Skip to main content

How to Get CMMC Certification: The Path and What the Pause Changed

The Department of War paused the outside assessment step for CMMC certification in July 2026, but the security requirements in your contract didn't change. Here's the full path and what's actually required of you right now.

Get the Level 2 checklist

Request a CMMC demo

Is CMMC certification still required?

Yes. On July 13, 2026 the Department of War suspended the transition to CMMC Phase 2 and opened a 60-day review. What was paused is the verification mechanism. What was not paused is the obligation.

Paused during the review

  • Phase 2, previously set for November 10, 2026
  • Level 2 (C3PAO) and Level 3 (DIBCAC) designations
  • C3PAO language in active solicitations and contracts
  • Phases 3 and 4, and all pending milestones
  • CMMC waiver procedures

Unchanged and still enforced

  • NIST SP 800-171 Rev 2, all 110 requirements
  • CMMC Level 1 and Level 2 self-assessments
  • SPRS score plus annual affirmation, signed by a named executive
  • DFARS 7012 safeguarding and 72-hour incident reporting
  • False Claims Act exposure
  • Prime contractor flowdown

Three things that follow from this.

Contract eligibility hasn’t changed.

These are still conditions of bidding, both with the government and with your primes, who set their own deadlines regardless of the government’s calendar. L3Harris Missile Solutions asked suppliers for proof of Level 2 by July 30, and Elbit’s July 16 letter told suppliers to keep going.

The requirement doesn’t disappear on its own.

C3PAO language comes out of an awarded contract at the next renewal or contract change, not automatically on July 13. Ask each of your primes, in writing, what they still need and when.

There’s an upside.

The outside assessment costs $25,000 to $30,000 and it’s now deferred. Do the readiness work now and get assessed later. That’s a better position than you were in on July 12.

What happens next: A reform task force reports back in mid-to-late September, and because the pause came through internal memos rather than a change to the rule, Phase 2 can return on a new timeline, in a new form, or both.

The certification path, step by step

Most contractors land at Level 2: all 110 requirements in NIST SP 800-171, checked against 320 assessment objectives. If you handle any CUI, assume Level 2 and look for DFARS 252.204-7021 in your contract. If you only handle FCI, you're at Level 1. (More on the three levels and what Level 2 requires.)

The requirements didn't get easier. What changed is who checks your work.

  1. Map where CUI lives. Find where it comes in, where it sits, and where it goes, then decide whether to wall it off or secure everything.
  2. Sort your assets. Every system falls into one of five categories, and where each one lands decides how closely an assessor looks at it.
  3. Find your gaps. Compare what you have against the 110 requirements. This is where most of the time and money goes.
  4. Write your SSP and fix what’s broken. Document as you go, and put anything unfinished on a POA&M with a date.
  5. Score yourself and post it to SPRS. Use NIST SP 800-171A to do the scoring, submit, and name the executive who signs off.
  6. Book an outside assessor. Paused right now. If you’re already in progress, check with your prime and your assessor before cancelling anything.
  7. Get assessed. Also paused.

A cloud-native enclave plus managed devices typically cuts CUI scope by 60 to 80%. That's the single biggest lever on what CMMC costs you, and you make the decision before implementing a single control.

Most contractors go wrong at step one. Draw the boundary too wide and you pay for complexity you don't need. Draw it too narrow and you fail, whether that shows up in a self-assessment you signed or an assessment someone else runs.

How Secureframe compresses the path

Know what to protect

Defense Navigator turns the 110 requirements into scoping decisions and control implementation while tracking your SPRS score. Automated Cloud Provisioning stands up GCC High or Google Workspace to receive and store CUI in minutes, against 8 to 10 weeks for a traditional enclave deployment. Virtual Desktops and Federal MDM let people reach CUI without pulling every laptop and user into scope: that’s where the 60 to 80% scope reduction comes from.

Prove what you’ve done

Automated Documentation generates your SSP, POA&M, policies, and evidence from your live environment rather than templates, with evidence collected across AWS GovCloud, Azure Government, and GCC High.

Stay ready as requirements evolve

Continuous control monitoring with CMMC-specific drift detection, real-time SPRS score tracking, and executive-ready affirmation packages, so the person signing has evidence behind the signature instead of a spreadsheet from last quarter.

Unlike handing everything to an MSP, you keep visibility into your own posture, and you own the tenant. Secureframe is CMMC Level 2 certified itself, under real assessment conditions.

When you’re dealing with 110 controls and around 320 control objectives, going into each platform to demonstrate how each control is being implemented and doing that continuously is a massive lift. Using Secureframe to get NIST 800-171 and CMMC compliant has saved us at least 500 hours over the past two years.
David HoenischLead Cybersecurity Engineer, Manufacturing Consulting Concepts LLC

Frequently Asked Questions

Talk to a CMMC expert

Yes. The pause covers the third-party assessment step, not the obligation. DFARS 252.204-7012 still requires all 110 NIST 800-171 Rev 2 requirements, an SSP, 72-hour incident reporting, and 90-day image preservation. You still self-assess, submit a score to SPRS, and a named senior executive still signs an annual affirmation. Primes set their own supplier deadlines independent of the DoW calendar.

The certification requirement paused.The one in your contract did not.

Request a CMMC demo