Key facts
- Controls
- Level 1: 15 requirements (FAR 52.204-21). Level 2: 110 requirements (NIST SP 800-171 Rev 2). Level 3 program design: Level 2 plus 24 selected NIST SP 800-172 requirements.
- Recertification cycle
- Current Phase I: Level 1 self-assessment annually; Level 2 self-assessment every 3 years. Program design: Level 2 C3PAO and Level 3 DIBCAC certification statuses last 3 years.
- Ongoing oversight
- Level 1 assessment and affirmation annually; Level 2 affirmation after assessment and annually thereafter in the Supplier Performance Risk System (SPRS)
- Public registry
- Cyber AB CMMC Marketplace β
- Common gap categories
- Access control (AC); Configuration management (CM); System and communications protection (SC); Audit and accountability (AU); Incident response (IR); Media protection (MP)
- Related standards
What is CMMC?
CMMC (Cybersecurity Maturity Model Certification) is the US defense acquisition program for verifying safeguards on Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) in nonfederal systems. The 32 CFR Part 170 rule defines three levels, but on July 13, 2026 the Department suspended Phase II and paused implementation in Phase I. Current guidance retains Level 1 and Level 2 self-assessment requirements while the program is reviewed.
Is CMMC a certification or an attestation?
CMMC uses both self-assessed statuses and certification statuses. Under the current Phase I pause, Level 1 is self-assessed annually and Level 2 is self-assessed every three years, with required affirmations. The program rule also defines a C3PAO-led Level 2 certification and a DIBCAC-led Level 3 certification, but the general Phase II rollout of Level 2 C3PAO requirements is suspended.
Who needs CMMC?
Defense contractors and subcontractors whose solicitation or contract specifies a CMMC status for systems that process, store, or transmit FCI or CUI. Phase I began November 10, 2025. On July 13, 2026 the Department suspended Phase II and kept Phase I self-assessment requirements in place pending a program review.
What does CMMC cost and how long does it take?
The Department does not set a standard price for internal readiness, remediation, tooling, advisory work, or a future C3PAO engagement. Current Phase I paths are self-assessments; effort depends on the applicable level, environment, existing gaps, and external support. The Phase II third-party rollout is suspended, so obtain current written requirements before requesting assessment quotes.
CMMC implementation is paused in Phase I. Phase II was suspended on July 13, 2026, so do not rely on the former November 10, 2026 expansion date. Check the current Department page and the solicitation before stating that a C3PAO assessment is required.