cmmc compliance in 2026 what contractors must know

If your organization does business with the Department of War, the rules have changed twice in the past year. First, CMMC moved from voluntary self-reporting to a requirement written directly into contracts. Then, on July 13, 2026, the DoD suspended Phase 2 of the rollout and ordered a full review of the program.

Some contractors are reading that suspension as a break. It is not one. Self-assessments are still a pre-award requirement. The 110 security controls in NIST SP 800-171 are still a legal obligation. And the government is actively pursuing companies that claim compliance they cannot back up. The contractors falling behind right now are the ones treating this news as permission to stop.

What CMMC Actually Is, and Why 2026 Is Different

CMMC compliance is a core requirement for defense contractors that handle government information. The Cybersecurity Maturity Model Certification was created to make sure sensitive data in the defense supply chain is protected the same way by everyone who touches it.

At its core, CMMC builds on guidance from the National Institute of Standards and Technology, specifically NIST SP 800-171, which defines 110 security controls for protecting Controlled Unclassified Information (CUI). CUI is sensitive government data that is not classified but could still cause harm if it got out.

Before CMMC, contractors mostly self-attested to compliance. That system created inconsistency. Some organizations were fully compliant. Others were not, but reported that they were anyway.
Closing that gap is the reason CMMC exists. The DoD’s July decision changed the schedule for how compliance gets verified. It did not change the obligation.

The Phase Rollout, and the July 2026 Suspension

The rollout was built in phases, and knowing what was planned versus what was suspended tells you exactly where you stand today.

CMMC compliance phases timeline showing Phase 1, Phase 2 suspension, Phase 3, and Phase 4 rollout changes in 2026

Phase 1 began in November 2025 and introduced self-assessments for Level 1 and some Level 2 contracts. These assessments became a pre-award requirement, meaning your compliance status now affects whether you win contracts at all. Phase 1 remains fully in effect.

Phase 2 was scheduled for November 10, 2026. It would have required many organizations handling CUI to pass an audit by a Certified Third-Party Assessment Organization (C3PAO), an outside assessor checking whether your controls actually work. On July 13, 2026, the DoD suspended Phase 2. The department pointed to compliance costs it called prohibitive and a serious shortage of assessors, then stood up a CMMC Reform Task Force with 60 days to recommend changes.

Phases 3 and 4, which would have brought Level 3 government-led assessments in 2027 and full program implementation by 2028, are suspended until further notice as part of the same review.

Here is what that means in practice. Verification did not go away. It shifted. During the suspension, the DoD is relying on Level 1 and Level 2 self-assessments submitted to the Supplier Performance Risk System (SPRS), backed by a signed affirmation from a senior company official, plus select government-led assessments. And whatever framework comes out of the review, DoD officials have said plainly it will still be built on NIST SP 800-171. Work you do now is not wasted.

For organizations in manufacturing and defense supply chains, this connects directly to DoD Cybersecurity Compliance for Manufacturers.

The Three Levels of CMMC Compliance in 2026 Explained Clearly

CMMC 2.0 is structured into three levels, each tied to different types of data and risk.

CMMC Level Information Protected Requirements Assessment Type
Level 1 Federal Contract Information (FCI) 15 basic cybersecurity practices Annual self-assessment
Level 2 Controlled Unclassified Information (CUI) 110 NIST SP 800-171 controls Self-assessment via SPRS (C3PAO requirement suspended July 2026)
Level 3 Critical Defense Programs Enhanced controls based on NIST SP 800-172 Government-led assessment (suspended pending DoD review)

Level 1: Basic Protection for Federal Contract Information

Level 1 applies to Federal Contract Information (FCI), which is government-related data not meant for public release. It requires 15 basic cybersecurity practices such as strong passwords, system updates, and basic access control, verified through an annual self-assessment.

Level 2: Core Requirement for CUI Protection

Level 2 is where most defense subcontractors fall. It requires full implementation of the 110 controls from NIST SP 800-171 and applies to organizations handling CUI.

Level 2 is still the center of gravity for most contractors. The third-party assessment requirement that was set to begin in November 2026 is on hold, but Level 2 self-assessments are not. They must be scored against all 110 controls and submitted to SPRS with an executive affirmation before applicable contracts are awarded.

Level 3: High-Sensitivity Defense Programs

Level 3 adds advanced protections based on NIST SP 800-172 and is reserved for critical defense systems. These assessments are performed directly by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). Level 3 assessments are among the milestones paused during the DoD’s review.

Which Level Applies to Your Organization?

If you are not sure which level applies to your contracts, a cybersecurity readiness and risk assessment is the right first step. It maps your current controls against what is required and shows you exactly where the gaps are.

The Subcontractor Reality in CMMC Compliance in 2026 That Nobody Is Talking About

One of the most overlooked parts of CMMC is how requirements flow down the supply chain.

Prime contractors are required to enforce CMMC requirements on their subcontractors. So even if your organization never signs a contract with the DoD directly, you may still need to comply if you handle CUI or FCI for someone who does. The suspension did not change this. Primes are still asking suppliers for proof.

This is already happening in manufacturing and aerospace supply chains, where compliance has become a condition of doing business with prime contractors. More information can be found in Vancord’s manufacturing cybersecurity compliance resources.

More information on this can be found in Vancord’s manufacturing cybersecurity compliance resources.

The legal pressure is real too. In December 2025, the Department of Justice criminally indicted a former senior manager at a federal contractor for allegedly misrepresenting a cloud platform’s compliance with required security controls and obstructing federal auditors. That case is aimed at a person, not just a company. Accountability now reaches past the IT department.

What Level 2 CMMC Compliance Actually Requires

Reaching Level 2 compliance is not a single task. It is a structured process that takes time and documentation.

Organizations must maintain a System Security Plan (SSP), which documents how systems are configured and how controls are implemented. They must also maintain a Plan of Action and Milestones (POA&M), which tracks any open gaps and the steps to close them.

Then there is your SPRS score. Under the suspension, that self-assessment score is the compliance record contracting officers see, and it is backed by a signed affirmation from a senior official at your company. If the score is inflated or inaccurate, that signature carries False Claims Act exposure.

If C3PAO assessments come back in some form after the review, organizations that scored themselves honestly will already be ready for outside scrutiny. The ones that did not will have a much harder conversation ahead.

This is why many organizations use Vancord’s Privacy & Compliance Audits to prepare in advance and reduce assessment risk.

If you’re reading this and realizing your organization doesn’t have a clear picture of where it stands against the 110 NIST SP 800-171 controls, Vancord’s Security GAP Analysis is a practical starting point. It gives you an honest look at your current posture and a clear path forward.

Why “We’ve Always Self-Attested” Is No Longer Enough in CMMC Compliance in 2026

For years, defense contractors operated under self-attestation rules tied to DFARS 252.204-7012, which required compliance with NIST SP 800-171.

The problem was enforcement. Many organizations believed they were compliant without evidence to support it. That changed with 32 CFR Part 170, which formalized assessment requirements and introduced verification standards.

The July suspension shifted verification back toward self-assessment for now, but this is not a return to the old honor system. Today’s self-assessments require a scored evaluation against every control, submission to SPRS, and a signed affirmation of compliance. In fiscal year 2025 alone, the Justice Department recovered more than $52 million across cybersecurity fraud cases, and several of those started with whistleblowers inside the companies.

Compliance in 2026 is still about proof, not claims. The only thing the suspension changed is who checks the proof first.

For deeper context, the CyberSound podcast episode on CMMC Level 2 Compliance provides a practical breakdown of what the process looks like in real environments.

Continuous Security and Long-Term Compliance

CMMC Compliance in 2026 is not a one-time achievement. It is an ongoing requirement.

Organizations must keep monitoring systems, updating controls, and maintaining evidence of compliance. That includes reporting changes, keeping documentation current, and making sure the supply chain stays aligned. Without steady oversight, gaps can open within months.

This is also the direction the DoD itself is signaling. In announcing the suspension, department leadership said the focus going forward is real cyber hygiene rather than certification paperwork. Contractors who build actual security programs are aligned with where this is heading. Contractors who built binders are not.

This is why many organizations adopt Continuous Vulnerability Management to maintain ongoing readiness instead of reacting before audits.

For leadership support, a virtual Information Security Office (vISO) provides strategic oversight through vISO & vDPO Security Leadership, helping organizations stay aligned over time without the cost of a full-time hire.

FAQ: CMMC Compliance in 2026

Is CMMC still required after the July 2026 suspension?

Yes. The DoD suspended Phase 2, the planned rollout of mandatory third-party assessments, along with future milestones, pending a 60-day review. Phase 1 remains fully in effect. Applicable contracts still require Level 1 and Level 2 self-assessments in SPRS, and NIST SP 800-171 and DFARS 252.204-7012 obligations have not changed. The suspension changed how compliance is verified, not whether you have to comply.

Does CMMC Compliance in 2026 apply to subcontractors?

Yes. Requirements flow down through the supply chain. If you handle FCI or CUI for a prime contractor, you are likely in scope.

What happens if my organization isn’t certified by the time a contract requires it?

You may become ineligible for new contracts and renewals that require certification. Contracting officers verify compliance status before awarding work, currently through your SPRS self-assessment score and affirmation. An inaccurate submission carries legal risk on top of lost eligibility.

How long does CMMC compliance take to achieve?

Most organizations need six to twelve months depending on current maturity, gaps, and readiness.

Is Level 1 the same as Level 2?

No. Level 1 is basic security for FCI, covering 15 practices with an annual self-assessment. Level 2 applies to CUI and requires full implementation of 110 NIST controls, currently verified through a scored self-assessment submitted to SPRS. The planned third-party assessment requirement is suspended as of July 2026.

The Practical Next Step

CMMC compliance in 2026 isn’t a checkbox, and the suspension did not make it one. It’s a security program, and for most mid-sized defense contractors, building or improving that program is a real project with real timelines. The DoD’s review will finish in roughly 60 days, and nobody knows exactly what comes after it. What we do know is that NIST 800-171 stays at the foundation, self-assessments stay mandatory, and an honest look at where you stand today is the clearest thing you can do to reduce uncertainty.

If you are ready to understand your actual compliance posture and map a realistic path forward, request a security assessment with Vancord. It’s a practical conversation, not a sales pitch, and it starts with where you are, not where you wish you were.