CMMC for DoD Suppliers: What It Means for Your Organization

If your organization works on Department of Defense contracts or subcontracts and handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) on its own systems, the Cybersecurity Maturity Model Certification (CMMC) program can apply to you when your solicitation or contract includes a CMMC requirement. CMMC checks that you have put required security controls in place, at a level set by your contract, and that a senior leader in your company affirms it every year. The first phase has been in effect since November 10, 2025. DoD suspended the move to Phase 2 on July 13, 2026, but the self-assessment requirements and your existing contract safeguarding duties stay in place. ALCON DTS can run many of the technical controls behind your CMMC program and help you keep the evidence ready.

Talk with ALCON DTSSee what you need in place

At a glance

  • Program rule: 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program, effective December 16, 2024
  • Contract clause: DFARS 252.204-7021, added by a final rule effective November 10, 2025, the start of Phase 1
  • Who it applies to: DoD contractors and subcontractors at all tiers that process, store or transmit FCI or CUI on their own information systems
  • Levels: Level 1 (15 FAR 52.204-21 requirements), Level 2 (the 110 requirements in NIST SP 800-171 Rev. 2) and Level 3 (24 selected NIST SP 800-172 requirements)
  • Current status: Phase 1. On July 13, 2026, DoD suspended the Phase 2 transition that had been scheduled for November 10, 2026, and put all later CMMC implementation milestones on hold until further notice. During the suspension, DoD program offices may designate only Level 1 (Self) or Level 2 (Self), and existing Level 2 (C3PAO) or Level 3 requirements are being removed from solicitations and contracts.
  • Official source: DoW CIO CMMC program pages and 32 CFR Part 170 on eCFR
  • Last reviewed: September 30, 2026

What is CMMC?

CMMC is the Department of Defense program for verifying that defense contractors protect the contract information they hold. DoD’s program pages now also use the name Department of War. The program rule, 32 CFR Part 170, took effect December 16, 2024. It establishes “requirements for defense contractors and subcontractors to implement prescribed cybersecurity standards” for that information (32 CFR 170.1).

The rule itself does not put CMMC into your contract. That happens through the DFARS clause at 252.204-7021, added by a separate acquisition final rule published September 10, 2025 and effective November 10, 2025. When your contract includes that clause, you must “have and maintain for the duration of the contract a current CMMC status” at the level the contracting officer fills in, for every information system that processes, stores or transmits FCI or CUI in performance of the contract.

CMMC protects two kinds of information:

  • Federal Contract Information (FCI): information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government. It does not include information the Government makes public or simple transactional information, such as information needed to process payments.
  • Controlled Unclassified Information (CUI): information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation or Governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls (32 CFR 2002.4(h)).

What does CMMC cover, and what doesn’t it?

It covers:

  • Your own information systems that process, store or transmit FCI or CUI in performance of a DoD contract or subcontract, and the assets that protect them.
  • The level your contract requires, how that level is assessed, how often, and the annual affirmation of continuing compliance by a senior official of your company.

It does not:

  • Apply to Federal information systems that contractors operate on behalf of the Government (32 CFR 170.3(b)).
  • Apply to contracts solely for commercially available off-the-shelf (COTS) items, or to contracts at or below the micro-purchase threshold (32 CFR 170.3(c)).
  • Replace DFARS 252.204-7012. Your duties to safeguard covered defense information, implement NIST SP 800-171 and report cyber incidents within 72 hours continue under that clause.
  • Make any provider, tool or consultant responsible for your status. The company being assessed specifies its scope, and its own senior official affirms compliance.

Does CMMC apply to you?

CMMC applies to “all DoD contract and subcontract awardees that will process, store, or transmit information, in performance of the DoD contract, that meets the standards for FCI or CUI on contractor information systems” (32 CFR 170.3(a)(1)). DoD program managers or requiring activities select the level for each contract based on the type of information involved (32 CFR 170.3(d)).

It flows down. Prime contractors must comply and must require subcontractors to comply “throughout the supply chain at all tiers” (32 CFR 170.23(a)). The minimum level for a subcontractor depends on what it handles:

  • A subcontractor that handles only FCI needs Level 1 (Self).
  • A subcontractor that handles CUI needs at least Level 2 (Self).
  • If the prime contract requires Level 2 (C3PAO) or Level 3 (DIBCAC), a subcontractor that handles CUI needs at least Level 2 (C3PAO).

The DFARS clause also requires the contractor to flow the correct CMMC level down to subcontracts, including those for commercial products and services, and to make sure the subcontractor has a current CMMC status before award (DFARS 252.204-7021(d) and (f)).

Quick check: does CMMC apply to you?

  • You hold a DoD contract or a subcontract under one, or you are bidding on one.
  • You receive, create or store FCI or CUI on your own computers, email, file storage or other systems while doing that work.

If both are true, check each solicitation and subcontract for a CMMC requirement (DFARS 252.204-7021) and for DFARS 252.204-7012, 7019 and 7020, which can apply even where CMMC does not. There is nothing Texas-specific in the federal rule; suppliers meet the same requirements in every state.

What do you need to have in place?

What each level requires

Levels, assessment types and timing from 32 CFR 170.14 through 170.18, 170.21 and 170.22. Suspension row from the Under Secretary of War for Acquisition and Sustainment memorandum implementing the DoW CIO’s suspension of CMMC Phase 2 requirements, July 13, 2026.
Level 1 (Self) Level 2 (Self) Level 2 (C3PAO) Level 3 (DIBCAC)
Information FCI CUI CUI CUI
Requirements 15 requirements in FAR 52.204-21(b)(1) 110 requirements in NIST SP 800-171 Rev. 2 110 requirements in NIST SP 800-171 Rev. 2 24 selected NIST SP 800-172 requirements, plus a Final Level 2 (C3PAO) status first
Who assesses Your company Your company An authorized or accredited CMMC Third-Party Assessment Organization (C3PAO) DCMA’s Defense Industrial Base Cybersecurity Assessment Center (DIBCAC)
How often Every year Every three years Every three years Every three years, with a new Level 2 (C3PAO) assessment
Plan of action (POA&M) Not permitted Permitted within limits; close out within 180 days Permitted within limits; close out within 180 days Permitted within limits; close out within 180 days
Affirmation by your senior official After each assessment and every year After each assessment, after POA&M closeout and every year After each assessment, after POA&M closeout and every year After each assessment, after POA&M closeout and every year
Where results go SPRS SPRS C3PAO enters results in CMMC eMASS, which transmits them to SPRS DIBCAC enters results in CMMC eMASS, which transmits them to SPRS
During the current suspension May be required May be required May not be designated May not be designated

Self-assessment or third-party assessment?

  • Self-assessment. Your company evaluates its own systems against the requirements, scores the result and posts it in the Supplier Performance Risk System (SPRS). Level 1 is scored MET or NOT MET in full. Level 2 uses the CMMC scoring methodology.
  • Certification assessment. An outside assessor evaluates your systems. For Level 2 (C3PAO), your company must obtain the assessment from an authorized or accredited C3PAO. For Level 3, DIBCAC performs it on DoD’s behalf.

Either way, DoD may conduct a DIBCAC assessment of your company under DFARS 252.204-7020. If that assessment finds the requirements were not achieved or maintained, its results take precedence over your earlier status (32 CFR 170.16(a)(1)(iv) and 170.17(a)(1)(iv)).

How is Level 2 scored?

The maximum Level 2 score equals the total number of Level 2 requirements, which is 110. Each requirement NOT MET subtracts its assigned value (for example, 1, 3 or 5 points), and the result can be negative (32 CFR 170.24(c)(2)). This follows the same approach as the NIST SP 800-171 DoD Assessment Methodology referenced in DFARS 252.204-7019 and 7020, where a summary score is posted as, for example, “95 out of 110.”

Final status requires a MET result for every requirement in scope. Conditional status is allowed only when all of these are true (32 CFR 170.21(a)(2)):

  • Your score divided by the total number of Level 2 requirements is at least 0.8, which is 88 of 110.
  • No requirement on your POA&M is worth more than 1 point, except that CUI encryption (SC.L2-3.13.11), worth 3 points in that case, may be included if you use encryption that is not FIPS-validated.
  • Your POA&M does not include any of six named requirements, including your system security plan (3.12.4) and several physical access and external connection requirements.

You then have 180 days from your Conditional status date to fix the open items and pass a POA&M closeout assessment. If you don’t, the Conditional status expires.

Which NIST SP 800-171 revision does Level 2 use?

Revision 2. The rule states: “The security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2” (32 CFR 170.14(c)(3)). NIST published Revision 3 in May 2024, and it supersedes Revision 2 on NIST’s site. CMMC Level 2 still uses Revision 2 until DoD changes the rule. DFARS 252.204-7012 as codified refers to the version of NIST SP 800-171 “in effect at the time the solicitation is issued.” DoD Class Deviation 2024-O0013 (Rev. 1, May 22, 2024) pinned the clause to Revision 2, and the September 3, 2026 DFARS Part 240 deviation text of the clause also names Revision 2. DoD’s July 13, 2026 guidance also states that during the suspension it will enforce “baseline compliance with NIST SP 800-171 Rev 2.”

When does CMMC show up in your contracts?

32 CFR 170.3(e) sets out four phases, each starting one calendar year after the one before it:

Phases from 32 CFR 170.3(e); Phase 3 and 4 dates calculated from the rule. Phase 1 start and Phase 2 suspension from the DoW CIO CMMC pages, the DoW CIO memorandum of July 13, 2026, and the Under Secretary of War for Acquisition and Sustainment implementing memorandum of July 13, 2026.
Phase Start What the rule says Status on September 30, 2026
Phase 1 November 10, 2025, the effective date of the DFARS clause rule Level 1 (Self) or Level 2 (Self) as a condition of award; Level 2 (C3PAO) at DoD’s discretion In effect
Phase 2 Scheduled for November 10, 2026 Adds Level 2 (C3PAO) as a condition of award for applicable contracts; Level 3 at DoD’s discretion Suspended July 13, 2026
Phase 3 One calendar year after Phase 2 (November 10, 2027, calculated from 32 CFR 170.3(e); no DoD page states this date) Level 2 (C3PAO) for all applicable contracts and option periods; Level 3 for all applicable contracts On hold: DoD has held all pending and future CMMC implementation milestones in abeyance until further notice
Phase 4 One calendar year after Phase 3 (November 10, 2028, calculated from 32 CFR 170.3(e); the DFARS clause prescription at 204.7504(a) uses the same date Full implementation in all applicable solicitations and contracts, including option periods on older contracts On hold: held in abeyance until further notice

The implementing memorandum from the Under Secretary of War for Acquisition and Sustainment directs that active solicitations with Level 2 (C3PAO) or Level 3 (DIBCAC) requirements be amended to remove them, and that existing contracts be modified to remove them before the next option period or at the next scheduled administrative modification. DoD has established a CMMC Reform Task Force for a 60-day review and says further guidance will follow. On September 3, 2026, DoD’s acquisition policy office issued a class deviation directing contracting officers to remove or revise CMMC requirements in line with the suspension. As of September 30, 2026, DoD had not published the review’s results or any change to the suspension. Check each solicitation and contract for the level it actually requires.

How can ALCON DTS help you?

You keep the compliance decisions. We can run the controls. CMMC puts specific decisions and signatures on your company, and those stay with you. ALCON DTS can run the identity, device, email, logging and backup controls your assessment will look at, keep the written procedures current, and sit with you when an assessor asks how the systems are operated.

What you own and what ALCON DTS can run

Your company owns ALCON DTS can run and support
Scoping decisions: which systems, people and locations handle FCI or CUI (32 CFR 170.19) The technical controls on the systems in scope
The system security plan: its content and approval Documentation support: written procedures that describe how the environment actually runs, who approves changes and how the system list stays current
The plan of action (POA&M) and its closeout decisions A work plan for closing gaps, and the technical work to close them
SPRS entries: scores, scope and CAGE codes Evidence collection from the live environment: what is logged, what is backed up, who can restore
Affirmations by your Affirming Official, the senior level representative from within your company (32 CFR 170.22) Status on the controls so your official can affirm with a clear picture
Contracting with a C3PAO and the assessment itself, when your contract requires one Sitting with you during the assessment when the assessor asks how systems are operated

Element to what ALCON DTS provides

CMMC element What ALCON DTS provides
Access control and identification (who can sign in and what they can reach) Identity and access with multifactor authentication and least-privilege administrator roles, plus joiner, mover and leaver changes kept current so unused access does not sit open
Guest and vendor access Guest and vendor accounts reviewed as part of the same identity picture when they can reach business information
Device protection Devices used for work kept updated, protected and encrypted, with a named owner for any lost or unmanaged device
Email threats Inbound filtering, email authentication, mailbox permissions and forwarding kept current
Audit logging and monitoring Logging and monitoring across identity, mail, devices and backup jobs, with alerts routed to a named owner who can act
Recovery Tested backup and recovery, so a restore is something that has been done
Shop floor and production systems Production and shop floor systems kept segmented from office IT when they are part of your environment
Program structure and gap planning A walk through your program using the NIST Cybersecurity Framework, with gaps turned into a work plan on Secure IT or a defined project
Written procedures and evidence Procedures that match the live environment, so the controls you run become the evidence the assessor walks through

The exact controls in your environment depend on your ALCON DTS plan and any project work. We will show you which are in place today and which would close a gap. ALCON DTS does not perform CMMC assessments and does not issue or hold any CMMC status for you.

Your managed IT provider may be in your assessment scope

32 CFR Part 170 treats an outside IT or security provider as an External Service Provider (ESP) when CUI or Security Protection Data, such as log data, configuration data or passwords that grant access to the in-scope environment, is processed, stored or transmitted on the provider’s assets. When that applies:

  • A provider that is not a cloud service provider and handles CUI: its services are in your assessment scope and are assessed against all Level 2 requirements.
  • A provider that handles Security Protection Data but not CUI: its services are in your assessment scope and are assessed as Security Protection Assets.
  • A cloud service provider that stores, processes or transmits CUI must meet the FedRAMP requirements in DFARS 252.204-7012, which call for security equivalent to the FedRAMP Moderate baseline.

In each case, the rule expects the relationship and the services to be documented in your system security plan, and an in-scope provider’s services to be described in a service description and customer responsibility matrix. A provider that does not process, store or transmit CUI or Security Protection Data on its own assets is not an ESP under the rule. If ALCON DTS processes, stores or transmits Security Protection Data for your in-scope systems (for example, logs, configuration data or administrator credentials) or CUI on ALCON DTS assets, plan for those ALCON DTS services to be in your assessment scope.

Want to know where your CMMC program stands? We will look at which systems handle FCI or CUI, what is already in place, and what would close the gaps for the level in your contract.

Talk with ALCON DTS

How does CMMC fit with other rules?

  • DFARS 252.204-7012, 7019 and 7020. These clauses existed before CMMC and remain in effect in contracts that include them. DFARS 252.204-7012 requires NIST SP 800-171 on covered contractor information systems, security equivalent to the FedRAMP Moderate baseline for cloud providers that handle covered defense information, and reporting of cyber incidents within 72 hours of discovery. DFARS 252.204-7019 requires a current NIST SP 800-171 DoD Assessment, not more than 3 years old unless the solicitation says otherwise, with summary scores posted in SPRS. DFARS 252.204-7020 describes Basic (self), Medium and High (Government) assessments.
  • Texas Cybersecurity Safe Harbor (SB 2610, Bus. and Com. Code Ch. 542). Texas businesses with fewer than 250 employees that own or license computerized sensitive personal information may avoid exemplary damages in a breach lawsuit if they show they implemented and maintained a qualifying cybersecurity program at the time of the breach. What qualifies depends on company size (Sec. 542.004(a)(4)). For businesses that must conform to a framework, the law lists “a current version” of several, including NIST special publication 800-171 (Sec. 542.004(b)(1)(B)). CMMC Level 2 is tied to NIST SP 800-171 Revision 2, while NIST’s current version is Revision 3, so talk with counsel about whether a CMMC program also meets the Texas standard for the personal information you hold. The two are separate: CMMC is a federal contract requirement, and the safe harbor is a Texas defense decided in court. See Texas SB 2610 Cybersecurity Safe Harbor.
  • NIST Cybersecurity Framework. NIST has published a mapping from Cybersecurity Framework v1.0 to NIST SP 800-171 Rev. 2. Many organizations use the Framework to explain their program to leadership and NIST SP 800-171 for the CUI requirements. Using the Framework does not satisfy CMMC on its own.
  • HIPAA. If you also handle patient information, for example as a medical device or health services supplier, you may run HIPAA and CMMC programs side by side. Controls such as multifactor authentication, encrypted devices, logging and tested backups can serve both, but each program has its own scope, requirements and documentation, and meeting one does not establish the other.

Frequently asked questions

Yes. Phase 1 began November 10, 2025, when the DFARS clause rule took effect. Contracts can require Level 1 (Self) or Level 2 (Self). On July 13, 2026, DoD suspended the Phase 2 transition that had been scheduled for November 10, 2026, and said all Phase 1 self-assessment requirements remain in place.

The level is set in the solicitation and contract, based on whether you will handle FCI or CUI. For subcontracts, the prime or next higher tier contractor flows down the level under 32 CFR 170.23. If you handle only FCI, it is Level 1. If you handle CUI, it is at least Level 2.

Not under current DoD guidance. During the suspension, program managers and requiring activities may designate only Level 1 (Self) or Level 2 (Self), and may not designate Level 2 (C3PAO) or Level 3 (DIBCAC). DoD’s acquisition office carried this into a September 3, 2026 class deviation for contracting officers. As of September 30, 2026, DoD has not announced when, or whether, third-party assessment requirements will return, and says further guidance will follow its program review. Check your solicitation and contract for the level they actually require.

No. 32 CFR 170.14(c)(3) says Level 2 requirements are identical to NIST SP 800-171 Revision 2.

Final Level 2 status requires every requirement in scope to be MET (a requirement that does not apply counts as MET), for a score of 110. Conditional status is allowed with a score of at least 88 of 110 (0.8 of the total) and a POA&M that meets the limits in 32 CFR 170.21, closed out within 180 days. Level 1 allows no POA&M.

Your Affirming Official: the senior level representative from within your company who is responsible for CMMC compliance and has authority to affirm it. Affirmations are entered in SPRS after each assessment, after any POA&M closeout, and every year. Under the DFARS clause, an assessment without a current affirmation is not current.

No provider can do that for you. Your company owns the scope, the system security plan, the POA&M, the SPRS entries, the affirmations and the assessment. A provider like ALCON DTS can run many of the technical controls, gather evidence and support the documentation. A provider that processes, stores or transmits your CUI or Security Protection Data on its own assets is an External Service Provider under the rule, and those services are in your assessment scope.

No. DFARS 252.204-7012 still applies where it is in your contract, including NIST SP 800-171 and 72-hour cyber incident reporting, and DoD says it will enforce NIST SP 800-171 Rev. 2 through self-assessments and select Government-led assessments during the suspension.

Sources

Last reviewed: September 30, 2026

This page is general information about the CMMC program and related rules as of September 30, 2026, not legal or contracting advice; confirm your requirements with your contracting officer and your own counsel.

Talk with ALCON DTS about your CMMC program

Not sure which systems handle FCI or CUI, or whether your controls match the level in your next contract? We will walk through your environment with you, show you what is already in place and give you a clear plan for the rest.

Email: info@alcondts.com ยท Phone: 512-892-6900

Talk with ALCON DTS