The implementation timeline changed
This article was originally published in February 2025; the following reflects the later policy developments reviewed in September 2026. The CMMC program rule appeared in October 2024, while the acquisition rule incorporating the revised contract requirements became effective on November 10, 2025. The broad phased contract rollout did not begin in early 2025.
The CIO’s July 2026 announcement suspended Phase II and retained Phase I self-assessments. The implementation memorandum directs requiring activities to designate Level 1 (Self) or Level 2 (Self) during the suspension, rather than Level 2 third-party or Level 3 CMMC assessments.
It also directs amendments to affected active solicitations and removal of those third-party or Level 3 requirements from existing agreements through the specified modification process. Contractors should obtain and retain the applicable amendment or modification; a policy announcement should not be treated as a substitute for understanding the terms in their own agreement.
The memorandum explicitly preserves DFARS 252.204-7012 safeguarding and cyber-incident-reporting requirements. Security implementation, accurate representations, and evidence remain operational responsibilities while the assessment program is reviewed.
Understand the level and the information boundary
CMMC distinguishes the type of information and assessment involved. Level 1 concerns basic safeguarding of Federal Contract Information. Level 2 is aligned with the 110 requirements in NIST SP 800-171 Revision 2 for Controlled Unclassified Information. The broader regulatory framework also describes third-party Level 2 assessments and government Level 3 assessments; their existence in the framework does not override the July implementation direction.
Revision numbers matter. CMMC Level 2’s specified baseline should not be silently replaced with another revision merely because NIST has published newer material. Read the applicable contract and program guidance together.
The practical scope question is where the information is processed, stored, or transmitted. That may include endpoints, servers, cloud services, collaboration tools, backups, support providers, and systems connected to the protected environment. A diagram of the intended boundary should match how employees and partners actually work.
Overlooking an everyday transfer—such as a document downloaded to an unmanaged device—can undermine a carefully designed enclave. Scoping is therefore a business-process exercise as well as a technical inventory.
Build evidence around the work
The CMMC contract clause describes status, system identifiers, reporting, annual affirmations, and flowdown responsibilities. A compliance program needs an owner who can connect those administrative records with the actual environment.
Useful preparation includes:
- Access control: show how access is approved, reviewed, changed, and removed when people or roles change.
- Logging: establish which events are collected, who reviews them, and how findings lead to action.
- Configuration management: maintain approved baselines and records of significant changes.
- Incident response: exercise the plan, verify reporting paths, and retain lessons and corrective actions.
- Vulnerability management: prioritize findings, track remediation, and document justified exceptions.
- Supplier responsibilities: identify which protections a provider supplies and which remain with the contractor.
These are practical areas to examine, not a claim that they are statistically the most common deficiencies across the industrial base. Policies, technical settings, and evidence of recurring operation should tell the same story.
The 14 families in the Revision 2 baseline span access control; awareness and training; audit and accountability; configuration management; identification and authentication; incident response; maintenance; media protection; personnel and physical security; risk and security assessment; system and communications protection; and system and information integrity. A readiness review should cover the applicable requirements across that full scope.
A remediation plan has limits
A Plan of Action and Milestones records work to close a gap. It does not make an unmet requirement implemented. The program’s conditional-status provisions limit which gaps may remain open and impose a closeout period; the contract clause describes conditional status as no older than 180 days and requires successful closeout of a valid plan.
Before relying on conditional status, check the exact assessment and scoring rules that apply. Some requirements cannot be deferred, and Level 1 does not provide the same conditional mechanism as Level 2. A remediation plan should identify an accountable owner, funding, evidence of completion, and a date that fits the applicable rule.
A workable readiness sequence
- Collect the current contract, solicitation, flowdowns, and any policy-driven amendments.
- Map FCI and CUI through the real workflow and identify the systems and providers in scope.
- Compare implemented controls with the applicable baseline using evidence, interviews, and technical checks.
- Remediate gaps and test that the changes work in routine operations.
- Complete the required assessment records and affirmations accurately.
- Schedule recurring reviews so staff turnover, new tools, and system changes do not erode the control environment.
Preparation still has competitive value because a customer needs confidence that its information will be protected and that contract obligations can be met. The July suspension changes the assessment path, so planning should avoid an assumed inevitable third-party deadline. The durable investment is a defensible security program with a clear scope and evidence that remains current.
Sources and further reading
- CIO: current CMMC implementation status
- CIO: implementing the Phase II suspension
- DFARS 252.204-7021: CMMC contract requirements
- Official November 2025 DFARS changes
Spartan X’s cybersecurity and compliance work connects contract obligations with the systems, people, and evidence that sustain them. That keeps readiness useful through policy changes and gives program teams a clearer view of the security they are relying on.



