Program · US defence · Department of War

CMMC compliance in 2026: levels, the Phase 2 pause and what still applies

CMMC compliance means meeting the Department of War's Cybersecurity Maturity Model Certification for contracts with federal contract information or CUI. Phase 1 self-assessments have applied since November 2025, but Phase 2 third-party certification was suspended on 13 July 2026. NIST SP 800-171 obligations under DFARS 7012 still apply.

Key takeaways

What you need to know about CMMC

Three levelsLevel 1 for FCI, Level 2 for CUI, Level 3 for the most sensitive programs.
Pause, not repealPhase 2 is suspended; Phase 1 and DFARS 7012 still apply.
Same 110 requirementsLevel 2 is NIST SP 800-171 Rev 2, which the DFARS clause already requires.
Score mattersSPRS scores are visible to contracting officers now.
Prepare anywayC3PAO capacity will be tight when certification resumes.

Who needs CMMC?

Defense contractors and subcontractors whose contracts involve FCI or CUI.

Prime contractorsCompanies bidding on Department of War contracts with FCI or CUI.
SubcontractorsRequirements flow down to every tier that handles FCI or CUI.
Manufacturers and engineersFirms holding technical drawings and export-controlled data.
IT and cloud providers to the DIBExternal service providers in a contractor's scope.
C3PAOs and RPOsAssessors and consultants serving the defense industrial base.

QULDEX helps here first: the readiness check shows where you stand before you commit budget.

What the program requires

What does CMMC require?

CMMC requires contractors to implement the security requirements for their level, assess them (self, C3PAO or DIBCAC), post results and annual affirmations in SPRS, and flow requirements down to subcontractors.

L1 FCI

Level 1

15 FAR 52.204-21 requirements, annual self-assessment.

In QULDEX: Ready-made Level 1 checklist
L2 CUI

Level 2

110 NIST SP 800-171 Rev 2 requirements.

In QULDEX: Pre-mapped requirements and objectives
L3 CUI+

Level 3

24 NIST SP 800-172 requirements on top.

In QULDEX: Extra requirements tracked
SPRS Score

Scores and affirmations

Results posted and affirmed every year.

In QULDEX: Score calculated from status
POA&M Gaps

Conditional status

Limited POA&M, closed within 180 days.

In QULDEX: Close-out timers
Flow Supply chain

Flow-down

Subcontractors meet the level for their data.

In QULDEX: Vendor register
Program explorer

Which CMMC program rules matter most?

These 17 program rules decide what you must do, how you are assessed and what the 2026 suspension changes. Select any one to see the detail and how QULDEX handles it.

Dec 2024program rule in effect
Nov 2025Phase 1 starts
Jul 2026Phase 2 suspended
Sep 2026Task Force report due

Showing up to 6 per group. Search, filter, or open a group to see all 17.

Levels and status 5

  1. Level 1Foundational (FCI)

    15 basic safeguarding requirements from FAR 52.204-21 for contractors handling Federal Contract Information; annual self-assessment and affirmation.

    In QULDEXLevel 1 requirements are a ready checklist with yearly affirmation reminders.

    Typical evidence
    Self-assessment, SPRS entry
    Maps to
    FAR 52.204-21

  2. Level 2Advanced (CUI)

    All 110 requirements of NIST SP 800-171 Rev 2 for contractors handling Controlled Unclassified Information; self-assessment or C3PAO assessment every three years, with annual affirmation.

    In QULDEXThe 110 requirements are pre-mapped with evidence requests per assessment objective.

    Typical evidence
    SSP, assessment results
    Maps to
    NIST SP 800-171 Rev 2

  3. Level 3Expert (CUI, highest priority)

    Level 2 certification plus 24 selected requirements from NIST SP 800-172, assessed by DIBCAC every three years.

    In QULDEXQULDEX tracks this as a programme requirement with an owner, evidence and a due date, alongside the 110 NIST SP 800-171 requirements it rests on.

    Typical evidence
    DIBCAC assessment
    Maps to
    NIST SP 800-172

  4. §170.21POA&M rules

    Conditional status is possible with a minimum score and only for eligible requirements; open POA&M items must close within 180 days.

    In QULDEXPOA&M items have 180-day close-out timers.

    Typical evidence
    POA&M, close-out assessment

  5. §170.22Affirmations

    A senior official affirms continuing compliance in SPRS after each assessment and every year.

    In QULDEXAffirmation dates are reminders on the dashboard.

    Typical evidence
    SPRS affirmation

Phases and 2026 status 4

  1. Phase 1Self-assessments (from 10 Nov 2025)2026 status

    Contracting officers can require Level 1 and Level 2 self-assessments as a condition of award.

    In QULDEXQULDEX tracks this as a programme requirement with an owner, evidence and a due date, alongside the 110 NIST SP 800-171 requirements it rests on.

  2. Phase 2C3PAO Level 2 (suspended)2026 status

    Would have made third-party Level 2 certification the default from 10 Nov 2026; suspended by the 13 July 2026 memo pending the Reform Task Force review.

    In QULDEXYour programme keeps moving: QULDEX tracks readiness for a C3PAO assessment whenever it resumes.

  3. Phases 3–4Level 3 and full rollout (on hold)2026 status

    Level 3 requirements and full implementation across contracts are on hold pending further notice.

    In QULDEXQULDEX tracks this as a programme requirement with an owner, evidence and a due date, alongside the 110 NIST SP 800-171 requirements it rests on.

  4. DFARS 7012Existing obligations still apply

    DFARS 252.204-7012 still requires NIST SP 800-171 Rev 2, 72-hour cyber incident reporting and FedRAMP Moderate equivalent cloud for CUI.

    In QULDEXIncident timers and cloud provider evidence sit with the 110 requirements.

    Typical evidence
    Incident reports, CSP evidence
    Maps to
    NIST 800-171

Scoping 5

  1. CUICUI assets

    Assets that process, store or transmit CUI are assessed against all Level 2 requirements.

    In QULDEXAssets are tagged by category in the asset inventory.

    Typical evidence
    Asset inventory

  2. SPASecurity Protection Assets

    Assets that provide security functions, such as identity and logging, are in scope.

    In QULDEXQULDEX tracks this as a programme requirement with an owner, evidence and a due date, alongside the 110 NIST SP 800-171 requirements it rests on.

  3. CRMAContractor Risk Managed Assets

    Assets that can, but are not intended to, handle CUI are documented in the SSP and risk-managed.

    In QULDEXQULDEX tracks this as a programme requirement with an owner, evidence and a due date, alongside the 110 NIST SP 800-171 requirements it rests on.

  4. SpecializedSpecialized Assets

    IoT, OT, test equipment and restricted systems are documented and managed through policy.

    In QULDEXQULDEX tracks this as a programme requirement with an owner, evidence and a due date, alongside the 110 NIST SP 800-171 requirements it rests on.

  5. ESPExternal service providers

    Cloud providers handling CUI must be FedRAMP Moderate or equivalent; other ESPs fall into the assessment scope.

    In QULDEXEach provider records its FedRAMP status or evidence.

    Typical evidence
    CSP evidence, customer responsibility matrix
    Maps to
    FedRAMP

Assessment 3

  1. SPRSSupplier Performance Risk System score

    Self-assessment scores (110 down to −203) are posted in SPRS and checked by contracting officers.

    In QULDEXQULDEX calculates the score from requirement status before you post it.

    Typical evidence
    SPRS score record
    Maps to
    NIST 800-171A

  2. C3PAOThird-party assessment

    A CMMC Third-Party Assessment Organisation, authorised by the Cyber AB, assesses Level 2 against each objective.

    In QULDEXAssessors get view-only, logged access to evidence.

    Typical evidence
    Assessment report

  3. Flow-downSubcontractors

    CMMC requirements flow down to subcontractors that handle FCI or CUI.

    In QULDEXSubcontractor status is tracked in the vendor register.

    Typical evidence
    Flow-down evidence

Based on 32 CFR Part 170, the 48 CFR DFARS rule and the July 2026 suspension memo and class deviation. Summaries are QULDEX paraphrases, not legal advice.

Compliance path

How do you prepare for CMMC Level 2?

Scope your CUI environment, implement the 110 requirements, score yourself in SPRS and get ready for a C3PAO. Most contractors need 6 to 18 months; the Phase 2 pause gives time but not an exemption.

  1. Identify FCI and CUI and set your level

    Check contracts and data flows to decide Level 1, 2 or 3.

  2. Scope the CUI environment

    Categorise assets and external service providers; shrink scope with an enclave where you can.

  3. Implement the 110 requirements

    Close gaps against NIST SP 800-171 Rev 2 and write the System Security Plan.

  4. Self-assess and post to SPRS

    Score against NIST SP 800-171A objectives and affirm.

  5. C3PAO assessment when required

    Plan for certification once Phase 2 resumes or a contract asks for it.

  6. Keep it current

    Every yearAffirmation in SPRS
    180 daysClose POA&M items
    Year 3Reassessment

Phase dates follow the 48 CFR rule and the 13 July 2026 suspension memo. Durations are QULDEX planning ranges.

Records to keep

Which documents does CMMC need?

Assessors start from the System Security Plan and ask for evidence against each objective.

DocumentRuleWhere it lives in QULDEX
System Security Plan (SSP)NIST 800-171 3.12.4Policy library
Asset inventory and scope categories32 CFR 170.19Risk register
Network and data-flow diagrams32 CFR 170.19Evidence vault
Policies and procedures for 14 familiesNIST 800-171 Rev 2Policy library
POA&M32 CFR 170.21CAPA automation
SPRS score and affirmations32 CFR 170.22Evidence vault
Customer responsibility matrix for cloud providersDFARS 252.204-7012Vendor register
Incident response plan and reportsDFARS 252.204-7012CAPA automation

Document names follow the CMMC rules and NIST SP 800-171; storage locations are QULDEX recommendations.

Time and cost

How long does CMMC Level 2 take and what drives the effort?

Most contractors need 6 to 18 months to reach Level 2 readiness. Scope size, the state of your SSP and whether CUI sits in a separate enclave drive most of the effort.

Where the time goes

Scoping3–6 wk
Implementing requirements4–12 mo
SSP and evidence1–3 mo
Self-assessment2–4 wk
C3PAO assessment1–3 mo

Bars show the upper end of each range on one scale (18 months = full width).

What changes the effort

  • Scope: an enclave can cut the asset count sharply
  • Starting SPRS score: low scores mean more remediation
  • Cloud providers: need FedRAMP Moderate or equivalent evidence
  • Subcontractors: flow-down adds supplier work
  • Existing ISO 27001 or NIST CSF: covers part of the requirements
Readiness check · 2 minutes

How ready are you for CMMC?

Check these eight things first. Nothing you enter leaves this page.

LevelDo you know which contracts involve FCI or CUI and which level applies?
ScopeIs your CUI environment scoped with asset categories?
SSPIs your System Security Plan current?
SPRSHave you posted a current score in SPRS?
3.1Is access to CUI limited to authorised users and devices?
3.5.3Is MFA in place for privileged and network access?
7012Can you report cyber incidents within 72 hours?
CloudAre cloud providers handling CUI FedRAMP Moderate or equivalent?
Crosswalk

How CMMC maps to NIST SP 800-171, NIST 800-53 and ISO 27001

CMMC Level 2 is NIST SP 800-171 Rev 2, which derives from NIST SP 800-53. ISO 27001 evidence covers part of it but not the CUI-specific requirements.

CMMC crosswalk

CMMC Level 2 domainNIST SP 800-171 Rev 2NIST SP 800-53 Rev 5ISO 27001:2022Shared evidence
Access Control (AC)3.1.1–3.1.22AC familyA.5.15–A.5.18, A.8.2–A.8.5Access reviews
Audit and Accountability (AU)3.3.1–3.3.9AU familyA.8.15–A.8.17Log samples
Configuration Management (CM)3.4.1–3.4.9CM familyA.8.9, A.8.32Baselines
Identification and Authentication (IA)3.5.1–3.5.11IA familyA.5.16–A.5.17, A.8.5MFA settings
Incident Response (IR)3.6.1–3.6.3IR familyA.5.24–A.5.26Incident reports
Risk Assessment (RA)3.11.1–3.11.3RA family6.1.2, A.8.8Risk assessment, scans
System and Communications Protection (SC)3.13.1–3.13.16SC familyA.8.20–A.8.24Network diagrams

Indicative mapping for planning. CMMC vs NIST 800-171 is compared in full on the blog.

Where QULDEX fits

How QULDEX runs CMMC from scoping to C3PAO assessment

QULDEX is CMMC compliance and audit management software built from EGV Group's audit delivery, used by defense contractors, their RPOs and the C3PAOs who assess them. Pick your role to see who does what.

For primes and subcontractors handling FCI or CUI.

  1. ScopeScope the CUI environmentAsset categories in the inventory
  2. ImplementClose gaps110 requirements mapped to evidence
  3. SSPWrite the SSPSSP linked to live evidence
  4. ScorePost to SPRSScore calculated from status
  5. POA&MClose open items180-day timers
  6. SustainAffirm every yearAffirmation reminders
Without one systemWith QULDEX
SSP written once and leftSSP linked to live evidence
SPRS score worked out by handScore calculated from status
POA&M dates missed180-day timers on every item
Subcontractor status unknownFlow-down tracked per supplier
10+years of audit delivery500+audits deliveredBoth sidesof the audit on one platformRBACand a full audit trail on every action
FAQ

CMMC questions people ask

Is CMMC suspended?

Phase 2, which would have required third-party Level 2 certification from 10 November 2026, was suspended on 13 July 2026, and Phases 3 and 4 are on hold. Phase 1 self-assessments and the DFARS 252.204-7012 obligations still apply.

What are the CMMC levels?

Level 1 covers 15 basic requirements for federal contract information; Level 2 covers the 110 NIST SP 800-171 Rev 2 requirements for CUI; Level 3 adds 24 NIST SP 800-172 requirements assessed by DIBCAC.

Do I still need NIST SP 800-171?

Yes. DFARS 252.204-7012 requires NIST SP 800-171 Rev 2 through a class deviation, whatever happens to CMMC Phase 2, and DFARS 7019 and 7020 require a current SPRS score.

What is a C3PAO?

A CMMC Third-Party Assessment Organisation authorised by the Cyber AB to conduct Level 2 certification assessments.

How long does CMMC Level 2 take?

Most contractors need 6 to 18 months to reach readiness, depending on scope, the starting SPRS score and how much of NIST SP 800-171 is already in place.

Sources

References

  1. 32 CFR Part 170, CMMC Program final rule. federalregister.gov / ecfr.gov
  2. DFARS Case 2019-D041 (48 CFR) final rule, effective 10 Nov 2025. federalregister.gov
  3. Department of War memo suspending CMMC Phase 2, 13 Jul 2026, and DFARS class deviation 2026-O0025 (Rev 3). acq.osd.mil
  4. NIST SP 800-171 Rev 2 and SP 800-172. csrc.nist.gov
  5. DoW CIO CMMC program pages. dodcio.defense.gov

Reviewed by

Manisha Dubey

Framework reviewer · QULDEX

Reviewed this page against 32 CFR Part 170, the 48 CFR rule and the July 2026 suspension: levels, phases and scoping.

Page history
  • : Page first built: levels, phases with the July 2026 suspension, scoping, readiness check

Be ready when CMMC certification resumes

Answer a short readiness check and get a gap summary and an estimated SPRS position. No sales call needed to see the result.

Schedule
Book a Demo