Framework · CMMC
The Cybersecurity Maturity Model Certification is mid-reform: mandatory third-party assessments were suspended in July 2026 while the program is reviewed. The obligations underneath it did not move. Here are the levels, the timeline, and the document at the centre of all of it, current as of September 2026.
Three levels
Federal Contract Information
Controlled Unclassified Information
The highest-sensitivity programs
Under review. The rules beneath it stay in force.
The Levels
The level is not a choice; it follows the data. Federal Contract Information puts you at Level 1. Controlled Unclassified Information puts you at Level 2, and that is where most of the defence industrial base lands, and where the System Security Plan becomes mandatory.
The 15 basic safeguarding requirements of FAR 52.204-21. An annual self-assessment and an annual affirmation in SPRS. No POA&Ms are permitted: all fifteen are met on the day, or the level is not met.
All 110 requirements of NIST SP 800-171 Rev 2, assessed against the 320 assessment objectives of SP 800-171A. Self-assessed or C3PAO-assessed on a three-year cycle, affirmed annually, and anchored on a current System Security Plan.
Everything in Level 2 plus 24 selected enhanced requirements from NIST SP 800-172. Assessed only by the government's own assessors (DIBCAC), and only after a final Level 2 certification from a C3PAO on the same scope.
The scoring beneath Level 2 is unforgiving: the DoD methodology runs from -203 to +110, docking 5, 3, or 1 points per unimplemented requirement by weight. A conditional status is allowed only at 88 points or above, only for 1-point items (with a handful excluded even then), and only for 180 days. Most of the 110 can never be deferred to a POA&M at all.
The Pause, Precisely
The suspension paused a schedule, not the rules. Read the two columns together and the priority is obvious: everything still binding points at the same document, the System Security Plan.
Suspended, pending review
C3PAO assessments were due to phase into new contracts from 10 November 2026. That start date is suspended, with no revised date announced.
The later milestones, including government-led Level 3 phase-in, are frozen while the program is reviewed.
The suspension is a policy memorandum, not rulemaking. 32 CFR Part 170 and the DFARS clauses remain on the books, unamended.
Binding today
Safeguarding covered defense information and 72-hour incident reporting, in force since long before CMMC.
All 110 requirements, wherever CUI lives. CMMC assesses against Rev 2; Rev 3 is final at NIST but not authorised for CMMC or SPRS.
Requirement 3.12.4. The DoD assessment methodology is blunt: without an SSP, an assessment cannot be completed.
The self-assessment score, posted and affirmed each year by a named Affirming Official. A wrong affirmation is a legal exposure, not a paperwork slip.
Where the -7021 clause applies, Level 1 or Level 2 self-assessment status is a condition of award today.
Four of the five binding obligations are the System Security Plan, or exist to score and affirm it. That is why the SSP, not the certificate, is the work: keep it accurate and up to date, and you are ready whatever the review decides.
The Timeline
CMMC exists because self-attestation kept failing quietly. It was paused because roughly a hundred authorised assessors cannot assess more than a hundred thousand companies on any workable timeline. Neither fact changes what a contract clause already requires of you.
32 CFR Part 170, the CMMC program rule, takes effect on 16 December 2024: the three levels, the scoring methodology, the POA&M rules, and the assessment types.
The 48 CFR acquisition rule takes effect and DFARS 252.204-7021 begins entering applicable new solicitations. Phase 1 opens: self-assessment status becomes a condition of award.
The department, renamed the Department of War, suspends Phase 2 by CIO memorandum before its November start, citing cost and capacity: more than 100,000 companies needing assessments against roughly 100 authorised C3PAOs. Phases 3 and 4 are frozen with it.
A CMMC Reform Task Force takes industry input (responses closed 14 August) and reviews the program top to bottom. Its report to the CIO is expected around late September 2026.
The self-assessment era continues: the SSP, the SPRS score, the annual affirmation, and DFARS 7012. Whatever the review concludes, those obligations exist independently of the phase schedule.
Flow-Down
CMMC follows the information, not the org chart. A subcontractor at any tier, in any country, that processes, stores, or transmits FCI or CUI carries its own obligation at the matching level. Only suppliers of exclusively commercial off-the-shelf items are exempt.
ISO 27001, the Essential Eight, and an IRAP assessment do not substitute for CMMC. A non-US company follows the same process as a US one, and C3PAOs can conduct assessments outside the United States.
AUKUS's licence-free defence trade environment, finalised in December 2025, makes it easier for Australian companies to join US defence programs. It removes export-licensing friction, not CMMC: an Australian subcontractor holding CUI has the same SSP, SPRS, and affirmation duties as a Texan one, in force now, in Phase 1.
Running an Australian program alongside a US one? The same record that supports CMMC also supports the Essential Eight and the ISM, and Alvor deploys on-premise or air-gapped where the work requires it.
With Alvor
Controls with owners, applicability decisions, implementation status, and evidence held as live records in the Compliance module, reused wherever more than one framework asks the same question, instead of a spreadsheet rebuilt before each affirmation.
ComplianceAlvor maintains the boundary, control set, applicability, and implementation status an SSP describes, so the document becomes a projection of a current record rather than an annual rewrite that drifts the day it is signed.
System Security PlanAssessment cost tracks the size of the boundary you draw. Diagrams, data flows, and trust boundaries in Secure by Design make the CUI enclave an explicit, documented decision an assessor can follow, not a hopeful sentence in a template.
Secure by DesignAlvor Advisory scopes the boundary, runs the gap against the 110 requirements and 320 objectives, builds the record, and writes the SSP and POA&M from it. The assessment itself always belongs to someone else, by design.
SSP as a ServiceQuestions
Yes, in its Phase 1 form. On 13 July 2026 the department suspended Phase 2, the wave that would have phased mandatory C3PAO assessments into new contracts from November 2026, while a reform task force reviews the program. The suspension is a policy memorandum, not rulemaking: 32 CFR Part 170 and the DFARS clauses stand, and where DFARS 252.204-7021 applies, Level 1 or Level 2 self-assessment status is a condition of award today. The review's report is expected around late September 2026.
No. Level 1 requires the 15 basic safeguarding requirements of FAR 52.204-21, an annual self-assessment, and an annual affirmation, but no SSP. The trade-off is that Level 1 permits no POA&Ms either: every one of the fifteen is met on assessment day or the level is not met. At Level 2 the SSP becomes mandatory (requirement 3.12.4), and the DoD assessment methodology states that without one an assessment cannot be completed.
Revision 2. CMMC Level 2 assesses the 110 requirements of NIST SP 800-171 Rev 2 against the 320 assessment objectives of SP 800-171A. Rev 3 has been final at NIST since May 2024, with 97 restructured requirements, but DoD's class deviation keeps DFARS compliance and SPRS scoring pegged to Rev 2, and no rule authorising Rev 3 for CMMC has been issued. Build to Rev 2, and track Rev 3 as a future migration rather than a current obligation.
Only narrowly. A conditional Level 2 status requires a score of at least 88 out of 110, with every 3-point and 5-point requirement fully met; only 1-point requirements can sit on the POA&M, a handful are excluded even from that, and everything must close within 180 days. Most of the 110 requirements can never be deferred at all, so a POA&M is a closing plan for the last few items, not an alternative to implementation.
Yes. CMMC follows the information: any subcontractor, at any tier, in any country, that processes, stores, or transmits FCI or CUI under a US defence contract carries its own obligation at the matching level. There is no reciprocity with ISO 27001, the Essential Eight, or an IRAP assessment, and C3PAOs can conduct assessments outside the United States. With AUKUS easing defence trade among the US, UK, and Australia, more Australian companies are entering exactly the programs that carry these clauses.
Industry estimates cluster around six to eighteen months from a standing start: a gap assessment against the 110 requirements, remediation, documentation including the SSP and POA&M, and then assessment scheduling. The single biggest cost and effort lever is scope: a deliberately drawn CUI boundary or enclave keeps most of the company out of assessment scope, which is why boundary design is worth doing before remediation, not after.
Get started
Whether you lead security, run IT, manage compliance, or sit in the C-suite - we'll show you your view.