If you sell to the Department of Defense, or you supply someone who does, you’ve almost certainly heard four letters thrown around with a mix of dread and confusion: CMMC.
The Cybersecurity Maturity Model Certification has been building toward a hard enforcement deadline for years. Then, in July 2026, the timeline shifted under everyone’s feet.
Let’s clear the fog: what CMMC actually is, what changed, and why the smart move right now is to keep building.
Why CMMC Exists
The Department of War’s (DoW) Cybersecurity Maturity Model Certification (CMMC) didn’t appear out of nowhere. For years, defense contractors were allowed to simply self-certify that they met federal cybersecurity standards.
When the DoW went back and audited, the picture wasn’t pretty: a large share of subcontractors handling sensitive information weren’t actually meeting the minimum requirements they’d attested to. This gap was costing the country taxpayer-funded intellectual property and sensitive data, siphoned off to foreign adversaries and cyberattacks.
CMMC was the answer. It takes cybersecurity policy that used to live on the honor system and turns it into an enforced framework baked directly into the Defense Federal Acquisition Regulation Supplement (DFARS).
The goals are straightforward: eliminate lax self-attestation, standardize the protection of sensitive data across hundreds of thousands of contractors, drive a genuine culture shift so cyber hygiene becomes a cost of doing business, and make prime contractors and their subcontractors legally accountable for security up and down the supply chain.
At its heart, this is about protecting two kinds of information. Federal Contract Information (FCI) is sensitive-but-unclassified data generated for the government under a contract- internal reports, contract performance details, communications with agencies- that isn’t meant for public release.
Controlled Unclassified Information (CUI) goes further: it’s unclassified data that laws or regulations require you to safeguard, including engineering drawings, technical specifications, export-controlled information, test data, and manufacturing processes. If your business touches either, CMMC is your world.
The Levels, in Plain English
CMMC sorts contractors into tiers based on the sensitivity of what they handle.
Level 1 (Foundational) covers the 17 practices in FAR clause 52.204-21 and applies to any DoW (formerly DoD) contractor handling FCI. It’s an annual self-assessment.
Level 2 (Advanced) is where most of the anxiety lives. It requires compliance with all 110 security requirements of NIST SP 800-171 and applies to contractors handling CUI. This is verified through a third-party assessment by a third-party assessment organization (C3PAO), conducted every three years.
Level 3 (Expert) layers NIST SP 800-172 controls on top for the most critical national security programs, assessed by the government itself.
For the vast majority of the defense industrial base, the question that matters is: do we handle CUI, and if so, are we ready for a Level 2 assessment?
Scoping: Where the Money Is Won or Lost
Before you spend a dollar on tools, you need to answer one question: where does CUI live, flow, process, or transit?
Your scope determines everything downstream—cost, complexity, assessment effort, and operational burden. A sprawling, poorly defined environment where sensitive data touches every laptop and server is expensive to secure and painful to assess.
A tightly segmented one, where CUI is corralled into a defined enclave, is dramatically cheaper.
This is where a lot of organizations stumble in both directions. Some over-scope, dragging their entire network into the assessment when they didn’t need to. Others convince themselves they don’t handle CUI at all, then get an unpleasant surprise.
Getting scope right is foundational, and it’s worth slowing down to do it properly.
Assess, Implement, and Prove It
Once you know your scope, the work breaks into building the right controls and—just as importantly—being able to prove they work.
A typical Level 2 security stack leans heavily on identity and access management (multi-factor authentication everywhere, conditional access, least-privilege principles), endpoint security (EDR/XDR, disk encryption, centralized device management), and logging and monitoring (a SIEM, alerting, log retention, and incident workflows). Identity has quietly become the new perimeter, and assessors scrutinize logging and monitoring closely.
But buying tools isn’t the same as passing. Assessors want evidence: screenshots, configuration exports, SIEM logs, ticket records, incident reports, training records, and complete System Security Plan (SSP) and Plan of Action & Milestones (POA&M) documentation.
Evidence collection should start early, because organizations routinely underestimate the documentation effort, and traceability matters as much as the underlying control.
A couple of scoring realities deserve special attention. Your SSP isn’t optional paperwork; without a complete one, an assessment can fail by default before it even begins. And encryption for CUI must be FIPS-validated—weak or absent encryption can sink an otherwise solid effort.
Even where a Plan of Action & Milestones is allowed for minor gaps, the margin is thin: you generally need to clear roughly 88 out of 110, and any approved POA&M comes with a hard 180-day window to close it out.
The Budget Reality
CMMC compliance is an investment, and it helps to size it honestly. Technology and risk tooling can run from $12K to $250K depending on what you already have.
Consulting and managed services like readiness work, policy development, and remediation often land in the $25K to $125K range.
The third-party assessment itself varies from roughly $30K to $150K based on size and complexity, and ongoing compliance (annual affirmations, licensing, training, continuous monitoring) adds $15K to $75K a year. Industry experts consistently recommend a 6-to-18-month runway to establish, document, and test all 110 controls.
About That Pause
Here’s the plot twist. On July 13, 2026, the Department of War hit pause on CMMC Phase II, the rule that would have required a formal third-party assessment before winning or keeping certain contracts starting November 10, 2026.
Phase III is on hold too. The reason was refreshingly candid: more than 100,000 contractors needed assessments, and only about 100 certified assessors existed to perform them. The math simply didn’t work.
That’s real relief if the timeline had you cornered. But read the fine print, because it’s the part that matters most: the underlying cybersecurity requirements haven’t gone anywhere.
What paused is the certification checkpoint, not your obligation to protect sensitive defense information.
If your contracts carry the DFARS cybersecurity clause, that obligation predates CMMC and remains fully in force, including the requirement to report cyber incidents quickly.
Self-assessments and SPRS scores now matter more, not less, and the Department has said it will lean on self-assessments and spot-checks during the pause, which puts the accuracy of your own score directly under the microscope.
And posting an inflated compliance score carries real legal exposure under federal fraud enforcement; suspending the certification program does nothing to suspend that risk.
A task force is gathering industry feedback and will return recommendations aimed at making the process faster and more accessible—not at lowering the security bar itself.
Why Now Is the Time to Get Ahead
It’s tempting to read “paused” as “stand down,” but that would be a mistake.
CMMC went through a similar review-and-pause cycle back in 2021, and it came back, with the bar the same or higher. Betting your business on a permanent reprieve is a gamble with poor odds.
The smarter play is to use this window. A mock assessment lets you validate your score and catch surprises on your own timeline rather than against a deadline. The toughest, highest-weighted controls were never eligible for a “fix it later” plan, so building your roadmap around them now pays off no matter what the review recommends.
And your prime contractors aren’t waiting, many have already written these cybersecurity expectations into their subcontracts independent of the federal timeline. Being ready protects your seat at the table.
The bottom line is simple. The certification appointment got pushed back. The work behind it didn’t. CMMC isn’t going away, a proactive approach beats a reactive scramble every time, and the consequences of falling short go well beyond losing a contract.
Compliance is absolutely achievable. The organizations that keep moving now will be the ones ready to move fast when Phase II returns.
Do you need help analyzing your current gaps and developing/implementing a plan for CMMC compliance? Contact us for a free, no-charge consultation today.
Tom Reynolds is the President of Export Solutions, a consultancy firm which specializes in helping companies with import/export compliance.
