The Pentagon suspended the CMMC third-party certification mandate on 13 July 2026. If you read that as a reason to stop, you have misread it — the security obligation did not move, only the audit clock did.
Most of what is written about the Cybersecurity Maturity Model Certification is written by people selling an assessment, a managed enclave, or a compliance platform. This is a reading for the technology and governance owners inside firms that sell into the United States defence supply chain — including EU and UK subcontractors who handle Controlled Unclassified Information for a US prime and assume, wrongly, that the programme stops at the American border. It does not. Where CUI flows, the obligation flows with it.
What has actually happened, and what has not
The programme rule (32 CFR) took effect on 16 December 2024. The acquisition rule that puts CMMC into contracts (the 48 CFR DFARS amendment) was published on 10 September 2025 and became effective on 10 November 2025, opening Phase 1 of a four-phase rollout planned to run to roughly 2028. Phase 1 requires self-assessment and annual affirmation for Level 1 and Level 2 contracts. Phase 2 — the point at which Level 2 requires a third-party certified assessment from a C3PAO rather than a self-attestation — was scheduled to start appearing in solicitations on 10 November 2026.
Free · 4 minutes
Would you survive contact with a determined attacker — or an auditor?
Fourteen questions on access, patching, detection, and recovery — the basics that prevent most real incidents, and the ones most often assumed rather than verified. Banded finding on screen, full sheet by email.
That Phase 2 transition is now suspended. On 13 July 2026 the Department of Defense announced an immediate pause on the third-party certification mandate for Level 2 and the government-led DIBCAC assessment mandate for Level 3, pending a 60-day review by a CMMC reform task force reporting in or around September 2026. A Request for Information invited industry cost and capacity data. The honest phrase in circulation is the accurate one: suspended is not repealed.
Read what stayed live. NIST SP 800-171 Revision 2 and its 110 requirements remain the standard. Level 1 and Level 2 self-assessments, SPRS scoring, and the signed annual affirmation remain contractual. DFARS 252.204-7012 — safeguarding and 72-hour cyber-incident reporting — was never in scope of the pause. Neither was the Department of Justice’s willingness to pursue false attestations under the False Claims Act. The task force is reviewing how verification happens, not whether the controls apply.
Why the reprieve changes almost nothing about your timeline
The work that takes months is not the assessment. It is everything that has to be true before an assessor — or your own affirming official — can defensibly sign. Scoping the CUI environment, closing 110 controls across fourteen families, standing up the evidence, and lodging a truthful SPRS score is a programme measured in quarters, not weeks. Firms that treat the suspension as permission to down tools will start that programme cold the day a prime flows the requirement down anyway, because primes set their own supply-chain terms independently of the DoD’s timeline. Building the capability before the regulation compels it is the same discipline as building an incident-disclosure muscle before it is demanded: the firms that wait for the mandate are the ones that fail the first real test.
Scope the CUI environment first, and scope it small
The single decision that governs cost and effort is the boundary. Every system that stores, processes, or transmits CUI is in scope; so is every system that provides security to those systems. The default failure mode is a boundary drawn too wide — the whole corporate network — which drags hundreds of endpoints into 110 controls that could have applied to a tightly defined enclave instead. The better move is to segment CUI into a defined environment, route it deliberately, and keep everything else out of assessment scope. For EU and UK firms this also forces the data-sovereignty question early: where CUI touches cloud, the provider must meet FedRAMP Moderate equivalence, and ITAR or EAR-controlled technical data carries handling and nationality constraints that a European-hosted estate will not satisfy by default.
Close the 110 controls, and know what an assessor will actually inspect
Under Level 2, each of the 110 requirements is scored against the assessment objectives in NIST SP 800-171A. This is not a binary tick. Requirements carry weighted deductions from a starting 110, some worth five points, and the SPRS score can fall below zero for an estate with real gaps. Access control and identification-and-authentication are the families where most firms lose the most points, because provisioning and de-provisioning are rarely evidenced to the standard an assessor expects. The same evidentiary rigour that access certification demands elsewhere applies here: not a policy that says access is reviewed, but the records that show who had what, when, and who approved it. Multi-factor authentication, FIPS-validated cryptography, and audit logging are the technical controls most often claimed and least often implemented to specification.
The SSP and the POA&M are the deliverables that survive scrutiny
Level 2 runs on documentation. The System Security Plan describes the boundary, the systems, and how each of the 110 requirements is met; a missing or inadequate SSP is itself an automatic failure, not a deduction. The Plan of Action and Milestones covers requirements not yet met — but only certain lower-weighted controls may sit on a POA&M, a minimum score is required to earn a conditional status, and the plan must be closed out within 180 days. The affirmation on top of it is a personal attestation by a senior official that the stated position is true, which is precisely the exposure the False Claims Act reaches. Treat the SPRS number as a board-level assertion, because that is what it is — the same posture as any risk figure that has to survive external scrutiny.
The ordered action list
- Confirm your CMMC level from your actual and anticipated contracts and flow-downs — most CUI-handling subcontractors land at Level 2.
- Map every flow of CUI and draw the smallest defensible assessment boundary around it.
- Resolve cloud and cross-border hosting against FedRAMP Moderate equivalence and ITAR/EAR constraints before you build.
- Run a gap assessment against all 110 NIST SP 800-171 requirements and their 800-171A objectives.
- Write the SSP as you remediate, not after — it is the evidence, not a summary of it.
- Stand up the 72-hour incident-reporting capability that DFARS 252.204-7012 requires, alongside the broader incident-reporting obligations now converging across regimes.
- Lodge a truthful SPRS score with a POA&M you can actually close in 180 days, and have the affirming official sign only what the evidence supports.
The task force may soften third-party verification, narrow it to higher-risk work, or replace it with something else. None of those outcomes gives you back the 110 controls or the months it takes to close them. The reprieve is on the audit, not on the standard — and the firm that mistakes one for the other will find that out at the worst possible moment, in front of a prime that has already moved on.
Free interactive tool
Website compliance checklist
What your site has to do, based on what it actually does
Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.
Everything that applies
Ordered by what to do first: legal requirements you can close quickly, then larger pieces of work, then what is expected rather than required. Not exhaustive, and not a legal audit.
Dated PDF, yours to keep or circulate.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Most technology problems are not technology problems. They are control problems.
The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming