How to Get CMMC Certification: The Path and What the Pause Changed
The Department of War paused the outside assessment step for CMMC certification in July 2026, but the security requirements in your contract didn't change. Here's the full path and what's actually required of you right now.
Get the Level 2 checklistIs CMMC certification still required?
Yes. On July 13, 2026 the Department of War suspended the transition to CMMC Phase 2 and opened a 60-day review. What was paused is the verification mechanism. What was not paused is the obligation.
Paused during the review
- Phase 2, previously set for November 10, 2026
- Level 2 (C3PAO) and Level 3 (DIBCAC) designations
- C3PAO language in active solicitations and contracts
- Phases 3 and 4, and all pending milestones
- CMMC waiver procedures
Unchanged and still enforced
- NIST SP 800-171 Rev 2, all 110 requirements
- CMMC Level 1 and Level 2 self-assessments
- SPRS score plus annual affirmation, signed by a named executive
- DFARS 7012 safeguarding and 72-hour incident reporting
- False Claims Act exposure
- Prime contractor flowdown
Three things that follow from this.
Contract eligibility hasn’t changed.
These are still conditions of bidding, both with the government and with your primes, who set their own deadlines regardless of the government’s calendar. L3Harris Missile Solutions asked suppliers for proof of Level 2 by July 30, and Elbit’s July 16 letter told suppliers to keep going.
The requirement doesn’t disappear on its own.
C3PAO language comes out of an awarded contract at the next renewal or contract change, not automatically on July 13. Ask each of your primes, in writing, what they still need and when.
There’s an upside.
The outside assessment costs $25,000 to $30,000 and it’s now deferred. Do the readiness work now and get assessed later. That’s a better position than you were in on July 12.
What happens next: A reform task force reports back in mid-to-late September, and because the pause came through internal memos rather than a change to the rule, Phase 2 can return on a new timeline, in a new form, or both.
The certification path, step by step
Most contractors land at Level 2: all 110 requirements in NIST SP 800-171, checked against 320 assessment objectives. If you handle any CUI, assume Level 2 and look for DFARS 252.204-7021 in your contract. If you only handle FCI, you're at Level 1. (More on the three levels and what Level 2 requires.)
The requirements didn't get easier. What changed is who checks your work.
- Map where CUI lives. Find where it comes in, where it sits, and where it goes, then decide whether to wall it off or secure everything.
- Sort your assets. Every system falls into one of five categories, and where each one lands decides how closely an assessor looks at it.
- Find your gaps. Compare what you have against the 110 requirements. This is where most of the time and money goes.
- Write your SSP and fix what’s broken. Document as you go, and put anything unfinished on a POA&M with a date.
- Score yourself and post it to SPRS. Use NIST SP 800-171A to do the scoring, submit, and name the executive who signs off.
- Book an outside assessor. Paused right now. If you’re already in progress, check with your prime and your assessor before cancelling anything.
- Get assessed. Also paused.
A cloud-native enclave plus managed devices typically cuts CUI scope by 60 to 80%. That's the single biggest lever on what CMMC costs you, and you make the decision before implementing a single control.
Most contractors go wrong at step one. Draw the boundary too wide and you pay for complexity you don't need. Draw it too narrow and you fail, whether that shows up in a self-assessment you signed or an assessment someone else runs.
How Secureframe compresses the path
Know what to protect
Defense Navigator turns the 110 requirements into scoping decisions and control implementation while tracking your SPRS score. Automated Cloud Provisioning stands up GCC High or Google Workspace to receive and store CUI in minutes, against 8 to 10 weeks for a traditional enclave deployment. Virtual Desktops and Federal MDM let people reach CUI without pulling every laptop and user into scope: that’s where the 60 to 80% scope reduction comes from.
Prove what you’ve done
Automated Documentation generates your SSP, POA&M, policies, and evidence from your live environment rather than templates, with evidence collected across AWS GovCloud, Azure Government, and GCC High.
Stay ready as requirements evolve
Continuous control monitoring with CMMC-specific drift detection, real-time SPRS score tracking, and executive-ready affirmation packages, so the person signing has evidence behind the signature instead of a spreadsheet from last quarter.
Unlike handing everything to an MSP, you keep visibility into your own posture, and you own the tenant. Secureframe is CMMC Level 2 certified itself, under real assessment conditions.
“When you’re dealing with 110 controls and around 320 control objectives, going into each platform to demonstrate how each control is being implemented and doing that continuously is a massive lift. Using Secureframe to get NIST 800-171 and CMMC compliant has saved us at least 500 hours over the past two years.”
Frequently Asked Questions
Talk to a CMMC expertYes. The pause covers the third-party assessment step, not the obligation. DFARS 252.204-7012 still requires all 110 NIST 800-171 Rev 2 requirements, an SSP, 72-hour incident reporting, and 90-day image preservation. You still self-assess, submit a score to SPRS, and a named senior executive still signs an annual affirmation. Primes set their own supplier deadlines independent of the DoW calendar.
Unknown. The CMMC Reform Task Force reports to the DoW CIO around mid-to-late September 2026. The suspension came through two memos rather than a rule change, and 32 CFR Part 170 is still on the books. A memo changes discretion, not the rule, and can be reversed as quickly as it was issued. Phase 2 may return on a revised timeline, in a revised form, or both.
Preparation dominates the timeline, not the assessment. Most organizations spend 8 to 17 months getting ready for Level 2. Remediation is the bulk of it: six to twelve months depending on where you start. Work backward from your contract deadline rather than the government’s calendar; primes set their own supplier deadlines independent of the DoW schedule.
$100,000 to $250,000 all-in for readiness is the industry average, and it varies with company size and scope. The C3PAO assessment is $25,000 to $30,000 of that and is currently deferred. Scope is the biggest lever, which is why the boundary decision comes first: an enclave plus managed devices typically cuts CUI scope by 60 to 80%.
If you only handle FCI, Level 1 self-assessment. If you handle CUI or Security Protection Data, Level 2. Your contract clauses specify: look for DFARS 252.204-7021. When unsure, ask your contracting officer or prime.
Right now, that’s the only available path. Program managers can’t designate C3PAO during the review. Self-assessment covers the same 110 requirements and 320 assessment objectives; the only thing that changes is who checks. Score yourself against NIST SP 800-171A, submit to SPRS, and have your Affirming Official sign.
No. The assessor must be independent. Secureframe gets you assessment-ready with automation and support from CMMC Registered Practitioners, and connects you with vetted C3PAO partners at preferred pricing when that step reopens.
