Field Primer · Defense Eligibility
The CMMC gate: what DoD work requires before you can bid
Many small businesses chasing their first defense dollar don't learn about CMMC until it's already shaping the bid. It's the Department of Defense's cybersecurity requirement, written into solicitations. The program is mid-reform in 2026 — the third-party audit at Level 2 was suspended in July, and the reform task force reports in mid-September — but a self-assessment can still be a condition of award the moment a contract has your company handling Federal Contract Information or Controlled Unclassified Information. What's required shifted this year; what's prudent didn't.
(The department is being rebranded the "Department of War," but it remains DoD in the DFARS and the federal registry — same agency, same rules.)
Program status · as of August 15, 2026
On July 13, 2026, DoD suspended the ramp-up of third-party (Level 2) assessments — the C3PAO audit set to phase in November 10, 2026 — under USD(A&S) Memorandum 26-P-1023, and opened a 60-day, top-to-bottom review run by a CMMC Reform Task Force. Where it stands now:
- The task force reports to the DoD CIO in mid-September 2026. The industry RFI that fed it closed August 14; the comment window is shut.
- During the review, only Level 1 (Self) and Level 2 (Self) may be designated. Level 2 (C3PAO) and Level 3 (DIBCAC) designations are not permitted, and no waivers will be granted.
- Existing contracts carrying Phase II requirements will have them removed by modification — before the next option period, or at the next scheduled administrative modification. If you hold one, that clause governs until your contracting officer modifies it.
- Nothing else moved. DFARS 252.204-7012, NIST SP 800-171 Rev. 2, SPRS scores, and incident reporting all remain in force, and False Claims Act exposure on a false affirmation is unchanged. Government-led DIBCAC assessments continue.
Expect the framework to keep changing; the underlying security practices are the durable part. This page is dated for that reason — confirm the current requirement in any live solicitation.
What CMMC actually is
The Cybersecurity Maturity Model Certification is how DoD verifies that a contractor protects government information. It enters your world through DFARS clause 252.204-7021, written into the solicitation, and it steps up in three levels according to how sensitive the data you touch is. One thing to be clear on: CMMC governs unclassified information only — Federal Contract Information and Controlled Unclassified Information. Classified work runs on a separate clearance regime entirely.
The three levels
Foundational
Federal Contract Information (FCI)- The floor. Triggered by any contract that generates FCI — which is essentially all of them. Without it, your company can't exchange information with a defense customer or be eligible for award.
- 15 basic safeguarding practices (FAR 52.204-21): access control, user identification, media handling, physical and basic system protection.
- And it all has to be written, complete, and compliant — a documentation stack, not a checkbox. The artifacts you must have on file:
- System Security Plan (SSP)
- General Security Policy
- Access Control Policy
- Configuration Management Policy
- Media Protection Policy
- Physical & Environmental Security Policy
- Incident Response Plan (IRP)
- Plan of Action & Milestones (POA&M)
- Self-assessed and affirmed. You score against the practices, post to SPRS, and a senior official signs — no third party at Level 1. But a false affirmation is False Claims Act exposure, and the documentation has to hold up the moment you're audited or challenged. At Levels 2 and 3, an assessor — a C3PAO, or the government's DIBCAC at Level 3 — reviews this exact stack before award.
- And the shredder is the cheap part. Destroying FCI takes a compliant cross-cut shredder — the line item people notice, and the smallest one. Meeting the 15 practices means a secured environment to stand up and maintain: servers, locked-down workstations for authorized users, access controls and monitoring — plus the outside help most small teams need to keep it defensible. Five figures a year, every year. Teams routinely underestimate Level 1 until they are inside it.
Advanced
Controlled Unclassified Information (CUI)- The moment you exchange technical data with a service branch, you are almost certainly in CUI — and that is Level 2, a materially bigger lift.
- All 110 controls of NIST SP 800-171 (Rev. 2). The third-party C3PAO assessment scheduled to phase in from November 10, 2026 was suspended in July 2026 pending the program review. This is the part most often misread: the pause removed the outside assessor, not the controls. During the suspension a Level 2 self-assessment can still be designated and can still gate an award — same 110 controls, self-attested, with the same False Claims Act exposure on the affirmation. Worth meeting regardless of how the audit regime is reformed.
- Carries an enclave, tooling, documentation, and an outside assessment — an ongoing program, not a one-time filing.
Expert
The most sensitive CUI · APT protection- Reserved for the most sensitive programs — roughly 1% of contractors — and built to withstand advanced persistent threats.
- The 110 NIST 800-171 controls plus 24 enhanced controls from NIST SP 800-172 (134 total), assessed by the government's DIBCAC, not a third party.
Real work — but no imminent third-party clock
Meeting the underlying safeguards — the System Security Plan, the practices, the SPRS attestation — is still a genuine effort, not a deadline-week form, and a self-assessment at Level 1 or Level 2 can still gate an award. What changed is the layer above it: the mandatory third-party Level 2 certification once set for November 10, 2026 is suspended, and no C3PAO or DIBCAC designation can be imposed during the review. So the move in 2026 is proportion — meet the security controls that serve you under any framework, and don't over-invest in an audit the department has paused.
The bottom line
Here's the part most teams miss: even mid-reform, a self-assessment can still gate an award — and at Level 2 that means all 110 NIST 800-171 controls, self-attested, not the 15-practice Level 1 floor. What changed in July 2026 is the third-party audit timeline, not the security itself. The task isn't to panic and it isn't to ignore it; it's to invest in proportion to what a given solicitation actually requires. And with the reform task force reporting in mid-September, this is a picture that will change again within weeks.
That's exactly the terrain a commercialization plan has to map before you commit to a defense topic. At WiseExecution, eligibility and the compliance runway are part of the go / no-go from day one — and I track where the program's reform lands, so your plan reflects what a solicitation requires now, not a headline from last year.
WiseExecution does not perform CMMC assessments or compliance work. I can help you understand what a given level requires — the plans and documentation involved — and where submissions are made within federal channels. For the hands-on system planning and implementation itself, I refer vetted technology partners who deliver those services.
Weighing a DoD opportunity? Let's map the eligibility runway before the window opens →
Informational primer — not legal or compliance advice. CMMC status is established through self-assessment, an authorized C3PAO, or DIBCAC, depending on level. Requirements and dates reflect DoD guidance as of August 15, 2026, including the July 13, 2026 suspension of Phase Two third-party assessments under USD(A&S) Memorandum 26-P-1023 and the CMMC Reform Task Force report due to the DoD CIO in mid-September 2026. This is a fast-moving area — always confirm the current requirement and the specific level in the live solicitation.