Program status, as of 13 July 2026
On 13 July 2026 the Department of War announced an immediate suspension of CMMC Phase II requirements. Those requirements had been scheduled for 10 November 2026. All Phase I self-assessment requirements remain. The About page says implementation is paused in Phase 1 and may only require self-assessments at two levels.
The same page says this pause does not eliminate the safeguarding obligation in DFARS clause 252.204-7012, and that during the review the Department will enforce NIST SP 800-171 Rev. 2 through self-assessments and select government-led assessments. Re-check dodcio.defense.gov/CMMC/ before you treat a later date as settled. Reform-task-force changes after this review date are unknown until that hub says otherwise.
What category this is
CMMC, the Cybersecurity Maturity Model Certification program, is how the Department of War verifies that Defense Industrial Base contractors and subcontractors safeguard Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Assessments check implementation. The level flows through the contract.
Official pages use Department of War (DoW) branding and still speak to the historical Defense Department program. This page's label says DoD/DoW once. The live site name to follow is Department of War. Public-sector readers who know FISMA are in a different lane: agency information-security management, not this contractor assessment program.
FCI and CUI, at literacy depth
FCI, in the FAR 4.1901 theme on the About page, is information not intended for public release that is provided by or generated for the Government under a contract to develop or deliver a product or service, excluding information the Government provides to the public and simple transactional information.
CUI, in the 32 CFR 2002.4 theme on the same page, is information the Government creates or possesses, or that an entity creates or possesses for the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle with safeguarding or dissemination controls. Categories live on the official registry. This page does not drill them.
Levels 1 and 2 under the Phase I pause
Level 1 (Self) is basic safeguarding of FCI: the 15 security requirements in FAR clause 52.204-21, an annual self-assessment, and an annual affirmation, with results in the Supplier Performance Risk System (SPRS). The About page says a plan of action and milestones is not permitted at Level 1.
Level 2 (Self) is broad protection of CUI: the 110 security requirements in NIST SP 800-171 Revision 2, a self-assessment every three years, and an annual affirmation, again in SPRS. 32 CFR 170.14 says the Level 2 security requirements are identical to NIST SP 800-171 R2. Plan-of-action rules exist in the program text. This page does not turn them into steps.
Level 3 remains in the model. Section 170.14 selects enhanced requirements from NIST SP 800-172 (February 2021) for that level. Whether a solicitation now requires Level 3 is unknown while Phase II is suspended. Re-open the hub. Do not treat a model table as current homework, and do not treat an SPRS screenshot as a status that lasts forever.
Not FedRAMP, and not a NIST badge
FedRAMP is a different program: a standardized, reusable authorization path for cloud products and services that federal agencies use. The labeled explainer is the FedRAMP page. Mapping a system to NIST SP 800-53 or to the Cybersecurity Framework does not finish CMMC.
CMMC Level 2, in the current program text, aligns to SP 800-171 Revision 2 even though NIST has published Revision 3. The publication pin lives on the SP 800-171 explainer.
Sort the three lanes, then ask contracts
Contractor self-assessment program, cloud product Authorization program, and NIST special publication are three sorts. Phase II was suspended on 13 July 2026. Phase I self-assessment requirements remain. The habit is to re-check the official hub.
At work, ask the contracts lead which CMMC level language appears in active solicitations. Do that privately. Do not paste CUI or solicitation files into Atlas.
CMMC, FedRAMP, and NIST are not one badge
Teaching table only. It does not assign CMMC Status, a FedRAMP Authorization, or a finding that a NIST publication has been met.
| Phrase people say | Literacy correction |
|---|---|
| We are CMMC, FedRAMP, and NIST compliant, as one blob. | CMMC is the Department of War contractor assessment program for safeguarding Federal Contract Information and CUI. FedRAMP is the federal cloud Authorization program for cloud products and services used by agencies. SP 800-171 is NIST's recommended security requirements for protecting CUI in nonfederal systems. Implementing pieces of a NIST special publication is not program Status and is not a FedRAMP Authorization. |
| 800-171 Rev. 3 is what CMMC Level 2 assesses today. | Verify against current program text. The CMMC About page and 32 CFR 170.14 frame Level 2 security requirements as NIST SP 800-171 Revision 2. NIST has also published SP 800-171 Rev. 3 (Final, 14 May 2024). The edition in a contract or program can lag the latest NIST Final. Do not collapse Revision 2 and Revision 3. |
| CMMC Phase II is mandatory everywhere now. | On 13 July 2026 the Department of War announced an immediate suspension of CMMC Phase II requirements, which had been scheduled for 10 November 2026. Phase I self-assessment requirements remain. Re-open the official CMMC hub before you treat a timeline as current. Later reform-task-force dates are unknown until that page says otherwise. |
Claims to retire
CMMC is the same as FedRAMP.
CMMC is the contractor assessment program for FCI and CUI. FedRAMP is the federal cloud Authorization program. Read the FedRAMP explainer for that lane.
If we map to NIST SP 800-53 or the Cybersecurity Framework, CMMC is done.
Those are different maps. CMMC Level 2, in current program text, follows NIST SP 800-171 Revision 2. A framework row is not CMMC Status.
Phase II third-party certification is currently required in all new Department of War contracts.
Phase II was suspended on 13 July 2026. Phase I self-assessment requirements remain. Re-check the official hub before you treat a certification path as required.
CMMC Level 2 assesses SP 800-171 Rev. 3.
The About page and 32 CFR 170.14 point Level 2 at NIST SP 800-171 Revision 2. Revision 3 is the current NIST Final. The program has not collapsed the two.
An SPRS score screenshot means we are certified forever.
SPRS is where self-assessment results are entered. Level 2 status is time-limited in the program table, and an annual affirmation can lapse. A screenshot is not a permanent Status, and Atlas does not issue one.
Sort three lanes
Teaching sort only. It does not decide the level in a real solicitation, and it does not assign Status or Authorization.
| Name | Lane | What this page is teaching |
|---|---|---|
| CMMC | Contractor assessment program for FCI and CUI | Under the Phase I pause, Level 1 is FCI and FAR 52.204-21. Level 2 is CUI and SP 800-171 Revision 2. Phase II was suspended on 13 July 2026. |
| FedRAMP | Cloud product Authorization program | A federal path for cloud products and services used by agencies. The labeled explainer is the FedRAMP page. |
| NIST SP 800-171 | NIST publication for CUI in nonfederal systems | Revision 3 is the 14 May 2024 Final. The publication pin is not CMMC Status. |
CHECK THE CATEGORY
Which sort matches this page?
Glossary and nearby pages
Use the agency page in the sources for the authoritative text. This page has no figure.