38 current facts. Each one: a claim, a pinpoint citation, a verbatim quote retrieved from the source, the date last verified, and a labeled confidence tier. Superseded versions are kept — the audit trail is the warranty.
The CMMC Program was established by a DoD final rule published October 15, 2024 (89 FR 83092, document 2024-22905), codified at 32 CFR Part 170, and effective December 16, 2024.
With this final rule, DoD establishes the Cybersecurity Maturity Model Certification (CMMC) Program in order to verify contractors have implemented required security measures necessary to safeguard Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
32 CFR Part 170 establishes requirements for defense contractors and subcontractors to implement prescribed cybersecurity standards for safeguarding FCI and CUI, and for assessing compliance on contractor information systems that process, store, or transmit FCI or CUI.
This part describes the Cybersecurity Maturity Model Certification (CMMC) Program of the Department of Defense (DoD) and establishes requirements for defense contractors and subcontractors to implement prescribed cybersecurity standards for safeguarding Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
The statutory authority for 32 CFR Part 170 is 5 U.S.C. 301 and section 1648 of the National Defense Authorization Act for Fiscal Year 2020 (Pub. L. 116-92).
Authority: 5 U.S.C. 301; Sec. 1648, Pub. L. 116-92, 133 Stat. 1198.
The CMMC Program uses three security standards: 48 CFR 52.204-21; NIST SP 800-171 Revision 2 (February 2020, includes updates as of January 28, 2021); and selected requirements from NIST SP 800-172 (February 2021).
The CMMC Program utilizes the security standards set forth in the 48 CFR 52.204-21; National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, ... Revision 2, February 2020 (includes updates as of January 28, 2021) (NIST SP 800-171 R2); and selected requirements from the NIST SP 800-172
CMMC Level 2 assesses against NIST SP 800-171 Revision 2 specifically — not Revision 3 — with the Level 2 security requirements being identical to the 110 requirements of SP 800-171 R2 as incorporated by reference in 32 CFR 170.2.
CMMC Level 2 security requirements. The security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2.
CMMC Level 1 consists of the 15 basic safeguarding requirements set forth in FAR clause 52.204-21(b)(1)(i) through (xv), applicable to Federal Contract Information.
CMMC Level 1 security requirements. The security requirements in CMMC Level 1 are those set forth in 48 CFR 52.204-21(b)(1)(i) through (xv).
CMMC Level 1 requires an annual self-assessment with results submitted in SPRS, all 15 requirements must be MET, and no POA&Ms are permitted at any time for Level 1.
No POA&Ms are permitted for CMMC Level 1. ... To maintain compliance with the requirements for the CMMC Status of Final Level 1 (Self), the OSA must conduct a Level 1 self-assessment on an annual basis and submit the results in SPRS, or its successor capability.
CMMC Level 2 (Self) requires the organization to conduct a self-assessment against all Level 2 requirements every three years and submit results in SPRS.
To maintain compliance with the requirements for a CMMC Status of Level 2 (Self), the OSA must conduct a Level 2 self-assessment every three years and submit the results in SPRS
CMMC Level 2 (C3PAO) status requires a certification assessment performed by an authorized or accredited CMMC Third-Party Assessment Organization, with results submitted into the CMMC instantiation of eMASS (which transmits to SPRS), and the assessment must be repeated within three years to maintain the status.
The OSC must obtain a Level 2 certification assessment from an authorized or accredited C3PAO ... The C3PAO must submit the Level 2 certification assessment results into the CMMC instantiation of eMASS, which then provides automated transmission to SPRS.
CMMC Level 3 certification assessments are performed by DCMA DIBCAC (the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center) on behalf of DoD, must be performed every three years, and a CMMC Status of Final Level 2 (C3PAO) on the same scope is a prerequisite.
The OSC must achieve a CMMC Status of Final Level 2 (C3PAO) on the Level 3 CMMC Assessment Scope ... prior to initiating a Level 3 certification assessment, which will be performed by DCMA DIBCAC ... on behalf of the DoD.
CMMC Level 3 adds 24 selected enhanced security requirements from NIST SP 800-172 (February 2021), enumerated with DoD-assigned Organization-Defined Parameters in Table 1 to 32 CFR 170.14(c)(4), items (i) through (xxiv).
The security requirements in CMMC Level 3 are selected from NIST SP 800-172 Feb2021, and where applicable, Organization-Defined Parameters (ODPs) are assigned. Table 1 to this paragraph identifies the selected requirements and applicable ODPs that represent the CMMC Level 3 security requirements.
Which information type triggers which level: a subcontractor handling only FCI (not CUI) requires CMMC Level 1 (Self); a subcontractor handling CUI requires at minimum Level 2 (Self).
If a subcontractor will only process, store, or transmit FCI (and not CUI) in performance of the subcontract, then a CMMC Status of Level 1 (Self) is required ... If a subcontractor will process, store, or transmit CUI ... then a CMMC Status of Level 2 (Self) is the minimum requirement
CMMC requirements apply to prime contractors and subcontractors at all tiers of the supply chain that will process, store, or transmit FCI or CUI, and primes must flow down the applicable CMMC level and assessment type to subcontracts.
CMMC requirements apply to prime contractors and subcontractors throughout the supply chain at all tiers that will process, store, or transmit any FCI or CUI on contractor information systems in the performance of the DoD contract or subcontract.
When a prime contract requires CMMC Level 3 (DIBCAC), subcontractors handling CUI need at minimum Level 2 (C3PAO) — the Level 3 requirement itself does not automatically flow down.
If a subcontractor will process, store, or transmit CUI in performance of the subcontract and the associated prime contract has a requirement for the CMMC Status of Level 3 (DIBCAC), then the CMMC Status of Level 2 (C3PAO) is the minimum requirement for the subcontractor.
A Conditional Level 2 CMMC Status with a POA&M is only permitted if the assessment score divided by the total number of Level 2 requirements is at least 0.8, no POA&M item is worth more than 1 point (except SC.L2-3.13.11 CUI Encryption when non-FIPS-validated encryption is employed), and six named requirements are never POA&M-eligible.
The assessment score divided by the total number of CMMC Level 2 security requirements is greater than or equal to 0.8; (ii) None of the security requirements included in the POA&M have a point value of greater than 1 ... except SC.L2-3.13.11 CUI Encryption
A POA&M must be closed out via a POA&M closeout assessment within 180 days of the Conditional CMMC Status Date, or the Conditional CMMC Status for that information system expires.
The closing of a POA&M must be confirmed by a POA&M closeout assessment within 180-days of the Conditional CMMC Status Date. If the POA&M is not successfully closed out within the 180-day timeframe, the Conditional CMMC Status for the information system will expire.
An Affirming Official from each organization (prime or subcontractor) must affirm continuing CMMC compliance electronically in SPRS after every assessment, including POA&M closeout, and annually thereafter.
An Affirming Official from each OSA, whether a prime or subcontractor, must affirm the continuing compliance of their respective organizations with the specified security requirement after every assessment, including POA&M closeout, and annually thereafter. Affirmations are entered electronically in SPRS.
The Affirming Official is defined as the senior-level representative within each Organization Seeking Assessment who is responsible for ensuring CMMC compliance and has authority to affirm the organization's continuing compliance.
Affirming Official means the senior level representative from within each Organization Seeking Assessment (OSA) who is responsible for ensuring the OSA's compliance with the CMMC Program requirements and has the authority to affirm the OSA's continuing compliance with the specified security requirements
Under the CMMC Scoring Methodology, the Level 2 maximum score equals the total number of Level 2 requirements; each NOT MET requirement subtracts a weighted value of 5, 3, or 1 points, which can produce a negative score, and each requirement is found MET, NOT MET, or Not Applicable.
The maximum score achievable for a Level 2 self-assessment or Level 2 certification assessment is equal to the total number of CMMC Level 2 security requirements. ... For each requirement NOT MET, the associated value of the security requirement is subtracted from the maximum score, which may result in a negative score.
There is exactly one Accreditation Body for the DoD CMMC Program at any given time; it authorizes and accredits C3PAOs in accordance with ISO/IEC 17020:2012 and must itself comply with ISO/IEC 17011:2017.
The Accreditation Body is responsible for authorizing and ensuring the accreditation of CMMC Third-Party Assessment Organizations (C3PAOs) in accordance with ISO/IEC 17020:2012(E) ... At any given point in time, there will be only one Accreditation Body for the DoD CMMC Program.
32 CFR 170.3(e) prescribes a four-phase implementation: Phase 1 begins on the effective date of the complementary 48 CFR CMMC acquisition final rule, and Phases 2, 3, and 4 each begin one calendar year after the start of the preceding phase.
Implementation of CMMC Program requirements will occur over four (4) phases: (1) Phase 1. Begins on the effective date of the complementary 48 CFR part 204 CMMC Acquisition final rule. ... (2) Phase 2. Begins one calendar year following the start date of Phase 1.
The 48 CFR CMMC acquisition final rule (DFARS Case 2019-D041) was published September 10, 2025 at 90 FR 43560 and became effective November 10, 2025, which is therefore the start date of CMMC Phase 1.
DATES: This rule is effective November 10, 2025.
During Phase 1, DoD's stated intent is to include requirements for CMMC Status of Level 1 (Self) or Level 2 (Self) in applicable solicitations as a condition of contract award, and it may at its discretion require Level 2 (C3PAO) in place of Level 2 (Self); as of the July 2026 suspension that discretionary option is administratively inoperative pending the CMMC reform review (see F38).
DoD intends to include the requirement for CMMC Statuses of Level 1 (Self) or Level 2 (Self) for all applicable DoD solicitations and contracts as a condition of contract award. ... DoD may also, at its discretion, include the requirement for CMMC Status of Level 2 (C3PAO) in place of the Level 2 (Self)
Phase 2, scheduled by the codified text to begin November 10, 2026 (one calendar year after Phase 1), would add the requirement for CMMC Status of Level 2 (C3PAO) for applicable solicitations as a condition of contract award, with discretionary Level 3 (DIBCAC) requirements; implementation of this milestone was administratively suspended effective July 13, 2026 (see F31), while the regulatory text remains unchanged.
Phase 2. Begins one calendar year following the start date of Phase 1. In addition to Phase 1 requirements, DoD intends to include the requirement for CMMC Status of Level 2 (C3PAO) for applicable DoD solicitations and contracts as a condition of contract award.
The codified DFARS prescribes clause 252.204-7021 for CMMC-designated procurements until November 9, 2028, and on or after November 10, 2028 (Phase 4, full implementation) for all solicitations and contracts where contractor systems will process, store, or transmit FCI or CUI, except COTS-only acquisitions.
(1) Until November 9, 2028, in solicitations and contracts ... if the program office or requiring activity determines that the contractor is required to have a specific CMMC level. (2) On or after November 10, 2028 ... if the program office or requiring activity determines that the contractor is required to use contractor information systems ... to process, store, or transmit FCI or CUI.
DFARS clause 252.204-7021 (NOV 2025) requires the contractor to have and maintain, for the duration of the contract, a current CMMC status at the contract-specified level or higher for all information systems used in performance that process, store, or transmit FCI or CUI, and to insert the substance of the clause in subcontracts involving FCI or CUI (excluding COTS).
Have and maintain for the duration of the contract a current CMMC status at the following CMMC level, or higher ... for all information systems used in performance of the contract, task order, or delivery order that process, store, or transmit FCI or CUI
Under clause 252.204-7021, a CMMC status is 'current' if the Final Level 1 (Self) status is not older than 1 year, and Final Level 2 (Self), Final Level 2 (C3PAO), and Final Level 3 (DIBCAC) statuses are not older than 3 years — establishing a one-year validity for Level 1 and three-year validity for Level 2 and Level 3 assessments — each also requiring an affirmation not older than 1 year.
(i) Not older than 1 year for Final Level 1 (Self) ... (ii) Not older than 3 years for Final Level 2 (Self) assessments and Final Level 2 (C3PAO) assessments ... (iii) Not older than 3 years for Final Level 3 (DIBCAC) assessments ... A corresponding affirmation of continuous compliance, not older than 1 year
Under DFARS 204.7503, contracting officers must check SPRS and may not award a contract, exercise an option, or extend the period of performance unless the contractor has a current CMMC status posted in SPRS at or above the required level for each CMMC unique identifier (UID).
Contracting officers shall check SPRS and not award a contract, task order, or delivery order to an offeror that does not have a current CMMC status posted in SPRS at the CMMC level ... required by the solicitation, or higher, for each CMMC UID provided by the offeror.
CMMC applies to DoD solicitations and contracts involving FCI or CUI on unclassified contractor information systems, including commercial-item acquisitions, valued above the micro-purchase threshold, but not to acquisitions exclusively for COTS items nor to Federal information systems operated on behalf of the Government.
CMMC Program requirements apply to all DoD solicitations and contracts pursuant to which a defense contractor or subcontractor will process, store, or transmit FCI or CUI on unclassified contractor information systems, including those for the acquisition of commercial items (except those exclusively for COTS items) valued at greater than the micro-purchase threshold
CMMC operates alongside, and does not replace, the pre-existing DFARS cybersecurity clauses: 252.204-7012 (MAY 2024) requires adequate security per NIST SP 800-171 and rapid cyber incident reporting to DoD, and 252.204-7019/-7020 (NOV 2023) require a current (not more than 3 years old) NIST SP 800-171 DoD Assessment score posted in SPRS and Government access to conduct Medium or High assessments.
The Contractor shall provide access to its facilities, systems, and personnel necessary for the Government to conduct a Medium or High NIST SP 800-171 DoD Assessment
As of 2026-07-31, CMMC Phase 1 is the phase in effect: Phase 1 began November 10, 2025, and on July 13, 2026 DoD Chief Information Officer Kirsten Davies signed a memorandum suspending the Phase 2 requirements scheduled for November 10, 2026 and all pending and future CMMC milestones, pending a 60-day review by a newly established CMMC Reform Task Force (companion implementation guidance on active solicitations: see F38).
The current iteration of the Cybersecurity Maturity Model Certification (CMMC) program, while intended to enhance security, imposes significant and often prohibitive burdens on the Defense Industrial Base (DIB), particularly ...
Achieving a higher CMMC status satisfies lower requirements for the same assessment scope: Level 2 (Self) satisfies Level 1 (Self); Level 2 (C3PAO) satisfies Level 1 (Self) and Level 2 (Self); Level 3 (DIBCAC) satisfies all lower statuses.
Achieving a CMMC Status of Level 3 (DIBCAC) also satisfies the requirements for CMMC Statuses of Level 1 (Self), Level 2 (Self), and Level 2 (C3PAO) set forth in §§ 170.15 through 170.17 respectively for the same CMMC Assessment Scope.
Federal Contract Information (FCI) is information not intended for public release that is provided by or generated for the Government under a contract to develop or deliver a product or service, excluding information the Government provides to the public and simple transactional information such as payment-processing data.
information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, but not including information provided by the Government to the public (such as that on public Web sites) or simple transactional information, such as that necessary to process payments.
Controlled Unclassified Information (CUI) is information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls; it excludes classified information.
information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls.
CMMC compliance certifications and affirmations carry False Claims Act exposure: when a contractor certifies compliance with DFARS 252.204-7012 or CMMC requirements as a condition of payment or contract eligibility and that certification is false, it constitutes a false claim, and false or recklessly made certifications can trigger treble damages and per-claim penalties.
certifications that are false when made, or made with reckless disregard for their truth, can trigger treble damages and per-claim penalties ... When a contractor certifies compliance with DFARS 252.204-7012 or CMMC requirements as a condition of payment or contract eligibility, and that certification is false, the contractor has submitted a false claim
The organization currently serving as the CMMC Accreditation Body is The Cyber AB (legal name: Cybersecurity Maturity Model Certification Accreditation Body, Inc.).
We are The Cyber AB ... building trust and confidence in the CMMC Ecosystem ... Copyright © 2026 Cybersecurity Maturity Model Certification Accreditation Body, Inc.
The July 2026 suspension does not affect foundational cybersecurity obligations — DFARS 252.204-7012 remains in effect, along with NIST SP 800-171 R2 compliance, cloud security obligations, and cyber incident reporting duties — and alongside the suspension DoD issued a public Request for Information seeking industry feedback on reforming CMMC, with responses due August 14, 2026.
The suspension does not affect contractors' foundational cybersecurity obligations. ... DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, is still in effect, as are NIST SP 800-171 Rev. 2 compliance requirements, cloud security obligations, and cyber incident reporting duties. ... DoD/W has issued a request for information (RFI) seeking industry feedback on reforming CMMC ... Responses are due August 14, 2026.
Companion implementation guidance accompanying the July 2026 CMMC suspension directs that active solicitations and contracts be amended to remove the suspended CMMC designations — reported as the Level 2 (C3PAO) and Level 3 requirements.
active solicitations and contracts must be amended to remove those designations