CMMC for DoD Suppliers: What It Means for Your Organization
If your organization works on Department of Defense contracts or subcontracts and handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) on its own systems, the Cybersecurity Maturity Model Certification (CMMC) program can apply to you when your solicitation or contract includes a CMMC requirement. CMMC checks that you have put required security controls in place, at a level set by your contract, and that a senior leader in your company affirms it every year. The first phase has been in effect since November 10, 2025. DoD suspended the move to Phase 2 on July 13, 2026, but the self-assessment requirements and your existing contract safeguarding duties stay in place. ALCON DTS can run many of the technical controls behind your CMMC program and help you keep the evidence ready.
This page answers:
At a glance
- Program rule: 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program, effective December 16, 2024
- Contract clause: DFARS 252.204-7021, added by a final rule effective November 10, 2025, the start of Phase 1
- Who it applies to: DoD contractors and subcontractors at all tiers that process, store or transmit FCI or CUI on their own information systems
- Levels: Level 1 (15 FAR 52.204-21 requirements), Level 2 (the 110 requirements in NIST SP 800-171 Rev. 2) and Level 3 (24 selected NIST SP 800-172 requirements)
- Current status: Phase 1. On July 13, 2026, DoD suspended the Phase 2 transition that had been scheduled for November 10, 2026, and put all later CMMC implementation milestones on hold until further notice. During the suspension, DoD program offices may designate only Level 1 (Self) or Level 2 (Self), and existing Level 2 (C3PAO) or Level 3 requirements are being removed from solicitations and contracts.
- Official source: DoW CIO CMMC program pages and 32 CFR Part 170 on eCFR
- Last reviewed: September 30, 2026
What is CMMC?
CMMC is the Department of Defense program for verifying that defense contractors protect the contract information they hold. DoD’s program pages now also use the name Department of War. The program rule, 32 CFR Part 170, took effect December 16, 2024. It establishes “requirements for defense contractors and subcontractors to implement prescribed cybersecurity standards” for that information (32 CFR 170.1).
The rule itself does not put CMMC into your contract. That happens through the DFARS clause at 252.204-7021, added by a separate acquisition final rule published September 10, 2025 and effective November 10, 2025. When your contract includes that clause, you must “have and maintain for the duration of the contract a current CMMC status” at the level the contracting officer fills in, for every information system that processes, stores or transmits FCI or CUI in performance of the contract.
CMMC protects two kinds of information:
- Federal Contract Information (FCI): information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government. It does not include information the Government makes public or simple transactional information, such as information needed to process payments.
- Controlled Unclassified Information (CUI): information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation or Governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls (32 CFR 2002.4(h)).
What does CMMC cover, and what doesn’t it?
It covers:
- Your own information systems that process, store or transmit FCI or CUI in performance of a DoD contract or subcontract, and the assets that protect them.
- The level your contract requires, how that level is assessed, how often, and the annual affirmation of continuing compliance by a senior official of your company.
It does not:
- Apply to Federal information systems that contractors operate on behalf of the Government (32 CFR 170.3(b)).
- Apply to contracts solely for commercially available off-the-shelf (COTS) items, or to contracts at or below the micro-purchase threshold (32 CFR 170.3(c)).
- Replace DFARS 252.204-7012. Your duties to safeguard covered defense information, implement NIST SP 800-171 and report cyber incidents within 72 hours continue under that clause.
- Make any provider, tool or consultant responsible for your status. The company being assessed specifies its scope, and its own senior official affirms compliance.
Does CMMC apply to you?
CMMC applies to “all DoD contract and subcontract awardees that will process, store, or transmit information, in performance of the DoD contract, that meets the standards for FCI or CUI on contractor information systems” (32 CFR 170.3(a)(1)). DoD program managers or requiring activities select the level for each contract based on the type of information involved (32 CFR 170.3(d)).
It flows down. Prime contractors must comply and must require subcontractors to comply “throughout the supply chain at all tiers” (32 CFR 170.23(a)). The minimum level for a subcontractor depends on what it handles:
- A subcontractor that handles only FCI needs Level 1 (Self).
- A subcontractor that handles CUI needs at least Level 2 (Self).
- If the prime contract requires Level 2 (C3PAO) or Level 3 (DIBCAC), a subcontractor that handles CUI needs at least Level 2 (C3PAO).
The DFARS clause also requires the contractor to flow the correct CMMC level down to subcontracts, including those for commercial products and services, and to make sure the subcontractor has a current CMMC status before award (DFARS 252.204-7021(d) and (f)).
Quick check: does CMMC apply to you?
- You hold a DoD contract or a subcontract under one, or you are bidding on one.
- You receive, create or store FCI or CUI on your own computers, email, file storage or other systems while doing that work.
If both are true, check each solicitation and subcontract for a CMMC requirement (DFARS 252.204-7021) and for DFARS 252.204-7012, 7019 and 7020, which can apply even where CMMC does not. There is nothing Texas-specific in the federal rule; suppliers meet the same requirements in every state.
What do you need to have in place?
What each level requires
| Level 1 (Self) | Level 2 (Self) | Level 2 (C3PAO) | Level 3 (DIBCAC) | |
|---|---|---|---|---|
| Information | FCI | CUI | CUI | CUI |
| Requirements | 15 requirements in FAR 52.204-21(b)(1) | 110 requirements in NIST SP 800-171 Rev. 2 | 110 requirements in NIST SP 800-171 Rev. 2 | 24 selected NIST SP 800-172 requirements, plus a Final Level 2 (C3PAO) status first |
| Who assesses | Your company | Your company | An authorized or accredited CMMC Third-Party Assessment Organization (C3PAO) | DCMA’s Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) |
| How often | Every year | Every three years | Every three years | Every three years, with a new Level 2 (C3PAO) assessment |
| Plan of action (POA&M) | Not permitted | Permitted within limits; close out within 180 days | Permitted within limits; close out within 180 days | Permitted within limits; close out within 180 days |
| Affirmation by your senior official | After each assessment and every year | After each assessment, after POA&M closeout and every year | After each assessment, after POA&M closeout and every year | After each assessment, after POA&M closeout and every year |
| Where results go | SPRS | SPRS | C3PAO enters results in CMMC eMASS, which transmits them to SPRS | DIBCAC enters results in CMMC eMASS, which transmits them to SPRS |
| During the current suspension | May be required | May be required | May not be designated | May not be designated |
Self-assessment or third-party assessment?
- Self-assessment. Your company evaluates its own systems against the requirements, scores the result and posts it in the Supplier Performance Risk System (SPRS). Level 1 is scored MET or NOT MET in full. Level 2 uses the CMMC scoring methodology.
- Certification assessment. An outside assessor evaluates your systems. For Level 2 (C3PAO), your company must obtain the assessment from an authorized or accredited C3PAO. For Level 3, DIBCAC performs it on DoD’s behalf.
Either way, DoD may conduct a DIBCAC assessment of your company under DFARS 252.204-7020. If that assessment finds the requirements were not achieved or maintained, its results take precedence over your earlier status (32 CFR 170.16(a)(1)(iv) and 170.17(a)(1)(iv)).
How is Level 2 scored?
The maximum Level 2 score equals the total number of Level 2 requirements, which is 110. Each requirement NOT MET subtracts its assigned value (for example, 1, 3 or 5 points), and the result can be negative (32 CFR 170.24(c)(2)). This follows the same approach as the NIST SP 800-171 DoD Assessment Methodology referenced in DFARS 252.204-7019 and 7020, where a summary score is posted as, for example, “95 out of 110.”
Final status requires a MET result for every requirement in scope. Conditional status is allowed only when all of these are true (32 CFR 170.21(a)(2)):
- Your score divided by the total number of Level 2 requirements is at least 0.8, which is 88 of 110.
- No requirement on your POA&M is worth more than 1 point, except that CUI encryption (SC.L2-3.13.11), worth 3 points in that case, may be included if you use encryption that is not FIPS-validated.
- Your POA&M does not include any of six named requirements, including your system security plan (3.12.4) and several physical access and external connection requirements.
You then have 180 days from your Conditional status date to fix the open items and pass a POA&M closeout assessment. If you don’t, the Conditional status expires.
Which NIST SP 800-171 revision does Level 2 use?
Revision 2. The rule states: “The security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2” (32 CFR 170.14(c)(3)). NIST published Revision 3 in May 2024, and it supersedes Revision 2 on NIST’s site. CMMC Level 2 still uses Revision 2 until DoD changes the rule. DFARS 252.204-7012 as codified refers to the version of NIST SP 800-171 “in effect at the time the solicitation is issued.” DoD Class Deviation 2024-O0013 (Rev. 1, May 22, 2024) pinned the clause to Revision 2, and the September 3, 2026 DFARS Part 240 deviation text of the clause also names Revision 2. DoD’s July 13, 2026 guidance also states that during the suspension it will enforce “baseline compliance with NIST SP 800-171 Rev 2.”
When does CMMC show up in your contracts?
32 CFR 170.3(e) sets out four phases, each starting one calendar year after the one before it:
| Phase | Start | What the rule says | Status on September 30, 2026 |
|---|---|---|---|
| Phase 1 | November 10, 2025, the effective date of the DFARS clause rule | Level 1 (Self) or Level 2 (Self) as a condition of award; Level 2 (C3PAO) at DoD’s discretion | In effect |
| Phase 2 | Scheduled for November 10, 2026 | Adds Level 2 (C3PAO) as a condition of award for applicable contracts; Level 3 at DoD’s discretion | Suspended July 13, 2026 |
| Phase 3 | One calendar year after Phase 2 (November 10, 2027, calculated from 32 CFR 170.3(e); no DoD page states this date) | Level 2 (C3PAO) for all applicable contracts and option periods; Level 3 for all applicable contracts | On hold: DoD has held all pending and future CMMC implementation milestones in abeyance until further notice |
| Phase 4 | One calendar year after Phase 3 (November 10, 2028, calculated from 32 CFR 170.3(e); the DFARS clause prescription at 204.7504(a) uses the same date | Full implementation in all applicable solicitations and contracts, including option periods on older contracts | On hold: held in abeyance until further notice |
The implementing memorandum from the Under Secretary of War for Acquisition and Sustainment directs that active solicitations with Level 2 (C3PAO) or Level 3 (DIBCAC) requirements be amended to remove them, and that existing contracts be modified to remove them before the next option period or at the next scheduled administrative modification. DoD has established a CMMC Reform Task Force for a 60-day review and says further guidance will follow. On September 3, 2026, DoD’s acquisition policy office issued a class deviation directing contracting officers to remove or revise CMMC requirements in line with the suspension. As of September 30, 2026, DoD had not published the review’s results or any change to the suspension. Check each solicitation and contract for the level it actually requires.
How can ALCON DTS help you?
You keep the compliance decisions. We can run the controls. CMMC puts specific decisions and signatures on your company, and those stay with you. ALCON DTS can run the identity, device, email, logging and backup controls your assessment will look at, keep the written procedures current, and sit with you when an assessor asks how the systems are operated.
What you own and what ALCON DTS can run
| Your company owns | ALCON DTS can run and support |
|---|---|
| Scoping decisions: which systems, people and locations handle FCI or CUI (32 CFR 170.19) | The technical controls on the systems in scope |
| The system security plan: its content and approval | Documentation support: written procedures that describe how the environment actually runs, who approves changes and how the system list stays current |
| The plan of action (POA&M) and its closeout decisions | A work plan for closing gaps, and the technical work to close them |
| SPRS entries: scores, scope and CAGE codes | Evidence collection from the live environment: what is logged, what is backed up, who can restore |
| Affirmations by your Affirming Official, the senior level representative from within your company (32 CFR 170.22) | Status on the controls so your official can affirm with a clear picture |
| Contracting with a C3PAO and the assessment itself, when your contract requires one | Sitting with you during the assessment when the assessor asks how systems are operated |
Element to what ALCON DTS provides
| CMMC element | What ALCON DTS provides |
|---|---|
| Access control and identification (who can sign in and what they can reach) | Identity and access with multifactor authentication and least-privilege administrator roles, plus joiner, mover and leaver changes kept current so unused access does not sit open |
| Guest and vendor access | Guest and vendor accounts reviewed as part of the same identity picture when they can reach business information |
| Device protection | Devices used for work kept updated, protected and encrypted, with a named owner for any lost or unmanaged device |
| Email threats | Inbound filtering, email authentication, mailbox permissions and forwarding kept current |
| Audit logging and monitoring | Logging and monitoring across identity, mail, devices and backup jobs, with alerts routed to a named owner who can act |
| Recovery | Tested backup and recovery, so a restore is something that has been done |
| Shop floor and production systems | Production and shop floor systems kept segmented from office IT when they are part of your environment |
| Program structure and gap planning | A walk through your program using the NIST Cybersecurity Framework, with gaps turned into a work plan on Secure IT or a defined project |
| Written procedures and evidence | Procedures that match the live environment, so the controls you run become the evidence the assessor walks through |
The exact controls in your environment depend on your ALCON DTS plan and any project work. We will show you which are in place today and which would close a gap. ALCON DTS does not perform CMMC assessments and does not issue or hold any CMMC status for you.
Your managed IT provider may be in your assessment scope
32 CFR Part 170 treats an outside IT or security provider as an External Service Provider (ESP) when CUI or Security Protection Data, such as log data, configuration data or passwords that grant access to the in-scope environment, is processed, stored or transmitted on the provider’s assets. When that applies:
- A provider that is not a cloud service provider and handles CUI: its services are in your assessment scope and are assessed against all Level 2 requirements.
- A provider that handles Security Protection Data but not CUI: its services are in your assessment scope and are assessed as Security Protection Assets.
- A cloud service provider that stores, processes or transmits CUI must meet the FedRAMP requirements in DFARS 252.204-7012, which call for security equivalent to the FedRAMP Moderate baseline.
In each case, the rule expects the relationship and the services to be documented in your system security plan, and an in-scope provider’s services to be described in a service description and customer responsibility matrix. A provider that does not process, store or transmit CUI or Security Protection Data on its own assets is not an ESP under the rule. If ALCON DTS processes, stores or transmits Security Protection Data for your in-scope systems (for example, logs, configuration data or administrator credentials) or CUI on ALCON DTS assets, plan for those ALCON DTS services to be in your assessment scope.
Want to know where your CMMC program stands? We will look at which systems handle FCI or CUI, what is already in place, and what would close the gaps for the level in your contract.
How does CMMC fit with other rules?
- DFARS 252.204-7012, 7019 and 7020. These clauses existed before CMMC and remain in effect in contracts that include them. DFARS 252.204-7012 requires NIST SP 800-171 on covered contractor information systems, security equivalent to the FedRAMP Moderate baseline for cloud providers that handle covered defense information, and reporting of cyber incidents within 72 hours of discovery. DFARS 252.204-7019 requires a current NIST SP 800-171 DoD Assessment, not more than 3 years old unless the solicitation says otherwise, with summary scores posted in SPRS. DFARS 252.204-7020 describes Basic (self), Medium and High (Government) assessments.
- Texas Cybersecurity Safe Harbor (SB 2610, Bus. and Com. Code Ch. 542). Texas businesses with fewer than 250 employees that own or license computerized sensitive personal information may avoid exemplary damages in a breach lawsuit if they show they implemented and maintained a qualifying cybersecurity program at the time of the breach. What qualifies depends on company size (Sec. 542.004(a)(4)). For businesses that must conform to a framework, the law lists “a current version” of several, including NIST special publication 800-171 (Sec. 542.004(b)(1)(B)). CMMC Level 2 is tied to NIST SP 800-171 Revision 2, while NIST’s current version is Revision 3, so talk with counsel about whether a CMMC program also meets the Texas standard for the personal information you hold. The two are separate: CMMC is a federal contract requirement, and the safe harbor is a Texas defense decided in court. See Texas SB 2610 Cybersecurity Safe Harbor.
- NIST Cybersecurity Framework. NIST has published a mapping from Cybersecurity Framework v1.0 to NIST SP 800-171 Rev. 2. Many organizations use the Framework to explain their program to leadership and NIST SP 800-171 for the CUI requirements. Using the Framework does not satisfy CMMC on its own.
- HIPAA. If you also handle patient information, for example as a medical device or health services supplier, you may run HIPAA and CMMC programs side by side. Controls such as multifactor authentication, encrypted devices, logging and tested backups can serve both, but each program has its own scope, requirements and documentation, and meeting one does not establish the other.
Frequently asked questions
Is CMMC in effect now?
Which level do you need?
Do you need a third-party CMMC assessment right now?
Does CMMC Level 2 use NIST SP 800-171 Revision 3?
What score do you need in SPRS?
Who signs the annual affirmation?
Can a managed IT provider make you CMMC compliant?
Does the Phase 2 suspension mean you can pause your security program?
Sources
- 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program (eCFR)
- Cybersecurity Maturity Model Certification (CMMC) Program, final rule, 89 FR 83092, October 15, 2024, effective December 16, 2024 (Federal Register)
- DFARS: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041), final rule, 90 FR 43560, September 10, 2025, effective November 10, 2025 (Federal Register)
- DoW CIO, Cybersecurity Maturity Model Certification and About CMMC (DoW Chief Information Officer)
- DoW Chief Information Officer, Removing Barriers to Defense Industrial Base Expansion: Immediate Suspension and Strategic Review of CMMC Requirements, July 13, 2026 (memorandum signed by Kirsten A. Davies)
- Under Secretary of War for Acquisition and Sustainment, Implementing Department of War Chief Information Officer’s Suspension of the Advancement to CMMC Phase 2 Requirements, July 13, 2026 (memorandum signed by Michael P. Duffey)
- DPCAP, Class Deviation 2026-O0025, Revision 3, RFO Part 40 / DFARS Part 240, September 3, 2026 (signed by John M. Tenaglia, Principal Director, Defense Pricing, Contracting, and Acquisition Policy)
- Department of War, Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements, July 13, 2026 (press release)
- DoD Class Deviation 2024-O0013, Revision 1, May 22, 2024 (Defense Pricing and Contracting)
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (eCFR; also published on Acquisition.gov)
- DFARS 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements (eCFR; also published on Acquisition.gov)
- DFARS 252.204-7020, NIST SP 800-171 DoD Assessment Requirements (eCFR; also published on Acquisition.gov)
- NIST SP 800-171 Rev. 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (NIST)
- NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (NIST)
- Texas Business and Commerce Code, Chapter 542, Cybersecurity Program (Texas Constitution and Statutes)
Last reviewed: September 30, 2026
This page is general information about the CMMC program and related rules as of September 30, 2026, not legal or contracting advice; confirm your requirements with your contracting officer and your own counsel.
Talk with ALCON DTS about your CMMC program
Not sure which systems handle FCI or CUI, or whether your controls match the level in your next contract? We will walk through your environment with you, show you what is already in place and give you a clear plan for the rest.
Email: info@alcondts.com ยท Phone: 512-892-6900

