Does CMMC apply to you — and at what level?

Current as of August 1, 2026. Every claim below carries a [F##] tag resolving to a fact in the store, each with a pinpoint citation and a verbatim quote retrieved from the source. Most facts are primary-source (CFR, Federal Register, acquisition.gov); the remainder rest on secondary sources — the July 2026 suspension corroborated across multiple independent reports pending retrieval of the primary memo; the False Claims Act analysis a published legal alert; the accreditation-body identification the organization's own — the store labels each fact's confidence tier. This is education, not legal advice — confirm decisions about a specific contract with your contracting officer or counsel.

The one thing to know this month

If your company handles non-public DoD contract information on its own systems, CMMC already reaches you: DoD's stated intent in Phase 1 is to include self-assessment requirements as a condition of award in applicable solicitations — and where a solicitation carries the requirement, contracting officers may not award without your current status in SPRS F22F23F28. But the phase-up that everyone spent 2026 preparing for just moved. (Contracts exclusively for commercial off-the-shelf items are carved out — see below F29.) Phase 1 has been live since November 10, 2025 F22, and on July 13, 2026 the Pentagon suspended the Phase 2 requirements that were scheduled to begin November 10, 2026 — along with all pending and future CMMC milestones — pending a 60-day task-force review F31. The suspension is administrative: the underlying regulations were not amended, and the four-phase schedule still sits unchanged in the CFR F24F31. What you must do today hasn't gone away: independent reports of the memo consistently agree that self-assessment obligations, SPRS scores, and the pre-existing DFARS clause obligations continue to apply F31F30F37.

What CMMC is

The Cybersecurity Maturity Model Certification program is DoD's way of verifying — not just trusting — that contractors protect two kinds of information: Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) F01. It was established by a final rule published October 15, 2024, took effect December 16, 2024, and lives at 32 CFR Part 170 F01F02. Its legal authority is 5 U.S.C. 301 together with section 1648 of the FY2020 National Defense Authorization Act F03.

CMMC doesn't invent new security controls. It reuses three existing standards — the FAR's 15 basic safeguarding requirements, NIST SP 800-171, and selections from NIST SP 800-172 F04F06 — and layers verification on top: assessments at defined intervals and compliance affirmations in SPRS by a senior-level representative F01F17F18. And it doesn't replace your existing obligations: DFARS 252.204-7012 (adequate security plus rapid cyber incident reporting to DoD) and the -7019/-7020 assessment-score clauses continue to apply alongside it F30.

First: the two kinds of information

Everything in CMMC keys off two defined terms, so pin them down before anything else.

Federal Contract Information (FCI) is information not intended for public release that is provided by or generated for the government under a contract to develop or deliver a product or service — excluding what the government itself publishes and simple transactional data like payment processing F33. In practice that covers things like non-public statements of work, technical correspondence, and deliverables — illustrations of the definition, not a sourced list — so as working guidance, assume "we have FCI" unless your contracts are exclusively for COTS items F33F29.

Controlled Unclassified Information (CUI) is information the government creates or possesses — or that you create or possess on the government's behalf — that a law, regulation, or government-wide policy requires or permits an agency to protect with safeguarding or dissemination controls; classified information is a separate regime entirely F34. CUI is where the expensive obligations live F12, and identifying it is the hardest practical step: don't guess. Ask your contracting officer or your prime, in writing, to identify the CUI in your contract — misjudging this in either direction costs real money, because the CUI answer is what separates a 15-requirement Level 1 from a 110-requirement Level 2 F06F05.

Does it apply to you?

If your company — at any tier, prime or sub — will process, store, or transmit FCI or CUI on your own unclassified systems under a DoD contract, CMMC applies F13F29. That includes commercial-item acquisitions above the micro-purchase threshold; the carve-outs are acquisitions exclusively for COTS items and Federal information systems operated on behalf of the government — meaning government systems, not your own systems that merely handle government information F29. Primes are required to flow the applicable CMMC level down into subcontracts that involve FCI or CUI F13F26.

Which level are you?

If you're a prime, the required level is whatever the solicitation specifies — a program-office determination, not an automatic mapping F23F25. What the information type does determine is the floor, and for subcontractors the rule states it directly F12:

Higher statuses nest: a Level 2 (C3PAO) certification also satisfies Level 1 and Level 2 (Self) for the same scope, and Level 3 satisfies everything below it F32. One subtlety for subs on big programs: when the prime's contract requires Level 3, subcontractors handling CUI need Level 2 (C3PAO) at minimum — the Level 3 requirement itself doesn't automatically flow down F14.

C3PAOs are accredited by a single accreditation body — the rule requires exactly one to exist at any time; it accredits C3PAOs to ISO/IEC 17020 and must itself comply with ISO/IEC 17011 F20. The regulation doesn't name it; the organization currently holding the role is The Cyber AB F36.

Scores, POA&Ms, and the 180-day clock

Level 2 assessments are scored: the maximum equals the number of requirements, each NOT MET item subtracts 5, 3, or 1 points, and a bad assessment can go negative F19. You may achieve a Conditional Level 2 status with a POA&M only if your assessment score divided by the total number of Level 2 requirements is at least 0.8 — that is, at least 88 against the 110-point maximum — none of the open items is worth more than 1 point (with one narrow encryption exception), and none of six specifically excluded requirements is open F15F19.

The clock is stricter than it sounds: the POA&M's closure must be confirmed by a POA&M closeout assessment completed within 180 days of the Conditional CMMC Status Date, or the conditional status expires F16. Fixing the items internally by day 179 is not enough — the closeout assessment itself has to happen inside the window, so on the C3PAO track that means booking the assessor with lead time to spare F16F09.

One trap to name explicitly: "my score is in SPRS" can mean two different things. The NIST SP 800-171 DoD Assessment score required by the older -7019/-7020 clauses and your CMMC assessment results are separate submissions that both live in SPRS — the old clauses continue to apply alongside CMMC, so you maintain both F30F08. When a prime asks for "your SPRS score," find out which one they mean.

After every assessment — and annually thereafter — a senior-level representative of your organization must personally affirm continuing compliance in SPRS F17. The rule calls this person the Affirming Official: someone with actual authority over compliance, not a checkbox delegate F18. Treat that signature with respect: legal analyses of the program warn that a compliance certification made as a condition of payment or contract eligibility that is false when made — or made with reckless disregard for the truth — is a false claim under the False Claims Act, exposing the company to treble damages and per-claim penalties F35. The affirmation is a legal representation, not paperwork; affirm what you can evidence, nothing more.

What contracting officers now do with all this

Since November 10, 2025, the acquisition side has teeth. Contracting officers must check SPRS and may not award, exercise an option, or extend performance unless your current CMMC status is posted at or above the required level F28. Clause 252.204-7021 requires you to maintain that status for the life of the contract on every in-scope system, and to insert the clause's substance into your subcontracts that involve FCI or CUI (COTS-only subcontracts excepted) F26. "Current" is defined precisely: Level 1 self-assessments age out after one year; Level 2 and Level 3 assessments after three; and your affirmation must never be older than a year F27. Today the clause appears in procurements the program office designates. The codified DFARS text prescribes it as the default wherever contractor systems touch FCI or CUI (COTS excepted) on or after November 10, 2028 F25 — but that full-implementation milestone is among those administratively suspended pending the reform review, so treat the 2028 date as codified text whose arrival now depends on the review's outcome F31.

The timeline, honestly stated

The regulation prescribes four phases, each starting one year after the last F21. Phase 1 began November 10, 2025, when the DFARS acquisition rule took effect F22. In Phase 1, DoD's stated intent is to include Level 1 (Self) or Level 2 (Self) requirements in applicable solicitations as conditions of award — with rule-level discretion to require Level 2 (C3PAO) instead, though that option is administratively inoperative during the suspension F23F38. Phase 2 — which would make Level 2 (C3PAO) the norm for applicable CUI solicitations F24 — is the milestone suspended on July 13, 2026, together with all pending and future CMMC milestones, pending the reform review F31.

What this means for a small contractor right now: keep your Phase 1 obligations current — reports of the suspension memo consistently state that existing self-assessment, SPRS, and DFARS clause obligations continue to apply F31F30 — keep both SPRS submissions and your affirmation fresh F27F28F30, and treat the suspended phase-up dates as movement to watch, not a reprieve: the regulatory text that drives them is still on the books unchanged F24F31.

And if you're already on the C3PAO track, don't cancel your assessment booking as a reflex — the answer depends on which situation you're in. Reported implementation guidance accompanying the suspension directs that active solicitations and contracts be amended to remove the suspended Level 2 (C3PAO) and Level 3 designations F38F31 — so a booking driven only by a pending bid may genuinely have lost its deadline, and even an awarded contract may eventually be modified. But an amendment is not automatic relief: until your contracting officer actually issues the modification in writing, the clause in your awarded contract remains a binding term — treat the maintain-for-duration obligation F26 as in force until the mod arrives, never on the strength of a news report. And a certification you hold satisfies every lower requirement for the same scope F32, so it keeps its value if requirements return. Weigh your slot against your actual contracts and your primes' demands — deliberately, not off a headline.

What to do Monday

  1. Pull your contracts and list which of these clauses appear: 252.204-7012, -7019, -7020, -7021. That inventory is your obligation map F30F26.
  2. Get the CUI question answered in writing — ask your contracting officer or prime to identify the CUI (if any) in each contract; FCI you should assume you have F33F34F12.
  3. Check what's in SPRS for you today — both the NIST SP 800-171 assessment score the old clauses require and any CMMC assessment results — and note their dates against the currency clocks: one year for Level 1 and for every affirmation, three years for Level 2 CMMC assessments F27 — and the -7019 NIST assessment score itself must be not more than three years old F30.
  4. Calendar the affirmation and decide who your Affirming Official is — someone who understands they are signing a legal representation, not a form F17F18F35.
  5. Watch two dates: the CMMC reform task-force report, expected in September 2026 — the memo set a 60-day review clock, and reporting adds a 15-day report window from the task force's mid-July start F31 — and, if you want a voice in the outcome, the reform RFI comment window, which closes at **12:00 p.m. Eastern on August 14, 2026** F37.

Facts cited: F01–F38 · Store: facts/cmmc-seed.json · Verification: verification/ · This lesson has not yet received SME sign-off and is a Phase 0 proof artifact, not published guidance.

Lesson revision 8 · pending SME sign-off · tap any citation tag for the verbatim quote, source, and verification date.