APTSecurity Management

What Is CMMC? A Plain English Guide

Cody D. Martin//Updated August 9, 2026

CMMC is the Department of Defense framework verifying that contractors protect Federal Contract Information and Controlled Unclassified Information. Phase 2 was suspended in July 2026, pausing third party assessment. The underlying self assessment obligations under DFARS 252.204-7012 continue unchanged.

The Cybersecurity Maturity Model Certification is the Department of Defense’s framework for verifying that contractors protect government information. It exists because self attestation alone was not producing results, and because supply chain compromises kept originating with smaller suppliers.

That framework is currently in an unusual state, so it is worth separating what CMMC is from what is happening to it.

The levels

Level 1 applies to companies handling Federal Contract Information. Fifteen basic safeguarding requirements from FAR 52.204-21, confirmed by annual self assessment.

Level 2 applies to companies handling Controlled Unclassified Information. One hundred and ten practices aligned to NIST SP 800-171, plus a System Security Plan, a POA&M, an SPRS score and an annual affirmation.

Level 3 applies to a small number of programs handling the most sensitive information, assessed by the government directly.

Your contract clauses decide which applies. Not your company size, not your revenue, not how long you have held a contract.

What happened in July 2026

On 13 July 2026 the Department of War suspended Phase 2 of the CMMC implementation, which had been due to begin that November, and froze Phases 3 and 4 pending a reform review.

The stated reasons were cost and capacity. Small Business Administration figures put the annual cost of future phases to small and midsize business above seven billion dollars, and there were roughly one hundred authorised assessment organizations against a population of more than one hundred thousand companies needing assessment.

A reform task force was established to report on more realistic and scalable measures for the defense industrial base.

What that did and did not change

Paused Still in force
Level 2 (C3PAO) third party assessment NIST SP 800-171 Rev. 2 self assessment
Level 3 (DIBCAC) assessment System Security Plan
CMMC waivers POA&M and remediation
SPRS score posting
Annual affirmation

Suspended is not repealed. 32 CFR Part 170, DFARS 252.204-7012 and DFARS 252.204-7021 all remain in force exactly as written. What stopped is the Department exercising its discretion to require the higher assessment types.

During the suspension, requiring activities may designate only Level 1 (Self) or Level 2 (Self). Solicitations and contracts carrying a C3PAO or DIBCAC requirement are being amended to remove it.

What you owe today

If your contract carries DFARS 252.204-7012, you handle CUI, and you still:

  • Self assess against NIST SP 800-171 Rev. 2
  • Maintain a current System Security Plan
  • Track unmet requirements in a POA&M
  • Post and maintain a score in SPRS
  • Affirm compliance annually, signed by a senior company official

None of that was suspended. A contractor who stopped in July is out of compliance now, and the affirmation carries a name.

Whether to keep going

Yes, and the reasoning does not depend on predicting the review.

The requirements that survived are the same requirements a certification assessment would have checked. If CMMC returns strengthened, a contractor who kept working is ready. If it returns weakened, DFARS 7012 still binds and the work was still required.

The only scenario where stopping pays is one where the entire regulatory framework is repealed, which is not what a suspension pending review means.

There are eight free tools covering the parts of this that survived, if you want to work through it yourself.

  • CMMC
  • DFARS
  • NIST 800-171
  • DoD contracts

More on compliance