Skip to main content

CMMC Pause: What DoW & Primes Still Require

background

Who Needs CMMC? Defense Contractor Requirements in 2026

  • cmmc
  • Who Needs CMMC? Defense Contractor Requirements in 2026

Any organization in the Defense Industrial Base (DIB) that handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) under a U.S. Department of War (DoW) contract needs CMMC. This includes prime contractors, subcontractors, and service providers at every tier.

CMMC requirements did not go away when the DoW paused the CMMC Phase 2 transition on July 13, 2026 and opened a 60-day program review. During this interim period, Phase 1 CMMC requirements remain firmly in place. An accurate CMMC self-assessment, score, and a senior official's annual affirmation in SPRS are still required for pre-award verification to do business with the DoW and primes, and they still carry legal weight under the False Claims Act.

Below, we'll cover exactly who is required to have a current CMMC status and why pursuing CMMC can be worthwhile even for organizations without a CMMC clause (DFARS 252.204-7021) in their contracts yet.

Who does CMMC apply to?

CMMC is required for organizations in the Defense Industrial Base that want to bid on and perform contracts with the Department of Defense (DoD), now commonly referred to by its official secondary title DoW. Here's a detailed look at who must comply.

Defense contractors

Any company that seeks to work on defense contracts involving FCI and CUI must meet CMMC requirements. The level required depends on the sensitivity of the information handled and the specific contract. When CUI is processed by additional parties, CMMC can flow down to fourth-party vendors such as their own contractors or subcontractors.

Subcontractors in the defense supply chain

Suppliers providing goods or services that are part of the defense supply chain must comply if their work involves handling FCI or CUI, even if they are not directly contracted by the DoW. Primes, rather than DoW contracting officials, are responsible for ensuring their suppliers meet CMMC requirements. That responsibility is why so much enforcement pressure now originates with primes rather than the government.

See CMMC requirements for subcontractors and CMMC subcontractor oversight for how flowdown works in practice.

Recommended reading

How Are Primes Tracking CMMC Across Their Own Supply Chains? A Deep Dive into Boeing's ESLC

Read More

Which CMMC requirements do you need to comply with now?

Phase 1 CMMC self-assessment and affirmation requirements, along with DFARS 252.204-7012, determine contract eligibility today. When the DoW paused the transition to Phase 2, it did not cancel the CMMC program or the underlying rules that protect federal data.

The practical takeaway: New DoW solicitations can only require a Level 1 or Level 2 self-assessment during the review, but everything that decides whether you can bid and win work today is exactly the same:

  • full implementation of NIST 800-171 Rev 2
  • an accurate SPRS score
  • a defensible affirmation signed by a named senior executive
CMMC Level 1 CMMC Level 2
Applies to Contractors handling FCI Contractors handling CUI
Based on FAR 52.204-21 NIST SP 800-171 Rev 2
Requirements 15 basic safeguarding requirements 110 specific safeguarding requirements for CUI
Current assessment requirement Self-assessment and affirmation in SPRS every year Self-assessment every three years and affirmation in SPRS every year

Note DFARS 252.204-7012, the safeguarding and cyber-incident-reporting clause that has required contractors handling CUI to implement NIST SP 800-171 since 2017, is also untouched by the pause.

Recommended reading

CMMC Phase 2 Paused: Which Requirements Still Apply After the Latest DoW Announcement and Prime Notices?

Read More

Why do you still need CMMC during the Phase 2 pause?

The pause changed how CMMC must be assessed for some companies, not whether you are obligated to meet the underlying requirements now. Here are five reasons your cybersecurity posture still decides whether you can do DoW business during the review period.

1. Contract eligibility

NIST 800-171 and CMMC self-assessment requirements are still conditions of bidding and doing business with the DoW and primes. Non-compliance loses work now, not once the 60-day review and new report are delivered.

2. Assurance is required today

The DoW and primes still require self-assessments, SPRS scores, and executive affirmations, both pre-award and throughout the contract. Some primes may still flowdown

3. Readiness for the revised program

Third-party assessments are paused, but the CMMC program is firmly in place and expected to return in some form after the review. Getting ready now avoids a scramble when it does.

4. National security

Robust cybersecurity protects federal data, the supply chain, and the warfighter. That is the reason the requirements exist, and it did not change on July 13.

5. False Claims Act exposure

Cyber incidents or whistleblowers exposing inaccurate compliance claims can trigger False Claims Act penalties. This affects a small share of the DIB, but the exposure runs through the contract and the affirmation, not through a third-party certificate.

The risk of delaying CMMC readiness was never only a third-party assessment. It was signing a contract or an affirmation for a cybersecurity posture that isn't real. Removing the third-party check during the review only puts more weight on ensuring the accuracy of what you self-attest.

Recommended reading

Phase 1 CMMC Self-Assessments: How to Meet Level 1 and Level 2 Requirements and Prove It

Read More

Other organizations that may want CMMC

Some companies that aren't strictly required to comply still choose to, for strategic reasons. Here are the situations where pursuing CMMC proactively pays off.

Companies seeking new business opportunities

A current CMMC status in SPRS opens up new business with the DoW and other federal agencies, expanding market access. It also provides a competitive edge over non-compliant organizations when bidding for contracts that involve sensitive information, especially where lower-level requirements apply.

Organizations that handle sensitive information

Even outside the defense sector, companies dealing with sensitive data can adopt CMMC practices to strengthen their cybersecurity posture. This includes sectors like healthcare, finance, and critical infrastructure, where data protection is paramount.

Businesses looking to implement cybersecurity best practices

CMMC provides a structured framework for improving security. Organizations looking to protect themselves from cyber threats and data breaches can adopt its standards to build a stronger foundation, whether or not they bid on defense work.

Organizations already using GCC High or another FedRAMP-authorized environment

If your organization already uses Microsoft GCC High or another FedRAMP Moderate-authorized cloud environment, you've already addressed one of the most significant technical requirements for CMMC Level 2. DFARS 252.204-7012 requires cloud services handling CUI to meet security requirements equivalent to the FedRAMP Moderate baseline, which GCC High satisfies. Google Workspace offers a comparable path for the DIB.

Because you've already made that infrastructure investment, pursuing CMMC becomes more streamlined. You can focus on implementing and documenting the remaining NIST 800-171 controls rather than migrating your cloud environment or standing up a CUI enclave. This existing foundation can meaningfully reduce both the time and cost typically associated with CMMC.

Companies that are already NIST 800-171 Rev 2 compliant

Unlike NIST 800-171, CMMC is a certifiable framework, so it can provide third-party validation of strong security practices. Because there is significant overlap between the two, organizations already compliant with NIST 800-171 Rev 2 are well positioned to pursue a CMMC status, which can open doors to more business.

Note that while the DoW paused new Level 2 (C3PAO) designations as of July 13, 2026 for the duration of the review, C3PAO assessments themselves remain available during this period. If you have already scheduled or completed one, confirm the applicable requirement with your prime buyer before making changes. Organizations that hold a Level 2 (C3PAO) certification still provide the highest level of assurance that they can be trusted with CUI, and that certification fully covers the Level 2 self-assessment requirements that remain in force.

As Cyber AB Chief Executive Officer Matthew Travis noted in the organization's response to the DoW news: "A Level 2 certification by a C3PAO remains a compelling calling card for subcontracting viability to primes and the best insurance policy against False Claims Act risk."

How to decide if you need CMMC

To decide whether pursuing a CMMC status is right for your organization, work through these questions.

  1. Do your current or prospective DoW contracts require CMMC self-assessments? Assess the specific level required based on the nature of the information you handle.
  2. What is the market opportunity? Evaluate business with the DoW and other federal agencies that require CMMC, and weigh the long-term benefit of broader market access.
  3. How would CMMC improve your security posture and reduce risk? Consider whether its structured approach would strengthen your defenses beyond the measures you have in place today.
  4. Does CMMC align with standards you already meet? If you've implemented CIS, NIST 800-171, NIST 800-53, or FedRAMP, you likely have significant control overlap that reduces the CMMC burden.
  5. Do you already use GCC High or another FedRAMP-authorized cloud environment? If so, you've cleared one of the major technical hurdles for Level 2, making certification more streamlined.
  6. Are primes requesting proof of a CMMC status or readiness? Many primes began requiring subcontractors to demonstrate CMMC compliance or readiness well ahead of the DoW's phased rollout, driven by supply chain risk management rather than the government calendar. Nothing in the July 13 memo directs a prime to drop a requirement it set for its own reasons, so existing deadlines may still stand. Monitor communications from your primes, or reach out to confirm. Learn more about prime contractor CMMC requirements.
  7. Would CMMC give you an edge over non-certified competitors? For Manufacturing Consulting Concepts, for example, achieving CMMC compliance before the 48 CFR rule was even in effect differentiated them in competitive bids and reassured customers who were already asking for proof.

What to do after deciding you need CMMC

CMMC compliance is essential for organizations in the defense sector and beneficial for any company looking to strengthen its cybersecurity and operational resilience and expand federal business.

By weighing your contractual obligations, market potential, current security posture, and competitive dynamics, you can make an informed decision about pursuing CMMC on top of existing obligations like DFARS 7012.

Secureframe Defense was purpose-built for DIB organizations that need CMMC to reduce the cost and complexity of the actual cybersecurity requirements behind it so you know what to protect, prove what you've done, and stay ready as requirements evolve. Unlike disparate solutions, consultants, or manual approaches, Secureframe Defense automatically:

  • provisions a CMMC-compliant cloud environment in GCC High or Google Workspace for CUI
  • turns the 110 NIST 800-171 requirements into a guided implementation workflow
  • generates and maintains your evidence, policies, SSP, and POA&M from your live environment so your SPRS score and executive affirmation are always defensible

This post was originally published in September 2024 and has been updated on July 14, 2026 for accuracy and comprehensiveness.

One platform. Complete CMMC readiness.

Request a demo

FAQs

Who needs a CMMC certification?

All contractors and subcontractors working with the U.S. Department of War (DoW) that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) need to meet CMMC requirements. A contract that includes DFARS 252.204-7012 is a strong signal that your organization will need to comply.

What companies need CMMC compliance?

Any company that bids on or performs work for DoW contracts, from large prime contractors to small subcontractors and suppliers, needs CMMC compliance if it handles FCI or CUI. The requirement flows down the supply chain at every tier.

Do I still need CMMC after the July 2026 Phase 2 pause?

You may. The DoW paused the transition to third-party (C3PAO) assessments and opened a 60-day review, but Phase 1 self-assessment requirements remain in force. During the review, new solicitations can require a CMMC Level 1 or Level 2 self-assessment, and you still need a current SPRS score and an annual affirmation signed by a senior official. DFARS 252.204-7012 and NIST 800-171 Rev 2 are untouched.

Is CMMC only for the DoW?

CMMC is designed for organizations that do business with the Department of War (still legally the Department of Defense). Its principles and control requirements can benefit other sectors looking to strengthen their cybersecurity and compliance posture.

Loading...