CMMC Compliance for Small Defense Contractors
What the Phase 2 suspension actually changed, what still applies to your contracts today, and how to get ready without spending $50,000 to do it.
What’s in this guide
- What happened in July 2026
- What did not change
- FCI, CUI, and which level applies
- The rules that actually bind you
- The phase timeline
- Scoping: the biggest cost lever
- SPRS scoring explained
- The seven-step readiness path
- What this actually costs
- Five expensive mistakes
- What to do during the pause
- Frequently asked questions
- Primary sources
1. What happened in July 2026
On July 13, 2026, the Department of Defense suspended Phase 2 of the CMMC rollout and opened a 60-day top-to-bottom review of the entire program, run by a newly formed CMMC Reform Task Force.
Phase 2 was the phase with teeth. Beginning November 10, 2026, it would have required third-party certification — assessments conducted by an accredited C3PAO — for contracts involving Controlled Unclassified Information. That requirement is now paused until further notice, along with all pending and future CMMC milestones.
The memo from DoD CIO Kirsten Davies was unusually direct about why. It stated that the program “imposes significant and often prohibitive burdens on the Defense Industrial Base,” and that “administrative compliance cannot come at the cost of warfighting capability.” The review is chartered to prioritize speed to capability and lower barriers for small, medium, and non-traditional businesses — explicitly replacing what the memo called “prohibitive, third-party compliance models” with scalable, realistic security measures.
A large number of small contractors read the headline, concluded CMMC was dead, and stopped work. That is the single most expensive interpretation available, and this guide exists mostly to explain why.
2. What did not change
The certification process is under review. The cybersecurity obligation is not. Every one of the following remains in force today:
DFARS 252.204-7012 still applies
This clause has been in defense contracts since 2017. It requires you to implement NIST SP 800-171 and to report cyber incidents to DoD within 72 hours. It is in your contract right now, and nothing about the Phase 2 suspension touches it.
NIST SP 800-171 is still the standard
The 110 security requirements are the substance of the obligation. CMMC was a mechanism for verifying that you had implemented them. Reviewing the verification mechanism does not repeal the requirements.
If you look this up you will find NIST SP 800-171 Revision 3, finalised in May 2024, with 134 requirements across two new control families. That is not what binds you. 32 CFR Part 170 codifies Revision 2 and its 110 requirements, and moving to Rev 3 would require fresh rulemaking that DoD has not announced. Assess against Rev 2. Anyone quoting you for 134 controls is either ahead of the regulation or selling you something.
Self-assessments and SPRS reporting continue
Phase 1 took effect in November 2025 and remains in force. Under DFARS 252.204-7019 and 7020, you must conduct a self-assessment and post your score to the Supplier Performance Risk System. That obligation is live today.
False Claims Act exposure is unchanged — and arguably worse
Certifying a score you cannot substantiate is a false statement to the government. DOJ’s Civil Cyber-Fraud Initiative has pursued exactly this. If anything, the risk rose in July 2026, because a wave of contractors concluded the pressure was off and stopped maintaining scores they had already submitted.
Your SPRS score is a representation to the federal government. If it was accurate in June and your environment has drifted since, it is not accurate now. The suspension of Phase 2 does not change that, and “we thought CMMC was cancelled” is not a defense.
3. FCI, CUI, and which level applies to you
Almost every scoping error traces back to a contractor who never established which category of information they actually handle. Get this right first; everything downstream depends on it.
| Level | Information type | What it requires |
|---|---|---|
| Level 1 | Federal Contract Information (FCI) | 15 basic safeguarding requirements from FAR 52.204-21. Annual self-assessment with an affirming official. |
| Level 2 | Controlled Unclassified Information (CUI) | All 110 requirements of NIST SP 800-171. Under the suspended Phase 2 rules this would have required C3PAO assessment for most contracts; self-assessment remains operative during the pause. |
| Level 3 | CUI on the highest-priority programs | The 110 requirements plus a selected subset of NIST SP 800-172. Assessed by DoD directly, not by a third party. Applies to a small minority of contractors. |
The practical distinction
FCI is information provided by or generated for the government under a contract that isn’t intended for public release. If you hold a federal contract of any kind, you almost certainly have FCI. Level 1 is your floor.
CUI is a defined category with specific markings — technical drawings, specifications, export-controlled data, and similar. The critical point: CUI is identified by your contract, not by your judgment. Look for the DFARS 252.204-7012 clause and any CUI markings on what your customer sends you.
“We’re just a subcontractor, so CUI doesn’t reach us.” Flow-down clauses are real and enforced. If your prime handles CUI and passes work to you, the obligation very likely flows with it. Read the subcontract.
4. The rules that actually bind you
| Authority | What it does |
|---|---|
| 32 CFR Part 170 Effective December 2024 | The CMMC Program rule. Establishes the levels, the assessment framework, and the ecosystem — C3PAOs, the accreditation body, assessor qualifications. |
| 48 CFR / DFARS rule Published September 10, 2025 | The acquisition rule. This is what actually puts CMMC into contracts, via clause DFARS 252.204-7021. |
| DFARS 252.204-7012 In force since 2017 | Safeguarding covered defense information. Requires NIST SP 800-171 implementation and 72-hour incident reporting. Unaffected by the suspension. |
| DFARS 252.204-7019 / 7020 | Requires the NIST SP 800-171 self-assessment and posting your score to SPRS. Live and enforceable today. |
| FAR 52.204-21 | The 15 basic safeguarding requirements. The FCI floor — applies to essentially every federal contractor. |
Notice what this table shows: the obligations that bind you contractually today mostly predate CMMC entirely. CMMC was the enforcement wrapper. Removing the wrapper leaves the requirements standing.
5. The phase timeline
32 CFR Part 170 establishes the CMMC framework, levels, and assessment ecosystem.
The 48 CFR rule authorizes contracting officers to place CMMC requirements into solicitations via DFARS 252.204-7021.
Self-assessment requirements take effect for applicable contracts. Contracting officers gain discretion to require higher levels. This phase remains active today.
Mandatory third-party C3PAO certification for Level 2 contracts. Suspended July 13, 2026 pending program review.
CMMC Reform Task Force conducting a top-to-bottom review. All pending and future milestones suspended until further notice.
Everything above the suspension line is live. The review may reshape what comes after it, but the most likely outcomes — expanded self-assessment, risk-tiered requirements, a lighter path for small business — all still rest on NIST SP 800-171. Work you do against those controls holds its value under any plausible revision.
6. Scoping: the biggest cost lever you control
If you take one operational lesson from this guide, take this one. Scope determines cost more than any other decision you will make.
Two contractors of identical size, handling identical CUI, can differ by an order of magnitude in what compliance costs them. The difference is almost never the security tooling. It’s whether CUI was allowed to spread across the entire business or was deliberately confined.
The sprawl pattern
CUI arrives by email. It gets saved to the shared drive. Someone copies it to a laptop to work from home. It ends up in a cloud sync folder, a project management tool, and three inboxes. Now every one of those systems, and every endpoint that touches them, is in scope for all 110 controls.
The enclave pattern
CUI is confined to a defined environment — a segmented set of systems with controlled entry and exit. Only that enclave is in scope. The rest of your business carries the much lighter FCI requirements.
Building an enclave takes deliberate work and changes how some people do their jobs. It is almost always cheaper than the alternative, and the gap widens as you grow.
Map where CUI actually lives in your business today. Not where policy says it should live — where it is. Most small contractors are genuinely surprised by this exercise, and it is the input to every cost decision that follows.
7. SPRS scoring, explained honestly
Your SPRS score is a single number representing your NIST SP 800-171 implementation, calculated under the DoD Assessment Methodology and posted to SPRS.
You start at 110 — full implementation of all 110 requirements. Each unimplemented requirement subtracts points based on its security significance: 1, 3, or 5 points. Because some controls carry heavier weights and certain items compound, the theoretical floor is −203.
A negative score is not unusual for a contractor who has never done this deliberately. It is not a moral failing. It is a starting position.
What the number is actually for
Contracting officers can see it. Primes increasingly ask for it before awarding subcontracts. It is a procurement signal, not just a compliance artifact — which means an accurate, improving score is a business development asset, and a stale one is a liability.
Score honestly
The temptation to round up is obvious and the downside is severe. A score you cannot substantiate under scrutiny is a false statement. Score what you have actually implemented, document the gaps in a POA&M, and improve the number deliberately.
Remediate by point value, not by ease. Closing three 5-point gaps moves your score more than closing seven 1-point gaps, and usually costs less in total effort. Sort your gap list by weight before you plan any work.
8. The seven-step readiness path
Determine what you handle
FCI, CUI, or both. Read your contracts and look for DFARS 252.204-7012 and CUI markings. Do not infer this — establish it from documents.
Scope the environment
Map where that information actually flows and lives. Decide deliberately whether to enclave it. This step determines the cost of every step after it.
Run an honest self-assessment
Assess against all 110 requirements using the DoD Assessment Methodology. Resist the urge to give yourself credit for partial implementation — the methodology doesn’t, and neither will an assessor.
Write the System Security Plan
The SSP describes how each requirement is met in your specific environment. It is the document everything else references. Without it you do not have a program, you have intentions.
Build a POA&M and start closing gaps
For every gap, a Plan of Action and Milestones with a realistic owner and date. Prioritize by SPRS point value. Aspirational dates you miss are worse than honest ones you meet.
Post your score to SPRS
Submit the score with your assessment date and scope. Update it when your environment materially changes — a stale score is a live representation.
Operate it continuously
Compliance is a state, not a milestone. Access reviews, log monitoring, patching, training, and annual reassessment. This is the step that separates contractors who pass scrutiny from those who once produced a binder.
9. What this actually costs
Anyone quoting a number before understanding your scope is guessing. That said, contractors deserve better than “it depends,” so here is the honest shape of it.
The consulting market has historically charged small contractors $15,000 to $50,000 for Level 2 readiness engagements. A meaningful portion of that is documentation work — the SSP, policies, and POA&M — which is templatable and which many small contractors can complete themselves with the right structure.
Where money actually goes
- Scoping and architecture. The highest-leverage spend. Getting this wrong costs more than any other error.
- Documentation. Large effort, low complexity. The best candidate for doing it yourself.
- Technical remediation. MFA, logging, encryption, access control. Varies enormously with your starting point.
- Assessment. Currently self-assessment for most contracts, with Phase 2 paused. C3PAO cost was the largest single line item under the suspended model and is now an open question pending the review.
- Sustainment. The recurring cost nobody budgets for and everybody incurs.
If your environment is simple and you have someone organized, you should do most of the documentation yourself. We publish self-service CMMC packets starting at free for exactly this reason. Pay for judgment — scoping, architecture, and hard calls — not for filling in templates.
10. Five expensive mistakes
1. Treating the suspension as cancellation
Covered above, and worth repeating because it is currently the most common error in the defense industrial base. The controls remain contractual.
2. Scoping by default instead of by design
Letting CUI live wherever it lands, then trying to secure the whole business. Multiplies cost across every subsequent step.
3. Optimistic self-scoring
Giving yourself credit for controls that are policy statements rather than implemented practice. Creates legal exposure and a false sense of readiness simultaneously.
4. The write-once SSP
A System Security Plan produced for a deadline and never updated. Environments drift within months. An SSP that describes a system you no longer run is worse than useless under assessment — it demonstrates the program isn’t operating.
5. Ignoring flow-down
Assuming your own subcontractors and vendors are someone else’s problem. Your obligations flow down, and their failure becomes your exposure.
11. What to do during the pause
The review creates genuine uncertainty about the shape of future certification. It creates no uncertainty at all about what you should be doing right now.
Do these regardless of how the review lands
- Confirm your information types. Costs nothing, determines everything.
- Scope and, if warranted, enclave. Valuable under every plausible outcome, and the hardest thing to retrofit later.
- Get your SPRS score accurate. Contractually required today. Not optional.
- Write or refresh the SSP. Required under 7012 independent of CMMC.
- Close high-value gaps. MFA, logging, access control, encryption. These are good security regardless of what any framework requires.
Reasonable to defer
- Booking a C3PAO assessment before the review concludes, unless a specific contract requires it.
- Buying tooling sold specifically as “CMMC certification readiness” — wait and see what the requirement becomes.
Every signal from the review — lower barriers for small business, scalable measures, less reliance on third-party assessment — points toward a model that favors contractors who have genuinely implemented the controls and can demonstrate it themselves. The pause rewards preparation and punishes the assumption that it went away.
12. Frequently asked questions
Is CMMC cancelled?
No. Phase 2 is suspended pending a DoD review announced July 13, 2026. Phase 1 self-assessment requirements remain in effect, and the underlying NIST SP 800-171 obligations under DFARS 252.204-7012 are untouched.
Do I still need to post an SPRS score?
Yes. DFARS 252.204-7019 and 7020 are in force. This is a current contractual obligation, not a CMMC artifact.
Should I stop my CMMC preparation?
No. The controls are still contractually required, and every likely outcome of the review still rests on NIST SP 800-171. Contractors who pause will restart from behind.
What’s the difference between Level 1 and Level 2?
Level 1 covers FCI and comprises 15 requirements from FAR 52.204-21. Level 2 covers CUI and comprises all 110 requirements of NIST SP 800-171. Your contract determines which applies.
Can I be compliant with an open POA&M?
A POA&M is a normal and expected part of a functioning program. What matters is that it is realistic, actively worked, and honest about dates. A POA&M used to indefinitely defer significant controls is a different thing, and assessors recognize the difference.
How long does readiness take?
For a small contractor with a simple, well-scoped environment, a matter of months. For one with sprawling CUI and no starting documentation, considerably longer. Scoping is the variable.
Do I need a consultant?
Not necessarily. If your environment is simple and someone on your team is organized and willing to read carefully, the documentation is achievable in-house. Consultants earn their fee on scoping decisions, architecture, and hard judgment calls — not on templates.
Primary sources
Every claim in this guide traces to one of the following. Where a consultant’s summary and the regulation disagree, the regulation wins — read them yourself.
- 32 CFR Part 170 — the CMMC Program rule (eCFR). Levels, assessment framework, and the C3PAO ecosystem. See §170.14 for the CMMC model itself.
- DFARS 252.204-7012 — Safeguarding Covered Defense Information and Cyber Incident Reporting (Acquisition.gov).
- DFARS 252.204-7019 and 252.204-7020 — the self-assessment and SPRS posting requirements.
- FAR 52.204-21 — Basic Safeguarding of Covered Contractor Information Systems. The 15 requirements behind Level 1.
- NIST SP 800-171 Rev. 2 — the 110 requirements CMMC actually binds you to today.
- NIST SP 800-171 Rev. 3 — finalised May 2024, 134 requirements. Not yet incorporated into the CMMC rule.
- NIST SP 800-172 — the enhanced requirements behind Level 3.
- Supplier Performance Risk System (SPRS) — where your score is posted and where contracting officers read it.
- The Cyber AB — the CMMC accreditation body and C3PAO marketplace.
Find out where you actually stand
Nine plain-English questions. Two minutes. Instant results and a free PDF action plan — no jargon and no sales call required.
Take the Free CMMC Readiness Quiz Book a Strategy Call