CMMC is the most misunderstood acronym in the defense supply chain, and the confusion got worse in the summer of 2026 when a memorandum paused part of the rollout and half the industry read the headlines as the programme being cancelled. It was not cancelled. Understanding what actually changed requires understanding what CMMC is made of, so start there.
CMMC is not a cybersecurity standard. It is a verification mechanism wrapped around one. The standard underneath is NIST Special Publication 800-171, which sets out requirements for protecting sensitive federal information on non federal systems. CMMC is how the Department satisfies itself that a contractor actually implemented it.
What determines your obligation is the information you handle:
Neither is classified information. That is the point people miss. A yard can be entirely outside the classified world and still be squarely inside CMMC scope because an engineering drawing arrived by email.
"Nothing here is classified. That is exactly why so many suppliers assumed it did not apply to them."
CMMC took years to become enforceable, and it did so through two separate rules that do different jobs.
The programme rule, 32 CFR Part 170, took effect in December 2024. It defines the programme itself: the levels, the assessment types, scoping, scoring, and affirmation requirements. On its own it obliged nobody, because it created a framework without a contractual hook.
The acquisition rule, amending the DFARS, was published in September 2025 and took effect on 10 November 2025. This is the one that matters commercially. It authorised contracting officers to put CMMC into solicitations and contracts through DFARS provision 252.204-7025, which states the CMMC status required for award, and clause 252.204-7021, which requires the contractor to maintain that status during performance.
That date, 10 November 2025, started Phase 1 of a rollout designed to run in four annual phases.
There are three levels, and the level required is stated in the solicitation rather than chosen by the contractor.
| Level | Applies to | What is required | How it is verified |
|---|---|---|---|
| Level 1 | Contractors handling FCI | 15 basic safeguarding requirements | Annual self-assessment and affirmation posted in SPRS |
| Level 2 (Self) | Contractors handling CUI | 110 requirements from NIST SP 800-171 | Self-assessment in SPRS every three years, affirmed annually |
| Level 2 (C3PAO) | CUI on higher priority programmes | The same 110 requirements | Assessment by an accredited third party organisation |
| Level 3 | The most sensitive programmes | 800-171 plus selected 800-172 requirements | Government led assessment |
The distinction that trips people up is between Level 2 self-assessed and Level 2 assessed by a C3PAO. The security requirements are identical. What differs is who verifies them, and only the second is a certification in the ordinary sense of the word. Saying a company is at Level 2 without saying which assessment type is behind it does not answer the question a prime is actually asking.
On 13 July 2026 the Department suspended the transition to Phase 2. Phase 2 was the milestone that would have made third party certification by a C3PAO a condition of award on most CUI contracts beginning 10 November 2026. Phases 3 and 4, along with other pending milestones, were suspended at the same time. A CMMC Reform Task Force was established to review the programme and report to the Department Chief Information Officer within sixty days, informed by a public request for information whose comment window closed on 14 August 2026.
The stated aim was to reduce cost and administrative burden, particularly for small and non traditional suppliers, by reconsidering the third party assessment model. Departmental statements at the time were explicit that the security standard itself was not being relaxed.
Phase 1 self-assessment requirements remain live. DFARS 252.204-7012 and NIST SP 800-171 still apply. Contractors must still complete assessments and post scores and affirmations in SPRS, and inaccurate submissions continue to carry False Claims Act exposure. Existing third party assessment requirements come out of active solicitations, and out of awarded contracts at the next option exercise or administrative modification, not automatically. Until a contract is modified, the clause on it is the clause on it.
Two practical points follow. First, this was done by memorandum rather than by rule, which means it can be reversed as quickly as it was made. Second, the task force was due to report in the middle of September 2026, so any supplier planning around a permanent removal of third party assessment is planning on an assumption rather than a fact. Confirm what your specific awards require, in writing, rather than inferring it from a headline.
"The Department paused one verification mechanism. It did not pause the standard, the self-assessment, or the liability for getting the submission wrong."
A prime contractor cannot satisfy CMMC on behalf of its supply chain. Where covered information is passed to a subcontractor or supplier, the requirement travels with it, and the prime is expected to establish that its suppliers meet the level appropriate to what they handle.
In practice this arrives as a question on a supplier qualification form or a flow down clause in a subcontract, and it is asked before award rather than after. A company that cannot answer it is not usually told it has failed. It simply stops being shortlisted, which is why so many suppliers discover the problem as a slow decline in invitations rather than as a rejection letter.
Vessel drawings, system specifications, and repair packages for naval programmes are routinely CUI. Yards and the trade contractors feeding them are firmly in scope. See the shipbuilding EOR guide for the workforce side of this.
Airframe, propulsion, avionics, and munitions suppliers handle technical data packages as a matter of course. Tier two and tier three suppliers who never speak to a government contracting officer still receive CUI from their primes. The aerospace and defense EOR guide covers the staffing implications.
Firms providing design, analysis, or project engineering on defense programmes hold exactly the information the programme was written to protect, often with a small IT footprint and no dedicated security staff.
Depot maintenance, calibration, testing, and facilities work on defense sites frequently involves at least FCI, and often CUI in the form of maintenance procedures and system data.
The category most often overlooked, and the subject of the next section.
It is easy to think of CMMC as an engineering and IT problem. But consider what a staffing or EOR relationship on a defense programme actually involves. Role descriptions that reference programme specifics. Credentialing and clearance documentation. Site access requests naming a facility and a project. Timekeeping tied to a contract line. Correspondence with a programme office about who is working on what. Some of that is FCI. On a defense programme, some of it can be CUI.
If that information is sitting in an uncontrolled inbox at a vendor with no security programme, the exposure belongs to the prime as much as to the vendor. Which is why supplier questionnaires increasingly ask the workforce provider directly, and why an otherwise strong staffing partner can become the reason a placement does not proceed.
Revelation completed its CMMC assessment ahead of the requirement taking effect in contracts, and operates protected communications through a Government Community Cloud High environment for work involving covered information. The detail sits on the CMMC page. The reason it matters commercially is simple: it removes the workforce vendor from the list of things a prime has to worry about.
The other half of the defense workforce question is insurance, because naval yard work also triggers USL&H and, for crews afloat, MEL. Those requirements are unrelated to CMMC and arrive at the same time, which is the subject of the naval shipyard compliance stack.
Ask the question before the prime does. We can walk you through what your supply chain will be asked to prove.
BOOK A CONSULTATIONCybersecurity Maturity Model Certification. It is the mechanism used to verify that defense contractors and their suppliers have implemented required protections for Federal Contract Information and Controlled Unclassified Information, with NIST SP 800-171 as the underlying standard.
No. On 13 July 2026 the Department suspended the transition to Phase 2 and later phases and launched a reform task force. Phase 1 self-assessment requirements remain in force, as do DFARS 252.204-7012 and NIST SP 800-171. The suspension was made by memorandum rather than by rule.
FCI is information provided by or generated for the government under a contract that is not intended for public release. CUI requires safeguarding under law, regulation, or government wide policy and typically includes technical drawings, specifications, and engineering data. Handling FCI generally points to Level 1. Handling CUI points to Level 2.
Yes, where covered information flows to them. Requirements flow down through the supply chain, and a prime cannot satisfy the obligation on a supplier's behalf. Workforce vendors are commonly in scope because role descriptions, credentialing records, site access requests, and programme correspondence can constitute FCI or CUI.
Government Community Cloud High is a cloud environment built for organisations handling controlled information and data subject to export control regimes. It is not named as a requirement in the rules themselves, but it is a common route to meeting the requirements for handling CUI, particularly where export controlled data is involved.
Standing down carries real risk. The self-assessment and SPRS obligations are unchanged, the underlying security requirements are unchanged, and the pause was implemented by memorandum, which can be reversed quickly. Primes are also free to require more than the Department does as a condition of subcontract.