

President and CEO, E-N Computers
25+ years experience solving business IT problems in Virginia and Washington, D.C.
Updated Augst 10, 2026
CMMC — the Cybersecurity Maturity Model Certification — is the standard the Department of Defense uses to check that its contractors are protecting sensitive information. DoD announced it in 2019. It started appearing in contracts on November 10, 2025, when Phase 1 of the rollout took effect. If your business depends on defense contracts or subcontract work, the requirements probably already apply to you.
The program exists because of the supply chain. DoD shares sensitive information with tens of thousands of companies in the Defense Industrial Base (DIB), and that data has been a standing target for foreign states and criminal groups. Before CMMC, contractors reported on their own security with no consistent way for DoD to check the answer.
CMMC is also mid-change. On July 13, 2026, DoD suspended Phase 2 — the tier that would have required a third-party assessment — and a task force is reviewing the program now. This guide covers where things stand as of August 2026, what you’re required to do today, and how to get ready for what comes next.
What Are the Current Cybersecurity Standards for Defense Contractors?
Cybersecurity requirements for contractors are already spelled out in the Defense Federal Acquisition Regulation Supplement (DFARS), in DFARS Clause 252.204-7012. This regulation requires that contractors handling unclassified but sensitive information follow the security controls outlined in NIST Special Publication 800-171. This includes things like authentication, access control, configuration management, and other basic cybersecurity requirements for systems that deal with controlled unclassified information (CUI).
Previously, contractors could self-certify that they are complying with DFARS 7012 — there are no third-party auditing requirements in place. However, as you can imagine, the vast majority of contractors fail to comply with the rule.
Therefore, the DoD announced the creation of the Cybersecurity Maturity Model Certification to address these gaps in compliance and enforcement of cybersecurity regulations.
If your business depends on defense contracts or subcontract work, then you’ll want to make sure that you understand the CMMC regulations, and that you’re prepared when they take effect.
How Will the CMMC Work?
CMMC is largely based on the same NIST SP 800-171 security controls in use today. In that case, contractors will be assigned a score from 1 to 5 in each of the 14 control “families” outlined in 800-171, based on how many of the controls in that family have been implemented.
Additionally, separate scores will be issued for “sophistication” and “institutionalization” of these security practices. This means that it’s not enough to just have secure policies in theory — your organization needs to actually follow them consistently in order to achieve a high CMMC score.
How Will CMMC Affect My Business?
Phase 1 of the CMMC rollout took effect on November 10, 2025. Contracts involving federal contract information (FCI) or controlled unclassified information (CUI) now carry a Level 1 or Level 2 self-assessment requirement, and each contract spells out which level applies.
Phase 2 was set to follow on November 10, 2026. It would have required a third-party assessment by a C3PAO for contracts involving CUI. On July 13, 2026, DoD suspended it. Later phases are on hold too, and a CMMC Reform Task Force is reviewing the program. Its recommendations go to the DoD CIO in mid-September 2026.
The suspension came through two memos rather than a rule change. 32 CFR Part 170 and the DFARS cybersecurity clauses are still on the books. The pause applies to the third-party assessment — the security requirements behind it still apply. You have to meet NIST SP 800-171, post a score in SPRS, and file an annual affirmation. Primes can also write a certification requirement into their subcontracts regardless of what DoD does.
So the case for getting ready now hasn’t changed much. It can easily take a year to be assessment ready, and the requirement can come back through whatever rulemaking follows the task force report. In the meantime, a high self-assessment score is what a prime sees when it’s deciding who to put on a bid. You can also weigh whether the increased IT costs that come with CMMC are worth it.
But what steps can you take now to get ready for CMMC?
Understanding CMMC’s Cybersecurity Requirements
It’s widely expected that the CMMC standards will closely resemble NIST Special Publication 800-171 in scope. Therefore, making sure that your systems are already compliant with 800-171 will give you a big boost when it comes time for CMMC certification.
Within NIST SP 800-171, there are fourteen security requirement families, each dealing with a particular aspect of information security. Within these families, basic security requirements outline the overall goal of a particular control. For example, “Limit system access to authorized users.” The means to achieve those goals are listed as derived security requirements. For example, “Limit unsuccessful logon attempts”.
Appendix F contains a short discussion of each one of the security requirements, including the reasoning behind the requirement and perhaps an example of how to implement it.
Reading through and discussing each one of these requirements with your IT personnel and other stakeholders will be critical to successfully receiving a high CMMC score.
Create a System Security Plan
Once you understand the requirements in SP 800-171, it’s time to put into writing what compliance with those requirements will look like in your environment. This document is called a System Security Plan (SSP) — and having an SSP in place is actually a requirement of 800-171.
This means documenting your current systems, and what needs to be done to secure them in compliance with 800-171. Likely this will involve several key people within your organization, including senior management, IT, and human resources. The more people that understand the requirements, and give input on how to meet them, the easier it will be to get the SSP written and implemented.
Create a Plan of Action
Are there gaps between your current cybersecurity posture and what your SSP says it should be? Don’t feel like you need to fix everything overnight. The second document to write up is called a Plan of Action (POA). The POA describes how your organization plans to implement the security controls or mitigations that are required to meet your SSP. This should include milestones, or specific timeframes when you expect to be able to implement the security requirements.
Since both an SSP and POA are required according to NIST 800-171, expect that having them on hand and up-to-date will be a requirement of CMMC as well. Get a head start on CMMC by working on them now.
CMMC Implementation Next Steps
With all of the changes that CMMC will bring, it will pay to find a trusted partner to help guide you through the requirements. Many small businesses are turning to cloud providers — such as Microsoft 365 GCC High — for turnkey compliance with many of the NIST 800-171 controls.
An IT Managed Service Provider (MSP) can provide you with on-demand cybersecurity and CMMC expertise, guidance and auditing. We have recently worked with several of our clients to prepare System Security Plans (SSPs) and Plans of Action (POAs) to get ready for CMMC’s implementation. You can also work with us on a project basis to prepare a CMMC gap analysis.
Two of our veteran engineers are Registered Practitioners (RP) with The Cyber AB, which validates their expertise as CMMC consultants. ENC is also a Registered Practitioner Organization (RPO).
If you have questions or concerns about your readiness for CMMC, contact us today for a free consultation.
Complimentary review with an experienced engineer
Are you ready for CMMC?

Get a free strategic consultation to start or streamline your journey toward CMMC compliance.
Related articles
Learn more about CMMC
Guides, case studies, and tools for defense contractors navigating compliance
CMMC Managed IT
Virginia CMMC Managed IT Services
Best CMMC managed IT services providers in the DMV
Best Virginia CMMC managed IT services providers
Finding help
Best CMMC RPOs near Washington, DC
Best Virginia Registered Practitioner Organizations
Case Study: Virginia Government Contractor Nears CMMC Compliance
Best CMMC assessors near Washington, DC
CMMC consulting services for small and medium-sized businesses
Virginia CMMC consulting services
Washington, DC CMMC consulting services
Understanding CMMC
The Ultimate Guide to DFARS and NIST 800-171 (in plain English)
What is FCI and should I worry about it?
What is CUI and should I worry about it?
CMMC compliance deadlines: Key dates and what they mean
Tools & training
How to buy GCC High and what’s involved
We found the best GRC tool for CMMC
What is Microsoft GCC High and do I need it?
CMMC Level 1 guide as audio book
CMMC Level 2 guide as audio book
CUI enclaves in CMMC compliance: Are they right for your business?

Industries
Locations
Waynesboro, VA
Corporate HQ
215 Fifth St.
Waynesboro, VA 22980
Sales: 540-217-6261
Service: 540-885-3129
Accounting: 540-217-6260
Fax: 703-935-2665
Washington D.C.
1126 11th ST. NW
Suite 603
Washington, DC 20001-4366
Sales: 202-888-2770
Service: 866-692-9082
VA DCJS # 11-6604
Locations
Harrisonburg, VA
45 Newman Ave.
Harrisonburg, VA 22801
Sales: 540-569-3465
Service: 866-692-9082
Richmond, VA
3026A W. Cary St.
Richmond, VA 23221
Sales: 804-729-8835
Service: 866-692-9082
