ALVOR
Platform
Advisory
PricingBlog
Get Demo
ALVOR
Platform
Advisory
PricingBlog
Get Demo

Framework · CMMC

CMMC, explained: what still applies during the pause.

The Cybersecurity Maturity Model Certification is mid-reform: mandatory third-party assessments were suspended in July 2026 while the program is reviewed. The obligations underneath it did not move. Here are the levels, the timeline, and the document at the centre of all of it, current as of September 2026.

Get DemoWhat Is Binding Today

Three levels

Level 1

Federal Contract Information

Level 2Requires an SSP

Controlled Unclassified Information

Level 3

The highest-sensitivity programs

Phase 2 · third-party waveSuspended 13 Jul 2026

Under review. The rules beneath it stay in force.

The Levels

Three levels, set by the information you hold.

The level is not a choice; it follows the data. Federal Contract Information puts you at Level 1. Controlled Unclassified Information puts you at Level 2, and that is where most of the defence industrial base lands, and where the System Security Plan becomes mandatory.

Level 1

Federal Contract Information

The 15 basic safeguarding requirements of FAR 52.204-21. An annual self-assessment and an annual affirmation in SPRS. No POA&Ms are permitted: all fifteen are met on the day, or the level is not met.

Level 2Where the SSP lives

Controlled Unclassified Information

All 110 requirements of NIST SP 800-171 Rev 2, assessed against the 320 assessment objectives of SP 800-171A. Self-assessed or C3PAO-assessed on a three-year cycle, affirmed annually, and anchored on a current System Security Plan.

Level 3

The highest-sensitivity programs

Everything in Level 2 plus 24 selected enhanced requirements from NIST SP 800-172. Assessed only by the government's own assessors (DIBCAC), and only after a final Level 2 certification from a C3PAO on the same scope.

The scoring beneath Level 2 is unforgiving: the DoD methodology runs from -203 to +110, docking 5, 3, or 1 points per unimplemented requirement by weight. A conditional status is allowed only at 88 points or above, only for 1-point items (with a handful excluded even then), and only for 180 days. Most of the 110 can never be deferred to a POA&M at all.

The Pause, Precisely

What stopped on 13 July 2026, and what did not.

The suspension paused a schedule, not the rules. Read the two columns together and the priority is obvious: everything still binding points at the same document, the System Security Plan.

Suspended, pending review

Phase 2's mandatory third-party wave

C3PAO assessments were due to phase into new contracts from 10 November 2026. That start date is suspended, with no revised date announced.

Phases 3 and 4

The later milestones, including government-led Level 3 phase-in, are frozen while the program is reviewed.

Not the rules themselves

The suspension is a policy memorandum, not rulemaking. 32 CFR Part 170 and the DFARS clauses remain on the books, unamended.

Binding today

DFARS 252.204-7012

Safeguarding covered defense information and 72-hour incident reporting, in force since long before CMMC.

NIST SP 800-171 Rev 2

All 110 requirements, wherever CUI lives. CMMC assesses against Rev 2; Rev 3 is final at NIST but not authorised for CMMC or SPRS.

A current System Security Plan

Requirement 3.12.4. The DoD assessment methodology is blunt: without an SSP, an assessment cannot be completed.

SPRS score and annual affirmation

The self-assessment score, posted and affirmed each year by a named Affirming Official. A wrong affirmation is a legal exposure, not a paperwork slip.

Phase 1 conditions of award

Where the -7021 clause applies, Level 1 or Level 2 self-assessment status is a condition of award today.

Four of the five binding obligations are the System Security Plan, or exist to score and affirm it. That is why the SSP, not the certificate, is the work: keep it accurate and up to date, and you are ready whatever the review decides.

The Timeline

How CMMC got here: from final rule to the July 2026 pause.

CMMC exists because self-attestation kept failing quietly. It was paused because roughly a hundred authorised assessors cannot assess more than a hundred thousand companies on any workable timeline. Neither fact changes what a contract clause already requires of you.

Dec 2024

The program rule lands

32 CFR Part 170, the CMMC program rule, takes effect on 16 December 2024: the three levels, the scoring methodology, the POA&M rules, and the assessment types.

10 Nov 2025

Contracts start carrying it

The 48 CFR acquisition rule takes effect and DFARS 252.204-7021 begins entering applicable new solicitations. Phase 1 opens: self-assessment status becomes a condition of award.

13 Jul 2026

Phase 2 suspended

The department, renamed the Department of War, suspends Phase 2 by CIO memorandum before its November start, citing cost and capacity: more than 100,000 companies needing assessments against roughly 100 authorised C3PAOs. Phases 3 and 4 are frozen with it.

Aug 2026

The reform review runs

A CMMC Reform Task Force takes industry input (responses closed 14 August) and reviews the program top to bottom. Its report to the CIO is expected around late September 2026.

Today

Phase 1, still in force

The self-assessment era continues: the SSP, the SPRS score, the annual affirmation, and DFARS 7012. Whatever the review concludes, those obligations exist independently of the phase schedule.

Flow-Down

CMMC flows down to subcontractors, including outside the US.

Every tier, every country

CMMC follows the information, not the org chart. A subcontractor at any tier, in any country, that processes, stores, or transmits FCI or CUI carries its own obligation at the matching level. Only suppliers of exclusively commercial off-the-shelf items are exempt.

No reciprocity

ISO 27001, the Essential Eight, and an IRAP assessment do not substitute for CMMC. A non-US company follows the same process as a US one, and C3PAOs can conduct assessments outside the United States.

The Australian angle

AUKUS's licence-free defence trade environment, finalised in December 2025, makes it easier for Australian companies to join US defence programs. It removes export-licensing friction, not CMMC: an Australian subcontractor holding CUI has the same SSP, SPRS, and affirmation duties as a Texan one, in force now, in Phase 1.

Running an Australian program alongside a US one? The same record that supports CMMC also supports the Essential Eight and the ISM, and Alvor deploys on-premise or air-gapped where the work requires it.

With Alvor

How Alvor helps you prepare for CMMC.

One living record for the 110

Controls with owners, applicability decisions, implementation status, and evidence held as live records in the Compliance module, reused wherever more than one framework asks the same question, instead of a spreadsheet rebuilt before each affirmation.

Compliance

An SSP that stays current

Alvor maintains the boundary, control set, applicability, and implementation status an SSP describes, so the document becomes a projection of a current record rather than an annual rewrite that drifts the day it is signed.

System Security Plan

Scope is the cost lever

Assessment cost tracks the size of the boundary you draw. Diagrams, data flows, and trust boundaries in Secure by Design make the CUI enclave an explicit, documented decision an assessor can follow, not a hopeful sentence in a template.

Secure by Design

Readiness, assessor-ready and stop

Alvor Advisory scopes the boundary, runs the gap against the 110 requirements and 320 objectives, builds the record, and writes the SSP and POA&M from it. The assessment itself always belongs to someone else, by design.

SSP as a Service

Questions

Common questions about CMMC.

Yes, in its Phase 1 form. On 13 July 2026 the department suspended Phase 2, the wave that would have phased mandatory C3PAO assessments into new contracts from November 2026, while a reform task force reviews the program. The suspension is a policy memorandum, not rulemaking: 32 CFR Part 170 and the DFARS clauses stand, and where DFARS 252.204-7021 applies, Level 1 or Level 2 self-assessment status is a condition of award today. The review's report is expected around late September 2026.

No. Level 1 requires the 15 basic safeguarding requirements of FAR 52.204-21, an annual self-assessment, and an annual affirmation, but no SSP. The trade-off is that Level 1 permits no POA&Ms either: every one of the fifteen is met on assessment day or the level is not met. At Level 2 the SSP becomes mandatory (requirement 3.12.4), and the DoD assessment methodology states that without one an assessment cannot be completed.

Revision 2. CMMC Level 2 assesses the 110 requirements of NIST SP 800-171 Rev 2 against the 320 assessment objectives of SP 800-171A. Rev 3 has been final at NIST since May 2024, with 97 restructured requirements, but DoD's class deviation keeps DFARS compliance and SPRS scoring pegged to Rev 2, and no rule authorising Rev 3 for CMMC has been issued. Build to Rev 2, and track Rev 3 as a future migration rather than a current obligation.

Only narrowly. A conditional Level 2 status requires a score of at least 88 out of 110, with every 3-point and 5-point requirement fully met; only 1-point requirements can sit on the POA&M, a handful are excluded even from that, and everything must close within 180 days. Most of the 110 requirements can never be deferred at all, so a POA&M is a closing plan for the last few items, not an alternative to implementation.

Yes. CMMC follows the information: any subcontractor, at any tier, in any country, that processes, stores, or transmits FCI or CUI under a US defence contract carries its own obligation at the matching level. There is no reciprocity with ISO 27001, the Essential Eight, or an IRAP assessment, and C3PAOs can conduct assessments outside the United States. With AUKUS easing defence trade among the US, UK, and Australia, more Australian companies are entering exactly the programs that carry these clauses.

Industry estimates cluster around six to eighteen months from a standing start: a gap assessment against the 110 requirements, remediation, documentation including the SSP and POA&M, and then assessment scheduling. The single biggest cost and effort lever is scope: a deliberately drawn CUI boundary or enclave keeps most of the company out of assessment scope, which is why boundary design is worth doing before remediation, not after.

Get started

See how Alvor works for your role

Whether you lead security, run IT, manage compliance, or sit in the C-suite - we'll show you your view.

Request DemoView Pricing
ALVOR

Security architecture management and compliance: connected into one source of truth.

Security,
Simplified.

Platform

  • Overview
  • AI Assistant
  • On-Premise Deployment
  • System Security Plan
  • Security Architecture
  • Assets
  • Components
  • Dependency Mapping
  • Data Governance
  • Secure by Design
  • Security Design Review
  • Threat Modeling
  • Risk
  • Compliance
  • Policy
  • Security Management
  • Business Continuity
  • Third-Party Risk Management

Solutions

  • All solutions
  • CISO
  • Security architect
  • GRC lead
  • Engineering leader
  • Startups
  • Mid-Market
  • Enterprise
  • Regulated & Sovereign

Frameworks

  • ISO 27001
  • SOC 2
  • NIST CSF
  • HIPAA
  • GDPR
  • PCI DSS
  • Essential Eight
  • CMMC
  • FedRAMP

Company

  • About
  • Advisory
  • Compliance
  • Blog
  • Security
  • Pricing
  • Compare

Legal

  • Privacy
  • Cookie Policy
  • Terms
  • Disclosure

© 2026 Alvor Pty Ltd · ABN 40 700 022 546 · All rights reserved.

LinkedIn