17 July 2026, Written by Kimberly Farmer

The Need for CMMC

The U.S. Defense Industrial Base (DIB) is massive with the Department of Defense/War currently contracting with over a hundred thousand organizations (including primes, subcontractors, and service providers). Many of these contractors are handling Controlled Unclassified Information (CUI), which is essentially data that is not classified, but still requires specific safeguarding under federal laws, regulations, or government-wide policies. Just as defense systems are required to ensure systems handle the data securely (NIST SP 800-53), so too are the third-party organizations that are also entrusted with the government’s data. And here enters the Cybersecurity Maturity Model Certification (CMMC) program.

Prior to this program, contractors were still required to protect CUI data (by implementing security controls found in NIST SP 800-171) through self-assessments and self-reporting, however, CMMC provides additional security assurance by requiring an independent, third party assessing organization (i.e., C3PAO) for most contracts handling CUI for CMMC Level 2 certification. Of note, as of 13 July 2026, this C3PAO assessment requirement has been suspended until further notice by the DoD/W CIO.

Implementation Delays

There have been multiple starts and stops of the CMMC program (the most recent being the pausing of CMMC Level 2 assessments as of 13 July 2026). While the program’s concept was initially introduced in 2019, it wasn’t until 2025 that we began seeing the first contracts and solicitations with CMMC requirements. Because of these delays, it can be tempting for organizations to put a pause themselves on working towards becoming CMMC certified, however, as security controls for 800-171 remain in effect, it would behoove organizations to continue to implement both for the upcoming CMMC requirements and for the sheer sake of being more secure.

Requirements

According to the DoW’s CIO CMMC site (https://dodcio.defense.gov/cmmc/About/), the CMMC program has three distinct tiers that any organization handling FCI or CUI data must be certified to: Level 1: Foundational, Level 2: Advanced, and Level 3: Expert (currently on pause). After the 13 July CIO announcement of pausing the level 2 for further evaluation, both levels 1 and 2 allow for self-assessment of implementing the applicable security controls (15 required by FAR Clause 52.204-21 for Level 1 and NIST SP 800-171 R2 for Level 2). Prior to this announcement of the pause in CMMC implementation, Level 2 could require either a self-assessment OR an assessment by a C3PAO.

Implications

So what are the implications for the DIB? If you want to do business with the DoD in the future (i.e., be awarded a contract), you will not be able to be awarded a contract with CMMC level requirements if you do not have the requisite CMMC certifications (set to whatever level the contract/solicitation requires). As Level 1 is the only level that is still in full force, if you are interested in continuing work with the DoD/W, in the interim of concrete DoW CIO direction, I would focus my efforts on ensuring you are at least able to meet the CMMC level 1 requirements.

Resources – Source of CMMC Truth

As you would expect with a program with such widespread impact on the Defense Industrial Base (DIB) ecosystem, there are many resources to help organizations get a handle on CMMC (this post and related video being one). There are currently around 400 Registered Provider Organizations (RPO) (organizations that are officially authorized to provide official CMMC consulting), over 6 thousand YouTube videos, and countless articles (and growing). With the deluge of information, it’s critical to go to the source: The Department of War’s CIO CMMC webpage: https://dodcio.defense.gov/CMMC/ . On this site you will find clear explanation of the purpose and timeline of CMMC, resources related to CMMC (including the source documents such as 32 CFR Part 170 Cybersecurity Maturity Model Certification Program and NIST SP 800-171 Rev 2 Protecting CUI in Nonfederal Systems), a detailed Frequently Asked Questions (FAQ) section, and contacts for various stakeholders including the military service CIO links. Grab a chair, favorite beverage, and start reading.

CMMC Acronyms Defined

C3PAO – Certified Third-Party Assessor Organizations

CCA – Certified CMMC Assessors

CMMC – Cybersecurity Maturity Model Certification

CUI – Controlled Unclassified Information

DFARS – Defense Federal Acquisition Regulation Supplement

DIB – Defense Industrial Base

DIBCAC – DIB Cybersecurity Assessment Center

FCI – Federal Contract Information

NIST – National Institute of Standards & Technology

POA&M – Plan of Action & Milestone

RP – Registered Practitioner

RPO – Registered Provider Organizations

SPRS – Supplier Performance Risk System