Defense Compliance  ·  CMMC

What CMMC Actually Requires, and Why Your Workforce Partner Needs It Too

The levels, the two rules that put CMMC into contracts, what the July 2026 pause did and did not change, and why the requirement reaches your staffing and EOR vendors as well as you.

11 min read  ·  August 2026
$500M+
Payroll Funded
25,000+
Employees Placed
50
US States
30+
Years in Business
99%
Close Ratio

Key Takeaways

  • CMMC is the mechanism the Department uses to verify that contractors protect Federal Contract Information and Controlled Unclassified Information. The underlying security standard is NIST SP 800-171.
  • Two rules make it real: the program rule at 32 CFR Part 170, effective December 2024, and the DFARS acquisition rule, effective 10 November 2025, which put the clause into contracts.
  • Phase 1 has been in force since November 2025 and requires a current self-assessment posted in SPRS to be eligible for award on applicable contracts.
  • On 13 July 2026 the Department suspended Phase 2, which would have made third party certification a condition of award from November 2026, and stood up a reform task force. The standard did not change. The verification mechanism is under review.
  • Requirements flow down to subcontractors and suppliers, including staffing and EOR vendors whose systems touch covered information. A prime's compliance does not cover its vendors.

CMMC is the most misunderstood acronym in the defense supply chain, and the confusion got worse in the summer of 2026 when a memorandum paused part of the rollout and half the industry read the headlines as the programme being cancelled. It was not cancelled. Understanding what actually changed requires understanding what CMMC is made of, so start there.

Start With the Information, Not the Certification

CMMC is not a cybersecurity standard. It is a verification mechanism wrapped around one. The standard underneath is NIST Special Publication 800-171, which sets out requirements for protecting sensitive federal information on non federal systems. CMMC is how the Department satisfies itself that a contractor actually implemented it.

What determines your obligation is the information you handle:

  • Federal Contract Information (FCI). Information provided by or generated for the government under a contract, not intended for public release. Ordinary contract correspondence and delivery schedules often qualify. This is a low bar and catches far more suppliers than expect it.
  • Controlled Unclassified Information (CUI). Information that requires safeguarding under law, regulation, or government wide policy. In an industrial setting this is technical drawings, specifications, test data, and engineering documentation for a defense programme.

Neither is classified information. That is the point people miss. A yard can be entirely outside the classified world and still be squarely inside CMMC scope because an engineering drawing arrived by email.

"Nothing here is classified. That is exactly why so many suppliers assumed it did not apply to them."

The Two Rules That Made It Binding

CMMC took years to become enforceable, and it did so through two separate rules that do different jobs.

The programme rule, 32 CFR Part 170, took effect in December 2024. It defines the programme itself: the levels, the assessment types, scoping, scoring, and affirmation requirements. On its own it obliged nobody, because it created a framework without a contractual hook.

The acquisition rule, amending the DFARS, was published in September 2025 and took effect on 10 November 2025. This is the one that matters commercially. It authorised contracting officers to put CMMC into solicitations and contracts through DFARS provision 252.204-7025, which states the CMMC status required for award, and clause 252.204-7021, which requires the contractor to maintain that status during performance.

That date, 10 November 2025, started Phase 1 of a rollout designed to run in four annual phases.

The Levels, in Plain Terms

There are three levels, and the level required is stated in the solicitation rather than chosen by the contractor.

LevelApplies toWhat is requiredHow it is verified
Level 1Contractors handling FCI15 basic safeguarding requirementsAnnual self-assessment and affirmation posted in SPRS
Level 2 (Self)Contractors handling CUI110 requirements from NIST SP 800-171Self-assessment in SPRS every three years, affirmed annually
Level 2 (C3PAO)CUI on higher priority programmesThe same 110 requirementsAssessment by an accredited third party organisation
Level 3The most sensitive programmes800-171 plus selected 800-172 requirementsGovernment led assessment

The distinction that trips people up is between Level 2 self-assessed and Level 2 assessed by a C3PAO. The security requirements are identical. What differs is who verifies them, and only the second is a certification in the ordinary sense of the word. Saying a company is at Level 2 without saying which assessment type is behind it does not answer the question a prime is actually asking.

What Changed in July 2026, and What Did Not

On 13 July 2026 the Department suspended the transition to Phase 2. Phase 2 was the milestone that would have made third party certification by a C3PAO a condition of award on most CUI contracts beginning 10 November 2026. Phases 3 and 4, along with other pending milestones, were suspended at the same time. A CMMC Reform Task Force was established to review the programme and report to the Department Chief Information Officer within sixty days, informed by a public request for information whose comment window closed on 14 August 2026.

The stated aim was to reduce cost and administrative burden, particularly for small and non traditional suppliers, by reconsidering the third party assessment model. Departmental statements at the time were explicit that the security standard itself was not being relaxed.

What is still in force

Phase 1 self-assessment requirements remain live. DFARS 252.204-7012 and NIST SP 800-171 still apply. Contractors must still complete assessments and post scores and affirmations in SPRS, and inaccurate submissions continue to carry False Claims Act exposure. Existing third party assessment requirements come out of active solicitations, and out of awarded contracts at the next option exercise or administrative modification, not automatically. Until a contract is modified, the clause on it is the clause on it.

Two practical points follow. First, this was done by memorandum rather than by rule, which means it can be reversed as quickly as it was made. Second, the task force was due to report in the middle of September 2026, so any supplier planning around a permanent removal of third party assessment is planning on an assumption rather than a fact. Confirm what your specific awards require, in writing, rather than inferring it from a headline.

"The Department paused one verification mechanism. It did not pause the standard, the self-assessment, or the liability for getting the submission wrong."

Flow Down Is the Part That Catches Suppliers

A prime contractor cannot satisfy CMMC on behalf of its supply chain. Where covered information is passed to a subcontractor or supplier, the requirement travels with it, and the prime is expected to establish that its suppliers meet the level appropriate to what they handle.

In practice this arrives as a question on a supplier qualification form or a flow down clause in a subcontract, and it is asked before award rather than after. A company that cannot answer it is not usually told it has failed. It simply stops being shortlisted, which is why so many suppliers discover the problem as a slow decline in invitations rather than as a rejection letter.

Which Industries This Actually Reaches

Naval shipbuilding and ship repair

Vessel drawings, system specifications, and repair packages for naval programmes are routinely CUI. Yards and the trade contractors feeding them are firmly in scope. See the shipbuilding EOR guide for the workforce side of this.

Aerospace and defense manufacturing

Airframe, propulsion, avionics, and munitions suppliers handle technical data packages as a matter of course. Tier two and tier three suppliers who never speak to a government contracting officer still receive CUI from their primes. The aerospace and defense EOR guide covers the staffing implications.

Engineering and design firms

Firms providing design, analysis, or project engineering on defense programmes hold exactly the information the programme was written to protect, often with a small IT footprint and no dedicated security staff.

Industrial services and maintenance contractors

Depot maintenance, calibration, testing, and facilities work on defense sites frequently involves at least FCI, and often CUI in the form of maintenance procedures and system data.

Staffing companies and workforce providers

The category most often overlooked, and the subject of the next section.

Why Your Workforce Partner Is in Scope

It is easy to think of CMMC as an engineering and IT problem. But consider what a staffing or EOR relationship on a defense programme actually involves. Role descriptions that reference programme specifics. Credentialing and clearance documentation. Site access requests naming a facility and a project. Timekeeping tied to a contract line. Correspondence with a programme office about who is working on what. Some of that is FCI. On a defense programme, some of it can be CUI.

If that information is sitting in an uncontrolled inbox at a vendor with no security programme, the exposure belongs to the prime as much as to the vendor. Which is why supplier questionnaires increasingly ask the workforce provider directly, and why an otherwise strong staffing partner can become the reason a placement does not proceed.

Revelation completed its CMMC assessment ahead of the requirement taking effect in contracts, and operates protected communications through a Government Community Cloud High environment for work involving covered information. The detail sits on the CMMC page. The reason it matters commercially is simple: it removes the workforce vendor from the list of things a prime has to worry about.

The other half of the defense workforce question is insurance, because naval yard work also triggers USL&H and, for crews afloat, MEL. Those requirements are unrelated to CMMC and arrive at the same time, which is the subject of the naval shipyard compliance stack.

Bidding defense work with a workforce vendor you have not vetted?

Ask the question before the prime does. We can walk you through what your supply chain will be asked to prove.

BOOK A CONSULTATION

Frequently Asked Questions

What does CMMC stand for?

+

Cybersecurity Maturity Model Certification. It is the mechanism used to verify that defense contractors and their suppliers have implemented required protections for Federal Contract Information and Controlled Unclassified Information, with NIST SP 800-171 as the underlying standard.

Was CMMC cancelled in 2026?

+

No. On 13 July 2026 the Department suspended the transition to Phase 2 and later phases and launched a reform task force. Phase 1 self-assessment requirements remain in force, as do DFARS 252.204-7012 and NIST SP 800-171. The suspension was made by memorandum rather than by rule.

What is the difference between FCI and CUI?

+

FCI is information provided by or generated for the government under a contract that is not intended for public release. CUI requires safeguarding under law, regulation, or government wide policy and typically includes technical drawings, specifications, and engineering data. Handling FCI generally points to Level 1. Handling CUI points to Level 2.

Does CMMC apply to subcontractors and staffing vendors?

+

Yes, where covered information flows to them. Requirements flow down through the supply chain, and a prime cannot satisfy the obligation on a supplier's behalf. Workforce vendors are commonly in scope because role descriptions, credentialing records, site access requests, and programme correspondence can constitute FCI or CUI.

What is GCC High and is it mandatory?

+

Government Community Cloud High is a cloud environment built for organisations handling controlled information and data subject to export control regimes. It is not named as a requirement in the rules themselves, but it is a common route to meeting the requirements for handling CUI, particularly where export controlled data is involved.

Should we pause our compliance work while the review runs?

+

Standing down carries real risk. The self-assessment and SPRS obligations are unchanged, the underlying security requirements are unchanged, and the pause was implemented by memorandum, which can be reversed quickly. Primes are also free to require more than the Department does as a condition of subcontract.

CMMC CUI NIST 800-171 DFARS Defense Supply Chain Aerospace
Revelation Workforce Solutions

Your Workforce. Our Responsibility.

Headquartered in Mobile, Alabama. Serving all 50 US states. Specialty insurance coverage no one else can match. 30+ years. Zero missed payrolls.

BOOK A CONSULTATION
$500M+
Payroll Funded
25,000+
Employees Placed
50
US States
30+
Years in Business
99%
Close Ratio
$0
Setup Fees
$0
Termination Fees
Weekly
Payroll Cycle
Mobile, AL (HQ)  ·  Houston, TX  ·  Pascagoula, MS
Coming 2026: Newport News, VA  ·  Lafayette, LA
Revelation Workforce Solutions, LLC  ·  All 50 US States
revelationeor.com  ·  1 800 436 1746
☎ Call Us Book Consultation