Cybersecurity Maturity Model Certification (CMMC)
The Cybersecurity Maturity Model Certification (CMMC) is the DoD program verifying that contractors protect federal contract information and CUI. Its three levels map to FAR 52.204-21, NIST SP 800-171, and NIST SP 800-172; contract requirements took effect November 10, 2025, currently held at self-assessment Phase 1.
The program rule at 32 CFR Part 170, effective December 16, 2024, defines three levels. Level 1 is an annual self-assessment against the 15 basic safeguards of FAR 52.204-21, for federal contract information. Level 2 covers the 110 requirements of NIST SP 800-171 Revision 2 — self-assessed or certified by a third-party assessor (C3PAO) every three years — for CUI. Level 3 adds 24 enhanced requirements from NIST SP 800-172, assessed by DIBCAC after Level 2 certification.
The contract mechanics arrived in the DFARS final rule effective November 10, 2025: provision 252.204-7025 states the required level, and clause 252.204-7021 makes a current CMMC status in SPRS, plus an annual affirmation of continuous compliance, a condition of award. In July 2026 the department suspended the transition to Phase 2 — the move to required third-party certification — holding the program at Phase 1 self-assessments pending review.
The affirmation is the trap. It is a standing representation, renewed annually in SPRS, that every requirement remains implemented; the suspension changed who assesses, not what applies. The clause flows down to subcontractors handling FCI or CUI, COTS-only sellers excepted.
Regulatory Reference
32 CFR Part 170; DFARS Subpart 204.75; DFARS 252.204-7021; DFARS 252.204-7025
RFO Status
CMMC lives in 32 CFR Part 170 and the DFARS rather than the FAR, so the overhaul does not rewrite it; the July 2026 Phase 2 suspension is a separate DoD program review, and the proposed FAR Part 40 CUI framework would sit alongside CMMC, not replace it.
Category
Programs & Pathways
How AcqBot Helps
AcqBot identifies the CMMC level a requirement should carry under the current phase, drafts the 252.204-7025 fill-in, and checks an apparent awardee's SPRS status and affirmation before award — the eligibility check that otherwise surfaces as a post-award problem.
Related glossary entries
SBIR/STTR (Small Business Innovation Research)
SBIR and STTR are congressionally mandated programs requiring federal agencies with large R&D budgets to fund small business innovation through phased awards — feasibility (Phase I), development (Phase II), and commercialization (Phase III), which carries sole-source follow-on authority.
8(a) Business Development Program
The 8(a) Business Development Program, authorized by Section 8(a) of the Small Business Act, gives SBA-certified firms owned by socially and economically disadvantaged individuals a nine-year term of access to sole-source and competitive set-aside federal contracts under 13 CFR Part 124.
HUBZone Program
The HUBZone program, created by the HUBZone Act of 1997 and run by SBA, steers federal contracts to small businesses that keep their principal office in a historically underutilized business zone and draw at least 35 percent of employees from HUBZone residents.
Women-Owned Small Business Program (WOSB/EDWOSB)
The Women-Owned Small Business (WOSB) program, created by section 8(m) of the Small Business Act, lets contracting officers set aside contracts, and make limited sole-source awards, to SBA-certified women-owned small businesses in NAICS codes where SBA finds women-owned firms underrepresented.