six days later the rules changed, so here is the updated picture. CMMC is real and in force, but only partly. The CMMC program rule (32 CFR Part 170) took effect on 16 December 2024. The DFARS rule that puts CMMC into contracts took effect on 10 November 2025 and started Phase 1: solicitations can require a Level 1 or Level 2 self-assessment, and the contracting officer checks the Supplier Performance Risk System (SPRS) for a current status before award.

On 13 July 2026 the Department of War suspended Phase 2 and every later phase, and set up a CMMC Reform Task Force for a 60-day review. Phase 2, scheduled for 10 November 2026, was the step that would have required third-party (C3PAO) Level 2 certification in solicitations. As of late September 2026, no new Phase 2 date has been announced.

What did not change: Phase 1 self-assessments, SPRS scores and annual affirmations are still required, and DFARS 252.204-7012 still requires you to protect CUI using NIST SP 800-171. The CMMC contract clause is DFARS 252.204-7021, the solicitation provision that names your level is 252.204-7025, and the 252.204-7019 and -7020 rules on NIST SP 800-171 assessment scores still apply too.

How many companies does this touch? When DoD wrote the CMMC rule, its regulatory impact analysis estimated about 221,000 companies would need a CMMC assessment during the rollout.

So what? The pause bought you time on third-party certification, not on security. If you handle CUI, you already owe the government NIST SP 800-171 compliance and an honest SPRS score. Use the breathing room to get ready, not to relax.

Free Starter Kit

Get the Acqlerate Acquisition Starter Kit (Free)

Key terms, ACAT levels, career roadmaps, and the 5 most common acquisition mistakes. Tailored to your role: USG, contractor, or career changer.

CMMC 2.0: What's Required Now

The three levels haven't changed. What changed is which assessment a solicitation can demand right now. Each level matches the type of information you handle:

  • Level 1 (Foundational): If you only handle Federal Contract Information (FCI), you do an annual self-assessment against the 15 requirements of FAR 52.204-21 (renumbered 52.240-93 under the Revolutionary FAR Overhaul). This is the entry point, but you still need documentation and internal processes that hold up.
  • Level 2 (Advanced): If you handle Controlled Unclassified Information (CUI), you meet the 110 requirements of NIST SP 800-171. The rule allows two ways to prove it: a self-assessment or a certification assessment by a CMMC Third-Party Assessment Organization (C3PAO). During Phase 1, solicitations use the self-assessment. The C3PAO requirement was due with Phase 2 and is suspended, though you can still book a C3PAO assessment voluntarily.
  • Level 3 (Expert): Reserved for CUI on the highest-priority programs. You need a Level 2 C3PAO certification first, then a government-led assessment by DCMA's Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) against 24 selected requirements from NIST SP 800-172. Level 3 in solicitations was planned for a later phase, which is also suspended.

Understanding which level applies to your organization is the first step. The solicitation will specify the required CMMC level, and you need a current status at that level in SPRS to be eligible for award. For scale, DoD's rule analysis expected about 63% of affected companies to need only Level 1, about 35% to need Level 2 certification, and about 1% to need Level 3.

CMMC Level Description Assessment Type Primary Standard Who Needs It?
Level 1 (Foundational) Safeguards Federal Contract Information (FCI) Annual Self-Assessment FAR 52.204-21 (15 requirements) Companies handling only FCI
Level 2 (Advanced) Protects Controlled Unclassified Information (CUI) Self-assessment in solicitations today (Phase 1). C3PAO certification was due in Phase 2, suspended 13 July 2026. NIST SP 800-171 (110 requirements) Companies handling CUI
Level 3 (Expert) Protects CUI for high-priority programs Government-Led Assessment (DCMA DIBCAC), after Level 2 C3PAO certification 24 selected NIST SP 800-172 requirements Companies handling CUI on critical, high-risk DoD programs

So what? Identify your required CMMC level now. It sets your whole compliance roadmap, from the security controls you need to the type of assessment you'll face.

C3PAO Certification: Paused, Not Cancelled

Phase 2 would have made C3PAO certification a condition of award for many CUI contracts starting 10 November 2026. That deadline is suspended. The task force could restore Phase 2, change it or push it out, and as of late September 2026 it had not announced a decision. You can still get a C3PAO assessment voluntarily, for example if a prime asks for one.

Budget either way. DoD's regulatory impact analysis put a Level 2 C3PAO certification for a small company at about $105,000 over a three-year cycle (about $77,000 of that for the assessment itself), and about $118,000 for a larger company. It estimated the whole program at roughly $4 billion a year across industry and government. Those figures cover assessments; for many firms the bigger bill is implementing and fixing controls.

Example (illustrative). A 40-person engineering firm that has never written a System Security Plan may need new hardware and software, outside help, training and staff time to close its NIST SP 800-171 gaps. For a firm starting from scratch, that work can cost more than the assessment.

Key Insight: CMMC isn't merely an IT problem; it's a fundamental business risk. Underestimating its complexity and cost can lead to significant financial strain and loss of market share.

Assessments also recur. Level 1 self-assessments repeat every year. Level 2 and Level 3 status lasts three years, with an annual affirmation from a senior company official in between.

So what? Don't cancel your plans; re-sequence them. Finish your gap analysis and remediation, keep your SPRS score honest, and decide whether a voluntary C3PAO assessment makes sense for your customers. If Phase 2 returns on a short fuse, the firms that kept going will be ready.

Why Contractors Are Still Behind (and How to Catch Up)

Why do contractors fall behind? Common pitfalls include:

  • Underestimating Complexity: Believing CMMC is just another "checkbox" exercise rather than a comprehensive overhaul of their cybersecurity posture.
  • Waiting for "The Perfect Time": First it was the final rule, now it's the task force. The NIST SP 800-171 requirement in DFARS 252.204-7012 didn't wait for either.
  • Lack of Budget & Resources: Failing to allocate sufficient funds and personnel to tackle the extensive technical and administrative requirements.
  • Poor Documentation: Having some controls in place but lacking the System Security Plan (SSP), Plans of Action and Milestones (POAMs), and other evidence-based documentation required for an assessment.
  • Neglecting the Supply Chain: Primes failing to vet their subcontractors' readiness, and subcontractors failing to prepare to demonstrate compliance to primes.

To avoid being left behind, here's what you need to be doing, or doing more aggressively, right now:

  • Perform a Gap Analysis: If you haven't already, conduct a thorough assessment against NIST SP 800-171 (for Level 2) or FAR 52.204-21 (for Level 1). Understand exactly where you stand and what needs fixing.
  • Prioritize Remediation: This is the most time-consuming and costly part. Develop a clear, budgeted plan to address all identified gaps. You need to not only implement controls but ensure they are operational and effective.
  • Document Everything: CMMC assessments are evidence-based. Your SSP, POAMs, policies, procedures, network diagrams, and evidence of implementation (logs, screenshots, meeting minutes) are your proof. If it's not documented, it didn't happen in the eyes of an assessor.
  • Train Your Team: Cybersecurity is everyone's responsibility. Ensure all employees handling CUI are adequately trained on best practices and your organization's security policies.
  • Vet Your Supply Chain: Primes, your CMMC readiness is only as strong as your weakest link. Subcontractors, be prepared to demonstrate your compliance to primes; it’s a competitive differentiator.

So what? Stop making excuses. Take an evidence-based approach to cybersecurity, and treat CMMC compliance as ongoing operations, not a one-time project.

Learn More on Acqlerate

Module: Defense Contracting Fundamentals

This post touches on concepts covered in depth in the Defense Contracting Fundamentals module. Contract types, source selection, IDIQs, GWACs, modifications, and the COR role.

Start This Module Free →

The Stakes Are High: Don't Get Excluded

Phase 2 is paused, but CMMC is not gone. Phase 1 is in solicitations today, it touches the whole acquisition lifecycle, and DFARS 252.204-7012 still applies while the task force works. The rule is blunt: without a current CMMC status in SPRS at the level a solicitation requires, the contracting officer can't award you the contract.

On the other side, being ready is a competitive advantage. It shows you take national security seriously, that you're a mature partner, and that you can protect sensitive information. For many program managers, a contractor with its cyber house in order is a lower-risk contractor.

So what? Your ability to work in the DIB depends on your cybersecurity, with or without Phase 2. Make it a priority, fund it, and treat it as an investment in your future with the DoD.

CMMC Level Requirements Reference

LevelApplies ToKey RequirementAssessment Type
Level 1 (Foundational)All DoD contractors handling FCI15 basic safeguarding requirementsAnnual self-assessment
Level 2 (Advanced)Contractors handling CUI110 NIST SP 800-171 requirementsSelf-assessment today (Phase 1); triennial C3PAO certification planned for Phase 2, suspended July 2026
Level 3 (Expert)Contractors on highest-priority programsLevel 2 plus 24 selected NIST SP 800-172 requirementsGovernment-led assessment (DCMA DIBCAC)

Drafted with AI from public sources. Spot a mistake? Email lucas@acqlerate.com and I'll fix it.

Master Defense Acquisitions

Start Free. Fourteen Modules, 124 Lessons

Built for DoD program managers, contracting officers, and defense contractors. Novice through advanced. The Defense Contracting Fundamentals module goes deep on everything covered in this post.

Start Learning Free → See all modules →