CMMC in 2026: What Still Applies and How to Prepare
CMMC still applies in 2026, just not in the form many suppliers expected. Third-party (C3PAO) assessments under Phase 2 were suspended on July 13, 2026, and a September 3, 2026 DoD class deviation told contracting officers to remove them from contracts. Self-assessments, SPRS scores, annual affirmations and DFARS 252.204-7012 safeguarding all remain in force.
Key facts
- The rule: the CMMC program rule, 32 CFR Part 170, took effect on December 16, 2024. The DFARS rule began phasing CMMC into contracts on November 10, 2025 (Phase 1: self-assessments).
- The pause: Phase 2 (C3PAO assessments), due to start November 10, 2026, was suspended on July 13, 2026. Class Deviation 2026-O0025 Revision 3, issued September 3, 2026, strips third-party assessment requirements from contracts.
- Level 1: 15 requirements from FAR 52.204-21, self-assessed and affirmed in SPRS every year. No POA&M allowed.
- Level 2: 110 requirements from NIST SP 800-171 Rev 2, tested through 320 assessment objectives. SPRS scores run from 110 down to −203.
- Conditional Level 2: a score of at least 88 out of 110, only eligible items on the POA&M, and every item closed within 180 days.
- Records: keep your assessment evidence for six years from your CMMC status date.
Is CMMC still required in 2026?
Yes. If your contract, or your prime contractor's flowdown, includes CMMC or NIST SP 800-171 requirements, you still owe them. What changed is who checks: for now you assess yourself, and a senior person in your company signs for the result.
The Department of Defense (DoD) paused Phase 2 on July 13, 2026 and set up a reform task force with a 60-day review. That review window closed on September 11, 2026, and at the time of writing its recommendations had not been published. Before that, on September 3, a class deviation (a formal, temporary change to acquisition rules) directed contracting officers to take third-party assessment requirements out of contracts and accept self-assessments instead.
The pause lowers the cost of proving compliance. It does not lower the standard. Every score you post and every affirmation you sign is a statement to the federal government. The Department of Justice has continued to settle False Claims Act cases in 2026 over inaccurate NIST 800-171 self-assessments, and DoD can still send its own assessors (DCMA's DIBCAC team), whose findings override your self-assessed status.
What are the CMMC levels, and how is each one assessed now?
CMMC has three levels. Level 1 protects Federal Contract Information (FCI), Level 2 protects Controlled Unclassified Information (CUI), and Level 3 adds enhanced requirements for a small number of high-priority programs. Most small suppliers sit at Level 1 or Level 2.
| Level | Protects | Requirements | How it is assessed now | POA&M allowed? |
|---|---|---|---|---|
| Level 1 | FCI | 15 requirements in FAR 52.204-21 | Self-assessment and affirmation in SPRS every year | No |
| Level 2 | CUI | 110 requirements in NIST SP 800-171 Rev 2 | Self-assessment every three years plus annual affirmation; C3PAO certification paused | Yes, limited |
| Level 3 | CUI on high-priority programs | Level 2 plus 24 requirements from NIST SP 800-172 | Government assessment by DCMA DIBCAC, which first requires Final Level 2 (C3PAO) status | Yes, limited |
In plain terms: FCI is non-public contract information, such as order quantities and delivery dates. CUI is information the government requires you to safeguard, such as a drawing marked with a distribution statement.
What does the Phase 2 pause change, and what does it not change?
The pause removes the need to hire an outside assessor. It does not remove any security requirement, any reporting duty or your liability for what you affirm.
What changed
- C3PAO certification assessments for Level 2 are on hold.
- The November 10, 2026 start of Phase 2 is suspended.
- Contracting officers are removing third-party assessment requirements from solicitations and contracts and accepting Level 1 and Level 2 self-assessments.
What did not change
- Level 1 annual self-assessment and affirmation.
- Level 2 self-assessment where your contract requires CMMC Level 2 (Self).
- A current summary score in SPRS (no more than three years old) under DFARS 252.204-7019 and 7020.
- DFARS 252.204-7012: implement NIST SP 800-171, report cyber incidents to DoD within 72 hours of discovery, and flow the clause down to subcontractors.
- Annual affirmation by your Affirming Official, and False Claims Act exposure if it is wrong.
How is an SPRS score calculated?
You start at 110 and subtract points for every requirement you have not fully met. Each requirement is worth 5, 3 or 1 point depending on how much harm its absence could cause, so the score can fall as low as −203.
- 44 requirements are worth up to 5 points, for example 3.5.3 (multifactor authentication) and 3.11.2 (vulnerability scanning).
- 14 requirements are worth 3 points.
- 51 requirements are worth 1 point.
- 3.12.4, the System Security Plan, has no point value, but without a current SSP the assessment cannot be completed at all.
Two requirements allow partial credit. Multifactor authentication (3.5.3) costs 3 points instead of 5 if it covers remote and privileged users but not everyone. FIPS-validated encryption (3.13.11) costs 3 instead of 5 if you encrypt CUI but the encryption module is not FIPS-validated.
Worked example. Harborline Precision Machining (fictional), a 38-person machine shop, finds these gaps: MFA only for remote and administrator accounts (−3), encryption that is not FIPS-validated (−3), no vulnerability scanning (−5) and five 1-point gaps (−5), one of which is physical access logs. Its score is 110 − 16 = 94. That clears 88, but it still does not qualify for Conditional Level 2 status: the scanning gap is worth 5 points, the MFA gap 3, and physical access logs (3.10.4) are excluded by name. Fix those three and the score becomes 103, with only eligible items left. See the step-by-step SPRS guide for the full calculation.
What can go on a CMMC POA&M?
A POA&M (Plan of Action and Milestones) is your written plan to fix open gaps, with owners and dates. For CMMC Level 2 it only earns Conditional status when all four of these conditions are true:
- Your score is at least 88 out of 110 (80 percent).
- Every item on it is worth 1 point, except 3.13.11 when you encrypt CUI without FIPS validation.
- None of these six are on it: 3.1.20 (external connections), 3.1.22 (publicly posted information), 3.12.4 (SSP), 3.10.3 (escorting visitors), 3.10.4 (physical access logs) and 3.10.5 (physical access devices).
- You close every item and complete a closeout self-assessment within 180 days. Otherwise the conditional status expires.
Level 1 allows no POA&M at all. All 15 requirements must be met on the day you affirm.
What documents do you need for CMMC?
At minimum you need a System Security Plan, a POA&M if you have open gaps, approved policies and procedures, and evidence that you actually do what they say. Assessors, and DoD if it ever reviews you, judge the evidence, not the binder.
- System Security Plan (SSP): your boundary, your assets and a statement for each of the 110 requirements explaining how it is met. Required by 3.12.4.
- POA&M: each open gap, the fix, the owner and the target date.
- Policies and procedures: covering all 14 requirement families, from access control to system integrity. They must be final and approved; drafts do not count as evidence.
- Evidence: configuration screenshots, access reviews, training records, visitor logs and scan results.
- Scoping records: an asset inventory, a network diagram, CUI data flows and the customer responsibility matrix from any cloud or managed IT provider.
- SPRS records: the score you posted, the CAGE codes covered and each affirmation.
What does a 90-day CMMC preparation plan look like?
Ninety days is enough for a small, well-scoped company to produce an honest self-assessment, a real SSP and a credible POA&M. Some technical fixes may take longer, which is acceptable as long as your score says so.
- Days 1–10: Confirm what you owe. Read your contracts and flowdowns for FAR 52.204-21 and DFARS 252.204-7012, 7019, 7020 and 7021. Ask your prime or contracting officer, in writing, whether you receive CUI.
- Days 11–30: Draw the boundary. List where FCI and CUI enter, live and leave: email, file shares, CAD workstations, CNC controllers, cloud storage and your IT provider. Keep CUI in as few places as possible.
- Days 31–55: Assess honestly. Test each requirement against its objectives in NIST SP 800-171A. A requirement is met only when every applicable objective is met.
- Days 56–75: Write it down. Draft the SSP from what is true today, finalize policies and build the POA&M.
- Days 76–85: Close the quick wins. Session locks, a visitor log, login banners and removing admin rights nobody needs.
- Days 86–90: Score, review, affirm. Calculate the score, walk leadership through it, post it in SPRS and have your Affirming Official affirm only what the evidence supports.
What are the most common CMMC mistakes?
The expensive mistakes are rarely technical. They come from unclear scope and paperwork that does not match reality.
- Scope creep. Letting CUI spread to every laptop and inbox, so all 110 requirements apply everywhere. Contain it first.
- CUI ambiguity. Guessing whether a drawing is CUI instead of checking its markings and asking the customer. Guessing wrong in either direction costs money.
- Copy-paste SSPs. Statements lifted from a sample that describe tools you do not own. Assessors compare every statement with screens and interviews.
- Overstated scores. Marking a requirement met because a policy exists, or because most of its objectives are met. An inflated score in SPRS is the fastest route to False Claims Act exposure.
- Treating the pause as a holiday. The requirements and your affirmations still apply.
Which CMMC template fits your situation?
Match the kit to the level in your contract. Every template is an editable Word or Excel file for one organization, delivered as an instant download.
| Your situation | Start with | Price |
|---|---|---|
| You handle FCI only and want to see where you stand | Free CMMC Level 1 Self-Assessment Checklist | Free |
| You handle FCI only and need to complete and document the annual self-assessment | CMMC Level 1 Self-Assessment Kit | $79 |
| You handle CUI and need a score, an SSP and a POA&M quickly | CMMC Level 2 Starter Bundle (Assessment Workbook + SSP + POA&M) | $175 (was $207) |
| You handle CUI and also need policies and procedures for all 14 families | CMMC Level 2 Compliance Toolkit | $279 (was $336) |
| You only need one piece | Assessment Workbook ($79), SSP Template ($99), POA&M Template & Tracker ($29) or Policy & Procedure Pack ($129) | From $29 |
Templates help you prepare and document an honest self-assessment. They cannot promise a particular score, a passing assessment or contract eligibility. Those depend on what you actually implement.
Last reviewed: 29 September 2026. CMMC rules are still moving. Check your contract, your prime's flowdown and the current rule before you rely on any date.
Frequently asked questions
Do I need a C3PAO assessment for CMMC right now?
Not for contracts covered by the September 3, 2026 class deviation. It directs contracting officers to remove third-party assessment requirements and accept Level 1 and Level 2 self-assessments instead. That may change once DoD acts on its reform review, so keep your SSP and evidence in a state an outside assessor could check, and read each new solicitation for the CMMC level it states.
Can I still win DoD contracts with an SPRS score below 110?
Often, yes, depending on what the solicitation requires. DFARS 252.204-7019 asks for a current score in SPRS, not a perfect one, along with the date you expect to reach 110. A CMMC Level 2 (Self) requirement is stricter: you need 110, or at least 88 with only eligible items on a POA&M that you close within 180 days.
Does CMMC use NIST SP 800-171 Revision 2 or Revision 3?
Revision 2. NIST published Revision 3 in 2024, but the CMMC rule incorporates Revision 2 by reference, and the DoD scoring method behind SPRS is built on its 110 requirements. Revision 3 is useful for seeing where things are heading. Build your SSP, score and POA&M on Revision 2 until DoD formally changes the baseline.
Who signs the CMMC affirmation in SPRS?
Your Affirming Official: a senior person who is responsible for CMMC compliance and has the authority to affirm it, often the owner, president or operations head. They affirm after each assessment and every year after, stating that the required security requirements are implemented and will be maintained. They should only sign what the evidence supports.
If the rules might change again, why prepare now?
Because the underlying obligations have not moved. DFARS 252.204-7012 has required NIST SP 800-171 in covered contracts for years, your SPRS score has to stay current, and affirmations are ongoing. Whatever the reform review decides about who assesses you, the 110 requirements and your records are what any assessor, prime or investigator will examine.
Not ready to buy? Start with the free CMMC Level 1 checklist
15 plain-English questions, one per FAR 52.204-21 requirement, to find the gaps before you affirm in SPRS.