COMPLIANCE POSTURE

CMMC

The Department of War program that verifies whether a defense contractor has actually implemented required cybersecurity safeguards before it can be awarded applicable work.

Also called Cybersecurity Maturity Model Certification

Last reviewed

What is CMMC?

CMMC — the Cybersecurity Maturity Model Certification — is the Department of War’s mechanism for checking that its contractors actually do the cybersecurity they have been contractually required to do for years. It does not create many new security requirements. It creates verification of existing ones.

That distinction explains most of the confusion around the program. Defense contractors handling sensitive information have been obligated to implement a specific requirement set for the better part of a decade. What was missing was any reliable way for the government to know whether they had. CMMC supplies the missing half: assessment, certification, and an affirmation that carries legal consequences if it is false.

For a technology company, the effect is that compliance posture moves from the marketing surface to the bid surface. A solicitation that carries a CMMC requirement is not asking whether you intend to be compliant.

The three levels

The model is tiered by the sensitivity of the information involved.

  • Level 1 — basic safeguarding. Applies to Federal Contract Information, which is information provided by or generated for the government under a contract that is not intended for public release. Met by an annual self-assessment against a short set of fundamental practices.
  • Level 2 — Controlled Unclassified Information. Built on the NIST SP 800-171 requirement set. Depending on what the contract specifies, satisfied either by self-assessment or by certification from an authorized third-party assessment organization.
  • Level 3 — highest sensitivity. A government-led assessment adding selected enhanced requirements, reserved for the programs where the consequence of compromise is greatest.

Most technology companies entering defense work land at Level 1 or Level 2, and the difference between them is whether the data you touch is Federal Contract Information or CUI.

Flowdown — why “we’re a subcontractor” is not an exemption

CMMC requirements flow down. A prime with a Level 2 obligation is required to pass the applicable requirement to subcontractors that will handle the same information, which means a small software vendor two tiers down the chain can face a certification requirement it never saw in a solicitation.

In practice this arrives as a question from a prime’s supply-chain team, often with a short deadline attached. Companies that already know their posture answer it. Companies that do not, lose the subcontract to someone who could.

The rollout, and the date that no longer exists

The program was designed to phase in over several years rather than switching on at once. Its second phase — the one that would have made certification by an authorized third-party assessment organization the required path on applicable contracts — was suspended on 13 July 2026 by DoD CIO Memo 26-P-1023. No replacement date has been published.

Read that narrowly, because the thing that was suspended is narrow. What paused is the mandatory third-party certification step. What did not pause is the requirement set underneath it: DFARS 252.204-7012 still obliges adequate security by reference to NIST SP 800-171, the separate self-assessment requirement is still in force, and the 72-hour cyber incident reporting obligation is untouched.

So the useful question was never “when does CMMC apply to everyone,” and it is less useful now than it was. It is what the solicitation in front of you actually asks for. An applicable contract can still specify a certified assessment, and a prime can still flow the requirement down by contract regardless of what the program’s phase schedule says.

Why waiting is the expensive option

The gap between “we have a security program” and “we can pass an assessment” is usually measured in quarters, not weeks. Closing it involves scoping the environment that holds the data, implementing requirements that were never fully implemented, generating evidence, and — at the certified levels — scheduling an assessor whose calendar is not infinite.

None of that fits inside a proposal window, and the suspension of Phase 2 does not change the arithmetic — it removes a date, not the work. The companies that treat posture as a pipeline prerequisite rather than a post-award task are the ones that stay eligible when an applicable solicitation arrives, whenever the mandatory certification step is reinstated.

The affirmation

CMMC requires a senior official to affirm continuing compliance. That affirmation is a representation to the government, and false representations about cybersecurity compliance have already produced civil enforcement actions against contractors under the False Claims Act.

This is the strongest argument for accuracy over optimism in your compliance posture. Overstating readiness in marketing copy is a reputational risk; overstating it in an affirmation is a legal one.

COMMON QUESTIONS

Who does CMMC apply to?

Contractors and subcontractors handling Federal Contract Information or Controlled Unclassified Information on Department of War contracts. It is not limited to primes and it is not limited to defense-focused companies — a commercial software vendor whose product holds CUI for a defense program is in scope, and the requirement flows down through the subcontract chain.

What are the CMMC levels?

Level 1 covers basic safeguarding of Federal Contract Information and is met by an annual self-assessment. Level 2 covers Controlled Unclassified Information and is built on the NIST SP 800-171 requirement set, met either by self-assessment or by certification from an authorized third-party assessor depending on the contract. Level 3 adds a government-led assessment and selected enhanced requirements for the most sensitive programs.

Is there a CMMC certification deadline?

Not at present. The Phase 2 requirement for mandatory certification by an authorized third-party assessment organization was suspended on 13 July 2026 by DoD CIO Memo 26-P-1023, and no replacement date has been published. The underlying obligations did not move — NIST SP 800-171 under DFARS 252.204-7012 applies today, and the separate self-assessment requirement is still in force. Plan against the requirement set, not against a date.

Can I get certified before I have a contract?

Yes, and for most companies that is the point. Certification is tied to your environment rather than to a specific award, so a company that expects defense work can complete the assessment ahead of a solicitation. Remediation reliably takes longer than a proposal window, which is why waiting for a requirement to appear is the expensive path.

HOW GOVEXPRESS SCORES THIS

Compliance Posture

CMMC turns Compliance Posture from a sales-page claim into a bid gate, because an applicable solicitation will not accept a proposal from a company whose required assessment is not on file.

One of the 12 categories in the Federal Readiness Score. The methodology is public — including the things this platform will never claim.

CMMC is one signal. See all of them.

Get your free score