Cybersecurity Maturity Model Certification
· About Cybersecurity Maturity Model Certification
Key Takeaways
- CMMC 2.0 applies to Department of Defense contracting activity that requires handling Federal Contract Information or Controlled Unclassified Information, and Phase 1 self-assessments have been in force since 10 November 2025. [1][2]
- Phase 2, which would have required third-party Level 2 certification for many CUI-handling contractors, was suspended on 13 July 2026 pending a CMMC reform review, so the November 2026 rollout is not currently active. [1][2][3]
- Contractors seeking DoD awards or option exercises tied to CMMC must maintain the required level in the Supplier Performance Risk System, and false or stale representations can trigger contractual remedies and fraud exposure. [2][4]
- The program reaches primes and subcontractors in the defense industrial base, and requirements can flow down when a contract or solicitation includes the CMMC clauses. [2][4]
- CMMC does not replace NIST SP 800-171 or FAR 52.204-21; it operationalizes those cybersecurity baselines through self-assessment, third-party assessment, and contract eligibility gates. [2][5]
- The current posture is pause, not repeal: the underlying regulatory framework remains in place unless and until DoD issues a new rule, class deviation, or amended implementation schedule. [3][5]
What It Is
Cybersecurity Maturity Model Certification is the Department of Defense’s contract-based cybersecurity program for the defense industrial base, intended to verify that contractors and subcontractors protect sensitive unclassified information using defined cybersecurity practices. The program is administered by the DoD Chief Information Officer and implemented through the CMMC program rule and related DFARS contracting clauses. [1][2][5]
The program’s enforcement body is the Department of Defense, acting through contracting officers and the DoD CIO/CMMC implementation apparatus. The official DoW CMMC page states that Phase II was suspended on 13 July 2026 and that a CMMC Reform Task Force was established to review the program. [1][2]
Key dates are as follows: the CMMC program rule was finalized before Phase 1 took effect on 10 November 2025; Phase 1 self-assessment requirements became effective on 10 November 2025; and Phase 2 had been scheduled to begin on 10 November 2026 before being suspended on 13 July 2026. [1][2][5]
Who Must Comply
CMMC applies to contractors and subcontractors in the defense supply chain when DoD solicitation or contract language requires a particular CMMC level. At present, the active baseline is Phase 1, which covers Level 1 self-assessments and some Level 2 self-assessments, while Phase 2 third-party assessments are suspended. [1][2][4]
The practical applicability threshold depends on the data involved: Federal Contract Information generally maps to Level 1, while Controlled Unclassified Information generally maps to Level 2. Level 2 was designed to require a third-party assessment for many CUI-bearing contracts, but that third-party requirement is paused as of 13 July 2026. [2][4][5]
CMMC has extraterritorial reach in the ordinary federal procurement sense: any entity, including foreign or non-U.S. affiliates, can be bound if it seeks or performs a DoD contract that includes the relevant clauses. The decisive factor is contractual inclusion and the handling of covered information, not the entity’s domicile. [2][4]
No broad statutory exemption removes the program for defense contractors simply because they are small, commercial, or subcontractors. The more limited issue is whether a given solicitation actually includes CMMC clauses and whether the contractor handles only information that fits a lower level or no covered information at all. [2][4]
Core Requirements
- Perform the correct assessment level. Contractors subject to Level 1 must complete the required self-assessment, and contractors in scope for Level 2 must preserve readiness for either self-assessment or, when reinstated, third-party assessment depending on the contract’s clause package. [2][4][5]
- Enter and maintain assessment results in SPRS. The DoD materials direct contractors to submit self-assessment scores in the Supplier Performance Risk System, and the score must remain current enough to support contract eligibility and annual updates where required. [2][4]
- Implement the underlying cybersecurity controls. CMMC is built on control sets that map to FAR 52.204-21 and NIST SP 800-171, so covered contractors must actually operate the security practices, not merely document them. [2][5]
- Preserve evidence for assessments and audits. Contractors should retain policies, system boundaries, inventories, access controls, incident records, and remediation evidence because CMMC assessments and contracting oversight depend on demonstrable implementation. [4][5]
- Flow requirements down to relevant subcontractors. When contract clauses require CMMC at a given level, primes must ensure the required level is maintained across subcontract tiers that store, process, or transmit covered information. [2][4]
- Avoid false attestations. A contractor that represents compliance without meeting the level risks termination, award ineligibility, and potential civil or criminal exposure under procurement integrity and false-claims theories. [4][5]
Deadlines and Penalties
| milestone | date | what applies | |---|---:|---| | Phase 1 effective date | 10 November 2025 | Level 1 self-assessments and related contract clauses began to apply in covered DoD contracts. [1][2] | | Phase 2 scheduled date | 10 November 2026 | Third-party Level 2 implementation had been scheduled to begin. [1][3] | | Phase 2 suspension | 13 July 2026 | DoD suspended Phase 2 and launched a reform review; the rollout is not currently active. [1][2][3] |
Maximum sanctions are not stated as a single CMMC-specific civil penalty schedule in the program materials. The principal consequences are contractual: non-award, disqualification, stop-work or termination, loss of option exercise, removal from competitive range, and potential flow-down disruption. [2][4][5]
Where a contractor makes false certifications or misrepresents its cybersecurity posture, broader federal remedies can apply, including False Claims Act exposure, suspension or debarment, and criminal liability in serious cases. Those sanctions arise from general federal procurement and fraud law rather than a bespoke CMMC fine table. [4][5]
How to Comply
- Map your contract scope. Identify which systems, facilities, and subcontractors handle FCI or CUI, then tie each workstream to the correct CMMC level and clause set. [2][5]
- Build a control baseline. Use NIST CSF 2.0 as the executive framework, NIST SP 800-171 for CUI protection, and ISO 27001 as the management-system backbone for policies, ownership, and auditability. [2][5]
- Harden the evidence trail. Create a living compliance binder with network diagrams, asset inventories, access reviews, incident response records, and remediation logs that can survive a third-party review if Phase 2 returns. [4][5]
- Automate assessment readiness. Run recurring self-assessments, track POA&Ms, and assign remediation deadlines so SPRS scores remain accurate and defensible at bid time and during performance. [2][4]
- Train the supply chain. Push requirement summaries and evidence requests to subcontractors that handle covered information, and include flow-down language in subcontracts and work orders. [2][4]
- Adopt governance for AI and cyber overlap. ISO 42001 can help govern AI-related data handling, but it does not replace CMMC controls; use it only where AI systems touch contract data, logs, or security operations. [5]
- Monitor rule changes continuously. Because Phase 2 is suspended rather than repealed, track DoD CIO notices, DFARS updates, and solicitation language before assuming third-party assessment is permanently off the table. [1][3][5]
Related Regulations
- FAR 52.204-21 overlaps because it supplies the basic safeguarding requirements for federal contract information that CMMC Level 1 operationalizes. [2][5]
- NIST SP 800-171 overlaps because it is the principal control baseline for protecting CUI and underpins CMMC Level 2. [2][5]
- DFARS 252.204-7012 overlaps because it governs safeguarding and incident reporting for covered defense information and often appears alongside CMMC clauses. [4][5]
- State privacy and breach-notification laws can conflict in incident response timing and disclosure strategy when a contractor experiences a cyber event affecting non-federal personal data. [5]
- The FCA and federal suspension/debarment regime overlap because inaccurate compliance claims can turn a cybersecurity lapse into procurement fraud or responsibility issues. [4][5]
FAQ
Does CMMC apply to companies outside the United States?
Yes, if they seek or perform a DoD contract that includes CMMC requirements. The program is contract-based, so nationality does not control applicability; the presence of covered information and contract clauses does. Foreign subcontractors can also be pulled in through flow-down requirements. [2][4]
Is Phase 2 of CMMC currently in effect?
No. DoD announced on 13 July 2026 that Phase 2 was immediately suspended while a CMMC Reform Task Force reviews the program, so the previously scheduled 10 November 2026 third-party assessment rollout is not currently active. [1][2][3]
Do contractors still need self-assessments during the Phase 2 suspension?
Yes, Phase 1 remains in force, and covered contracts can still require Level 1 self-assessment and certain Level 2 self-assessment activity. The suspension only paused the Phase 2 third-party transition, not the entire program. [1][2][4]
What happens if a contractor loses CMMC readiness after award?
The most immediate risks are contractual, including stop-work, termination, or loss of future awards and options. If the contractor falsely represented its status, the issue can also escalate into fraud or suspension/debarment exposure. [4][5]
Does CMMC replace NIST 800-171 or ISO 27001?
No. CMMC is a procurement mechanism that verifies implementation of control baselines, especially NIST SP 800-171 for CUI, while ISO 27001 is a voluntary management standard that can help organize a compliant security program. ISO 27001 may support CMMC readiness, but it is not a substitute for the required DoD controls. [2][5]
Sources
- DoW CIO — Cybersecurity Maturity Model Certification
- DoW CIO — About CMMC
- DoD Business — CMMC: What Every DoD Contractor Needs to Know (PDF)
- Morrison Foerster — Department of Defense Finalizes Long-Awaited Cybersecurity Rule
- WilmerHale — Pentagon Suspends CMMC Phase 2 Requirements and Launches Review
- Government Contracts Law — DoD Suspends CMMC Phase 2
- Latham & Watkins — What Defense Contractors Should Know About DOD Suspension of CMMC Phase 2
- NatLawReview — DoD CIO Suspend Implementation of CMMC Phase II
Put it into practice
- Generate the policy: CMMC policy generator (generatepolicy.com)
- Buy the policy pack: CMMC Level 2 Bundle (cyberpolicy.shop)
- Build it yourself: CMMC 2.0 Readiness Accelerator (ciso.diy)