Updated July 2026

CMMC Compliance for Small Defense Contractors

What the Phase 2 suspension actually changed, what still applies to your contracts today, and how to get ready without spending $50,000 to do it.

SBA Service-Disabled Veteran-Owned Certified Florida Certified Veteran-Owned Business SBA Service-Disabled Veteran-Owned Certified · Florida Certified Veteran-Owned Business
CyberCloudAI Consulting LLCService-Disabled Veteran-Owned Small Business
Ken HaynesCISSP, PMP, MBA — Former Senior Army Officer

1. What happened in July 2026

On July 13, 2026, the Department of Defense suspended Phase 2 of the CMMC rollout and opened a 60-day top-to-bottom review of the entire program, run by a newly formed CMMC Reform Task Force.

Phase 2 was the phase with teeth. Beginning November 10, 2026, it would have required third-party certification — assessments conducted by an accredited C3PAO — for contracts involving Controlled Unclassified Information. That requirement is now paused until further notice, along with all pending and future CMMC milestones.

The memo from DoD CIO Kirsten Davies was unusually direct about why. It stated that the program “imposes significant and often prohibitive burdens on the Defense Industrial Base,” and that “administrative compliance cannot come at the cost of warfighting capability.” The review is chartered to prioritize speed to capability and lower barriers for small, medium, and non-traditional businesses — explicitly replacing what the memo called “prohibitive, third-party compliance models” with scalable, realistic security measures.

The part most contractors got wrong

A large number of small contractors read the headline, concluded CMMC was dead, and stopped work. That is the single most expensive interpretation available, and this guide exists mostly to explain why.

2. What did not change

The certification process is under review. The cybersecurity obligation is not. Every one of the following remains in force today:

DFARS 252.204-7012 still applies

This clause has been in defense contracts since 2017. It requires you to implement NIST SP 800-171 and to report cyber incidents to DoD within 72 hours. It is in your contract right now, and nothing about the Phase 2 suspension touches it.

NIST SP 800-171 is still the standard

The 110 security requirements are the substance of the obligation. CMMC was a mechanism for verifying that you had implemented them. Reviewing the verification mechanism does not repeal the requirements.

Rev 2 or Rev 3? A question worth settling

If you look this up you will find NIST SP 800-171 Revision 3, finalised in May 2024, with 134 requirements across two new control families. That is not what binds you. 32 CFR Part 170 codifies Revision 2 and its 110 requirements, and moving to Rev 3 would require fresh rulemaking that DoD has not announced. Assess against Rev 2. Anyone quoting you for 134 controls is either ahead of the regulation or selling you something.

Self-assessments and SPRS reporting continue

Phase 1 took effect in November 2025 and remains in force. Under DFARS 252.204-7019 and 7020, you must conduct a self-assessment and post your score to the Supplier Performance Risk System. That obligation is live today.

False Claims Act exposure is unchanged — and arguably worse

Certifying a score you cannot substantiate is a false statement to the government. DOJ’s Civil Cyber-Fraud Initiative has pursued exactly this. If anything, the risk rose in July 2026, because a wave of contractors concluded the pressure was off and stopped maintaining scores they had already submitted.

Worth saying plainly

Your SPRS score is a representation to the federal government. If it was accurate in June and your environment has drifted since, it is not accurate now. The suspension of Phase 2 does not change that, and “we thought CMMC was cancelled” is not a defense.

3. FCI, CUI, and which level applies to you

Almost every scoping error traces back to a contractor who never established which category of information they actually handle. Get this right first; everything downstream depends on it.

Which CMMC level applies to you A decision flow: holding any federal contract means you handle FCI and Level 1 applies. A contract carrying DFARS 252.204-7012 or CUI-marked material means Level 2 and all 110 NIST SP 800-171 requirements apply. Highest-priority DoD programs fall under Level 3. Which level applies to you Determined by your contract, not by your judgement Do you hold a federal contract of any kind? Almost certainly yes You handle FCI LEVEL 1 15 requirements · FAR 52.204-21 annual self-assessment Does your contract carry DFARS 252.204-7012 or CUI markings? Read the contract — do not infer this one You handle CUI LEVEL 2 110 requirements NIST SP 800-171 Is this one of DoD’s highest-priority programs? A small minority of contractors Level 3 scope LEVEL 3 110 + selected NIST SP 800-172 assessed by DoD
Your contract determines the level — check for DFARS 252.204-7012 and CUI markings before assuming Level 1.
LevelInformation typeWhat it requires
Level 1 Federal Contract Information (FCI) 15 basic safeguarding requirements from FAR 52.204-21. Annual self-assessment with an affirming official.
Level 2 Controlled Unclassified Information (CUI) All 110 requirements of NIST SP 800-171. Under the suspended Phase 2 rules this would have required C3PAO assessment for most contracts; self-assessment remains operative during the pause.
Level 3 CUI on the highest-priority programs The 110 requirements plus a selected subset of NIST SP 800-172. Assessed by DoD directly, not by a third party. Applies to a small minority of contractors.

The practical distinction

FCI is information provided by or generated for the government under a contract that isn’t intended for public release. If you hold a federal contract of any kind, you almost certainly have FCI. Level 1 is your floor.

CUI is a defined category with specific markings — technical drawings, specifications, export-controlled data, and similar. The critical point: CUI is identified by your contract, not by your judgment. Look for the DFARS 252.204-7012 clause and any CUI markings on what your customer sends you.

A common and costly assumption

“We’re just a subcontractor, so CUI doesn’t reach us.” Flow-down clauses are real and enforced. If your prime handles CUI and passes work to you, the obligation very likely flows with it. Read the subcontract.

4. The rules that actually bind you

AuthorityWhat it does
32 CFR Part 170
Effective December 2024
The CMMC Program rule. Establishes the levels, the assessment framework, and the ecosystem — C3PAOs, the accreditation body, assessor qualifications.
48 CFR / DFARS rule
Published September 10, 2025
The acquisition rule. This is what actually puts CMMC into contracts, via clause DFARS 252.204-7021.
DFARS 252.204-7012
In force since 2017
Safeguarding covered defense information. Requires NIST SP 800-171 implementation and 72-hour incident reporting. Unaffected by the suspension.
DFARS 252.204-7019 / 7020Requires the NIST SP 800-171 self-assessment and posting your score to SPRS. Live and enforceable today.
FAR 52.204-21The 15 basic safeguarding requirements. The FCI floor — applies to essentially every federal contractor.

Notice what this table shows: the obligations that bind you contractually today mostly predate CMMC entirely. CMMC was the enforcement wrapper. Removing the wrapper leaves the requirements standing.

5. The phase timeline

CMMC implementation timeline as of July 2026 Four milestones are in force: the 32 CFR program rule from December 2024, the 48 CFR acquisition rule from September 2025, and Phase 1 self-assessments from November 2025. Phase 2, which would have required third-party C3PAO certification from November 2026, was suspended on 13 July 2026. A program review by the CMMC Reform Task Force is underway with no announced end date. CMMC timeline — what is in force, what is paused Status as of July 2026 DEC 2024 32 CFR Part 170 Program rule effective IN FORCE SEP 2025 48 CFR rule Acquisition rule published IN FORCE NOV 2025 Phase 1 Self-assessments begin IN FORCE NOV 2026 Phase 2 C3PAO certification SUSPENDED TBD DoD review Reform Task Force UNDERWAY Suspended does not mean cancelled. DFARS 252.204-7012, NIST SP 800-171 and SPRS reporting all remain contractually binding today.
Phase 2 was suspended on 13 July 2026. Everything to its left remains in force.
Program rule effective In force
December 2024

32 CFR Part 170 establishes the CMMC framework, levels, and assessment ecosystem.

Acquisition rule published In force
September 10, 2025

The 48 CFR rule authorizes contracting officers to place CMMC requirements into solicitations via DFARS 252.204-7021.

Phase 1 begins In force
November 2025

Self-assessment requirements take effect for applicable contracts. Contracting officers gain discretion to require higher levels. This phase remains active today.

Phase 2 Suspended
Was scheduled November 10, 2026

Mandatory third-party C3PAO certification for Level 2 contracts. Suspended July 13, 2026 pending program review.

Program review Underway
60 days from July 13, 2026

CMMC Reform Task Force conducting a top-to-bottom review. All pending and future milestones suspended until further notice.

How to read this

Everything above the suspension line is live. The review may reshape what comes after it, but the most likely outcomes — expanded self-assessment, risk-tiered requirements, a lighter path for small business — all still rest on NIST SP 800-171. Work you do against those controls holds its value under any plausible revision.

6. Scoping: the biggest cost lever you control

If you take one operational lesson from this guide, take this one. Scope determines cost more than any other decision you will make.

CUI scoping: sprawl compared with an enclave Left: when CUI is allowed to spread across email, shared drives, laptops, cloud sync, project tools and inboxes, every one of those systems falls in scope for all 110 controls. Right: when CUI is confined to a defined enclave, only the enclave carries the 110 controls and the rest of the business carries the lighter FCI requirements. Scoping decides your cost The same CUI, two architectures, very different bills SPRAWL CUI lands wherever work happens Email in scope Shared drive in scope Laptops in scope Cloud sync in scope PM tool in scope Inboxes in scope All 6 systems in scope · 110 controls each ENCLAVE CUI confined by design CUI ENCLAVE Controlled systems 110 controls apply here and only here Email General file store Everything else FCI requirements only 1 environment in scope
Two contractors with identical CUI can differ by an order of magnitude in compliance cost. Architecture, not tooling, is the variable.

Two contractors of identical size, handling identical CUI, can differ by an order of magnitude in what compliance costs them. The difference is almost never the security tooling. It’s whether CUI was allowed to spread across the entire business or was deliberately confined.

The sprawl pattern

CUI arrives by email. It gets saved to the shared drive. Someone copies it to a laptop to work from home. It ends up in a cloud sync folder, a project management tool, and three inboxes. Now every one of those systems, and every endpoint that touches them, is in scope for all 110 controls.

The enclave pattern

CUI is confined to a defined environment — a segmented set of systems with controlled entry and exit. Only that enclave is in scope. The rest of your business carries the much lighter FCI requirements.

Building an enclave takes deliberate work and changes how some people do their jobs. It is almost always cheaper than the alternative, and the gap widens as you grow.

Do this before anything else

Map where CUI actually lives in your business today. Not where policy says it should live — where it is. Most small contractors are genuinely surprised by this exercise, and it is the input to every cost decision that follows.

7. SPRS scoring, explained honestly

Your SPRS score is a single number representing your NIST SP 800-171 implementation, calculated under the DoD Assessment Methodology and posted to SPRS.

You start at 110 — full implementation of all 110 requirements. Each unimplemented requirement subtracts points based on its security significance: 1, 3, or 5 points. Because some controls carry heavier weights and certain items compound, the theoretical floor is −203.

A negative score is not unusual for a contractor who has never done this deliberately. It is not a moral failing. It is a starting position.

What the number is actually for

Contracting officers can see it. Primes increasingly ask for it before awarding subcontracts. It is a procurement signal, not just a compliance artifact — which means an accurate, improving score is a business development asset, and a stale one is a liability.

Score honestly

The temptation to round up is obvious and the downside is severe. A score you cannot substantiate under scrutiny is a false statement. Score what you have actually implemented, document the gaps in a POA&M, and improve the number deliberately.

Prioritization tip

Remediate by point value, not by ease. Closing three 5-point gaps moves your score more than closing seven 1-point gaps, and usually costs less in total effort. Sort your gap list by weight before you plan any work.

8. The seven-step readiness path

1

Determine what you handle

FCI, CUI, or both. Read your contracts and look for DFARS 252.204-7012 and CUI markings. Do not infer this — establish it from documents.

2

Scope the environment

Map where that information actually flows and lives. Decide deliberately whether to enclave it. This step determines the cost of every step after it.

3

Run an honest self-assessment

Assess against all 110 requirements using the DoD Assessment Methodology. Resist the urge to give yourself credit for partial implementation — the methodology doesn’t, and neither will an assessor.

4

Write the System Security Plan

The SSP describes how each requirement is met in your specific environment. It is the document everything else references. Without it you do not have a program, you have intentions.

5

Build a POA&M and start closing gaps

For every gap, a Plan of Action and Milestones with a realistic owner and date. Prioritize by SPRS point value. Aspirational dates you miss are worse than honest ones you meet.

6

Post your score to SPRS

Submit the score with your assessment date and scope. Update it when your environment materially changes — a stale score is a live representation.

7

Operate it continuously

Compliance is a state, not a milestone. Access reviews, log monitoring, patching, training, and annual reassessment. This is the step that separates contractors who pass scrutiny from those who once produced a binder.

9. What this actually costs

Anyone quoting a number before understanding your scope is guessing. That said, contractors deserve better than “it depends,” so here is the honest shape of it.

The consulting market has historically charged small contractors $15,000 to $50,000 for Level 2 readiness engagements. A meaningful portion of that is documentation work — the SSP, policies, and POA&M — which is templatable and which many small contractors can complete themselves with the right structure.

Where money actually goes

  • Scoping and architecture. The highest-leverage spend. Getting this wrong costs more than any other error.
  • Documentation. Large effort, low complexity. The best candidate for doing it yourself.
  • Technical remediation. MFA, logging, encryption, access control. Varies enormously with your starting point.
  • Assessment. Currently self-assessment for most contracts, with Phase 2 paused. C3PAO cost was the largest single line item under the suspended model and is now an open question pending the review.
  • Sustainment. The recurring cost nobody budgets for and everybody incurs.
Our position on this

If your environment is simple and you have someone organized, you should do most of the documentation yourself. We publish self-service CMMC packets starting at free for exactly this reason. Pay for judgment — scoping, architecture, and hard calls — not for filling in templates.

10. Five expensive mistakes

1. Treating the suspension as cancellation

Covered above, and worth repeating because it is currently the most common error in the defense industrial base. The controls remain contractual.

2. Scoping by default instead of by design

Letting CUI live wherever it lands, then trying to secure the whole business. Multiplies cost across every subsequent step.

3. Optimistic self-scoring

Giving yourself credit for controls that are policy statements rather than implemented practice. Creates legal exposure and a false sense of readiness simultaneously.

4. The write-once SSP

A System Security Plan produced for a deadline and never updated. Environments drift within months. An SSP that describes a system you no longer run is worse than useless under assessment — it demonstrates the program isn’t operating.

5. Ignoring flow-down

Assuming your own subcontractors and vendors are someone else’s problem. Your obligations flow down, and their failure becomes your exposure.

11. What to do during the pause

The review creates genuine uncertainty about the shape of future certification. It creates no uncertainty at all about what you should be doing right now.

Do these regardless of how the review lands

  • Confirm your information types. Costs nothing, determines everything.
  • Scope and, if warranted, enclave. Valuable under every plausible outcome, and the hardest thing to retrofit later.
  • Get your SPRS score accurate. Contractually required today. Not optional.
  • Write or refresh the SSP. Required under 7012 independent of CMMC.
  • Close high-value gaps. MFA, logging, access control, encryption. These are good security regardless of what any framework requires.

Reasonable to defer

  • Booking a C3PAO assessment before the review concludes, unless a specific contract requires it.
  • Buying tooling sold specifically as “CMMC certification readiness” — wait and see what the requirement becomes.
The strategic read

Every signal from the review — lower barriers for small business, scalable measures, less reliance on third-party assessment — points toward a model that favors contractors who have genuinely implemented the controls and can demonstrate it themselves. The pause rewards preparation and punishes the assumption that it went away.

12. Frequently asked questions

Is CMMC cancelled?

No. Phase 2 is suspended pending a DoD review announced July 13, 2026. Phase 1 self-assessment requirements remain in effect, and the underlying NIST SP 800-171 obligations under DFARS 252.204-7012 are untouched.

Do I still need to post an SPRS score?

Yes. DFARS 252.204-7019 and 7020 are in force. This is a current contractual obligation, not a CMMC artifact.

Should I stop my CMMC preparation?

No. The controls are still contractually required, and every likely outcome of the review still rests on NIST SP 800-171. Contractors who pause will restart from behind.

What’s the difference between Level 1 and Level 2?

Level 1 covers FCI and comprises 15 requirements from FAR 52.204-21. Level 2 covers CUI and comprises all 110 requirements of NIST SP 800-171. Your contract determines which applies.

Can I be compliant with an open POA&M?

A POA&M is a normal and expected part of a functioning program. What matters is that it is realistic, actively worked, and honest about dates. A POA&M used to indefinitely defer significant controls is a different thing, and assessors recognize the difference.

How long does readiness take?

For a small contractor with a simple, well-scoped environment, a matter of months. For one with sprawling CUI and no starting documentation, considerably longer. Scoping is the variable.

Do I need a consultant?

Not necessarily. If your environment is simple and someone on your team is organized and willing to read carefully, the documentation is achievable in-house. Consultants earn their fee on scoping decisions, architecture, and hard judgment calls — not on templates.

Primary sources

Every claim in this guide traces to one of the following. Where a consultant’s summary and the regulation disagree, the regulation wins — read them yourself.

Find out where you actually stand

Nine plain-English questions. Two minutes. Instant results and a free PDF action plan — no jargon and no sales call required.

Take the Free CMMC Readiness Quiz Book a Strategy Call
Scroll to Top