
by Ian MacRae
President and CEO, E-N Computers
29+ years experience solving business IT problems in Virginia and Washington, D.C.
Updated Augst 18, 2026
CMMC — the Cybersecurity Maturity Model Certification — is the standard the Department of Defense uses to check that its contractors are protecting sensitive information. DoD announced it in 2019. It started appearing in contracts on November 10, 2025, when Phase 1 of the rollout took effect. If your business depends on defense contracts or subcontract work, the requirements probably already apply to you.
The program exists because of the supply chain. DoD shares sensitive information with tens of thousands of companies in the Defense Industrial Base (DIB), and that data has been a standing target for foreign states and criminal groups. Before CMMC, contractors reported on their own security with no consistent way for DoD to check the answer.
CMMC is also mid-change. On July 13, 2026, DoD suspended Phase 2 — the tier that would have required a third-party assessment — and a task force is reviewing the program now. This guide covers where things stand as of August 2026, what you’re required to do today, and how to get ready for what comes next.
What cybersecurity standards apply to defense contractors now?
Cybersecurity requirements for contractors are already spelled out in the Defense Federal Acquisition Regulation Supplement (DFARS), in DFARS Clause 252.204-7012. This regulation requires that contractors handling unclassified but sensitive information follow the security controls outlined in NIST Special Publication 800-171 Revision 2. This includes things like authentication, access control, configuration management, and other basic cybersecurity requirements for systems that deal with controlled unclassified information (CUI).
DFARS 7012 has been in defense contracts since 2017, and for most of that time contractors reported on their own compliance with no outside check. DFARS 252.204-7019 and 7020 later required contractors to post a self-assessment score to SPRS and gave DoD the right to verify it. What was missing was a consistent way to confirm that the score reflected reality.
CMMC is DoD’s answer to that gap. It doesn’t add new security controls at Level 2 — it adds verification and accountability on top of the controls that were already required.
If your business depends on defense contracts or subcontract work, then you’ll want to make sure that you understand the CMMC regulations, and that you’re prepared when they take effect.
How CMMC works: three levels
CMMC has three levels. Which one applies to you is written into the contract, and it depends on the kind of information you handle. You don’t get to pick.
Level 1 covers federal contract information (FCI) — information the government gives you, or that you generate for a contract, that isn’t meant for public release. It requires the 15 basic safeguarding requirements in FAR 52.204-21, confirmed by an annual self-assessment.
Level 2 covers controlled unclassified information (CUI). It requires all 110 security requirements in NIST SP 800-171 Revision 2. Depending on the contract, you either self-assess or bring in a CMMC third-party assessment organization (C3PAO). The third-party version is the piece DoD suspended in July 2026.
Level 3 applies to CUI on DoD’s highest-priority programs. It adds 24 requirements selected from NIST SP 800-172 on top of everything in Level 2, and only the Defense Contract Management Agency’s DIBCAC assesses it.
A Level 2 self-assessment produces a single score out of 110. You post that score in SPRS — the Supplier Performance Risk System, where DoD tracks contractor scores — and a company officer files an annual affirmation that the information is accurate. That affirmation carries real weight: it’s a statement to the government, and the Department of Justice has pursued False Claims Act cases over inaccurate ones.
How does CMMC affect my business?
Phase 1 of the CMMC rollout took effect on November 10, 2025. Contracts involving FCI or CUI now carry a Level 1 or Level 2 self-assessment requirement, and each contract spells out which level applies.
Phase 2 was set to follow on November 10, 2026. It would have required a third-party assessment by a C3PAO for contracts involving CUI. On July 13, 2026, DoD suspended it. Later phases are on hold too, and a CMMC Reform Task Force is reviewing the program. Its recommendations go to the DoD CIO in mid-September 2026.
The suspension came through two memos rather than a rule change. 32 CFR Part 170 and the DFARS cybersecurity clauses are still on the books. The pause applies to the third-party assessment — the security requirements behind it still apply. You have to meet NIST SP 800-171, post a score in SPRS, and file an annual affirmation. Primes can also write a certification requirement into their subcontracts regardless of what DoD does.
So the case for getting ready now hasn’t changed much. It can easily take a year to be assessment ready, and the requirement can come back through whatever rulemaking follows the task force report. In the meantime, a high self-assessment score is what a prime sees when it’s deciding who to put on a bid. You can also weigh whether the increased IT costs that come with CMMC are worth it.
But what steps can you take now to get ready for CMMC?
Understanding CMMC’s cybersecurity requirements
At Level 2, CMMC uses the same 110 requirements as NIST SP 800-171 Revision 2. The practice numbers even map straight across. So, any work you do on 800-171 today counts directly toward CMMC. One thing to watch: NIST published Revision 3 in 2024, but DoD issued a class deviation keeping contractors on Revision 2, and that’s still the version CMMC references. Prepare against Rev 2.
NIST SP 800-171 groups its requirements into fourteen families, each covering one aspect of information security. Within these families, basic security requirements outline the overall goal of a particular control. For example, “Limit system access to authorized users.” The means to achieve those goals are listed as derived security requirements. For example, “Limit unsuccessful logon attempts”.
Each requirement in Chapter 3 comes with a discussion section explaining the reasoning behind it, often with an example of how to implement it. (In Revision 1 this material sat in Appendix F. Revision 2 moved it inline.)
Reading through each requirement with your IT staff and other stakeholders is the groundwork for a high score. Skip it and you end up guessing at what you’ve implemented.
Create a system security plan
Once you understand the requirements in SP 800-171, it’s time to put into writing what compliance with those requirements will look like in your systems. This document is called a System Security Plan (SSP) — and having an SSP in place is a requirement of 800-171.
This means documenting your current systems, and what needs to be done to secure them in compliance with 800-171. Likely this will involve several key people within your organization, including senior management, IT, and human resources. The more people that understand the requirements, and give input on how to meet them, the easier it will be to get the SSP written and implemented.
An assessor works from your SSP. If a control isn’t described there, there’s nothing to assess it against, and it won’t count toward your score.
Create a plan of action and milestones
Are there gaps between your current cybersecurity setup and what your SSP says it should be? Don’t feel like you need to fix everything overnight. The second document to write up is called a Plan of Action and Milestones (POA&M). The POA&M describes how your organization plans to implement the security controls or mitigations that are required to meet your SSP. This should include milestones, or specific timeframes when you expect to be able to implement the security requirements.
Both an SSP and a POA&M are required under NIST 800-171, and CMMC requires them too. But CMMC limits how far a POA&M can carry you. Some requirements can’t go on a POA&M at all, you need a minimum score to qualify for one, and anything on it has to be closed out within 180 days. Treat it as a short runway, not a place to park problems.
The following resources may help:
What to do next
The suspension bought you time, not a pass. The most useful thing you can do with it is close the gap between your posted SPRS score and what you can actually document. Many small contractors move to a cloud platform built for this — Microsoft 365 GCC High is the common choice — which handles a portion of the 800-171 requirements at the platform level. It doesn’t make you compliant on its own, but it takes a meaningful chunk of the work off your plate.
If you’re trying to work out which CMMC level applies to you, whether your SPRS score would hold up, or what the Phase 2 suspension changes for the contracts you already hold, E-N Computers can help. Two of our veteran engineers are Registered Practitioners (RP) with The Cyber AB, which validates their expertise as CMMC consultants. ENC is also a Registered Practitioner Organization (RPO). We’ve written SSPs and POA&Ms for defense contractors across Virginia and the DC metro area, and we can start by looking at where you stand today.
Complimentary review with an experienced engineer
Are you ready for CMMC?

Get a free strategic consultation to start or streamline your journey toward CMMC compliance.
Learn more about CMMC
Guides, case studies, and tools for defense contractors navigating compliance

Industries
Locations
Waynesboro, VA
Corporate HQ
215 Fifth St.
Waynesboro, VA 22980
Sales: 540-217-6261
Service: 540-885-3129
Accounting: 540-217-6260
Fax: 703-935-2665
Washington D.C.
1126 11th ST. NW
Suite 603
Washington, DC 20001-4366
Sales: 202-888-2770
Service: 866-692-9082
VA DCJS # 11-6604
Locations
Harrisonburg, VA
45 Newman Ave.
Harrisonburg, VA 22801
Sales: 540-569-3465
Service: 866-692-9082
Richmond, VA
3026A W. Cary St.
Richmond, VA 23221
Sales: 804-729-8835
Service: 866-692-9082
