Updated September 30, 2026 to reflect the Department of War’s July 13, 2026 suspension of CMMC Phase II.
The Cybersecurity Maturity Model Certification (CMMC) is the Department of War’s program for verifying that defense contractors and subcontractors protect the government information they handle. It does not create a new security standard for most companies. Instead, it checks whether contractors actually meet the requirements already in their contracts: FAR 52.204-21 for Federal Contract Information (FCI) and NIST SP 800-171 for Controlled Unclassified Information (CUI).
July 2026 Update: CMMC Phase II Is Suspended
On July 13, 2026, the Department of War (DoW, formerly the Department of Defense) suspended Phase II of the CMMC rollout. Phase II was scheduled to begin November 10, 2026 and would have required most contractors handling CUI to earn a third-party certification from a C3PAO as a condition of contract award. The Department formed a CMMC Reform Task Force to review the program and asked industry for input on cost, burden, and alternatives to third-party assessment.
What the suspension did not change:
- Phase I remains in effect. Level 1 and Level 2 self-assessments, SPRS score submissions, and annual affirmations are still required where your contracts call for them.
- DFARS 252.204-7012 still applies. If you handle CUI, you are still contractually obligated to protect it to NIST SP 800-171.
- Enforcement continues. The Department still verifies compliance through select government-led assessments, and inaccurate cybersecurity attestations continue to carry False Claims Act risk.
- Voluntary certification is still available. C3PAOs can still perform Level 2 certification assessments for companies that want one.
In short, the suspension changed how compliance is verified, not what is required. The Task Force’s recommendations had not been made public at the time of this update, so we will revise this article as the Department announces next steps.
Who Needs CMMC?
CMMC applies to companies in the Defense Industrial Base, including prime contractors and subcontractors at every tier. If your company receives, stores, or transmits FCI or CUI as part of a defense contract or subcontract, the requirements apply to you. Primes flow these obligations down to their suppliers, so many small manufacturers, machine shops, engineering firms, and IT providers first learn about CMMC from a customer rather than from a solicitation.
The Three CMMC Levels
The current program, often called CMMC 2.0, has three levels. The earlier five-level model was retired in 2021.
- Level 1 (Foundational): For companies that handle FCI only. It covers the 15 basic safeguarding requirements in FAR 52.204-21 and is met through an annual self-assessment and affirmation.
- Level 2 (Advanced): For companies that handle CUI, which is where most defense suppliers land. It covers all 110 security requirements in NIST SP 800-171 Rev. 2. It can be met through a self-assessment or a certification assessment by a C3PAO, depending on the contract, with an annual affirmation either way.
- Level 3 (Expert): For programs involving the most sensitive CUI. It adds selected requirements from NIST SP 800-172 on top of Level 2 and is assessed by the government’s Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).
How CMMC Assessments Work
Self-assessments are scored using the DoW assessment methodology, and the resulting score is posted to the Supplier Performance Risk System (SPRS). A senior official at your company then affirms that the score is accurate, which is why an honest, well-documented assessment matters so much.
Third-party certification assessments are performed by C3PAOs, which are authorized by The Cyber AB (formerly the CMMC Accreditation Body). The assessor reviews your System Security Plan (SSP), evidence, and technical controls against each requirement. Companies that are close but not complete may be able to document remaining gaps in a Plan of Action and Milestones (POA&M), within limits set by the program.
CMMC Rollout Timeline
- November 10, 2025: Phase I began. Level 1 and Level 2 self-assessment requirements started appearing in contracts.
- July 13, 2026: Phase II suspended and CMMC Reform Task Force formed.
- November 10, 2026: Former Phase II start date for third-party Level 2 certification. No longer in effect.
- Later phases: Level 3 requirements and full implementation were scheduled to follow. These milestones are on hold pending the review.
What Defense Contractors Should Do Now
- Confirm what your contracts require. Check solicitations and subcontract flow-downs for FAR 52.204-21, DFARS 252.204-7012, and CMMC clauses.
- Scope your CUI environment. Identify which systems actually touch CUI. A tightly scoped enclave reduces cost and effort.
- Complete an honest gap assessment. Score yourself against all 110 NIST SP 800-171 requirements and make sure your SPRS score reflects reality.
- Build and maintain your documentation. Keep your SSP and POA&M current, since they are the first things an assessor reviews.
- Keep improving. Readiness takes months. Work done now counts no matter how the certification program changes.
How BlueKey IT Helps
BlueKey IT is a CyberAB Registered Practitioner Organization with a Certified CMMC Professional (CCP) on staff. We help defense contractors scope CUI environments, close NIST 800-171 gaps, produce an accurate SPRS score, build SSP and POA&M documentation, and prepare for voluntary or required C3PAO assessments. Learn more about our cybersecurity compliance services or see our local CMMC services in Arizona, Colorado, Texas, Utah, and Tennessee.
Schedule a free CMMC strategy call or call (866) 844-0536.





