
CMMC compliance means a defense contractor or subcontractor has the required Cybersecurity Maturity Model Certification status for the systems covered by a DoD contract or subcontract. In practice, that means identifying whether you handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), determining the applicable CMMC level, implementing the required safeguards, documenting evidence, and maintaining the required assessment and affirmation status.
As of the Department’s July 13, 2026 release, Phase II CMMC requirements and pending and future implementation milestones were suspended, while Phase I self-assessment requirements remained in place. Contractors and subcontractors also remain responsible for safeguarding covered defense information under existing DFARS requirements. That makes current-state readiness important, or more precisely, it makes readiness important for obligations that still apply now, but it also means contractors should verify obligations against actual contract language rather than relying on stale rollout timelines.
What CMMC compliance means
CMMC stands for Cybersecurity Maturity Model Certification, it is DoD’s framework for assessing whether contractors have implemented applicable information-security protections for systems that process, store, or transmit FCI or CUI. Where a contract includes the CMMC clause, the contractor must maintain the required CMMC status for the in-scope systems and flow applicable requirements to subcontractors as required by the clause (DFARS 252.204-7021).
CMMC is closely tied to existing safeguarding requirements rather than being a standalone security product. Level 1 maps to basic safeguarding for FCI under FAR 52.204-21. Level 2 uses NIST SP 800-171 Rev. 2 requirements for CUI. Existing DFARS safeguarding policy also requires adequate security for covered contractor information systems and references NIST SP 800-171 requirements for covered defense information on nonfederal contractor systems (DFARS 204.7302, DFARS 252.204-7008).
Owning a security tool or using a cloud provider with compliance resources does not, by itself, make a contractor compliant. The contractor remains responsible for scoping systems, operating controls, retaining evidence, and making required affirmations for the CMMC status specified by contract.
Who needs CMMC compliance?
A contractor or subcontractor may need CMMC status when its DoD contract or subcontract includes a CMMC requirement for systems handling FCI or CUI. Applicability is not automatic for every organization that sells to the government; it depends on contract terms, information handled, and the systems used to process, store, or transmit that information.
FCI is nonpublic information provided by or generated for the Government under a contract, excluding public information and simple transactional information (FAR 52.204-21). CUI is information requiring safeguarding or dissemination controls under applicable law, regulation, or government-wide policy (National Archives CUI Program). Not all nonpublic business information is CUI, so contractors should confirm markings, contract clauses, and government direction before scoping systems.
Use this decision tree as a practical starting point, not as an official DoD applicability test:
The most important first scoping question is not “Do we work with defense customers?” but “Which systems, users, vendors, and workflows touch FCI or CUI under the contract, and where do they touch it?”
CMMC levels: what Level 1, Level 2, and Level 3 mean
The CMMC program rule defines three levels. The levels differ by information type, requirement set, and assessment path (CMMC Program, 89 FR 83092).
| CMMC level | Practical meaning | Requirement set | Assessment note |
|---|---|---|---|
| Level 1 | Basic safeguarding for FCI | 15 safeguards in FAR 52.204-21 | Self-assessment |
| Level 2 | Protection of CUI | 110 NIST SP 800-171 Rev. 2 requirements | Self-assessment or C3PAO assessment, depending on contract requirement |
| Level 3 | More advanced protection for specified needs | 24 selected NIST SP 800-172 requirements in addition to Level 2 | Requires a prior Final Level 2 (C3PAO) status for the same assessment scope |
For most contractors, the practical fork: whether the organization handles only FCI or also handles CUI. If CUI is in scope, Level 2 planning usually becomes the relevant readiness discussion. If Level 3 is specified, the organization should treat it as an advanced requirement layered on top of a Level 2 C3PAO-assessed scope.
Current official status: self-assessment, SPRS, affirmations, and POA&Ms
As of the Department’s July 13, 2026 release, Phase II CMMC requirements and pending and future CMMC implementation milestones were suspended. Phase I self-assessment requirements remained in place, and the Department said contractors and subcontractors remain contractually obligated to safeguard covered defense information under DFARS 252.204-7012 (Department release, July 13, 2026).
For applicable CMMC statuses, Level 1 self-assessments are annual. Level 2 self-assessments are performed every three years, with results entered in SPRS. CMMC affirmations are required after an assessment and annually thereafter for applicable CMMC statuses (CMMC Program, 89 FR 83092, DFARS 252.204-7021).
POA&Ms need careful handling. Level 1 does not permit POA&Ms. Conditional Level 2 and Level 3 statuses may use only eligible POA&Ms, and remediation plus a closeout assessment must occur within 180 days of the Conditional CMMC Status Date or the conditional status expires. For Level 2 assessments, assessment evidence must be retained for six years from the CMMC Status Date (CMMC Program, 89 FR 83092).
The practical takeaway is basically to separate three things: current contract obligations, current self-assessment and SPRS requirements, and any future certification milestones. Do not assume an old vendor timeline reflects the current official position.
What contractors should do first
A practical readiness sequence starts with scope, not tooling.
- Identify whether contracts involve FCI or CUI. Review contract clauses, data markings, prime-contractor instructions, and government direction.
- Define the in-scope environment. Map systems, users, applications, vendors, endpoints, storage locations, and workflows that process, store, or transmit FCI or CUI.
- Determine the likely CMMC level and assessment path. Use contract language as the deciding source, then align readiness to Level 1, Level 2, or Level 3 requirements.
- Compare current practices against official requirements. For Level 1, review FAR 52.204-21 safeguards. For Level 2, compare against NIST SP 800-171 Rev. 2 requirements as used by the CMMC rule.
- Document policies, procedures, configurations, and evidence. Readiness depends on both implemented controls and proof that those controls are operating for the scoped environment.
- Enter or update required information in SPRS where applicable. Level 2 self-assessment results are entered in SPRS for applicable CMMC statuses.
- Create and manage POA&Ms only where allowed. Treat a POA&M as a controlled remediation record, not as a substitute for implementing required safeguards.
- Prepare for assessment or reassessment based on current official requirements. Keep affirmations, evidence retention, and contract-specific assessment obligations aligned with the applicable CMMC status.
This sequence is not a legal interpretation or a complete implementation plan. It is a way to reduce ambiguity before spending money on assessments, tools, or architecture changes.
What evidence to prepare for CMMC readiness
The following checklist is useful readiness evidence to organize. The exact evidence needed depends on scope, applicable level, assessment type, and contract requirements.
| Readiness stage | Evidence to organize |
|---|---|
| Scope | Boundary description, included and excluded systems, users, facilities, business units, and subcontractor dependencies |
| Systems and data flows | Asset inventories, application lists, network diagrams, data-flow notes for FCI or CUI, storage and transmission locations |
| Policies and procedures | Security policies, access procedures, incident response procedures, configuration standards, change-management procedures |
| Technical control evidence | Access-control settings, identity and authentication configurations, MFA configuration evidence where applicable, encryption and system-hardening records |
| Logs and monitoring | Logging configurations, alert records, monitoring procedures, review evidence, escalation notes |
| Vulnerability and patching | Scan records, patch records, exception records, remediation evidence |
| Incident response | Incident response plan, test or exercise records where applicable, incident tickets, lessons-learned documentation |
| Training and awareness | Training records, role-based awareness materials, acknowledgement records where applicable |
| Vendor and shared responsibility | Vendor security documentation, responsibility matrices, inherited-control notes, subcontractor flow-down records |
| SPRS | Submitted assessment records and update history where applicable |
| Affirmations | Initial and annual affirmation records for applicable CMMC statuses |
| POA&Ms | Eligible POA&M entries, owners, due dates, remediation evidence, closeout assessment records |
| Review cadence | Internal review schedule, evidence-refresh owners, change triggers for reassessment or scope updates |
For Level 2 assessments, retain assessment evidence for six years from the CMMC Status Date. That retention period makes evidence management an operating discipline, not a one-time folder assembled before an assessment.
How cloud platforms, security tools, and compliance software fit
Cloud providers, security tools, and compliance software can help with CMMC readiness, but they do not make the contractor compliant by default. A provider’s security capabilities may support the assessment scope, but the contractor still needs to document responsibility boundaries and evidence for the requirements it must satisfy.
A useful way to think about responsibility is:
| Responsibility type | What it means for readiness |
|---|---|
| Provider-supported | The provider offers security capabilities, documentation, or platform controls that may support your environment |
| Shared | Both the provider and contractor have responsibilities, such as secure configuration, access management, logging, or monitoring |
| Contractor-owned | The contractor must implement, operate, document, and affirm the control activity for its scoped systems |
For example, a cloud service may provide logging features, but the contractor still needs to decide what to log, configure retention, review alerts, restrict access, and preserve evidence. A compliance workflow tool may help organize owners, evidence, risks, and POA&Ms, but it does not replace control operation, contract review, or assessment judgment.
If you use Ciphrix or another compliance operations platform, treat it as part of the evidence and workflow layer: a way to keep ownership, documentation, gap tracking, and review activity in one place. The compliance obligation still sits with the contractor.
Conclusion
Start by confirming whether your contracts and information flows involve FCI or CUI, then map the systems and vendors in scope. From there, align to the applicable CMMC level, verify current official requirements, maintain SPRS and affirmation records where required, and manage evidence and POA&Ms as an ongoing operating process, not something pulled together right before an assessment.
