Program · US defence · Department of War
CMMC compliance means meeting the Department of War's Cybersecurity Maturity Model Certification for contracts with federal contract information or CUI. Phase 1 self-assessments have applied since November 2025, but Phase 2 third-party certification was suspended on 13 July 2026. NIST SP 800-171 obligations under DFARS 7012 still apply.
Defense contractors and subcontractors whose contracts involve FCI or CUI.
QULDEX helps here first: the readiness check shows where you stand before you commit budget.
CMMC requires contractors to implement the security requirements for their level, assess them (self, C3PAO or DIBCAC), post results and annual affirmations in SPRS, and flow requirements down to subcontractors.
15 FAR 52.204-21 requirements, annual self-assessment.
In QULDEX: Ready-made Level 1 checklist110 NIST SP 800-171 Rev 2 requirements.
In QULDEX: Pre-mapped requirements and objectives24 NIST SP 800-172 requirements on top.
In QULDEX: Extra requirements trackedResults posted and affirmed every year.
In QULDEX: Score calculated from statusLimited POA&M, closed within 180 days.
In QULDEX: Close-out timersSubcontractors meet the level for their data.
In QULDEX: Vendor registerThese 17 program rules decide what you must do, how you are assessed and what the 2026 suspension changes. Select any one to see the detail and how QULDEX handles it.
Showing up to 6 per group. Search, filter, or open a group to see all 17.
Level 1Foundational (FCI)15 basic safeguarding requirements from FAR 52.204-21 for contractors handling Federal Contract Information; annual self-assessment and affirmation.
In QULDEXLevel 1 requirements are a ready checklist with yearly affirmation reminders.
Level 2Advanced (CUI)All 110 requirements of NIST SP 800-171 Rev 2 for contractors handling Controlled Unclassified Information; self-assessment or C3PAO assessment every three years, with annual affirmation.
In QULDEXThe 110 requirements are pre-mapped with evidence requests per assessment objective.
Level 3Expert (CUI, highest priority)Level 2 certification plus 24 selected requirements from NIST SP 800-172, assessed by DIBCAC every three years.
In QULDEXQULDEX tracks this as a programme requirement with an owner, evidence and a due date, alongside the 110 NIST SP 800-171 requirements it rests on.
§170.21POA&M rulesConditional status is possible with a minimum score and only for eligible requirements; open POA&M items must close within 180 days.
In QULDEXPOA&M items have 180-day close-out timers.
§170.22AffirmationsA senior official affirms continuing compliance in SPRS after each assessment and every year.
In QULDEXAffirmation dates are reminders on the dashboard.
Phase 1Self-assessments (from 10 Nov 2025)2026 statusContracting officers can require Level 1 and Level 2 self-assessments as a condition of award.
In QULDEXQULDEX tracks this as a programme requirement with an owner, evidence and a due date, alongside the 110 NIST SP 800-171 requirements it rests on.
Phase 2C3PAO Level 2 (suspended)2026 statusWould have made third-party Level 2 certification the default from 10 Nov 2026; suspended by the 13 July 2026 memo pending the Reform Task Force review.
In QULDEXYour programme keeps moving: QULDEX tracks readiness for a C3PAO assessment whenever it resumes.
Phases 3–4Level 3 and full rollout (on hold)2026 statusLevel 3 requirements and full implementation across contracts are on hold pending further notice.
In QULDEXQULDEX tracks this as a programme requirement with an owner, evidence and a due date, alongside the 110 NIST SP 800-171 requirements it rests on.
DFARS 7012Existing obligations still applyDFARS 252.204-7012 still requires NIST SP 800-171 Rev 2, 72-hour cyber incident reporting and FedRAMP Moderate equivalent cloud for CUI.
In QULDEXIncident timers and cloud provider evidence sit with the 110 requirements.
CUICUI assetsAssets that process, store or transmit CUI are assessed against all Level 2 requirements.
In QULDEXAssets are tagged by category in the asset inventory.
SPASecurity Protection AssetsAssets that provide security functions, such as identity and logging, are in scope.
In QULDEXQULDEX tracks this as a programme requirement with an owner, evidence and a due date, alongside the 110 NIST SP 800-171 requirements it rests on.
CRMAContractor Risk Managed AssetsAssets that can, but are not intended to, handle CUI are documented in the SSP and risk-managed.
In QULDEXQULDEX tracks this as a programme requirement with an owner, evidence and a due date, alongside the 110 NIST SP 800-171 requirements it rests on.
SpecializedSpecialized AssetsIoT, OT, test equipment and restricted systems are documented and managed through policy.
In QULDEXQULDEX tracks this as a programme requirement with an owner, evidence and a due date, alongside the 110 NIST SP 800-171 requirements it rests on.
ESPExternal service providersCloud providers handling CUI must be FedRAMP Moderate or equivalent; other ESPs fall into the assessment scope.
In QULDEXEach provider records its FedRAMP status or evidence.
SPRSSupplier Performance Risk System scoreSelf-assessment scores (110 down to −203) are posted in SPRS and checked by contracting officers.
In QULDEXQULDEX calculates the score from requirement status before you post it.
C3PAOThird-party assessmentA CMMC Third-Party Assessment Organisation, authorised by the Cyber AB, assesses Level 2 against each objective.
In QULDEXAssessors get view-only, logged access to evidence.
Flow-downSubcontractorsCMMC requirements flow down to subcontractors that handle FCI or CUI.
In QULDEXSubcontractor status is tracked in the vendor register.
Nothing matches that search.
Based on 32 CFR Part 170, the 48 CFR DFARS rule and the July 2026 suspension memo and class deviation. Summaries are QULDEX paraphrases, not legal advice.
Scope your CUI environment, implement the 110 requirements, score yourself in SPRS and get ready for a C3PAO. Most contractors need 6 to 18 months; the Phase 2 pause gives time but not an exemption.
Check contracts and data flows to decide Level 1, 2 or 3.
Categorise assets and external service providers; shrink scope with an enclave where you can.
Close gaps against NIST SP 800-171 Rev 2 and write the System Security Plan.
Score against NIST SP 800-171A objectives and affirm.
Plan for certification once Phase 2 resumes or a contract asks for it.
Phase dates follow the 48 CFR rule and the 13 July 2026 suspension memo. Durations are QULDEX planning ranges.
Assessors start from the System Security Plan and ask for evidence against each objective.
| Document | Rule | Where it lives in QULDEX |
|---|---|---|
| System Security Plan (SSP) | NIST 800-171 3.12.4 | Policy library |
| Asset inventory and scope categories | 32 CFR 170.19 | Risk register |
| Network and data-flow diagrams | 32 CFR 170.19 | Evidence vault |
| Policies and procedures for 14 families | NIST 800-171 Rev 2 | Policy library |
| POA&M | 32 CFR 170.21 | CAPA automation |
| SPRS score and affirmations | 32 CFR 170.22 | Evidence vault |
| Customer responsibility matrix for cloud providers | DFARS 252.204-7012 | Vendor register |
| Incident response plan and reports | DFARS 252.204-7012 | CAPA automation |
Document names follow the CMMC rules and NIST SP 800-171; storage locations are QULDEX recommendations.
Most contractors need 6 to 18 months to reach Level 2 readiness. Scope size, the state of your SSP and whether CUI sits in a separate enclave drive most of the effort.
Bars show the upper end of each range on one scale (18 months = full width).
Check these eight things first. Nothing you enter leaves this page.
CMMC Level 2 is NIST SP 800-171 Rev 2, which derives from NIST SP 800-53. ISO 27001 evidence covers part of it but not the CUI-specific requirements.
| CMMC Level 2 domain | NIST SP 800-171 Rev 2 | NIST SP 800-53 Rev 5 | ISO 27001:2022 | Shared evidence |
|---|---|---|---|---|
| Access Control (AC) | 3.1.1–3.1.22 | AC family | A.5.15–A.5.18, A.8.2–A.8.5 | Access reviews |
| Audit and Accountability (AU) | 3.3.1–3.3.9 | AU family | A.8.15–A.8.17 | Log samples |
| Configuration Management (CM) | 3.4.1–3.4.9 | CM family | A.8.9, A.8.32 | Baselines |
| Identification and Authentication (IA) | 3.5.1–3.5.11 | IA family | A.5.16–A.5.17, A.8.5 | MFA settings |
| Incident Response (IR) | 3.6.1–3.6.3 | IR family | A.5.24–A.5.26 | Incident reports |
| Risk Assessment (RA) | 3.11.1–3.11.3 | RA family | 6.1.2, A.8.8 | Risk assessment, scans |
| System and Communications Protection (SC) | 3.13.1–3.13.16 | SC family | A.8.20–A.8.24 | Network diagrams |
Indicative mapping for planning. CMMC vs NIST 800-171 is compared in full on the blog.
QULDEX is CMMC compliance and audit management software built from EGV Group's audit delivery, used by defense contractors, their RPOs and the C3PAOs who assess them. Pick your role to see who does what.
For primes and subcontractors handling FCI or CUI.
For Registered Practitioner Organisations and internal audit.
For authorised third-party assessment organisations.
Requirements with owners, test steps and the crosswalk to 50+ frameworks.
Explore →EvidenceEvidence linked to controls and findings, with upload, review and approval history.
Explore →RiskRisk assessment and treatment, with decisions traced to the controls they drive.
Explore →FindingsFindings from internal and external audits tracked to closure with due dates.
Explore →Phase 2, which would have required third-party Level 2 certification from 10 November 2026, was suspended on 13 July 2026, and Phases 3 and 4 are on hold. Phase 1 self-assessments and the DFARS 252.204-7012 obligations still apply.
Level 1 covers 15 basic requirements for federal contract information; Level 2 covers the 110 NIST SP 800-171 Rev 2 requirements for CUI; Level 3 adds 24 NIST SP 800-172 requirements assessed by DIBCAC.
Yes. DFARS 252.204-7012 requires NIST SP 800-171 Rev 2 through a class deviation, whatever happens to CMMC Phase 2, and DFARS 7019 and 7020 require a current SPRS score.
A CMMC Third-Party Assessment Organisation authorised by the Cyber AB to conduct Level 2 certification assessments.
Most contractors need 6 to 18 months to reach readiness, depending on scope, the starting SPRS score and how much of NIST SP 800-171 is already in place.
NIST CSF, 800-53 and CIS Controls articles.
blog.quldex.comHow governance outcomes support a defense compliance programme.
blog.quldex.comA file-naming scheme assessors can follow.
blog.quldex.comHow many samples assessors look at.
Reviewed by
Answer a short readiness check and get a gap summary and an estimated SPRS position. No sales call needed to see the result.