CMMC Compliance: Levels, Requirements, and Current Program Status
The Cybersecurity Maturity Model Certification (CMMC) is the Department of War’s framework for verifying that defense contractors adequately protect Controlled Unclassified Information (CUI) and Federal Contract Information (FCI). It applies to any organization in the Defense Industrial Base (DIB) that handles this data on behalf of the department, and it builds directly on cybersecurity requirements that already exist independently of CMMC itself.
The program has changed significantly since its introduction, most recently on July 13, 2026, when the certification requirement was suspended pending a program-wide review. This guide covers what CMMC requires, how its three levels work, and — critically — the current status of the program and what that means for contractors right now.

Executive Summary
Main Idea: CMMC verifies that defense contractors meet cybersecurity requirements that already exist under DFARS 252.204-7012 and NIST SP 800-171 — it does not create new security obligations so much as it creates a formal mechanism to verify compliance with obligations contractors have carried since 2017. As of July 2026, the third-party certification component of that verification mechanism is paused pending review, but the underlying cybersecurity requirements are not.
Why You Should Care: Contractors who read the Phase 2 suspension as a signal to deprioritize cybersecurity investment are misreading the situation. NIST SP 800-171 compliance, System Security Plan documentation, SPRS score maintenance, and DFARS 252.204-7012 obligations remain fully enforceable — including False Claims Act exposure through the DoJ’s Civil Cyber-Fraud Initiative for contractors who misrepresent their compliance posture. The certification requirement moved. The underlying standard did not.
Key Takeaways
- CMMC verifies compliance with requirements that already exist. DFARS 252.204-7012 has required defense contractors handling CUI to implement NIST SP 800-171’s 110 security controls since 2017. CMMC did not create this obligation — it created a certification mechanism to verify contractors are actually meeting it, replacing a self-attestation model that DoD determined was insufficiently reliable. This is the single most important thing to understand about any change to the CMMC program: changes to certification requirements do not change the underlying security controls contractors must implement.
- CMMC has three levels tied to data sensitivity. Level 1 (Foundational) applies to contractors handling FCI and requires 17 basic safeguarding practices, verified by annual self-assessment. Level 2 (Advanced) applies to contractors handling CUI and requires all 110 NIST SP 800-171 controls, verified by either self-assessment or third-party certification depending on program criticality. Level 3 (Expert) applies to the highest-priority programs and adds controls from NIST SP 800-172, verified by government-led assessment.
- Phase 2 — the third-party certification requirement — was suspended on July 13, 2026. The Department of War suspended the requirement for Certified Third-Party Assessment Organization (C3PAO) assessments that was scheduled to take effect November 10, 2026. A CMMC Reform Task Force is conducting a 60-day review, with findings expected around mid-September 2026. Phase 1 self-assessment requirements, which took effect November 10, 2025, remain in force and unaffected.
- The suspension does not touch DFARS 252.204-7012 or NIST SP 800-171 obligations. Every legal analysis of the pause has emphasized the same point: the pause applies to the CMMC certification mechanism, not to the underlying contractual cybersecurity requirements. Contractors subject to DFARS 252.204-7012 must continue implementing NIST SP 800-171, maintaining accurate System Security Plans, posting current scores to the Supplier Performance Risk System (SPRS), and remediating deficiencies through documented Plans of Action and Milestones (POA&Ms.
- The review is a checkpoint, not a resolution — and could reshape the program rather than end it. Legal and policy analysts tracking the pause have been consistent that a 60-day review producing recommendations is different from a rulemaking process that changes requirements, which takes months at minimum. The review could delay the C3PAO requirement further, narrow which contracts require third-party assessment versus self-assessment, or restructure the assessment model itself. It is very unlikely to weaken the underlying NIST SP 800-171 standard, since that standard is written into DFARS independently of CMMC.
Program Status: The July 2026 Phase 2 Suspension
On July 13, 2026, the Department of War (DoW, formerly and still commonly referred to as the Department of Defense, or DoD) announced the immediate suspension of CMMC Phase 2 requirements. The memo, issued by DoW Chief Information Officer Kirsten Davies and numbered 26-P-1023, halted the requirement that would have inserted mandatory C3PAO third-party certification assessments into new solicitations and contracts starting November 10, 2026. The suspension also paused all pending and future CMMC implementation milestones — meaning Phases 3 and 4 of the originally planned four-phase rollout are on hold as well.
The Department simultaneously announced a CMMC Reform Task Force to conduct a top-to-bottom, 60-day review of the program. The review follows sustained concern — raised repeatedly by small and mid-sized defense contractors — about the cost and operational burden of third-party certification, and reflects the Department’s broader Acquisition Transformation System priorities around speed to capability and reducing barriers to entry for small, medium, and non-traditional defense contractors. A public Request for Information is soliciting industry feedback on the cost, implementation, and effectiveness of the current certification framework, with responses due August 14, 2026. The Task Force is expected to deliver findings to the DoW CIO around mid-September 2026.
What the suspension changes: New solicitations and contracts are, during the review period, limited to CMMC Level 1 and Level 2 self-assessment requirements. The mandatory C3PAO third-party certification requirement that would have taken effect November 10, 2026 is paused. Program managers cannot currently insert Phase 2, 3, or 4 requirements into new contracts.
What the suspension does not change: Phase 1 self-assessment requirements, in effect since November 10, 2025, remain fully in force. Contractors subject to DFARS 252.204-7012 must continue implementing NIST SP 800-171’s 110 controls, maintaining current and accurate System Security Plans, and posting scores to SPRS. Contractors subject to DFARS 252.204-7021 Level 1 or Level 2 self-assessment requirements must continue to affirm compliance annually. The Department of Justice’s Civil Cyber-Fraud Initiative continues to pursue False Claims Act cases against contractors who misrepresent their cybersecurity compliance — a legal exposure entirely independent of the CMMC certification pause.
What contractors should do now: Treat mid-September 2026 as a checkpoint for new information, not a deadline or a resolution. Continue maintaining current self-assessments, SSP documentation, and SPRS scores as if certification requirements remain on their original timeline, since a review producing recommendations is a different process than rulemaking that changes requirements — and rulemaking takes months at minimum even after recommendations are issued. Continue remediating identified gaps through documented POA&Ms. Do not interpret the pause as a signal to deprioritize cybersecurity investment; the security posture DoD is verifying has not changed, only the verification mechanism for it is under review.
What CMMC Requires
CMMC’s requirements are organized around the type of data a contractor handles and, as a result, which level of certification applies.
Federal Contract Information (FCI) is information not intended for public release that is provided by or generated for the government under a contract to develop or deliver a product or service. Contractors handling only FCI are subject to CMMC Level 1.
Controlled Unclassified Information (CUI) is sensitive information that requires safeguarding under law, regulation, or government-wide policy, but that does not meet the threshold for classification. CUI includes categories such as technical drawings, export-controlled data, and certain procurement-sensitive information. Contractors handling CUI are subject to CMMC Level 2.
The three CMMC levels:
Level 1 (Foundational). Applies to contractors handling FCI. Requires implementation of 17 basic safeguarding practices aligned with FAR 52.204-21. Verified through annual self-assessment — no third-party audit required at this level, regardless of the Phase 2 review’s outcome.
Level 2 (Advanced). Applies to contractors that process, store, or transmit CUI. Requires implementation of all 110 security controls specified in NIST SP 800-171. Verification method depends on program criticality: prioritized programs involving critical national security information require third-party certification via an accredited C3PAO (currently paused under the July 2026 suspension); nonprioritized programs require annual self-assessment (unaffected by the pause).
Level 3 (Expert). Applies to the highest-priority programs handling the most sensitive CUI. Adds a subset of enhanced security requirements from NIST SP 800-172 on top of the Level 2 baseline. Verified through government-led assessment. Level 3 is a smaller population of contracts and was not directly affected by the July 2026 Phase 2 suspension, which specifically addressed the C3PAO requirement for Level 2.
How CMMC Relates to NIST SP 800-171 and DFARS
Understanding the relationship between these three elements is what makes sense of why the Phase 2 pause doesn’t reduce contractor obligations.
DFARS 252.204-7012 is the contract clause, in effect since 2017, that requires defense contractors handling covered defense information to implement adequate security — defined as NIST SP 800-171 compliance — and to rapidly report cyber incidents. This clause exists independently of CMMC and has not been suspended, modified, or paused by any recent action.
NIST SP 800-171 is the technical standard — 110 specific security controls across 14 control families — that defines what “adequate security” means under DFARS 252.204-7012. This is the actual security work contractors must do: access control, incident response, encryption, audit logging, configuration management, and more. CMMC did not create these requirements; they predate CMMC by several years.
CMMC is the verification and certification layer built on top of the DFARS/NIST 800-171 foundation. Its purpose is to move from a self-attestation model (which DoD determined was insufficiently reliable, given documented cases of contractors certifying compliance they had not actually implemented) to a verified model involving either rigorous self-assessment with SPRS scoring or independent third-party assessment. The July 2026 pause affects only the third-party assessment component of this verification layer — not the underlying DFARS clause or the NIST 800-171 controls it requires.
This is why every legal and policy analysis of the pause has converged on the same framing: the certification schedule moved, the security requirements did not.
What CUI Protection Actually Requires in Practice
NIST SP 800-171’s 110 controls translate into specific technical and organizational capabilities that contractors must implement and be able to demonstrate, regardless of whether verification happens through self-assessment or third-party certification.
Access control. CUI access must be limited to authorized users and systems, with authentication mechanisms appropriate to the sensitivity of the information, and access logged and auditable.
Encryption. CUI must be protected using FIPS-validated cryptography, both at rest and in transit. FIPS 140-3 is the current validation standard.
Audit and accountability. Systems handling CUI must generate audit records sufficient to enable monitoring, analysis, investigation, and reporting of security incidents — and those logs must be protected from unauthorized access or alteration.
Configuration management. Organizations must establish and maintain baseline configurations for systems handling CUI, and control changes to those configurations.
Incident response. Contractors must maintain an operational incident response capability and report cyber incidents involving covered defense information within 72 hours, per DFARS 252.204-7012.
System Security Plan (SSP) and Plan of Action and Milestones (POA&M). Every contractor subject to DFARS 252.204-7012 must maintain a current SSP documenting how each of the 110 controls is implemented, and a POA&M documenting remediation timelines for any controls not yet fully implemented. These documents are the artifacts that both self-assessment scoring and third-party assessment rely on — and their accuracy is what the DoJ’s Civil Cyber-Fraud Initiative scrutinizes when pursuing False Claims Act cases.
How Kiteworks Supports CMMC Compliance
Kiteworks is built around the specific technical requirements that NIST SP 800-171 imposes on organizations handling CUI — independent of how the CMMC certification layer evolves.
On encryption: Kiteworks applies AES-256 encryption at both the file and disk level, with FIPS 140-3 Level 1 validated encryption and customer-owned encryption keys. TLS 1.2 is the floor for all data in transit, with TLS 1.3 available. This directly addresses the NIST 800-171 System and Communications Protection (SC) control family.
On access control and audit logging: a unified Data Policy Engine enforces role-based and attribute-based access controls across every channel — secure email, secure file sharing, secure managed file transfer, SFTP, and secure data forms. Every access event is logged to a single, immutable, consolidated audit trail — directly supporting the Audit and Accountability (AU) control family and giving contractors exportable, assessor-ready evidence regardless of whether verification occurs via self-assessment or C3PAO review.
On FedRAMP inheritance: Kiteworks holds FedRAMP Moderate Authorization, independently assessed by Coalfire and continuously monitored since June 2017. Because FedRAMP Moderate and NIST SP 800-171 share substantial control overlap, contractors using a FedRAMP-authorized platform inherit documented evidence for a meaningful portion of their CMMC control set — compressing the assessment scope regardless of whether that assessment is a self-assessment or a future C3PAO review. Kiteworks has also achieved FedRAMP High In Process authorization for its Secure Gov Cloud offering, meeting the government’s most stringent control requirements for its most sensitive unclassified data — the standard agencies and their contractors need for ITAR, EAR, and the upper tiers of CMMC 2.0.
Kiteworks supports nearly 90% of CMMC Level 2 requirements out of the box, giving contractors a documented technical foundation that remains relevant no matter how the current program review resolves — because the underlying NIST 800-171 controls the platform addresses are not what’s under review.
To see how Kiteworks supports your specific CMMC compliance requirements, schedule a custom demo.
Frequently Asked Questions
CMMC Level 1 and Level 2 self-assessment requirements remain fully in force and are being included in new solicitations and contracts. What was suspended on July 13, 2026 is specifically the Phase 2 requirement for mandatory third-party (C3PAO) certification assessment, which was scheduled to take effect November 10, 2026. That requirement is paused pending a 60-day CMMC Reform Task Force review, with findings expected around mid-September 2026. Contractors should continue meeting all current self-assessment and documentation obligations as if the original schedule remains in effect, since a review producing recommendations is not the same as a rulemaking process that formally changes requirements.
No. Every legal analysis of the July 2026 pause has been explicit on this point: the suspension applies only to the CMMC certification verification mechanism, not to the underlying contractual cybersecurity requirements. DFARS 252.204-7012 continues to require defense contractors handling covered defense information to implement NIST SP 800-171’s 110 security controls, maintain accurate System Security Plans, and report cyber incidents within required timelines. These obligations exist independently of CMMC and predate the certification program by several years. The Department of Justice’s Civil Cyber-Fraud Initiative also continues pursuing False Claims Act cases against contractors who misrepresent their compliance posture, entirely separate from the certification pause.
CMMC Level 1 (Foundational) applies to contractors handling Federal Contract Information and requires 17 basic safeguarding practices, verified annually through self-assessment. Level 2 (Advanced) applies to contractors handling Controlled Unclassified Information and requires all 110 security controls in NIST SP 800-171, verified through either self-assessment (nonprioritized programs) or third-party C3PAO certification (prioritized programs — currently paused pending the July 2026 program review). Level 3 (Expert) applies to the highest-priority programs handling the most sensitive CUI and adds enhanced requirements from NIST SP 800-172 on top of the Level 2 baseline, verified through government-led assessment.
The Task Force is expected to deliver findings to the Department of War’s Chief Information Officer around mid-September 2026, based on the 60-day review timeline announced July 13, 2026 and industry feedback collected through a public Request for Information (responses due August 14, 2026). Policy analysts have noted the review could take several forms: delaying the C3PAO third-party certification requirement further, narrowing which contracts require third-party assessment versus expanded self-assessment, or restructuring the assessment model itself. Analysts widely agree the review is unlikely to weaken the underlying NIST SP 800-171 security standard, since that standard is written into DFARS 252.204-7012 independently of the CMMC certification program. Contractors should treat the Task Force findings as a checkpoint for new information rather than an immediate change in requirements, since formal rulemaking to implement any recommendations would take additional months at minimum.
NIST SP 800-171 is the technical security standard — 110 controls across 14 control families — that DFARS 252.204-7012 has required defense contractors to implement since 2017. CMMC is the verification and certification framework built on top of that existing requirement. Before CMMC, contractors self-attested to NIST 800-171 compliance without independent verification; CMMC introduced a formal assessment mechanism (self-assessment with SPRS scoring, or third-party C3PAO certification for higher-priority programs) to verify that self-attested compliance is accurate. Changes to the CMMC certification framework, including the July 2026 Phase 2 pause, affect how compliance is verified — they do not change what NIST SP 800-171 requires contractors to implement.
Additional Resources
- Blog Post CMMC Compliance for Small Businesses: Challenges and Solutions
- Blog Post CMMC Compliance Guide for DIB Suppliers
- Blog Post CMMC Audit Requirements: What Assessors Need to See When Gauging Your CMMC Readiness
- Guide CMMC 2.0 Compliance Mapping for Sensitive Content Communications
- Blog Post The True Cost of CMMC Compliance: What Defense Contractors Need to Budget For