On this page
The fast answer
CMMC is the Department of Defense program for verifying that contractors and subcontractors have implemented the required cybersecurity protections for federal contract information and controlled unclassified information on contractor systems.
As of July 13, 2026, the Department suspended Phase II implementation requirements and paused CMMC implementation in Phase I. Phase I Level 1 and Level 2 self-assessment requirements remain in place, the Level 2 baseline remains NIST SP 800-171 Rev. 2, and required affirmations in SPRS still matter. No replacement Phase II date has been announced.
How to use this guide
Use this guide when you need one place that answers the questions owners, primes, compliance leads, internal IT, and procurement teams keep asking. If you want a deeper answer, jump to the specialist pages linked throughout the article.
The answers below prioritize official requirements first and then explain what those requirements usually mean in practice. When the government does not publish a one-size-fits-all answer, the answer says that directly instead of pretending there is one.
Questions this page answers
- What CMMC is and who it applies to.
- How Level 1, Level 2, and Level 3 differ.
- What the current Phase I pause and Phase II suspension mean.
- How self-assessments, C3PAO assessments, DIBCAC assessments, and annual affirmations fit together.
- How scoping, asset categories, enclaves, logical separation, encryption, VDI, cloud, MSPs, and ESPs affect your program.
- What SPRS, POA&Ms, passing scores, and conditional status actually mean.
Core concepts every buyer should understand
CMMC is easiest to understand when you separate five questions: what information you handle, what level applies, what assessment type applies, what systems are in scope, and what evidence you can actually show.
Most confusion happens because companies skip the scoping question. They hear about GCC High, an enclave, or a C3PAO and start with tools or vendors instead of first asking what information is present, where it lives, who touches it, and which assets are actually supporting that environment.
Current rollout dates that matter
| Phase | Date | What it means |
|---|---|---|
| Phase I | Began Nov. 10, 2025; currently paused | Level 1 and Level 2 self-assessment requirements remain in place. |
| Phase II | Suspended July 13, 2026 | The former Nov. 10, 2026 start date is no longer current; no replacement date has been announced. |
| Later phases | Schedule under review | The Department is conducting a comprehensive CMMC review. Do not rely on the former Phase III or full-implementation calendar as a current deadline. |
The exact clause language and the requiring activity still determine what a particular solicitation needs.
Where the specialist pages go deeper
- Read CMMC consulting for defense contractors for package guidance when you need help turning FAQ answers into scoping, readiness, documentation, remediation, or managed compliance work.
- Read CMMC Level 2 requirements for the 110 requirements, 14 domains, evidence expectations, and the current Rev. 2 baseline.
- Read CMMC self-assessment vs C3PAO for contract eligibility, conditional vs final status, and who uploads results where.
- Read CMMC scoping and boundary for asset categories, enclaves, logical separation, and VDI.
- Read CMMC cloud, FedRAMP, and GCC High if your Microsoft 365, enclave, or SaaS design is the big question.
- Read SPRS, POA&Ms, and CMMC scores for scoring, passing thresholds, affirmations, and closeout timing.
Frequently asked questions
What is CMMC?
CMMC is the DoD program for assessing whether contractors and subcontractors are implementing the required cybersecurity standards to protect federal contract information (FCI) and controlled unclassified information (CUI) on contractor systems.
Who needs CMMC?
CMMC can apply to prime contractors and subcontractors at all tiers when they will process, store, or transmit FCI or CUI on contractor information systems in performance of a DoD contract or subcontract. The solicitation or contract controls the level and assessment type that applies.
What is the difference between FCI and CUI?
FCI is information provided by or generated for the Government under contract that is not intended for public release. CUI is unclassified information that the Government creates or owns, or that a law, regulation, or Government-wide policy requires to be safeguarded or dissemination controlled. CUI is not the same as classified information.
Do all defense contractors need CMMC Level 2?
No. Level 1 is tied to FCI. Level 2 is tied to CUI. Level 3 is reserved for a smaller set of high-priority programs. A company should not assume it needs Level 2 unless the contract, subcontract, or actual information flow puts it there.
When did CMMC become active in contracts?
DoD began incorporating CMMC assessment requirements into applicable procurements on November 10, 2025, when the revised DFARS clause 252.204-7021 became effective.
What phase are we in right now?
CMMC implementation is paused in Phase I. Phase II requirements are suspended, while Phase I Level 1 and Level 2 self-assessment requirements remain in place. No replacement Phase II date has been announced.
How often do we need to be assessed?
Under the current Phase I pause, Level 1 requires an annual self-assessment and Level 2 Self requires an assessment every three years. Both require affirmations as described on the current official CMMC page. Later C3PAO and Level 3 rollout requirements are suspended or under review.
What is the difference between a Level 2 self-assessment and a Level 2 C3PAO assessment?
A Level 2 self-assessment is performed by the organization seeking assessment. A Level 2 certification assessment is performed by an authorized or accredited C3PAO. Which one you need depends on the solicitation or contract requirement.
Does Level 2 use NIST SP 800-171 Rev. 3 now?
No. DoD’s January 2026 FAQ says Rev. 3 has not yet been incorporated as the assessment standard for CMMC Level 2. For now, the assessment baseline remains NIST SP 800-171 Rev. 2, with future incorporation of Rev. 3 to happen through later rulemaking.
Can we use a POA&M for CMMC?
Level 1 cannot use a POA&M. Levels 2 and 3 may use a POA&M only under the conditions in 32 CFR 170.21, and any conditional status must be closed out within 180 days.
What happens if we miss the annual affirmation?
If the annual affirmation is not submitted, the CMMC assessment lapses. A company may still have done a technical assessment, but it would not have a current status for contracting purposes.
If we only handle hard-copy CUI, do we need an IT-system assessment?
Not unless that CUI is placed onto an IT system. The official FAQ says an organization handling only hard-copy CUI does not need a CMMC assessment unless the hard-copy CUI is put onto its IT system.
Does encryption alone put data out of scope?
No. DoD’s FAQ says encryption alone does not create logical separation, and encrypted CUI remains CUI until it is formally decontrolled.
Can unmanaged VDI endpoints be out of scope?
They can be out of scope only if they are configured so they do not process, store, or transmit CUI beyond keyboard, video, and mouse functions, and other restrictions are in place such as blocking copy-paste, printing, and file transfer workflows.
Do we automatically need GCC High for CMMC?
No. The government does not impose a blanket rule that every contractor needs GCC High. The real requirement is that cloud services used to store, process, or transmit CUI meet the FedRAMP Moderate baseline or equivalent, and that the company’s architecture and scoping decisions support compliant handling of CUI.
Can a non-FedRAMP Moderate cloud store encrypted CUI?
No. DoD’s January 2026 FAQ says a non-FedRAMP Moderate cloud service offering may not store encrypted CUI unless it meets FedRAMP Moderate equivalency.
Does our MSP need its own CMMC certification?
If the MSP is not itself a cloud offering, it does not need its own CMMC assessment or certification just to support you, although it may elect to obtain one. If it provides security protection capabilities or otherwise acts as an external service provider, its services are assessed within the scope of your assessment.
How should we prepare before any assessment?
DoD’s FAQ recommends starting with a self-assessment against the applicable requirements, correcting gaps, and then pursuing the required assessment path. In practice, that means confirming scope, documenting assets and data flows, tightening technical controls, and organizing evidence before you schedule anything formal.
How long does CMMC take?
The government does not publish one official timeline because the real timeline depends on scope, current maturity, documentation quality, remediation needs, cloud design, and how much CUI is actually in play. Companies that start with scoping and a serious readiness assessment move faster than companies that jump straight into tools.
How much does CMMC cost?
The government does not publish a single standard price. Cost depends on the number of in-scope assets, the size of the boundary, the condition of your current controls, the amount of documentation that must be built, whether you use a cloud or enclave strategy, and the cost of external assessment if one is required.
Related articles
Official sources reviewed
Use this guide to plan readiness and communicate clearly with buyers, primes, and internal stakeholders. Contract language, current regulations, and assessor guidance control.
Want help turning this into a real readiness plan?
Velocity CMMC can scope the environment, map CUI flows, organize the documentation package, support remediation, and help your team prepare for the right assessment path without pretending to be the certifier.