All posts
Compliance Frameworks9 min readAug 16, 2026

CMMC compliance

Ashish / CEO/Co-Founder
CMMC compliance

CMMC compliance means a defense contractor or subcontractor has the required Cybersecurity Maturity Model Certification status for the systems covered by a DoD contract or subcontract. In practice, that means identifying whether you handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), determining the applicable CMMC level, implementing the required safeguards, documenting evidence, and maintaining the required assessment and affirmation status.

As of the Department’s July 13, 2026 release, Phase II CMMC requirements and pending and future implementation milestones were suspended, while Phase I self-assessment requirements remained in place. Contractors and subcontractors also remain responsible for safeguarding covered defense information under existing DFARS requirements. That makes current-state readiness important, or more precisely, it makes readiness important for obligations that still apply now, but it also means contractors should verify obligations against actual contract language rather than relying on stale rollout timelines.

What CMMC compliance means

CMMC stands for Cybersecurity Maturity Model Certification, it is DoD’s framework for assessing whether contractors have implemented applicable information-security protections for systems that process, store, or transmit FCI or CUI. Where a contract includes the CMMC clause, the contractor must maintain the required CMMC status for the in-scope systems and flow applicable requirements to subcontractors as required by the clause (DFARS 252.204-7021).

CMMC is closely tied to existing safeguarding requirements rather than being a standalone security product. Level 1 maps to basic safeguarding for FCI under FAR 52.204-21. Level 2 uses NIST SP 800-171 Rev. 2 requirements for CUI. Existing DFARS safeguarding policy also requires adequate security for covered contractor information systems and references NIST SP 800-171 requirements for covered defense information on nonfederal contractor systems (DFARS 204.7302, DFARS 252.204-7008).

Owning a security tool or using a cloud provider with compliance resources does not, by itself, make a contractor compliant. The contractor remains responsible for scoping systems, operating controls, retaining evidence, and making required affirmations for the CMMC status specified by contract.

Who needs CMMC compliance?

A contractor or subcontractor may need CMMC status when its DoD contract or subcontract includes a CMMC requirement for systems handling FCI or CUI. Applicability is not automatic for every organization that sells to the government; it depends on contract terms, information handled, and the systems used to process, store, or transmit that information.

FCI is nonpublic information provided by or generated for the Government under a contract, excluding public information and simple transactional information (FAR 52.204-21). CUI is information requiring safeguarding or dissemination controls under applicable law, regulation, or government-wide policy (National Archives CUI Program). Not all nonpublic business information is CUI, so contractors should confirm markings, contract clauses, and government direction before scoping systems.

Use this decision tree as a practical starting point, not as an official DoD applicability test:

The most important first scoping question is not “Do we work with defense customers?” but “Which systems, users, vendors, and workflows touch FCI or CUI under the contract, and where do they touch it?”

CMMC levels: what Level 1, Level 2, and Level 3 mean

The CMMC program rule defines three levels. The levels differ by information type, requirement set, and assessment path (CMMC Program, 89 FR 83092).

CMMC levelPractical meaningRequirement setAssessment note
Level 1Basic safeguarding for FCI15 safeguards in FAR 52.204-21Self-assessment
Level 2Protection of CUI110 NIST SP 800-171 Rev. 2 requirementsSelf-assessment or C3PAO assessment, depending on contract requirement
Level 3More advanced protection for specified needs24 selected NIST SP 800-172 requirements in addition to Level 2Requires a prior Final Level 2 (C3PAO) status for the same assessment scope

For most contractors, the practical fork: whether the organization handles only FCI or also handles CUI. If CUI is in scope, Level 2 planning usually becomes the relevant readiness discussion. If Level 3 is specified, the organization should treat it as an advanced requirement layered on top of a Level 2 C3PAO-assessed scope.

Current official status: self-assessment, SPRS, affirmations, and POA&Ms

As of the Department’s July 13, 2026 release, Phase II CMMC requirements and pending and future CMMC implementation milestones were suspended. Phase I self-assessment requirements remained in place, and the Department said contractors and subcontractors remain contractually obligated to safeguard covered defense information under DFARS 252.204-7012 (Department release, July 13, 2026).

For applicable CMMC statuses, Level 1 self-assessments are annual. Level 2 self-assessments are performed every three years, with results entered in SPRS. CMMC affirmations are required after an assessment and annually thereafter for applicable CMMC statuses (CMMC Program, 89 FR 83092, DFARS 252.204-7021).

POA&Ms need careful handling. Level 1 does not permit POA&Ms. Conditional Level 2 and Level 3 statuses may use only eligible POA&Ms, and remediation plus a closeout assessment must occur within 180 days of the Conditional CMMC Status Date or the conditional status expires. For Level 2 assessments, assessment evidence must be retained for six years from the CMMC Status Date (CMMC Program, 89 FR 83092).

The practical takeaway is basically to separate three things: current contract obligations, current self-assessment and SPRS requirements, and any future certification milestones. Do not assume an old vendor timeline reflects the current official position.

What contractors should do first

A practical readiness sequence starts with scope, not tooling.

  1. Identify whether contracts involve FCI or CUI. Review contract clauses, data markings, prime-contractor instructions, and government direction.
  2. Define the in-scope environment. Map systems, users, applications, vendors, endpoints, storage locations, and workflows that process, store, or transmit FCI or CUI.
  3. Determine the likely CMMC level and assessment path. Use contract language as the deciding source, then align readiness to Level 1, Level 2, or Level 3 requirements.
  4. Compare current practices against official requirements. For Level 1, review FAR 52.204-21 safeguards. For Level 2, compare against NIST SP 800-171 Rev. 2 requirements as used by the CMMC rule.
  5. Document policies, procedures, configurations, and evidence. Readiness depends on both implemented controls and proof that those controls are operating for the scoped environment.
  6. Enter or update required information in SPRS where applicable. Level 2 self-assessment results are entered in SPRS for applicable CMMC statuses.
  7. Create and manage POA&Ms only where allowed. Treat a POA&M as a controlled remediation record, not as a substitute for implementing required safeguards.
  8. Prepare for assessment or reassessment based on current official requirements. Keep affirmations, evidence retention, and contract-specific assessment obligations aligned with the applicable CMMC status.

This sequence is not a legal interpretation or a complete implementation plan. It is a way to reduce ambiguity before spending money on assessments, tools, or architecture changes.

What evidence to prepare for CMMC readiness

The following checklist is useful readiness evidence to organize. The exact evidence needed depends on scope, applicable level, assessment type, and contract requirements.

Readiness stageEvidence to organize
ScopeBoundary description, included and excluded systems, users, facilities, business units, and subcontractor dependencies
Systems and data flowsAsset inventories, application lists, network diagrams, data-flow notes for FCI or CUI, storage and transmission locations
Policies and proceduresSecurity policies, access procedures, incident response procedures, configuration standards, change-management procedures
Technical control evidenceAccess-control settings, identity and authentication configurations, MFA configuration evidence where applicable, encryption and system-hardening records
Logs and monitoringLogging configurations, alert records, monitoring procedures, review evidence, escalation notes
Vulnerability and patchingScan records, patch records, exception records, remediation evidence
Incident responseIncident response plan, test or exercise records where applicable, incident tickets, lessons-learned documentation
Training and awarenessTraining records, role-based awareness materials, acknowledgement records where applicable
Vendor and shared responsibilityVendor security documentation, responsibility matrices, inherited-control notes, subcontractor flow-down records
SPRSSubmitted assessment records and update history where applicable
AffirmationsInitial and annual affirmation records for applicable CMMC statuses
POA&MsEligible POA&M entries, owners, due dates, remediation evidence, closeout assessment records
Review cadenceInternal review schedule, evidence-refresh owners, change triggers for reassessment or scope updates

For Level 2 assessments, retain assessment evidence for six years from the CMMC Status Date. That retention period makes evidence management an operating discipline, not a one-time folder assembled before an assessment.

How cloud platforms, security tools, and compliance software fit

Cloud providers, security tools, and compliance software can help with CMMC readiness, but they do not make the contractor compliant by default. A provider’s security capabilities may support the assessment scope, but the contractor still needs to document responsibility boundaries and evidence for the requirements it must satisfy.

A useful way to think about responsibility is:

Responsibility typeWhat it means for readiness
Provider-supportedThe provider offers security capabilities, documentation, or platform controls that may support your environment
SharedBoth the provider and contractor have responsibilities, such as secure configuration, access management, logging, or monitoring
Contractor-ownedThe contractor must implement, operate, document, and affirm the control activity for its scoped systems

For example, a cloud service may provide logging features, but the contractor still needs to decide what to log, configure retention, review alerts, restrict access, and preserve evidence. A compliance workflow tool may help organize owners, evidence, risks, and POA&Ms, but it does not replace control operation, contract review, or assessment judgment.

If you use Ciphrix or another compliance operations platform, treat it as part of the evidence and workflow layer: a way to keep ownership, documentation, gap tracking, and review activity in one place. The compliance obligation still sits with the contractor.

Conclusion

Start by confirming whether your contracts and information flows involve FCI or CUI, then map the systems and vendors in scope. From there, align to the applicable CMMC level, verify current official requirements, maintain SPRS and affirmation records where required, and manage evidence and POA&Ms as an ongoing operating process, not something pulled together right before an assessment.

Get started

Ready to see Ciphrix in action?

Built by AWS Security Leaders | AWS Partner | Certified companies across 3 continents