Logo Menu

US defenseΒ·Last verified

CMMC

Bottom line

CMMC is contract-driven: the solicitation specifies the required status. As of August 11, 2026, implementation is paused in Phase I, where Level 1 and Level 2 use self-assessment paths. The planned Phase II expansion of Level 2 C3PAO assessments is suspended; existing DFARS safeguarding duties still apply.

Cost and timeline No fixed program price / scope-dependent

Key facts

Controls
Level 1: 15 requirements (FAR 52.204-21). Level 2: 110 requirements (NIST SP 800-171 Rev 2). Level 3 program design: Level 2 plus 24 selected NIST SP 800-172 requirements.
Recertification cycle
Current Phase I: Level 1 self-assessment annually; Level 2 self-assessment every 3 years. Program design: Level 2 C3PAO and Level 3 DIBCAC certification statuses last 3 years.
Ongoing oversight
Level 1 assessment and affirmation annually; Level 2 affirmation after assessment and annually thereafter in the Supplier Performance Risk System (SPRS)
Common gap categories
Access control (AC); Configuration management (CM); System and communications protection (SC); Audit and accountability (AU); Incident response (IR); Media protection (MP)
Related standards
NIST SP 800-171NIST SP 800-172DFARS 252.204-7012FedRAMPFISMA

What is CMMC?

CMMC (Cybersecurity Maturity Model Certification) is the US defense acquisition program for verifying safeguards on Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) in nonfederal systems. The 32 CFR Part 170 rule defines three levels, but on July 13, 2026 the Department suspended Phase II and paused implementation in Phase I. Current guidance retains Level 1 and Level 2 self-assessment requirements while the program is reviewed.

Is CMMC a certification or an attestation?

CMMC uses both self-assessed statuses and certification statuses. Under the current Phase I pause, Level 1 is self-assessed annually and Level 2 is self-assessed every three years, with required affirmations. The program rule also defines a C3PAO-led Level 2 certification and a DIBCAC-led Level 3 certification, but the general Phase II rollout of Level 2 C3PAO requirements is suspended.

Who needs CMMC?

Defense contractors and subcontractors whose solicitation or contract specifies a CMMC status for systems that process, store, or transmit FCI or CUI. Phase I began November 10, 2025. On July 13, 2026 the Department suspended Phase II and kept Phase I self-assessment requirements in place pending a program review.

What does CMMC cost and how long does it take?

Range No fixed program price / scope-dependent

The Department does not set a standard price for internal readiness, remediation, tooling, advisory work, or a future C3PAO engagement. Current Phase I paths are self-assessments; effort depends on the applicable level, environment, existing gaps, and external support. The Phase II third-party rollout is suspended, so obtain current written requirements before requesting assessment quotes.

One thing to watch

CMMC implementation is paused in Phase I. Phase II was suspended on July 13, 2026, so do not rely on the former November 10, 2026 expansion date. Check the current Department page and the solicitation before stating that a C3PAO assessment is required.

Go deeper on this

Other frameworks buyers ask about

See all frameworks β†’