Velocity CMMC is the dedicated CMMC practice of Velocity Technologies for defense contractors nationwide.
(602) 425-5630
Velocity CMMC Resource Center

Master CMMC FAQ for 2026: the answers defense contractors actually need

Use this FAQ to get fast, plain-English CMMC answers grounded in the current DoD program page, January 2026 FAQ, 32 CFR Part 170, DFARS 252.204-7021, and related official guidance.

Current status: On July 13, 2026, the Department suspended Phase II implementation requirements and paused CMMC in Phase I. Phase I self-assessment requirements remain in place, and no replacement Phase II date has been announced. Read the official update.

The fast answer

CMMC is the Department of Defense program for verifying that contractors and subcontractors have implemented the required cybersecurity protections for federal contract information and controlled unclassified information on contractor systems.

As of July 13, 2026, the Department suspended Phase II implementation requirements and paused CMMC implementation in Phase I. Phase I Level 1 and Level 2 self-assessment requirements remain in place, the Level 2 baseline remains NIST SP 800-171 Rev. 2, and required affirmations in SPRS still matter. No replacement Phase II date has been announced.

How to use this guide

Use this guide when you need one place that answers the questions owners, primes, compliance leads, internal IT, and procurement teams keep asking. If you want a deeper answer, jump to the specialist pages linked throughout the article.

The answers below prioritize official requirements first and then explain what those requirements usually mean in practice. When the government does not publish a one-size-fits-all answer, the answer says that directly instead of pretending there is one.

Questions this page answers

  • What CMMC is and who it applies to.
  • How Level 1, Level 2, and Level 3 differ.
  • What the current Phase I pause and Phase II suspension mean.
  • How self-assessments, C3PAO assessments, DIBCAC assessments, and annual affirmations fit together.
  • How scoping, asset categories, enclaves, logical separation, encryption, VDI, cloud, MSPs, and ESPs affect your program.
  • What SPRS, POA&Ms, passing scores, and conditional status actually mean.

Core concepts every buyer should understand

CMMC is easiest to understand when you separate five questions: what information you handle, what level applies, what assessment type applies, what systems are in scope, and what evidence you can actually show.

Most confusion happens because companies skip the scoping question. They hear about GCC High, an enclave, or a C3PAO and start with tools or vendors instead of first asking what information is present, where it lives, who touches it, and which assets are actually supporting that environment.

Current rollout dates that matter

CMMC rollout phases
PhaseDateWhat it means
Phase IBegan Nov. 10, 2025; currently pausedLevel 1 and Level 2 self-assessment requirements remain in place.
Phase IISuspended July 13, 2026The former Nov. 10, 2026 start date is no longer current; no replacement date has been announced.
Later phasesSchedule under reviewThe Department is conducting a comprehensive CMMC review. Do not rely on the former Phase III or full-implementation calendar as a current deadline.

The exact clause language and the requiring activity still determine what a particular solicitation needs.

Where the specialist pages go deeper

Frequently asked questions

What is CMMC?

CMMC is the DoD program for assessing whether contractors and subcontractors are implementing the required cybersecurity standards to protect federal contract information (FCI) and controlled unclassified information (CUI) on contractor systems.

Who needs CMMC?

CMMC can apply to prime contractors and subcontractors at all tiers when they will process, store, or transmit FCI or CUI on contractor information systems in performance of a DoD contract or subcontract. The solicitation or contract controls the level and assessment type that applies.

What is the difference between FCI and CUI?

FCI is information provided by or generated for the Government under contract that is not intended for public release. CUI is unclassified information that the Government creates or owns, or that a law, regulation, or Government-wide policy requires to be safeguarded or dissemination controlled. CUI is not the same as classified information.

Do all defense contractors need CMMC Level 2?

No. Level 1 is tied to FCI. Level 2 is tied to CUI. Level 3 is reserved for a smaller set of high-priority programs. A company should not assume it needs Level 2 unless the contract, subcontract, or actual information flow puts it there.

When did CMMC become active in contracts?

DoD began incorporating CMMC assessment requirements into applicable procurements on November 10, 2025, when the revised DFARS clause 252.204-7021 became effective.

What phase are we in right now?

CMMC implementation is paused in Phase I. Phase II requirements are suspended, while Phase I Level 1 and Level 2 self-assessment requirements remain in place. No replacement Phase II date has been announced.

How often do we need to be assessed?

Under the current Phase I pause, Level 1 requires an annual self-assessment and Level 2 Self requires an assessment every three years. Both require affirmations as described on the current official CMMC page. Later C3PAO and Level 3 rollout requirements are suspended or under review.

What is the difference between a Level 2 self-assessment and a Level 2 C3PAO assessment?

A Level 2 self-assessment is performed by the organization seeking assessment. A Level 2 certification assessment is performed by an authorized or accredited C3PAO. Which one you need depends on the solicitation or contract requirement.

Does Level 2 use NIST SP 800-171 Rev. 3 now?

No. DoD’s January 2026 FAQ says Rev. 3 has not yet been incorporated as the assessment standard for CMMC Level 2. For now, the assessment baseline remains NIST SP 800-171 Rev. 2, with future incorporation of Rev. 3 to happen through later rulemaking.

Can we use a POA&M for CMMC?

Level 1 cannot use a POA&M. Levels 2 and 3 may use a POA&M only under the conditions in 32 CFR 170.21, and any conditional status must be closed out within 180 days.

What happens if we miss the annual affirmation?

If the annual affirmation is not submitted, the CMMC assessment lapses. A company may still have done a technical assessment, but it would not have a current status for contracting purposes.

If we only handle hard-copy CUI, do we need an IT-system assessment?

Not unless that CUI is placed onto an IT system. The official FAQ says an organization handling only hard-copy CUI does not need a CMMC assessment unless the hard-copy CUI is put onto its IT system.

Does encryption alone put data out of scope?

No. DoD’s FAQ says encryption alone does not create logical separation, and encrypted CUI remains CUI until it is formally decontrolled.

Can unmanaged VDI endpoints be out of scope?

They can be out of scope only if they are configured so they do not process, store, or transmit CUI beyond keyboard, video, and mouse functions, and other restrictions are in place such as blocking copy-paste, printing, and file transfer workflows.

Do we automatically need GCC High for CMMC?

No. The government does not impose a blanket rule that every contractor needs GCC High. The real requirement is that cloud services used to store, process, or transmit CUI meet the FedRAMP Moderate baseline or equivalent, and that the company’s architecture and scoping decisions support compliant handling of CUI.

Can a non-FedRAMP Moderate cloud store encrypted CUI?

No. DoD’s January 2026 FAQ says a non-FedRAMP Moderate cloud service offering may not store encrypted CUI unless it meets FedRAMP Moderate equivalency.

Does our MSP need its own CMMC certification?

If the MSP is not itself a cloud offering, it does not need its own CMMC assessment or certification just to support you, although it may elect to obtain one. If it provides security protection capabilities or otherwise acts as an external service provider, its services are assessed within the scope of your assessment.

How should we prepare before any assessment?

DoD’s FAQ recommends starting with a self-assessment against the applicable requirements, correcting gaps, and then pursuing the required assessment path. In practice, that means confirming scope, documenting assets and data flows, tightening technical controls, and organizing evidence before you schedule anything formal.

How long does CMMC take?

The government does not publish one official timeline because the real timeline depends on scope, current maturity, documentation quality, remediation needs, cloud design, and how much CUI is actually in play. Companies that start with scoping and a serious readiness assessment move faster than companies that jump straight into tools.

How much does CMMC cost?

The government does not publish a single standard price. Cost depends on the number of in-scope assets, the size of the boundary, the condition of your current controls, the amount of documentation that must be built, whether you use a cloud or enclave strategy, and the cost of external assessment if one is required.

Official sources reviewed

Use this guide to plan readiness and communicate clearly with buyers, primes, and internal stakeholders. Contract language, current regulations, and assessor guidance control.

Want help turning this into a real readiness plan?

Velocity CMMC can scope the environment, map CUI flows, organize the documentation package, support remediation, and help your team prepare for the right assessment path without pretending to be the certifier.