CMMC for the small defense supplier: what did the 48 CFR rule change?
Short answer
The 48 CFR CMMC acquisition rule changed CMMC from something defense suppliers could treat mainly as a cybersecurity readiness initiative into something that can directly affect eligibility for a DoD contract award.
The current DFARS includes:
- DFARS 252.204-7021, Contractor Compliance With the Cybersecurity
Maturity Model Certification Level Requirements
- DFARS 252.204-7025, Notice of Cybersecurity Maturity Model
Certification Level Requirements
When a solicitation includes the applicable CMMC requirement, the required CMMC status applies to each contractor information system that will process, store, or transmit Federal Contract Information, or FCI, or Controlled Unclassified Information, or CUI, during contract performance.
The solicitation provision at DFARS 252.204-7025 states that an offeror will not be eligible for award if it does not have the required current CMMC status and current affirmation of continuous compliance in the Supplier Performance Risk System, or SPRS, for the applicable systems.
That means CMMC can become a bid eligibility issue, not merely a cybersecurity improvement project.
There is also a critical current development.
On July 13, 2026, DoD announced the immediate suspension of CMMC Phase II requirements, which had been scheduled to begin November 10, 2026. DoD states that Phase I self assessment requirements remain in place while the Department conducts a broader CMMC review.
Because CMMC implementation is actively changing, small defense suppliers should verify the current DoD implementation status before every major compliance, contracting, or technology decision.
Important: This article is educational and is not legal, contractual, CMMC certification, or procurement advice. Always review the actual solicitation, contract, DFARS clauses, current DoD CMMC guidance, SPRS requirements, and advice from qualified contracting and CMMC professionals.
The two rules, and which one changed your bid
Why Was the 48 CFR Rule So Important?
There are two CMMC rules, and readers conflate them constantly. Putting both citations side by side is the fastest way to stop that.
- The program rule — the cybersecurity framework itself, codified at 32 CFR part 170. Published at 89 FR 83092 on 15 October 2024, effective 16 December 2024.
- The acquisition rule — the one that puts CMMC into contracts, DFARS Case 2019-D041. Published at 90 FR 43560 on 10 September 2025, effective 10 November 2025.
The program rule says what CMMC is. The acquisition rule is what makes it a condition of award. Both are in force today and neither has been amended.
That connection matters because contracting officers can now place CMMC requirements directly into applicable solicitations and contracts.
For a supplier, cybersecurity readiness can therefore affect whether the company can compete for or receive certain DoD awards.
What Does 48 CFR Mean?
Title 48 of the Code of Federal Regulations contains the Federal Acquisition Regulations System.
For DoD contractors, the Defense Federal Acquisition Regulation Supplement, or DFARS, adds DoD specific acquisition requirements.
CMMC acquisition requirements now appear in DFARS Part 204 and the associated provisions and clauses in Part 252.
The clauses: 7025, 7021, SPRS and the affirmation
What Is DFARS 252.204-7025?
DFARS 252.204-7025 is the solicitation provision titled:
Notice of Cybersecurity Maturity Model Certification Level Requirements
The provision allows the solicitation to identify the required CMMC level.
The available levels identified in the current provision include:
- CMMC Level 1 Self
- CMMC Level 2 Self
- CMMC Level 2 C3PAO
- CMMC Level 3 DIBCAC
The provision states that the specified level or higher is required prior to award for each contractor information system that will process, store, or transmit FCI or CUI during performance.
Can We Bid First and Become CMMC Compliant After Award?
Do not build your strategy around that assumption.
Where DFARS 252.204-7025 applies, the provision says the required current CMMC status and affirmation must exist for the applicable systems for award eligibility.
This is one of the biggest practical changes for small suppliers.
Historically, a company might see a cybersecurity clause and think:
"We will fix that after we win."
CMMC can move the cybersecurity gate earlier in the acquisition process.
What Is DFARS 252.204-7021?
DFARS 252.204-7021 is the contract clause titled:
Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements
Among other obligations, it requires the contractor to have and maintain the required current CMMC status for applicable information systems used in contract performance that process, store, or transmit FCI or CUI.
It also addresses:
- Annual affirmation
- SPRS
- CMMC UIDs
- Conditional status
- Plans of Action and Milestones
- Subcontract flowdown
What Is a CMMC UID?
The current DFARS clause defines a CMMC unique identifier, or CMMC UID, as the identifier assigned to a CMMC assessment and reflected in SPRS for a contractor information system.
The solicitation provision requires applicable CMMC UIDs to be provided in the proposal.
This makes the connection between the contract opportunity and the assessed information system much more explicit.
What Is SPRS?
SPRS is the Supplier Performance Risk System.
It is used for DoD supplier performance and cybersecurity information, including applicable CMMC assessment information and affirmations.
For CMMC, the current acquisition provisions connect award eligibility to information recorded in SPRS.
What Is an Affirmation of Continuous Compliance?
The current CMMC framework requires an affirming official to affirm continuous compliance.
DFARS 252.204-7021 requires annual affirmation for applicable systems.
This means CMMC is not intended to be treated as:
Pass assessment
→ Put certificate in drawer
→ Ignore cybersecurity for three years
The organization must maintain the required status and complete the required affirmations.
Who Is the Affirming Official?
Under the CMMC program, the affirming official is a senior organizational representative responsible for affirming continuing compliance.
Small businesses should treat this seriously.
The affirmation should be based on a real understanding of the organization's cybersecurity implementation rather than being treated as routine paperwork.
Who it applies to, and what counts as FCI or CUI
Does CMMC Apply to Small Businesses?
There is no blanket exemption simply because a contractor is small.
The determining factors include the contract, the information involved, the required CMMC level, and the systems used to perform the work.
A five person machine shop can have CMMC obligations if it receives information subject to the applicable requirements.
A much larger company may have systems or business units outside a particular CMMC assessment scope.
Size alone does not determine scope.
Are Commercial Products and Services Exempt?
Not automatically.
Current DFARS CMMC prescription language includes solicitations and contracts using FAR Part 12 procedures for commercial products and commercial services, subject to the applicable conditions.
However, acquisitions solely for commercially available off the shelf, or COTS, items are treated differently and are excluded from the CMMC clause prescription.
Small suppliers should not assume that calling their product "commercial" eliminates CMMC.
Are COTS Items Exempt?
The current DFARS specifically excludes acquisitions solely for commercially available off the shelf items from the CMMC clause prescription.
The details of a particular contract still matter.
If your company provides a mix of COTS products, services, engineering, customization, integration, or other work, have the actual solicitation reviewed rather than assuming the exemption applies.
What Is FCI?
FCI means Federal Contract Information.
The current DFARS CMMC clause defines FCI generally as nonpublic information provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, subject to the regulatory definition and exclusions.
CMMC Level 1 is associated with safeguarding FCI.
What Is CUI?
CUI means Controlled Unclassified Information.
CUI requires safeguarding or dissemination controls under applicable law, regulation, or Government wide policy.
CMMC Level 2 is associated with protection of CUI.
Levels, self-assessment and C3PAO
Does Every DoD Contract Require CMMC Level 2?
No.
The required CMMC level depends on the solicitation and the information involved.
The solicitation provision identifies the specific required level.
Do not assume:
DoD contract = Level 2 C3PAO
Read the solicitation.
What Is the Difference Between Level 2 Self and Level 2 C3PAO?
The CMMC framework allows different assessment requirements depending on the information and program.
Some Level 2 requirements may use a self assessment.
Others require assessment by a C3PAO.
The expansion is worth getting right, because the two rules do not agree. The program rule at 32 CFR 170.4 defines it as "CMMC Third-Party Assessment Organization" — "an organization that has been authorized or accredited by the Accreditation Body to conduct Level 2 certification assessments." The DFARS renders the same acronym as "certified third-party assessment organization." Both are current regulatory text. What it is not, in either rule, is "Certified Third-Party Assessor Organization," which circulates widely and appears in no regulation.
The solicitation identifies the applicable requirement.
What Is CMMC Level 3?
Level 3 applies to higher priority CUI environments and involves assessment by the Defense Industrial Base Cybersecurity Assessment Center, or DIBCAC, under the CMMC framework.
Most small suppliers should not assume they need Level 3 unless the contractual requirement says so.
The 2026 Phase 2 suspension: what actually happened
What Happened to the CMMC Phase In Schedule in 2026?
This is especially important because older articles may now be stale, and because almost every write-up of it gets the mechanism wrong.
As of 18 August 2026, a memorandum dated 13 July 2026 — "Implementing Department of War Chief Information Officer's Suspension of the Advancement to Cybersecurity Maturity Model Certification Phase 2 Requirements," signed by Michael P. Duffey, Under Secretary of War (Acquisition and Sustainment) — suspends the Phase 2 transition that had been scheduled for 10 November 2026.
Its operative sentence is narrow and specific:
Program offices and requiring activities are only permitted to include CMMC Level 1 (Self) or Level 2 (Self) assessments in procurement requests and requirement documents.
And, in the attachment: program managers and requiring activities may not designate CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments during this period.
Now the part that matters most, and that most coverage gets wrong. Nothing has been "delayed."
This is a policy memorandum, not a regulation. No effective date moved. No rule was stayed. No Federal Register document issued in 2026 has amended, delayed or suspended either CMMC rule — we checked the Federal Register for every 2026 CMMC document, and there are none that touch 32 CFR 170 or DFARS 204.75. The codified text at 32 CFR 170.3(e)(2) still states the Department's intent to require Level 2 (C3PAO) in Phase 2, and DFARS clause 252.204-7021 (NOV 2025) is fully operative.
So the regulation on the books currently requires something the executing policy has told contracting officers to stop asking for. That divergence has a practical consequence: a memorandum can be withdrawn in a day; a rule cannot. If the memo is superseded, Phase 2 returns on the existing regulatory footing with no new rulemaking needed.
There is a date attached to that risk. The memo sets no expiry, but it closes by promising that "further guidance will be promulgated at the conclusion of the CIO's 60-day review" — which points at roughly 11 September 2026. Anyone reading this after that date should re-check before relying on it.
Two other things the memo does that are easy to miss: no waivers are being granted during the review, and DFARS 252.204-7012 is untouched and remains in effect.
Therefore, businesses should not rely on an older CMMC timeline graphic, and should not rely on this article's status paragraph past mid-September without checking current guidance.
Does the Phase II Suspension Mean CMMC Is Gone?
No.
DoD's current guidance states that Phase I self assessment requirements remain in place.
The Department has announced a review and reform effort rather than declaring the entire cybersecurity framework irrelevant.
Existing contractual cybersecurity obligations, including applicable NIST SP 800-171 and DFARS requirements, should not be ignored.
If Our Contract Already Requires C3PAO, Can We Stop?
No — not until the modification actually issues. This is the single most expensive misreading available right now.
The memo binds DoD program managers and requiring activities going forward. It does not void an obligation already written into an awarded contract. It sets two different clocks:
- Active solicitations get an amendment removing the requirement "as soon as practicable."
- Existing contracts get a modification, but only "prior to the exercise of the next option period or during the next scheduled administrative modification."
That second clock can run for months. Until the modification issues, the requirement in your contract is still your requirement. Stop performing it early and you have a performance problem that no policy memorandum will cure.
Level 2 (C3PAO) also remains a valid CMMC status under the rule, and a higher status satisfies a lower one. A company that has already achieved it has not wasted the work.
Should We Stop Preparing for CMMC Because Phase II Was Suspended?
That would be risky.
A company that handles FCI or CUI still needs to understand and protect that information according to applicable contractual requirements.
Cybersecurity work such as:
- Asset inventory
- CUI identification
- Network diagrams
- Access control
- MFA
- Logging
- Vulnerability management
- Incident response
- System Security Plans
- Evidence collection
remains valuable even while acquisition implementation is being reviewed.
The prudent response to uncertainty is to stay aligned with current requirements while avoiding unsupported assumptions about future phases.
Which Phase Are We Actually In Today?
Phase 1, and we have been since 10 November 2025.
The CFR does not print calendar dates. 32 CFR 170.3(e) defines Phase 1 as beginning on the effective date of the 48 CFR acquisition rule, and each later phase as starting "one calendar year following" the one before it. The dates are derived from that:
| Phase | Derived start | Status as of 18 August 2026 |
|---|---|---|
| Phase 1 | 10 November 2025 | In effect — this is where we are |
| Phase 2 | 10 November 2026 | Suspended by the 13 July 2026 memorandum |
| Phase 3 | 10 November 2027 | Future, unchanged on paper |
| Phase 4 | 10 November 2028 | Future, unchanged on paper |
One subtlety worth holding onto: even inside Phase 1 the rule gives the Department discretion to require Level 2 (C3PAO) "in place of the Level 2 (Self) CMMC Status." The July memorandum is precisely the withdrawal of that discretion — not the removal of the underlying authority.
What Does the Current DFARS Say About the Broader Phase In?
The current DFARS text says that until November 9, 2028, the CMMC clause is used in applicable solicitations and contracts when the program office or requiring activity determines that a specific CMMC level is required.
The text also provides broader prescription language beginning November 10, 2028 for applicable contractor information systems processing, storing, or transmitting FCI or CUI.
However, because DoD separately announced the July 2026 Phase II suspension and broader program review, suppliers should check current DoD implementation guidance rather than interpreting the regulatory dates in isolation.
Eligibility, bid/no-bid and the sales conversation
Can CMMC Make Us Ineligible for an Award?
Yes, where the applicable solicitation provision requires a CMMC status that the offeror does not have.
DFARS 252.204-7025 explicitly addresses award eligibility.
This is why CMMC readiness belongs in the business development process, not only the IT department.
Should Our Sales Team Understand CMMC?
Yes.
A salesperson reviewing a DoD opportunity should know how to identify:
- DFARS 252.204-7025
- DFARS 252.204-7021
- Required CMMC level
- FCI
- CUI
- SPRS requirements
- CMMC UID requirements
- Flowdown implications
Sales does not need to become the cybersecurity team.
But sales should recognize when an opportunity has a cybersecurity eligibility gate.
Should CMMC Be Part of Bid No Bid Decisions?
Absolutely.
Before investing heavily in a proposal, ask:
- What CMMC level is required?
- Do we have that status?
- Which information system will perform the contract?
- Is the status current?
- Is the required affirmation current?
- Is the applicable information in SPRS?
- Do our subcontractors meet their requirements?
- Can we maintain compliance for the contract duration?
This can prevent wasted proposal effort.
What Happens if We Do Not Have the Required CMMC Status?
Depending on the solicitation, the company may not be eligible for award.
The practical response is to identify CMMC requirements before the solicitation you want to win arrives.
How Early Should a Small Supplier Start?
As early as possible.
CMMC preparation can involve:
- Scoping
- CUI discovery
- Asset inventory
- Policy development
- Technical remediation
- MFA
- Endpoint security
- Network changes
- Cloud service changes
- Logging
- Vulnerability remediation
- Documentation
- SSP development
- Evidence collection
- Assessment scheduling
Waiting until proposal week is too late for many organizations.
Scope: the single biggest lever a small supplier has
Can We Limit CMMC Scope?
Potentially.
Good architecture can reduce the number of systems that process, store, or transmit FCI or CUI.
For example, a company may build a controlled enclave rather than allowing CUI across every corporate system.
The scope must reflect reality.
Why Is Scope So Important for a Small Business?
Because every additional in scope asset can create:
- Security requirements
- Documentation
- Monitoring
- Administration
- Assessment evidence
- Cost
- Operational complexity
A deliberately designed CUI environment can make CMMC more manageable.
Can Microsoft 365 Expand Our Scope?
Potentially.
If CUI enters email, SharePoint, Teams, OneDrive, or other cloud services, those services and connected endpoints may become part of the relevant information flow.
Cloud authorization and contractual requirements also need to be considered.
Can Our Phone System Expand Scope?
Potentially.
CUI can enter a phone system through more paths than most people expect:
- Voice calls
- Voicemail
- Recordings
- Transcripts
- SMS
- Contact center interactions
- AI summaries
Modern communications platforms should be included in the data flow review.
Can Zoom Expand Scope?
Potentially.
Meetings, Phone, Team Chat, Whiteboard, recordings, transcripts, files, and AI can all process information.
The correct Zoom environment depends on the information flow, the contract, the cloud security requirements that apply, and the specific service authorization — which is a long enough question to have [its own article](/articles/zoom-for-government-cmmc-fedramp).
Can Our MSP Affect CMMC?
Yes.
If an MSP administers or protects the CUI environment, its systems, personnel, services, and contractual responsibilities may be relevant to scope and assessment.
Small suppliers should understand exactly what their MSP does.
Subcontractors and flow-down
Can Our Subcontractors Affect Our Eligibility or Performance?
Yes.
The current DFARS CMMC clause includes flowdown requirements.
Where a subcontract or other contractual instrument will involve processing, storing, or transmitting FCI or CUI, the prime contractor has responsibilities related to flowing down the appropriate CMMC requirement.
Do We Have to Check a Subcontractor Before Awarding Them Work?
The current DFARS 252.204-7021 clause requires the contractor, prior to awarding an applicable subcontract or other contractual instrument, to ensure that the subcontractor has a current CMMC certificate or status at the appropriate level for the information being flowed down.
This can change supplier management significantly.
Does the CMMC Clause Flow Down to Commercial Suppliers?
The current clause says to insert the substance of the clause into applicable subcontracts and other contractual instruments, including those for commercial products and commercial services, excluding COTS items, when the subcontract will require processing, storing, or transmitting FCI or CUI.
Again, do not assume "commercial" means "outside CMMC."
What if a Subcontractor Never Receives FCI or CUI?
The flowdown analysis depends on what information the subcontractor will process, store, or transmit.
Do not impose CMMC requirements mechanically without understanding the information flow.
At the same time, do not omit a requirement merely because the subcontractor is small.
Conditional status, POA&Ms and staying current
What Is Conditional CMMC Status?
The CMMC framework permits Conditional status in defined circumstances where certain requirements are addressed through an allowed Plan of Action and Milestones, or POA&M.
Conditional status is not permanent.
The current DFARS clause requires successful closure of a valid POA&M to achieve Final status.
Can We Put Everything on a POA&M?
No.
CMMC places limitations on which requirements can be included on a POA&M and the conditions for Conditional status.
A POA&M should not be treated as a universal escape hatch.
How Long Is a Final CMMC Level 2 Status Current?
The current DFARS clause defines Final Level 2 Self and Final Level 2 C3PAO statuses as current for up to three years, subject to no changes in compliance and the required annual affirmation of continuous compliance.
The annual affirmation remains important.
Does a Three Year Assessment Mean We Only Work on Cybersecurity Every Three Years?
No.
The organization must maintain compliance.
Cybersecurity changes continuously because:
- Employees join and leave
- Devices change
- Networks change
- Cloud applications change
- Vulnerabilities emerge
- Vendors change
- Administrators change
- CUI workflows change
Continuous compliance requires operational discipline.
What Happens When Our Environment Changes?
The organization should evaluate whether the change affects:
- Assessment scope
- Security controls
- SSP
- Asset inventory
- Network diagrams
- Evidence
- CMMC status
- Affirmation
Major architectural changes should not occur without security review.
Who owns this internally
Can We Buy CMMC Compliance?
No.
Products and services can support compliance.
You can buy:
- Firewalls
- EDR
- SIEM
- Managed security
- Cloud platforms
- MFA
- Monitoring
- Consulting
But CMMC evaluates how the organization implements and operates the applicable requirements.
Why Are Small Suppliers Especially Vulnerable?
Small companies often have:
- Limited IT staff
- Outsourced administration
- Flat networks
- Shared devices
- Consumer cloud applications
- Informal policies
- Personal device use
- Limited logging
- Minimal documentation
That does not mean CMMC is impossible.
It means architecture and scope discipline matter enormously.
Do We Need a Full Time CISO?
CMMC does not simply say every small contractor must hire a full time CISO.
Small organizations can use internal personnel and qualified external providers.
But responsibility cannot be outsourced into ambiguity.
Someone must own the cybersecurity program.
Can an MSP Do Everything?
An MSP can provide important technical and operational support.
But management still needs to understand:
- What is in scope
- What CUI the company receives
- Which contract requirements apply
- Who has responsibility
- What evidence exists
- What the company is affirming
The contractor remains responsible for its obligations.
Should CMMC Be Managed by IT Alone?
No.
CMMC touches:
- Executive leadership
- Contracts
- Business development
- IT
- Cybersecurity
- HR
- Facilities
- Legal
- Procurement
- Operations
- Subcontract management
For small organizations, one person may wear several of those hats.
The functions still need to be addressed.
What each team does
What Should Business Development Do When a New Solicitation Arrives?
Create a cybersecurity gate in the opportunity review.
Ask:
- Is DFARS 252.204-7025 present?
- What CMMC level is specified?
- Will we process FCI?
- Will we process CUI?
- Which information system will perform the work?
- Does it have the required current CMMC status?
- Is the affirmation current?
- Do we have the required CMMC UID?
- Will subcontractors receive FCI or CUI?
- Can we satisfy the requirement before award?
Do this before committing proposal resources.
What Should the Contracts Team Do?
Contracts personnel should understand:
- CMMC solicitation provisions
- Contract clauses
- Flowdown
- CUI requirements
- Subcontract requirements
- SPRS
- Affirmation
- Changes during performance
Cybersecurity requirements should be treated like other material contract requirements.
What Should Procurement Do?
Procurement should identify when suppliers or subcontractors will receive FCI or CUI.
The purchase order or subcontract process should incorporate the correct flowdown requirements where applicable.
What Should IT Do?
IT should maintain the actual technical environment supporting the claimed CMMC status.
That includes:
- Asset inventory
- Access control
- MFA
- Network security
- Endpoint security
- Logging
- Vulnerability management
- Backup
- Configuration
- Incident response support
- Documentation
What Should Management Do?
Management should understand what the organization is promising.
The annual affirmation requirement makes executive awareness particularly important.
Management should receive meaningful cybersecurity reporting rather than simply signing documents prepared by IT.
What to do right now
What Should a Small Defense Supplier Do Right Now?
1. Inventory DoD Contracts
Identify current and expected cybersecurity clauses.
2. Identify FCI and CUI
Know what information you actually receive.
3. Map Information Flows
Email, files, cloud platforms, phone, collaboration, engineering systems, endpoints.
4. Define the CMMC Scope
Determine which systems process, store, or transmit FCI or CUI and which systems provide security protection.
5. Review SPRS
Understand what assessment information is currently recorded.
6. Review Your SSP
Make sure it describes the real environment.
7. Build the Asset Inventory
Know what is in scope.
8. Build the Network Diagram
Document boundaries and connections.
9. Review Technical Gaps
MFA, EDR, logging, vulnerability management, segmentation, encryption, access.
10. Review Cloud Services
Know where CUI is stored and processed.
11. Review Communications
Phone, Zoom, voicemail, recordings, transcripts, SMS, AI.
12. Review Subcontractors
Know who receives FCI or CUI.
13. Build an Evidence Library
Collect evidence during normal operations.
14. Add CMMC to Bid Review
Do not discover the requirement at proposal submission.
15. Monitor DoD Changes
The 2026 Phase II suspension demonstrates why current guidance matters.
Opportunity checklist
Small Defense Supplier CMMC Opportunity Checklist
Opportunity Review
- Solicitation reviewed
- DFARS 252.204-7025 identified
- Required CMMC level identified
- FCI requirement identified
- CUI requirement identified
- Award eligibility confirmed
- CMMC UID available where required
Internal Readiness
- SPRS reviewed
- Current CMMC status understood
- Annual affirmation current where required
- SSP current
- Asset inventory current
- Network diagram current
- CUI flows documented
- Evidence library maintained
Technology
- MFA reviewed
- Endpoint security reviewed
- Firewall reviewed
- Network segmentation reviewed
- Logging reviewed
- Vulnerability management reviewed
- Cloud services reviewed
- Communications reviewed
- Remote access reviewed
Supply Chain
- Subcontractors identified
- FCI flowdown identified
- CUI flowdown identified
- Required subcontractor CMMC status identified
- Subcontractor status validated before applicable award
- Contract language updated
Management
- CMMC owner assigned
- Contracts team trained
- Business development trained
- IT responsibilities documented
- MSP responsibilities documented
- Affirming official identified
- Management receives cybersecurity status reporting
Current 2026 Status
- Current DoD CMMC website checked
- Phase II suspension considered
- Current solicitation language controls decision
- Older CMMC timeline graphics not relied upon without
verification
Frequently asked questions
What did the CMMC 48 CFR rule change?
It integrated CMMC requirements into the DoD acquisition process through DFARS provisions and clauses, allowing required CMMC status to become a condition of award for applicable solicitations.
Can CMMC prevent us from winning a DoD contract?
Yes. When DFARS 252.204-7025 applies, an offeror without the required current CMMC status and affirmation for applicable systems can be ineligible for award.
Does every DoD contract require CMMC Level 2?
No. The solicitation identifies the required CMMC level.
Do small businesses get a CMMC exemption?
There is no blanket small business exemption.
Are COTS suppliers exempt?
The current DFARS prescription excludes acquisitions solely for COTS items from the CMMC clause. Mixed products and services should be evaluated against the actual solicitation.
What is DFARS 252.204-7025?
It is the solicitation provision that identifies the required CMMC level and addresses award eligibility.
What is DFARS 252.204-7021?
It is the contract clause establishing CMMC compliance requirements during contract performance, including status, affirmation, SPRS, and subcontract flowdown obligations.
What is a CMMC UID?
It is the unique identifier associated with a CMMC assessment and reflected in SPRS for an information system.
Do we need CMMC before award?
Where the applicable solicitation requires it, the required current CMMC status must exist prior to award for the relevant systems.
Does CMMC flow down to subcontractors?
Yes, where applicable. The current DFARS clause includes flowdown requirements when subcontractors will process, store, or transmit FCI or CUI.
Can we become compliant after we win?
Do not assume so. Where CMMC is a pre award requirement, missing status can affect award eligibility.
Is CMMC Phase II still beginning November 10, 2026?
No. DoD announced on July 13, 2026 that Phase II implementation was immediately suspended. DoD states that Phase I self assessment requirements remain in place while the program is reviewed.
Is CMMC canceled?
No. Current DoD guidance describes a Phase II suspension and reform review, not elimination of all CMMC and cybersecurity requirements.
Should we stop CMMC preparation?
No. Contractors should continue meeting current contractual cybersecurity obligations and maintain readiness while monitoring official DoD updates.
How often must Level 2 be reassessed?
The current DFARS clause defines Final Level 2 statuses as current for up to three years, subject to continued compliance and annual affirmation requirements.
Related articles
- What network monitoring evidence does a CMMC Level 2 assessment ask for? — the evidence side of the same requirement.
- Zoom, Zoom for Government and CMMC — whether a cloud communications platform pulls into your scope.
References
Primary sources only. The two Federal Register documents are the rules; the memorandum is policy sitting on top of them, and the difference between those two things is most of this article.
- Federal Register — Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041)— the acquisition rule. 90 FR 43560, published 10 September 2025, effective 10 November 2025. Its DATES section reads, in full: "This rule is effective November 10, 2025."
- Federal Register — Cybersecurity Maturity Model Certification (CMMC) Program— the program rule. 89 FR 83092, published 15 October 2024, effective 16 December 2024. Codified at 32 CFR part 170.
- Department of War — Implementing the DoW CIO's Suspension of the Advancement to CMMC Phase 2 Requirements— the 13 July 2026 memorandum signed by Under Secretary of War (Acquisition and Sustainment) Michael P. Duffey. Source for the Level 1 (Self) / Level 2 (Self) restriction, the solicitation-amendment and contract-modification mechanics, the waiver freeze, and the 60-day review.
- eCFR — 32 CFR part 170, Cybersecurity Maturity Model Certification (CMMC) Program— the codified program rule. § 170.3(e) defines the four phases relative to the acquisition rule's effective date rather than by calendar date; § 170.4 defines C3PAO.
- eCFR — 48 CFR subpart 204.75 and clause 252.204-7021— the codified acquisition rule. Clause 252.204-7021 carries the date designation (NOV 2025) and remains operative.
- DoD CIO — Cybersecurity Maturity Model Certification— the Department's own status page. Confirms Phase 1 began 10 November 2025 and that "CMMC implementation is paused in Phase 1."
- DoD CIO — CMMC Frequently Asked Questions— last updated 13 July 2026. Confirms the Phase 2 suspension and the NIST SP 800-171 Revision 2 pairing.
- NIST — SP 800-171 Revision 2 (withdrawn)— withdrawn by NIST on 14 May 2024 in favour of Revision 3, but incorporated by reference into 32 CFR 170.2 and therefore still the standard CMMC assesses against.
Managed network and communications services, SDVOSB. We do the parts of a CMMC programme that are technology rather than paperwork: asset and circuit inventory, network diagrams and segmentation, logging and monitoring architecture, and reviewing whether your phone, Zoom and cloud services drag CUI into scope. CAGE 9QJS2 · UEI NJ7FKBV9X6L1. Support: (888) 989-4872 · support@adampulse.us