CMMC status

What’s still required right now

What paused

  • Level 2 certification by third-party assessors (C3PAOs)
  • Level 3 certification by the government’s own assessors (DIBCAC)

Paused July 13, 2026, while the program is reviewed.

What still applies

  • Level 1 and Level 2 self-assessments, with a yearly affirmation (since November 10, 2025)
  • Safeguarding and 72-hour incident reporting (DFARS 252.204-7012)
  • NIST SP 800-171 Revision 2 as the standard
  • Requirements your prime flows down to you
  • Federal enforcement

What could change this

When the rules change, we update this page and the date above.

Why the paperwork matters

Here is what stands behind the score you post.

What counts and what doesn’t

Without a System Security Plan, the DoD Assessment Methodology says an assessment can’t be completed. And a plan of action earns no points: a requirement that isn’t in place is scored as not in place, whether or not there’s a plan to fix it.

What the government has enforced

Recent federal settlements with defense contractors and a university turned on inaccurate cybersecurity statements, not on breaches. Getting hacked wasn’t the trigger. Saying something inaccurate was.

Contact

Talk to us

Call or email Josh. He’ll book a free 15-minute call with Juan, who answers the technical questions.

We don’t record calls.

Please don’t send drawings, contracts, or controlled information by email or through this site.