CMMC status
What’s still required right now
Status as of
What paused
- Level 2 certification by third-party assessors (C3PAOs)
- Level 3 certification by the government’s own assessors (DIBCAC)
Paused July 13, 2026, while the program is reviewed.
What still applies
- Level 1 and Level 2 self-assessments, with a yearly affirmation (since November 10, 2025)
- Safeguarding and 72-hour incident reporting (DFARS 252.204-7012)
- NIST SP 800-171 Revision 2 as the standard
- Requirements your prime flows down to you
- Federal enforcement
What could change this
When the rules change, we update this page and the date above.
Why the paperwork matters
Here is what stands behind the score you post.
What counts and what doesn’t
Without a System Security Plan, the DoD Assessment Methodology says an assessment can’t be completed. And a plan of action earns no points: a requirement that isn’t in place is scored as not in place, whether or not there’s a plan to fix it.
What the government has enforced
Recent federal settlements with defense contractors and a university turned on inaccurate cybersecurity statements, not on breaches. Getting hacked wasn’t the trigger. Saying something inaccurate was.
Contact
Talk to us
Call or email Josh. He’ll book a free 15-minute call with Juan, who answers the technical questions.
Call
(805) 253-2061We don’t record calls.
Please don’t send drawings, contracts, or controlled information by email or through this site.