Key Takeaways

  • CMMC has three levels: Level 1 (15 requirements from FAR 52.204-21, for FCI), Level 2 (110 requirements from NIST SP 800-171 Rev. 2, for CUI), and Level 3 (Level 2 plus 24 enhanced requirements from NIST SP 800-172).
  • Phase 1 began 10 November 2025 and requires Level 1 and Level 2 self-assessments posted in SPRS as a condition of award.
  • Phase 2, which would have required third-party C3PAO certification from 10 November 2026, was suspended on 13 July 2026 pending a 60-day program review.
  • The suspension removes no underlying security obligation. DFARS 252.204-7012 and the 110 NIST SP 800-171 requirements remain fully enforceable.
  • DoD’s own estimate for small-business Level 2 third-party certification is roughly $105,000–$118,000 over three years, excluding the implementation work most contractors still have ahead of them.

If you’ve been tracking CMMC deadlines, the one you had circled is gone. On 13 July 2026, the Department of War suspended Phase 2 of the Cybersecurity Maturity Model Certification programme, the transition to mandatory third-party certification that had been set for 10 November 2026.

That is not the same as CMMC going away, and the distinction matters more than the headline. Phase 1 is still in force: a current self-assessment posted in SPRS remains a condition of contract award. DFARS 252.204-7012 still applies. The 110 requirements of NIST SP 800-171 have been mandatory since December 2017 and are mandatory today. What moved is the audit gate, not the obligation behind it. For defense contractors, both prime and subcontractors, CMMC compliance is no longer a matter of if, but when and how.

So the question is whether the work is actually done, and if not, what it will take.

This checklist covers that: what CMMC compliance is and who it applies to, the three levels and the FCI-versus-CUI distinction that determines yours, the eight steps from scoping to annual affirmation, what it realistically costs, and where the programme goes once the reform task force reports in September.

What Is CMMC Compliance?

CMMC compliance is the process of meeting the Cybersecurity Maturity Model Certification requirements that the U.S. Department of War applies to defense contractors handling Federal Contract Information or Controlled Unclassified Information. It has three levels, verified by self-assessment or third-party assessment depending on the level and contract. 

Two rules govern it. 32 CFR Part 170, effective 16 December 2024, defines the programme itself: levels, assessment types, scoping and scoring. 

48 CFR (the DFARS acquisition rule), published 10 September 2025 and effective 10 November 2025, puts CMMC into contracts through provision 252.204-7025, which states the status a solicitation requires, and clause 252.204-7021, which obliges the contractor to maintain it.

What is the difference between FCI and CUI?

Federal Contract Information (FCI) is information provided by or generated for the government under a contract, not intended for public release — delivery schedules, internal correspondence about contract performance, draft deliverables. Almost every defence contractor handles it.

Controlled Unclassified Information (CUI) is information the government requires safeguarding under a specific law, regulation or policy — technical drawings, export-controlled data, engineering specifications. Not classified, but the category adversaries target.

This single distinction determines your level, your cost and your timeline. Handle only FCI and you are at Level 1. The moment CUI enters your environment you are at Level 2, and the difference is roughly a factor of ten in effort and spend.

What are the three CMMC 2.0 levels?

  • Level 1 (Foundational): This level applies to contractors that handle only FCI. It requires an annual self-assessment against 15 basic cybersecurity practices, drawn from FAR 52.204-21. No POA&Ms are permitted at this level.
  • Level 2 (Advanced): This level is for contractors that handle CUI. It aligns with the 110 security controls of NIST SP 800-171 Rev. 2, organised across 14 domains. Depending on the criticality of the CUI, some contractors may be allowed to perform self-assessments, while others will require a triennial third-party assessment by a CMMC Third-Party Assessment Organization (C3PAO). Following the July 2026 suspension, self-assessment is currently the standard path for new procurements.
  • Level 3 (Expert): This level is for contractors that handle CUI associated with the most critical defense programs. It will require a triennial government-led assessment by DIBCAC and is based on a subset of 24 requirements from NIST SP 800-172, in addition to the NIST SP 800-171 controls. Level 3 assessments are also currently suspended.

The 14 CMMC Level 2 domains

Domain Reqs Domain Reqs
Access Control (AC) 22 Personnel Security (PS) 2
Awareness and Training (AT) 3 Physical Protection (PE) 6
Audit and Accountability (AU) 9 Risk Assessment (RA) 3
Configuration Management (CM) 9 Security Assessment (CA) 4
Identification and Authentication (IA) 11 System and Communications Protection (SC) 16
Incident Response (IR) 3 System and Information Integrity (SI) 7
Maintenance (MA) 6 Media Protection (MP) 9

The domains are identical to the 14 control families in NIST SP 800-171 Rev. 2, down to the identifiers. If you have already mapped to 800-171, you have already mapped to CMMC Level 2.

Who Needs CMMC Certification?

Almost anyone in the defence supply chain who touches government information, at every tier, not just prime contractors. The reliable way to determine your obligation is to read your contracts rather than infer from your role. Three clauses do the work:

  • FAR 52.204-21 (Basic Safeguarding) present means you handle FCI, so Level 1 applies.
  • DFARS 252.204-7012 (Safeguarding Covered Defense Information) present means you handle CUI, so Level 2 applies.
  • DFARS 252.204-7021 / 252.204-7025 present means a specific CMMC status is a condition of award and performance.

Subcontractors are not exempt. Under 32 CFR 170.23, primes must flow CMMC requirements down through all tiers. Many large primes have been enforcing this ahead of the regulation and now decline to onboard suppliers who cannot demonstrate a posture. The main exclusion is commercially available off-the-shelf items and purchases below the micro-purchase threshold.

The CMMC Compliance Checklist: Step-by-Step

Determine Your Required CMMC Level

The first step is to identify the type of information your company handles and the corresponding CMMC level required. If you handle CUI, you will need to achieve at least CMMC Level 2. If you are involved in high-priority programs, you may need to target Level 3. Start from the contract clauses above rather than from an assumption about your tier. The DoD provides guidance to help contractors determine their required CMMC level.

Scope Your CUI Environment

The highest-leverage step in the process, and the one most often skipped. Identify precisely where CUI is created, received, stored, processed and transmitted — then decide how much of your environment genuinely needs to be in scope.

Most contractors do not need enterprise-wide Level 2 compliance. Isolating CUI into a defined enclave is the single largest cost reduction available: a narrower boundary means fewer systems to harden, fewer controls to evidence, and a materially shorter assessment.

Conduct a Gap Analysis & Self-Assessment

Once you have identified your target CMMC level, you need to assess your current cybersecurity posture against the required controls. A gap analysis will help you identify the areas where you are deficient and develop a plan for remediation. There are many resources available to help with this process, including the CMMC Assessment Guide from the DoD.

Score using the DoD Assessment Methodology against NIST SP 800-171A objectives and post the result in SPRS. Scoring runs to a maximum of 110 points, with deductions of 1, 3 or 5 per unmet requirement and a floor of −203. A score of 88 or above allows Conditional status with a POA&M, subject to a 180-day closeout window. Under Phase 1, a current score in SPRS is a condition of award.

Develop Your SSP, POA&M & Evidence

The SSP is a critical document that describes how your organization implements the security controls required by CMMC. It should be a living document that is regularly updated to reflect changes in your environment. The SSP is a key component of the CMMC assessment process and will be thoroughly reviewed by your C3PAO.

The POA&M records what is not yet met and when it will be. Evidence is where most first-time assessments fail: assessors are not satisfied by a policy stating that a control exists, they want artefacts showing it operating — logs, screenshots, tickets, training records, configuration exports, with dates. Build the evidence habit while you implement, not in the month before assessment.

Adopt a Compliant Platform

Where CUI is shared with external parties: primes, subs, advisors, counsel, acquirers,  the platform doing the sharing is in scope, and its own authorisation status becomes part of your evidence. A CMMC-compliant virtual data room keeps that exchange inside a controlled boundary with access controls and audit trails you can hand to an assessor.

Choosing the platform early matters more than it appears. Retrofitting a compliant sharing layer onto an established file-sharing habit is considerably harder than starting with one.

Implement the Required Security Controls

This is the most time-consuming and resource-intensive part of the CMMC compliance process. You will need to implement the technical, administrative, and physical security controls required by your target CMMC level. This may involve investing in new technologies, updating your policies and procedures, and training your employees. NIST SP 800-171 Rev. 2 provides a detailed list of the security controls required for CMMC Level 2.

Expect twelve to eighteen months from a low baseline. Sequence by risk and by score impact — the 5-point requirements in the DoD methodology move your SPRS number fastest.

Engage a C3PAO

If you require a third-party assessment, you will need to engage with an accredited C3PAO. The C3PAO will conduct a thorough assessment of your environment to verify that you have implemented the required security controls and submit results to CMMC eMASS. The Cyber AB provides a marketplace of accredited C3PAOs that can assist with your assessment.

Following the July 2026 suspension, this step is discretionary for most contractors rather than scheduled. Some programme offices had begun requiring C3PAO assessments ahead of the November date; those requirements are being removed by modification. Assessor capacity, previously the binding constraint, is temporarily less scarce, which makes this a reasonable window to get assessed voluntarily if certification is a commercial differentiator for you.

Maintain Continuous Monitoring & Annual Affirmation

CMMC compliance is not a one-time event. You need to continuously monitor your environment to ensure that your security controls remain effective and that you are prepared for your triennial assessments. This includes regularly scanning for vulnerabilities, managing your Plan of Action and Milestones (POA&M), and staying up-to-date on the latest threats and best practices.

A senior official must also submit an annual affirmation of continued compliance in SPRS. That affirmation carries False Claims Act exposure; it is a statement to the government, and treating it as a formality is the most expensive mistake available in this programme.

How long does CMMC certification take?

Added because the brief’s meta description promises a timeline but the structure has no section for it. Most contractors need 12 to 18 months from gap analysis to assessment-ready, depending on current maturity and scope size. Organizations with an existing NIST SP 800-171 programme move faster. Narrowing scope to a CUI enclave is the most effective way to shorten it.

How Much Does CMMC Compliance Cost?

There are two numbers in circulation and they are not measuring the same thing.

The DoD figures, published in the 32 CFR Part 170 regulatory impact analysis, cover assessment and affirmation only. For a small entity:

Path Initial Annual affirmation
Level 1 self-assessment ~$5,977 ~$560
Level 2 self-assessment ~$34,277 ~$1,459
Level 2 C3PAO certification ~$101,752 ~$1,459
Level 3 Level 2 plus ~$9,050 government assessment

 

Over three years, that puts small-business Level 2 certification at roughly $105,000–$118,000.

Why is the real number higher? DoD excluded implementation costs on the reasoning that NIST SP 800-171 has been mandatory since December 2017, so meeting it is not a new expense. Legally sound; operationally, many contractors have not fully implemented it, and the gap between the regulatory assumption and the actual environment is where the money goes.

Practitioner and vendor data from the 2026 assessment cycle puts realistic first-year totals at $60,000–$275,000 for most small and mid-sized contractors, with small-business averages around $138,000. Level 1 remains manageable at roughly $5,000–$15,000.

Where the variance comes from: Scope size above all, then baseline maturity, whether compliance is managed with spreadsheets or tooling, multi-site complexity, and how much consulting is bought versus built in-house. The enclave decision moves this number more than any other choice.

Deeper Dive: CMMC Implications for Primes and Subcontractors

Prime Contractor Responsibilities

Prime contractors are the lynchpin of CMMC compliance throughout the defense supply chain. They are not only responsible for their own CMMC certification but also for ensuring that their subcontractors meet the required CMMC level for the information they handle. This flow-down requirement is a significant undertaking and requires a robust supplier risk management program. Prime contractors must clearly define CMMC requirements in their subcontracts, verify the CMMC status of their subcontractors before awarding contracts, and continuously monitor the compliance of their subcontractors throughout the contract lifecycle.

Failure to do so can result in the prime contractor being held responsible for the non-compliance of their subcontractors, which can lead to contract termination, financial penalties, and reputational damage.

The suspension does not relieve primes of flow-down for Phase 1 self-assessment requirements. What it removes is the pressure to force certification onto suppliers before November.

Subcontractor Challenges and Opportunities

For subcontractors, CMMC compliance can be a significant challenge, particularly for small and medium-sized businesses (SMBs) that may not have the resources or expertise to implement the required security controls. However, CMMC also presents an opportunity for subcontractors to differentiate themselves from their competitors. By achieving a higher CMMC level, subcontractors can demonstrate their commitment to cybersecurity and become more attractive partners for prime contractors.

That pressure is what produced the July 2026 review. The inverse is the opportunity: with the deadline lifted and most of the supply chain pausing, a sub that continues remediating will be demonstrably ahead when the redesigned framework lands.

The Role of VDRs in CMMC M&A Due Diligence

Relocated from the article’s opening: Investment bankers and financial advisors operating in the defense sector must now consider CMMC compliance as a critical due diligence item. A company’s CMMC level is a direct reflection of its cybersecurity posture and its ability to protect sensitive government information, making it a key indicator of its overall health and attractiveness to potential buyers or investors.

In the context of M&A, CMMC compliance has become a critical due diligence item. Acquirers are increasingly scrutinizing the cybersecurity posture of their targets to assess the risks and potential liabilities associated with a transaction. A VDR can play a crucial role in facilitating CMMC-related due diligence by providing a secure and controlled environment for sharing sensitive information.

Key CMMC Due Diligence Questions

When conducting due diligence on a target company, acquirers should ask a number of key questions related to CMMC, including: What is the target’s required CMMC level? Has the target conducted a CMMC gap analysis? Does the target have a system security plan (SSP)? What is the status of the target’s CMMC implementation? Has the target engaged with a C3PAO? What is the current SPRS score and when was it posted? What is on the POA&M and how long has it been there? Who signs the annual affirmation, and what supports it?

How a VDR Facilitates CMMC Due Diligence

A VDR can help to streamline the CMMC due diligence process in a number of ways. It can securely share CMMC documentation, such as the SSP, gap analysis, and POA&M. It can track user activity by providing a complete audit trail of all user activity, allowing the acquirer to see who has accessed which documents and when. It can facilitate Q&A by managing the communication between the acquirer and the target, ensuring that all questions and answers are documented.

By using a VDR for CMMC due diligence, acquirers can gain a comprehensive understanding of the target’s cybersecurity posture and make more informed investment decisions. Running that exchange through a due diligence data room with a structured Q&A process keeps the diligence itself from becoming a compliance incident.

The Future of CMMC and the DIB

CMMC is not a static framework. It will continue to evolve over time to address the changing threat landscape and the evolving needs of the DoD.

The CMMC Reform Task Force is expected to report around mid-September 2026. What it recommends is genuinely open, but the Department has been consistent on one point: the objective is to reduce certification burden, particularly for small and non-traditional businesses, without lowering the security baseline. Officials have described the intent as prioritising tangible cyber hygiene over third-party certification and administrative overhead.

Plausible outcomes range from a scaled-back assessment model with more self-attestation and targeted government-led verification, to tiering by contract value or risk, to a longer runway with the same endpoint. What is not plausible is removal of the underlying requirement: NIST SP 800-171 sits in DFARS 252.204-7012, which the suspension does not touch.

The reasonable posture is to keep implementing and stop scheduling. Implementation work: scoping, controls, documentation, evidence, retains its value under any version of the framework. Assessment logistics can wait for the task force.

How CapLinked Streamlines CMMC Compliance for Deal Readiness

CMMC compliance is, in practice, a documentation problem wearing a cybersecurity costume. The controls matter, but what an assessor evaluates, and what an acquirer diligences, is whether you can produce the right artefact, to the right person, with a record of who saw it and when.

That is the layer CapLinked’s CMMC document sharing is built for. Where CUI moves between your organisation, your primes, your subs, your assessors and, in a transaction, your counterparty, the sharing environment is in scope. Using a general-purpose file tool for that exchange creates the exposure the programme exists to close.

CapLinked provides a secure and compliant virtual data room (VDR) solution that can help defense contractors streamline their CMMC compliance efforts and prepare for a successful transaction. Here’s how:

  • Secure Document Sharing: CapLinked provides a secure environment for sharing sensitive documents, including CUI, with internal and external stakeholders. This is essential for the due diligence process, as it allows potential buyers or investors to review sensitive information without compromising security. CapLinked’s VDR is built on a secure infrastructure that includes encryption in transit and at rest, and it is hosted in a FedRAMP-authorized data center. See the CMMC-compliant VDR for DoD supply-chain requirements.
  • Granular Access Controls: CapLinked allows you to set granular access controls, ensuring that only authorized personnel have access to specific documents. This is a key requirement of CMMC and helps to protect against unauthorized disclosure of CUI. Permissions can be set at the user, group, and document level, providing a high degree of control over who can view, download, and upload sensitive information. FileProtect DRM extends that control to files after download.
  • Comprehensive Audit Trails: CapLinked maintains a complete audit trail of all document activity, providing a detailed record of who has accessed which documents and when. This is essential for demonstrating compliance with CMMC and for providing transparency to potential buyers or investors. The audit trail is immutable and can be easily exported for review by auditors and assessors. This is the evidence artefact assessors ask for.
  • Centralized Compliance Hub: CapLinked can serve as a centralized hub for all of your CMMC compliance documentation, including your SSP, policies, and procedures. This makes it easy to manage your compliance efforts and to provide evidence of compliance to auditors and assessors. The platform’s version control capabilities ensure that everyone is working with the most up-to-date documents. Integrations and the CapLinked API connect it to systems your team already uses, and Concierge can build and maintain the repository for you. See the full feature set or review pricing.

If you want to put your CMMC evidence somewhere an assessor will accept, start your free trial today. 

CMMC Compliance FAQs

Is CMMC still required in 2026?

Yes. Phase 1 remains in force: Level 1 and Level 2 self-assessments posted in SPRS are still a condition of award. What was suspended on 13 July 2026 is Phase 2, the transition to mandatory third-party certification set for 10 November 2026. Underlying NIST SP 800-171 obligations are unchanged.

What is the difference between CMMC Level 1 and Level 2?

Level 1 applies to contractors handling only Federal Contract Information and covers 15 basic safeguards from FAR 52.204-21, verified by annual self-assessment. Level 2 applies to contractors handling Controlled Unclassified Information and covers all 110 requirements of NIST SP 800-171 Rev. 2 across 14 domains.

How much does CMMC compliance cost?

DoD estimates small-business Level 2 third-party certification at roughly $105,000 to $118,000 over three years, covering assessment and affirmation only. Real first-year totals including remediation typically run $60,000 to $275,000. Level 1 self-assessment is far lower, around $5,000 to $15,000.

How long does CMMC certification take?

Most contractors need 12 to 18 months from starting a gap analysis to being assessment-ready, depending on current maturity and scope size. Organisations with an existing NIST SP 800-171 programme move faster. Narrowing scope to a CUI enclave is the most effective way to shorten the timeline.

Do subcontractors need CMMC certification?

Yes. Under 32 CFR 170.23, prime contractors must flow CMMC requirements down to subcontractors at all tiers, at the level appropriate to the information each handles. Suppliers of commercially available off-the-shelf items and purchases below the micro-purchase threshold are generally excluded.

What is a C3PAO?

A CMMC Third-Party Assessment Organization is an accredited body authorised to conduct Level 2 certification assessments and submit results to CMMC eMASS. The Cyber AB maintains the marketplace of authorised C3PAOs. Assessor capacity was a primary reason cited for the July 2026 Phase 2 suspension.

What is SPRS and why does it matter?

The Supplier Performance Risk System is where contractors post their assessment scores. Under Phase 1, a current self-assessment or certification in SPRS is a condition of contract award. Scoring runs to a maximum of 110 points, with 88 or above permitting conditional status alongside a POA&M.

Does CMMC replace NIST SP 800-171?

No. NIST SP 800-171 defines what contractors must do to protect CUI; CMMC is the mechanism that verifies it has been done. Level 2 adopts all 110 NIST SP 800-171 Rev. 2 requirements without modification, using the same 14 families and the same control identifiers.