Current Requirements
What CMMC Requires Right Now: Contractor Obligations Still in Effect in 2026
Phase 2 mandatory third-party assessments are suspended, but the cybersecurity obligations written into defense contracts are not. This guide lays out what defense contractors must still do under current rules, with the primary source for each requirement.
Last reviewed: September 23, 2026 · 7 min read
The short version
Phase 2 mandatory third-party assessments are suspended. The underlying cybersecurity requirements are not. This guide covers what defense contractors must still do under current rules: self-assessments, SPRS score maintenance, NIST SP 800-171 controls, annual affirmation, and cyber incident reporting.
What changed and what did not
On July 13, 2026, the Department of War suspended Phase 2 of CMMC, which would have required mandatory third-party assessment by an accredited C3PAO beginning November 10, 2026. What the suspension changed: the requirement to pass a C3PAO assessment as a condition of contract award is currently paused. What the suspension did not change: the cybersecurity requirements written into defense contracts and federal regulation remain in force.
The program rule at 32 CFR Part 170 was not repealed. DFARS 252.204-7012, NIST SP 800-171, self-assessment obligations, and cyber incident reporting all continue to apply.
Source: Department of Defense CIO, dodcio.defense.gov/CMMC/
Self-assessment and SPRS reporting
Phase 1 of CMMC is fully in effect. For applicable contracts, contractors must:
Complete a self-assessment of compliance with the required CMMC Level (Level 1 or Level 2, as specified in the contract).
Post the resulting score to the Supplier Performance Risk System (SPRS).
Have a senior company official affirm compliance at the time of the assessment.
Contracting officers may still designate Level 1 (Self) or Level 2 (Self) assessment requirements in solicitations and contracts during the Phase 2 suspension. The SPRS score must be current and accurate. Submitting an inaccurate self-assessment score is a potential basis for False Claims Act liability, which the Department of Justice continues to enforce.
Sources: 32 CFR Part 170 sections 170.15 and 170.16 (eCFR); dodcio.defense.gov/CMMC/
NIST SP 800-171 controls
For contractors handling Controlled Unclassified Information (CUI), compliance with the 110 security requirements in NIST SP 800-171 Revision 2 is the baseline requirement under DFARS 252.204-7012. This applies regardless of Phase 2 status. The 110 requirements span 14 domains including access control, incident response, configuration management, and system and communications protection.
Each requirement must be either fully implemented or addressed through a Plan of Action and Milestones (POA&M). For Level 2 self-assessments, a POA&M allows a Conditional status with a 180-day window to close open items. At Level 1, no POA&M is permitted.
Sources: NIST SP 800-171 Rev 2 (csrc.nist.gov); 32 CFR Part 170 section 170.21 (eCFR)
DFARS 252.204-7012: the clause that does not pause
DFARS 252.204-7012 is the contractual clause requiring contractors to safeguard Covered Defense Information and report cyber incidents. It is not part of the CMMC phased rollout -- it is a standalone contract clause that appears in applicable defense contracts independently of CMMC phase timing.
If your contract includes DFARS 252.204-7012, you are required to:
Apply NIST SP 800-171 Rev 2 to systems that process, store, or transmit Covered Defense Information.
Report cyber incidents to the DoD Cyber Crime Center (DC3) within 72 hours of discovery.
Preserve images of compromised systems and submit them to DC3 if requested.
Flow down requirements to applicable subcontractors.
Source: DFARS 252.204-7012 (acquisition.gov)
Annual affirmation
Organizations that have achieved a CMMC status must submit an annual affirmation in SPRS. This is a certification by a senior company official that the organization continues to meet the required cybersecurity practices. The affirmation must be submitted at the time of each assessment and annually thereafter.
Source: 32 CFR Part 170 section 170.22 (eCFR)
What contractors should do right now
The most useful thing to do during the suspension is close the gaps that would have come up in a Phase 2 assessment anyway. Whatever the Task Force recommends, the underlying security requirements are not going away. Practical priorities:
Keep your SPRS score current and accurate
An outdated or overstated score is an enforcement risk regardless of Phase 2 status.
Maintain your System Security Plan (SSP)
A current SSP is required for both self-assessments and any eventual C3PAO assessment.
Work through your POA&M
Any open items should be actively remediated, not deferred.
Do not let incident reporting lapse
The 72-hour reporting window under DFARS 252.204-7012 applies to qualifying cyber incidents now.
Document your progress
Evidence of control implementation is what a future assessment evaluates.
Sources
- Department of Defense CIO, CMMC Program
- 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
- NIST SP 800-171 Rev 2, Protecting CUI in Nonfederal Systems
This guide is general information for defense contractors, not legal or compliance advice for your specific situation. CMMC rules and DoD contract clauses change over time. Confirm current obligations against your contract language and official DoD and Cyber AB sources before making decisions.
Keep reading