What is CMMC?
CMMC — the Cybersecurity Maturity Model Certification — is the Department of War’s mechanism for checking that its contractors actually do the cybersecurity they have been contractually required to do for years. It does not create many new security requirements. It creates verification of existing ones.
That distinction explains most of the confusion around the program. Defense contractors handling sensitive information have been obligated to implement a specific requirement set for the better part of a decade. What was missing was any reliable way for the government to know whether they had. CMMC supplies the missing half: assessment, certification, and an affirmation that carries legal consequences if it is false.
For a technology company, the effect is that compliance posture moves from the marketing surface to the bid surface. A solicitation that carries a CMMC requirement is not asking whether you intend to be compliant.
The three levels
The model is tiered by the sensitivity of the information involved.
- Level 1 — basic safeguarding. Applies to Federal Contract Information, which is information provided by or generated for the government under a contract that is not intended for public release. Met by an annual self-assessment against a short set of fundamental practices.
- Level 2 — Controlled Unclassified Information. Built on the NIST SP 800-171 requirement set. Depending on what the contract specifies, satisfied either by self-assessment or by certification from an authorized third-party assessment organization.
- Level 3 — highest sensitivity. A government-led assessment adding selected enhanced requirements, reserved for the programs where the consequence of compromise is greatest.
Most technology companies entering defense work land at Level 1 or Level 2, and the difference between them is whether the data you touch is Federal Contract Information or CUI.
Flowdown — why “we’re a subcontractor” is not an exemption
CMMC requirements flow down. A prime with a Level 2 obligation is required to pass the applicable requirement to subcontractors that will handle the same information, which means a small software vendor two tiers down the chain can face a certification requirement it never saw in a solicitation.
In practice this arrives as a question from a prime’s supply-chain team, often with a short deadline attached. Companies that already know their posture answer it. Companies that do not, lose the subcontract to someone who could.
The rollout, and the date that no longer exists
The program was designed to phase in over several years rather than switching on at once. Its second phase — the one that would have made certification by an authorized third-party assessment organization the required path on applicable contracts — was suspended on 13 July 2026 by DoD CIO Memo 26-P-1023. No replacement date has been published.
Read that narrowly, because the thing that was suspended is narrow. What paused is the mandatory third-party certification step. What did not pause is the requirement set underneath it: DFARS 252.204-7012 still obliges adequate security by reference to NIST SP 800-171, the separate self-assessment requirement is still in force, and the 72-hour cyber incident reporting obligation is untouched.
So the useful question was never “when does CMMC apply to everyone,” and it is less useful now than it was. It is what the solicitation in front of you actually asks for. An applicable contract can still specify a certified assessment, and a prime can still flow the requirement down by contract regardless of what the program’s phase schedule says.
Why waiting is the expensive option
The gap between “we have a security program” and “we can pass an assessment” is usually measured in quarters, not weeks. Closing it involves scoping the environment that holds the data, implementing requirements that were never fully implemented, generating evidence, and — at the certified levels — scheduling an assessor whose calendar is not infinite.
None of that fits inside a proposal window, and the suspension of Phase 2 does not change the arithmetic — it removes a date, not the work. The companies that treat posture as a pipeline prerequisite rather than a post-award task are the ones that stay eligible when an applicable solicitation arrives, whenever the mandatory certification step is reinstated.
The affirmation
CMMC requires a senior official to affirm continuing compliance. That affirmation is a representation to the government, and false representations about cybersecurity compliance have already produced civil enforcement actions against contractors under the False Claims Act.
This is the strongest argument for accuracy over optimism in your compliance posture. Overstating readiness in marketing copy is a reputational risk; overstating it in an affirmation is a legal one.